IP Blocklist Subscriptions
This honeypot automatically reports malicious IPs to AbuseIPDB, Blocklist.de, SANS DShield and AlienVault OTX — every hour, 24/7. If you run your own server, you can use these same feeds to block the same attackers before they reach you.
⚡ Protect your server with the same stack
Copy-paste to install CrowdSec (blocks 60k+ IPs at firewall level) and add Blocklist.de to Pi-hole.
# 1. Install CrowdSec — community firewall that blocks 60k+ known attackers $ curl -s https://packagecloud.io/crowdsec/crowdsec/script.deb.sh | sudo bash $ sudo apt install crowdsec crowdsec-firewall-bouncer-iptables $ sudo cscli hub update && sudo cscli collections install crowdsecurity/linux # 2. Pi-hole — Admin → Adlists → paste all these URLs then run pihole -g https://lists.blocklist.de/lists/all.txt https://lists.blocklist.de/lists/ssh.txt https://lists.blocklist.de/lists/ftp.txt https://lists.blocklist.de/lists/smtp.txt https://raw.githubusercontent.com/nicehash/blocklist/main/README.md https://raw.githubusercontent.com/nicehash/blocklist/main/blocklist.txt https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/tif.mini.txt https://raw.githubusercontent.com/nicehash/blocklist/main/README.md https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareAdGuard.txt https://iplists.firehol.org/files/firehol_level1.netset https://www.spamhaus.org/drop/drop.txt https://www.spamhaus.org/drop/edrop.txt $ pihole -g # We use even more — see the full Recommended section below ↓
📤 Where we report
CONTRIBUTING LIVEOur honeypot actively feeds attack data to these 4 platforms every hour.
AbuseIPDB
● We report hereCommunity IP abuse database. Every attacker captured by this honeypot is automatically reported here within the hour.
Blocklist.de
● We report hereFail2ban-based community blocklist. We submit SSH, FTP and multi-protocol attackers caught by Cowrie and OpenCanary.
SANS DShield
● We report hereInternet Storm Center distributed sensor network. Our logs contribute to the global attack trend analysis published daily.
AlienVault OTX
● We report hereOpen Threat Exchange. We publish IoC pulses with attacker IPs, credentials and malware hashes captured by the honeypot.
📥 Recommended subscriptions
CURATEDWe don't contribute here, but these are the best feeds to protect your infrastructure.
CrowdSec CTI
The same engine protecting this honeypot. 16k+ malicious IPs pre-blocked via community intelligence. Free for self-hosted.
Spamhaus DROP / EDROP
Don't Route Or Peer. Hijacked IP blocks controlled by spam/malware gangs. One of the most reliable CIDR blocklists.
Firehol Level 1–3
Aggregation of the best public IP blacklists, sorted by severity. Level 1 = most aggressive bots and scanners.
Binary Defense Banlist
Artillery project threat intelligence. Updated every 30 minutes with actively attacking IPs. No registration needed.
📡 Subscribe to this blog
Get notified whenever a new daily report drops via RSS.
https://threats.evitalios.com/rss.xml