{
  "generated_at": "2026-09-13T11:21:16Z",
  "database_file": "threat-intel.mmdb",
  "database_bytes": 72491456,
  "source_entries": 2805818,
  "source_addresses": 18866307,
  "excluded_networks": 1,
  "sources": [
    {
      "name": "TOR",
      "url": "https://check.torproject.org/torbulkexitlist",
      "description": "Public Tor exit relays used to reach the open internet.",
      "reason": "Classified by its Tor role; this does not by itself indicate abuse.",
      "fetched_at": "2026-09-13T11:21:16Z",
      "networks": 1327,
      "addresses": 1327
    },
    {
      "name": "ABUSEIPDB_1D",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/abuseipdb_1d.ipset",
      "description": "IPs with recent abuse reports collected by AbuseIPDB over the last day.",
      "reason": "Reported for suspicious or harmful activity; the short window reduces stale entries.",
      "fetched_at": "2026-09-13T11:21:16Z",
      "source_updated_at": "Sat Sep 12 11:57:42 UTC 2026",
      "networks": 51978,
      "addresses": 51978
    },
    {
      "name": "DE_BOTS",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/blocklist_de_bots.ipset",
      "description": "Addresses observed by Blocklist.de performing automated bot attacks.",
      "reason": "Included after an automated attack was reported against a monitored service.",
      "fetched_at": "2026-09-13T11:21:17Z",
      "source_updated_at": "Sun Sep 13 06:48:09 UTC 2026",
      "networks": 2401,
      "addresses": 2401
    },
    {
      "name": "DE_BRUTEFORCE",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/blocklist_de_bruteforce.ipset",
      "description": "Addresses associated with repeated brute-force access attempts.",
      "reason": "Observed repeatedly guessing credentials or attempting unauthorized login.",
      "fetched_at": "2026-09-13T11:21:18Z",
      "source_updated_at": "Sun Sep 13 06:48:11 UTC 2026",
      "networks": 863,
      "addresses": 863
    },
    {
      "name": "FEODO",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/feodo.ipset",
      "description": "Command-and-control infrastructure for tracked banking trojans and botnets.",
      "reason": "Identified by abuse.ch Feodo Tracker as active or recent C2 infrastructure.",
      "fetched_at": "2026-09-13T11:21:18Z",
      "source_updated_at": "Thu Mar 12 07:15:03 UTC 2026",
      "networks": 1,
      "addresses": 1
    },
    {
      "name": "SPAMHAUS_DROP",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/spamhaus_drop.netset",
      "description": "Network ranges associated with spam and professional cybercrime operations.",
      "reason": "Spamhaus recommends dropping all traffic to and from these ranges.",
      "fetched_at": "2026-09-13T11:21:18Z",
      "source_updated_at": "Fri Sep 11 14:37:26 UTC 2026",
      "networks": 1621,
      "addresses": 14861312
    },
    {
      "name": "SPAMHAUS_EDROP",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/spamhaus_edrop.netset",
      "description": "Extended DROP ranges covering smaller high-risk network allocations.",
      "reason": "Included as a DROP extension due to links with malicious operations.",
      "fetched_at": "2026-09-13T11:21:18Z",
      "source_updated_at": "Tue Apr  9 07:29:05 UTC 2024",
      "networks": 336,
      "addresses": 731392
    },
    {
      "name": "ANONYMIZER",
      "url": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_anonymous.netset",
      "description": "VPN, proxy, Tor, and other publicly known anonymizer exit addresses.",
      "reason": "Indicates hidden or shared traffic origin; this alone does not indicate abuse.",
      "fetched_at": "2026-09-13T11:21:18Z",
      "source_updated_at": "Sun Sep 13 07:31:19 UTC 2026",
      "networks": 2747291,
      "addresses": 3217033
    }
  ]
}
