Skip to main content

Modat — the scanner that publishes its list and actually sticks to it

by shop owners for shop owners.

How the PARC feed for Modat came about: an attack-surface scanner by Modat B.V. (NL) with its own ASN. Modat publishes an official IP list — and this time it is complete and fully FCrDNS-verifiable. 186 IPs.

Modat is an internet-wide attack-surface / asset-discovery scanner by Modat B.V. (Netherlands, own ASN MODAT-01). Not an SEO tool. Modat behaves well: fixed IPs, descriptive reverse DNS, and an official, published IP list. Unlike some other “official” feeds, here it is complete and fully FCrDNS-verifiable: 35 CIDRs = 186 IPs. Part of our PARC Security feed.

modat.json — view feed   Modat — official list →

The official list — and why it holds up this time

Modat publishes its scan IPs at scanner.modat.io/ipv4.txt35 CIDR blocks (186 addresses). With ONYPHE we learned that “official” lists are often incomplete. Not here: we held the list against our CINS blacklist — CINS captured 107 actively scanning Modat IPs, and every single one sits inside the official list. Not one scanner outside it. So the list is complete and taken as-is.

Triple-verified

23.111.14.183  →  l602.scanner.modat.io  →  23.111.14.183   ✓
  • Official list: scanner.modat.io/ipv4.txt
  • Reverse DNS: all 186 → *.modat.io (pattern lNNN.scanner.modat.io)
  • FCrDNS: 186 of 186 confirmed (forward record points back to the same IP) — 100%

This is our gold standard: a published list, bidirectionally confirmed, plus an own ASN (MODAT-01, Modat B.V.) — no rented cloud camouflage like Stretchoid or Infrawatch.

Who is behind it

Modat B.V. is a Dutch attack-surface intelligence company — it scans the internet for exposed assets, operating from its own infrastructure (ASN MODAT-01, plus some Leaseweb-SG/NewVM). Transparent operation: fixed reverse names, published list, identifiable.

Sources

← Back to PARC Security   Get in touch