Attacker Dataset

Active attack infrastructure: sources of exploitation attempts, scanners and malicious campaigns.

8K Records
Daily Updates
CSV · MMDB Formats
IPv4 + IPv6 Coverage

The Attacker dataset is a tighter, higher-severity list than Abuser: addresses actively launching attacks such as vulnerability exploitation, aggressive scanning and malware distribution, curated from security intelligence feeds.

Its small size makes it cheap to deploy everywhere, including in-line at the edge where every microsecond counts.

The data

Inside the file

One record per row, a commented header line first. This is what ipregistry-attacker.csv looks like:

CSV ipregistry-attacker.csv 227 KB · 7,859 records · rebuilt daily
# ip_start,ip_end202.50.241.0,202.50.241.255203.7.199.0,203.7.199.25547.245.137.98,47.245.137.9865.87.7.173,65.87.7.17349.238.64.0,49.238.127.255
sha256 65c1e46ce3e2…f7688207737a Download free sample

The rows above come from the free sample. Every build ships with MD5, SHA-1, SHA-256 and SHA-512 checksums so you can verify downloads.

Column Description
ip_start First IP address of the range, IPv4 or IPv6.
ip_end Last IP address of the range, inclusive.

The MMDB variant carries the same data in a memory-mapped binary tree, compatible with the standard MMDB reader libraries available for every major programming language.

Downloads

Available formats

Format Description Size
CSV Plain text, one range per line. Import into any database or data warehouse. 227 KB
CSV (zipped) Same file compressed for faster downloads and cheaper storage. 53.3 KB
MMDB Binary format for instant lookups with standard MMDB readers. 515 KB

Use cases

What you can build

Related use case: Cyber security

Datasets are available with an Ipregistry subscription and download from your dashboard, or over a stable URL for automated syncs. Prefer live data? The same intelligence is served by the Ipregistry API.