IP Reputation Tracker

Real-time IP threat intelligence. Automated detection, aggregation and reporting of malicious IP activity across monitored infrastructure.

24,514Tracked IPs
179,945Threat Reports

Worst Offenders β€” Last 3 Days

# IP Threat Level Reports Type Country Org Last Seen
6001 91.231.89.1 60 2 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 15:34
6002 195.184.76.217 60 4 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 15:32
6003 20.163.33.22 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (westus3) 19 Jun 2026 - 15:32
6004 91.196.152.183 60 2 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 15:30
6005 91.231.89.143 60 2 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 15:28
6006 195.184.76.135 60 2 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 15:27
6007 91.230.168.23 60 2 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 15:27
6008 91.196.152.39 60 2 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 15:25
6009 20.106.57.131 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (centralus) 19 Jun 2026 - 15:25
6010 20.106.195.24 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (eastus) 19 Jun 2026 - 15:18
6011 20.150.196.142 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (westus3) 19 Jun 2026 - 15:18
6012 195.184.76.39 60 2 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 15:13
6013 20.102.108.84 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (eastus) 19 Jun 2026 - 15:13
6014 65.49.20.99 60 2 πŸ‡ΊπŸ‡Έ United States The Shadow Server Foundation 19 Jun 2026 - 15:00
6015 65.49.20.67 60 2 πŸ‡ΊπŸ‡Έ United States The Shadow Server Foundation 19 Jun 2026 - 15:00
6016 13.89.125.255 60 1 πŸ‡ΊπŸ‡Έ United States Microsoft Azure Cloud (centralus) 19 Jun 2026 - 14:59
6017 195.184.76.223 60 4 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 14:59
6018 91.230.168.7 60 2 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 14:53
6019 91.231.89.119 60 2 πŸ‡«πŸ‡· France ONYPHE 19 Jun 2026 - 14:45
6020 195.184.76.119 60 2 πŸ‡ΊπŸ‡Έ United States ONYPHE 19 Jun 2026 - 14:43

About

UnwantedIP aggregates block events from multiple servers running the EagleEye security stack β€” WordPress firewalls, SSH honeypots, and web application scanners. Each detected attack is enriched with reverse DNS, geolocation, and ASN data and stored as a permanent threat record.

A REST API allows external sources to query IP reputation data and submit new threat reports. Search any IP address using the URL pattern /ip/x.x.x.x.