Threat statistics

How many malicious IP addresses our honeypots and spam traps log, day by day and month by month, plus the addresses that keep coming back. Counters are refreshed every hour.

63
Detections today (10 new IPs)
275,122
Detections in the last 7 days
518,120
Detections in the last 15 days
1,222,515
Detections in the last 30 days

Detections over time

"New" was seen for the first time; "updated" is a known address seen again.

Last 30 days

IPv4 addresses per day (1,222,515 in total)

Last 12 months

IPv4 detections per month (23,387,453 in total)

IPv6, last 30 days

IPv6 addresses per day (16,458 in total)

Most detected

The addresses with the highest number of attack days on record, refreshed hourly.

#IP addressCategoryFirst seenLast seenActive forAttack days
1 66.240.205.34 Unclassified 2017-05-03 2026-10-04 3,440 days 3,061
2 93.174.95.106 Socks Scan 2017-04-04 2026-10-04 3,469 days 2,988
3 71.6.146.185 Imap 2017-01-20 2026-10-04 3,544 days 2,869
4 71.6.146.186 Imap 2016-11-23 2026-10-04 3,602 days 2,822
5 94.102.49.193 Imap 2016-10-17 2026-10-04 3,639 days 2,805
6 66.240.192.138 Postfix 2016-11-04 2026-10-04 3,620 days 2,671
7 66.240.219.146 Imap 2016-12-17 2026-10-04 3,578 days 2,627
8 80.82.77.139 FTP 2017-03-27 2026-12-31 3,566 days 2,579
9 66.240.236.119 Postfix 2017-03-22 2026-12-31 3,571 days 2,577
10 71.6.167.142 Imap 2016-10-17 2026-10-02 3,637 days 2,577

Where the attacks come from

Countries and ASNs with the most attacking IPv4 addresses (last 30 days).

#CountryIPs
1🇨🇳 CN74,846
2🇺🇸 US65,011
3🇧🇷 BR34,440
4🇷🇺 RU20,339
5🇦🇷 AR20,321
6🇮🇳 IN14,414
7🇺🇦 UA13,652
8🇵🇰 PK12,097
9🇮🇩 ID10,651
10🇲🇽 MX10,421
#ASNOrgIPs
1AS14061DigitalOcean, LLC50,099
2AS4837CHINA UNICOM China169 Ba…31,070
3AS4134No.31,Jin-rong Street28,973
4AS9808China Mobile Communicati…8,710
5AS12389PJSC "Rostelecom". Techn…7,051
6AS396982Google LLC6,438
7AS8075Microsoft Corporation5,883
8AS8151Uninet S.A. de C.V.5,016
9AS7713PT Telekomunikasi Indone…4,983
10AS174Cogent Communications, L…4,920

Attack categories we track

Each detection is classified by the honeypot service that was hit.

  • Comment Spam
  • SSH Brute Force
  • Web Hacking
  • Postfix
  • Imap
  • FTP
  • Telnet
  • MySQL Attack
  • MS-SQL Attack
  • MS-DS Attack
  • VNC Attack
  • IRC Attack
  • Proxy Scan
  • Socks Scan
  • POP Attack
  • RpcBind Attack
  • Netbios Attack
  • RPC-WIN Attack
  • LDAP Attack
  • SMTP Attack
  • RDP Attack
  • POPS Attack
  • IMAP3 Attack
  • IIS Attack
  • X-Windows Attack
  • Mirai
  • SIP
  • Unclassified

Put the blocklist to work

Hourly CSV feeds of the IPs attacking our honeypots, ready for firewalls, fraud models and threat-intel platforms.