Threat statistics

How many malicious IP addresses our honeypots and spam traps log, day by day and month by month, plus the addresses that keep coming back. Counters are refreshed every hour.

8,254
Detections today (2,248 new IPs)
294,954
Detections in the last 7 days
510,775
Detections in the last 15 days
1,257,276
Detections in the last 30 days

Detections over time

"New" was seen for the first time; "updated" is a known address seen again.

Last 30 days

IPv4 addresses per day (1,257,276 in total)

Last 12 months

IPv4 detections per month (23,359,615 in total)

IPv6, last 30 days

IPv6 addresses per day (16,305 in total)

Most detected

The addresses with the highest number of attack days on record, refreshed hourly.

#IP addressCategoryFirst seenLast seenActive forAttack days
1 66.240.205.34 Unclassified 2017-05-03 2026-10-04 3,440 days 3,061
2 93.174.95.106 Socks Scan 2017-04-04 2026-10-03 3,468 days 2,987
3 71.6.146.185 Imap 2017-01-20 2026-10-03 3,542 days 2,868
4 71.6.146.186 Imap 2016-11-23 2026-10-02 3,600 days 2,821
5 94.102.49.193 Imap 2016-10-17 2026-10-03 3,638 days 2,804
6 66.240.192.138 Postfix 2016-11-04 2026-10-03 3,619 days 2,670
7 66.240.219.146 Imap 2016-12-17 2026-10-03 3,577 days 2,626
8 80.82.77.139 FTP 2017-03-27 2026-12-31 3,566 days 2,579
9 66.240.236.119 Postfix 2017-03-22 2026-12-31 3,571 days 2,577
10 71.6.167.142 Imap 2016-10-17 2026-10-02 3,637 days 2,577

Where the attacks come from

Countries and ASNs with the most attacking IPv4 addresses (last 30 days).

#CountryIPs
1🇨🇳 CN78,446
2🇺🇸 US67,669
3🇧🇷 BR36,646
4🇦🇷 AR21,294
5🇷🇺 RU21,197
6🇮🇳 IN14,985
7🇺🇦 UA14,130
8🇵🇰 PK12,539
9🇮🇩 ID11,216
10🇲🇽 MX11,046
#ASNOrgIPs
1AS14061DigitalOcean, LLC50,504
2AS4837CHINA UNICOM China169 Ba…32,545
3AS4134No.31,Jin-rong Street30,370
4AS9808China Mobile Communicati…9,166
5AS12389PJSC "Rostelecom". Techn…7,384
6AS396982Google LLC6,997
7AS8075Microsoft Corporation6,189
8AS8151Uninet S.A. de C.V.5,334
9AS7713PT Telekomunikasi Indone…5,251
10AS174Cogent Communications, L…5,240

Attack categories we track

Each detection is classified by the honeypot service that was hit.

  • Comment Spam
  • SSH Brute Force
  • Web Hacking
  • Postfix
  • Imap
  • FTP
  • Telnet
  • MySQL Attack
  • MS-SQL Attack
  • MS-DS Attack
  • VNC Attack
  • IRC Attack
  • Proxy Scan
  • Socks Scan
  • POP Attack
  • RpcBind Attack
  • Netbios Attack
  • RPC-WIN Attack
  • LDAP Attack
  • SMTP Attack
  • RDP Attack
  • POPS Attack
  • IMAP3 Attack
  • IIS Attack
  • X-Windows Attack
  • Mirai
  • SIP
  • Unclassified

Put the blocklist to work

Hourly CSV feeds of the IPs attacking our honeypots, ready for firewalls, fraud models and threat-intel platforms.