Skip to content

A list of malicious IP addresses associated with botnets, cyberattacks, and the generation of artificial traffic on websites. Useful for network administrators and security companies to block threats and protect against DDoS attacks.

License

Notifications You must be signed in to change notification settings

sefinek/Malicious-IP-Addresses

Repository files navigation

🤬 Malicious IP Address List

This repository contains a list of IP addresses associated with various malicious activities on the internet. Many of them belong to botnets or VPN/proxy networks used to carry out attacks, including DDoS and other forms of abuse. If you find this repository helpful, consider leaving a star. Thank you, have a nice day!

🌍 A trustworthy whitelist of known bot IP addresses is available at sefinek/known-bots-ip-whitelist.
📑 For solid and effective Cloudflare WAF rules, check out sefinek/Cloudflare-WAF-Expressions.

Tip

Looking for a better alternative? Visit sniffcat.com — a new and efficient alternative to AbuseIPDB. The service provides detailed reports on malicious IP addresses and offers filtering by confidence score, countries, categories, and IP version. Data can be downloaded in JSON or TXT format and is regularly updated based on submissions from our users. Results are generated automatically and available completely free of charge!
You can find the documentation here.

Do you have any questions or need assistance? Create a new issue or join my Discord server. I also post important updates and announcements there. My email address: [email protected] 😉

What can this list block?

  1. ✅ DDoS attacks (L7 – HTTP flood)
    • HTTP requests originating from known botnets
    • Traffic with unusual HTTP headers or suspicious endpoints
    • Connections from sources with confirmed malicious activity
    • Requests impersonating real browsers
  2. ✅ Malicious bots and crawlers
  3. ✅ Bots generating artificial views
    (especially useful if you use Google AdSense)
  4. ✅ Malicious VPNs and proxies used for abuse

Important

Blocking IP addresses should be done carefully to avoid restricting legitimate traffic.
Regular updates of the list are recommended.

Cron

Updates usually occur every 2 hours, but sometimes a delay of several days may occur. If you notice a longer lack of updates, you can report it via an issue. The list is actively maintained and will not be abandoned.

Available files

📄 TXT (recommended)

https://raw.githubusercontent.com/sefinek/Malicious-IP-Addresses/main/lists/main.txt

curl

curl -fsS -o blacklist.txt https://raw.githubusercontent.com/sefinek/Malicious-IP-Addresses/main/lists/main.txt

wget

wget -nv -O blacklist.txt https://raw.githubusercontent.com/sefinek/Malicious-IP-Addresses/main/lists/main.txt

📊 CSV

https://raw.githubusercontent.com/sefinek/Malicious-IP-Addresses/main/lists/details.csv

Important

This file contains user agents, endpoints, and IP addresses that have been blacklisted. Not all IP addresses from main.txt are included in details.csv!

curl

curl -fsS -o blacklist.csv https://raw.githubusercontent.com/sefinek/Malicious-IP-Addresses/main/lists/details.csv

wget

wget -nv -O blacklist.csv https://raw.githubusercontent.com/sefinek/Malicious-IP-Addresses/main/lists/details.csv

MIT License

Copyright © 2024–2025 Sefinek

About

A list of malicious IP addresses associated with botnets, cyberattacks, and the generation of artificial traffic on websites. Useful for network administrators and security companies to block threats and protect against DDoS attacks.

Topics

Resources

License

Stars

Watchers

Forks

Contributors 2

  •  
  •