Threat statistics

How many malicious IP addresses our honeypots and spam traps log, day by day and month by month, plus the addresses that keep coming back. Counters are refreshed every hour.

21,272
Detections today (4,194 new IPs)
311,535
Detections in the last 7 days
499,467
Detections in the last 15 days
1,310,979
Detections in the last 30 days

Detections over time

"New" was seen for the first time; "updated" is a known address seen again.

Last 30 days

IPv4 addresses per day (1,310,979 in total)

Last 12 months

IPv4 detections per month (23,329,405 in total)

IPv6, last 30 days

IPv6 addresses per day (16,330 in total)

Most detected

The addresses with the highest number of attack days on record, refreshed hourly.

#IP addressCategoryFirst seenLast seenActive forAttack days
1 66.240.205.34 Unclassified 2017-05-03 2026-10-03 3,439 days 3,060
2 93.174.95.106 Socks Scan 2017-04-04 2026-10-02 3,467 days 2,986
3 71.6.146.185 Imap 2017-01-20 2026-10-03 3,542 days 2,868
4 71.6.146.186 Imap 2016-11-23 2026-10-02 3,600 days 2,821
5 94.102.49.193 Imap 2016-10-17 2026-10-03 3,638 days 2,804
6 66.240.192.138 Postfix 2016-11-04 2026-10-03 3,619 days 2,670
7 66.240.219.146 Imap 2016-12-17 2026-10-02 3,576 days 2,625
8 80.82.77.139 FTP 2017-03-27 2026-12-31 3,566 days 2,579
9 66.240.236.119 Postfix 2017-03-22 2026-12-31 3,571 days 2,577
10 71.6.167.142 Imap 2016-10-17 2026-10-02 3,637 days 2,577

Where the attacks come from

Countries and ASNs with the most attacking IPv4 addresses (last 30 days).

#CountryIPs
1🇨🇳 CN84,060
2🇺🇸 US81,191
3🇧🇷 BR39,470
4🇦🇷 AR22,414
5🇷🇺 RU22,354
6🇮🇳 IN16,084
7🇺🇦 UA14,684
8🇵🇰 PK13,040
9🇮🇩 ID11,906
10🇲🇽 MX11,891
#ASNOrgIPs
1AS14061DigitalOcean, LLC54,047
2AS4837CHINA UNICOM China169 Ba…34,356
3AS4134No.31,Jin-rong Street32,424
4AS9808China Mobile Communicati…9,770
5AS12389PJSC "Rostelecom". Techn…7,775
6AS396982Google LLC7,540
7AS8075Microsoft Corporation7,061
8AS8151Uninet S.A. de C.V.5,750
9AS174Cogent Communications, L…5,723
10AS7713PT Telekomunikasi Indone…5,549

Attack categories we track

Each detection is classified by the honeypot service that was hit.

  • Comment Spam
  • SSH Brute Force
  • Web Hacking
  • Postfix
  • Imap
  • FTP
  • Telnet
  • MySQL Attack
  • MS-SQL Attack
  • MS-DS Attack
  • VNC Attack
  • IRC Attack
  • Proxy Scan
  • Socks Scan
  • POP Attack
  • RpcBind Attack
  • Netbios Attack
  • RPC-WIN Attack
  • LDAP Attack
  • SMTP Attack
  • RDP Attack
  • POPS Attack
  • IMAP3 Attack
  • IIS Attack
  • X-Windows Attack
  • Mirai
  • SIP
  • Unclassified

Put the blocklist to work

Hourly CSV feeds of the IPs attacking our honeypots, ready for firewalls, fraud models and threat-intel platforms.