Skip to main content

bruteforceblocker — SSH brute-force blacklist

by shop owners for shop owners.

SSH brute-force blacklist by Daniel Gerzo (FreeBSD committer, danger.rulez.sk) — profile and cross-check with AbuseIPDB.

Profile of bruteforceblocker

Category / attack surfaceSSH brute force (port 22) — host level
What it isAttacker-IP list of an SSH brute-force protection tool
How IPs get listedThe tool parses the sshd logs of participating servers; once an IP exceeds the failed-login threshold it is blocked locally and reported to the central project database.
Listing thresholdat least 3 failed login attempts
AuthorDaniel Gerzo („danger“), FreeBSD committer, Slovakia
Sincev1.0 since 2005-04-12
Update intervalpull ~3 h; rolling 30-day window (auto-delisting of inactive IPs)
Aggregated inFireHOL Level 3 · ipsum
Official sitedanger.rulez.sk/index.php/bruteforceblocker
Feed sourceblist.php — original list (TXT)

Cross-check with AbuseIPDB as of 2026-06-25

All 646 IP addresses from the bruteforceblocker feed were queried against AbuseIPDB over a 30-day period on 2026-06-25 and enriched with additional information.

AbuseIPDB score

95%100: 613 (95%), 75–99: 14 (2%), 50–74: 3 (0%), 25–49: 7 (1%), 1–24: 7 (1%), 0: 2 (0%)

Usage type

75%24%Data Center / Hosting: 487 (75%), Fixed Line ISP: 152 (24%), Commercial: 5 (1%), Mobile ISP: 1 (0%), University: 1 (0%)

Country distribution

37%15%12%8%18%BE: 236 (37%), CN: 100 (15%), VN: 75 (12%), US: 53 (8%), DE: 20 (3%), NL: 18 (3%), SG: 15 (2%), KR: 15 (2%), Sonstige: 114 (18%)

Provider distribution (ISP)

38%11%11%31%Google LLC: 246 (38%), Viettel Group: 73 (11%), Aliyun Computing: 73 (11%), DigitalOcean, LLC: 16 (2%), Alibaba Cloud LLC: 11 (2%), Amazon.com, Inc.: 10 (2%), Korea Telecom: 10 (2%), Microsoft Corporation: 8 (1%), Sonstige: 199 (31%)

Cross-check with PARC feeds (excluding blacklists) as of 2026-06-25

None of the 646 bruteforceblocker IPs appear in our PARC feeds — no overlap with scanners or bots.