https://github.com/ddrimus/http-threat-blocklist
A daily-updated blocklist of IP addresses involved in malicious HTTP attacks that bypassed multiple security layers. Ideal for protecting web servers against probing, exploits, and bot traffic.
https://github.com/ddrimus/http-threat-blocklist
blocklist cybersecurity firewall malware security threat-intelligence
Last synced: 5 months ago
JSON representation
A daily-updated blocklist of IP addresses involved in malicious HTTP attacks that bypassed multiple security layers. Ideal for protecting web servers against probing, exploits, and bot traffic.
- Host: GitHub
- URL: https://github.com/ddrimus/http-threat-blocklist
- Owner: ddrimus
- License: mit
- Created: 2025-06-23T10:15:14.000Z (about 1 year ago)
- Default Branch: main
- Last Pushed: 2026-01-26T02:00:42.000Z (5 months ago)
- Last Synced: 2026-01-26T17:39:42.400Z (5 months ago)
- Topics: blocklist, cybersecurity, firewall, malware, security, threat-intelligence
- Homepage:
- Size: 259 KB
- Stars: 5
- Watchers: 0
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# HTTP Threat Blocklist
This repository provides a **daily-updated blocklist** of IP addresses involved in malicious HTTP attacks targeting servers. Designed to protect both your systems and mine, the blocklist defends against common HTTP-based threats, including **probing**, **exploit attempts**, and **malicious bots**.
[](.)
[](.)
[](.)
## π About This List
This is my **private blocklist**, built from traffic that actually made it through multiple layers of defense β including **Cloudflare**, **CrowdSec**, and IP rate limits. I also block entire regions like **China** and **Russia**, so if something shows up here, it means it **slipped through all of that** and still tried something shady.
*In short: this list catches the ones that got further than they should have.*
## π Current Threat Status
```
+--------------------------------------+
| THREAT OVERVIEW |
+--------------------------------------+
| Status: HIGH |
| Active IPs: 333 |
| Total Reports: 11,199 |
| Unique Sources: 3,050 |
+--------------------------------------+
```
*Threat levels: significant malicious activity detected!*
## π― Attack Patterns
```
π₯ Most Common Attack Types
ββββββββββββββββββββββββββ
HTTP Probing β 3284 βββββββββββββββββββββββββββββββββββ ( 29.4%)
HTTP Bad User Agent β 2438 βββββββββββββββββββββββββ ( 21.9%)
HTTP Admin Interface Probing β 1264 βββββββββββββ ( 11.3%)
HTTP Sensitive Files β 1218 ββββββββββββ ( 10.9%)
HTTP Wordpress Scan β 747 βββββββ ( 6.7%)
HTTP Crawl Non Statics β 472 βββββ ( 4.2%)
HTTP Backdoors Attempts β 451 ββββ ( 4.0%)
CVE-2017-9841 Exploit β 415 ββββ ( 3.7%)
HTTP CVE Probing β 383 ββββ ( 3.4%)
CVE-2018-20062 (Thinkphp) β 142 β ( 1.3%)
CVE-2022-41082 Exploit β 114 β ( 1.0%)
Netgear RCE β 91 β ( 0.8%)
CVE-2021-26086 (Jira) β 51 β ( 0.5%)
HTTP Path Traversal Probing β 42 β ( 0.4%)
CVE-2019-18935 Exploit β 40 β ( 0.4%)
```
## π Geographic Distribution
```
πΊοΈ Top Source Countries
βββββββββββββββββββββββ
United States β 3449 βββββββββββββββββββββββββββββββββββ ( 35.9%)
United Kingdom β 1734 βββββββββββββββββ ( 18.0%)
Ireland β 1030 ββββββββββ ( 10.7%)
Netherlands β 726 βββββββ ( 7.5%)
Japan β 551 βββββ ( 5.7%)
France β 535 βββββ ( 5.6%)
Singapore β 526 βββββ ( 5.5%)
Germany β 385 βββ ( 4.0%)
Australia β 357 βββ ( 3.7%)
India β 327 βββ ( 3.4%)
```
## π Activity Timeline
```
π
Recent Activity (7 days)
ββββββββββββββββββββββββββ
2026-01-24 β 21 βββββββββββββββββ ( 9.3%)
2026-01-25 β 40 ββββββββββββββββββββββββββββββββββ ( 17.6%)
2026-01-26 β 41 βββββββββββββββββββββββββββββββββββ ( 18.1%)
2026-01-27 β 33 ββββββββββββββββββββββββββββ ( 14.5%)
2026-01-28 β 23 βββββββββββββββββββ ( 10.1%)
2026-01-29 β 31 ββββββββββββββββββββββββββ ( 13.7%)
2026-01-30 β 33 ββββββββββββββββββββββββββββ ( 14.5%)
2026-01-31 β 5 ββββ ( 2.2%)
```
## π Security Notes
- **False Positives**: This blocklist is generated from automated threat detection.
- **Legitimate Traffic**: Review before implementing in production environments.
- **Rate Limiting**: Consider implement rate limiting alongside IP blocking.
- **Monitoring**: Monitor your logs for blocked legitimate traffic.
## π€ Contributing
If you have any improvements, additional information, or notice any IPs that shouldn't be on the list, we'd love to hear from you! Feel free to open a pull request with your suggestions or details.
If you believe your IP has been mistakenly blocked and would like to request an unban, please provide all relevant information in an issue. I will review your case and address it promptly. Your contributions, suggestions, and feedback are always welcome and appreciated!