IP Reputation Tracker

Real-time IP threat intelligence. Automated detection, aggregation and reporting of malicious IP activity across monitored infrastructure.

24,398Tracked IPs
178,093Threat Reports

Worst Offenders β€” Last 3 Days

# IP Threat Level Reports Type Country Org Last Seen
5761 91.231.89.93 60 1 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 19:30
5762 66.132.195.153 60 1 πŸ‡ΊπŸ‡Έ United States Censys, Inc. 19 Jun 2026 - 19:30
5763 20.29.24.158 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (centralus) 19 Jun 2026 - 19:29
5764 69.5.169.205 60 3 πŸ‡©πŸ‡ͺ Germany Infrawatch Limited 19 Jun 2026 - 19:25
5765 64.62.156.79 60 1 πŸ‡ΊπŸ‡Έ United States The Shadow Server Foundation 19 Jun 2026 - 19:25
5766 65.49.20.98 60 1 πŸ‡ΊπŸ‡Έ United States The Shadow Server Foundation 19 Jun 2026 - 19:25
5767 135.237.125.196 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (eastus) 19 Jun 2026 - 19:25
5768 91.230.168.15 60 3 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 19:22
5769 20.65.194.87 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (southcentralus) 19 Jun 2026 - 19:19
5770 91.231.89.207 60 3 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 19:13
5771 195.184.76.23 60 3 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 19:11
5772 64.62.156.72 60 1 πŸ‡ΊπŸ‡Έ United States The Shadow Server Foundation 19 Jun 2026 - 19:09
5773 91.231.89.215 60 3 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 19:05
5774 91.231.89.133 60 3 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 19:03
5775 20.65.194.143 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (southcentralus) 19 Jun 2026 - 19:03
5776 91.196.152.223 60 3 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 19:00
5777 195.184.76.215 60 3 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 18:57
5778 195.184.76.71 60 3 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 18:57
5779 195.184.76.207 60 3 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 18:55
5780 91.231.89.111 60 3 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 18:55

About

UnwantedIP aggregates block events from multiple servers running the EagleEye security stack β€” WordPress firewalls, SSH honeypots, and web application scanners. Each detected attack is enriched with reverse DNS, geolocation, and ASN data and stored as a permanent threat record.

A REST API allows external sources to query IP reputation data and submit new threat reports. Search any IP address using the URL pattern /ip/x.x.x.x.