Dispatch

Plain IP blocklists

text/plain · one address per line Connecting

Shorter windows block aggressively with fewer stale entries; longer windows give broader coverage. Lists contain no reason codes, sensor names or log data — just addresses, one per line, ready to feed a firewall.

Feeds published3plain text, one address per line
Addresses listed5,416across all windows, with overlap
Downloads served2,868since records began
Latest signal16 minutes agocounts from this snapshot; files cached 2 min
Feed

10-day list

10d window
981addresses
98downloads

Active addresses observed within 10 days. Blocks aggressively with fewer stale entries.

Download
https://abuse.secureinsight.my/blocklists/10days.txt
Feed

15-day list

15d window
1,628addresses
62downloads

Active addresses observed within 15 days. A balance of coverage and freshness.

Download
https://abuse.secureinsight.my/blocklists/15days.txt
Feed

30-day list

30d window
2,807addresses
2,708downloads

Active addresses observed within 30 days. Broader coverage, more stale entries.

Download
https://abuse.secureinsight.my/blocklists/30days.txt
Integration

Automating updates

copy any snippet

Lists are regenerated continuously and cached for two minutes, so fetching more than once every few minutes returns the same bytes. Each response carries X-Abuse-Radar-Count and X-Abuse-Radar-Generated if you want to detect a change without diffing the body.

ipset / iptables

curl -fsS https://abuse.secureinsight.my/blocklists/10days.txt \
  | while read -r ip; do ipset add abuse-radar "$ip" -exist; done

nftables

nft add element inet filter abuse_radar \
  { $(curl -fsS https://abuse.secureinsight.my/blocklists/15days.txt | paste -sd, -) }

fail2ban / cron

*/30 * * * * curl -fsS -o /etc/abuse-radar.list \
  https://abuse.secureinsight.my/blocklists/30days.txt

Machine-readable index

GET https://abuse.secureinsight.my/api/v2/blocklists