Skip to content

Internet Scanners

The internet-scanners dataset is a Zstd-compressed CSV containing a list of IPs that have been observed scanning the Internet the past 24 hours. A new file is generated every day and the API makes the most recent 30 days of datafiles available. The first row of the file contains the headers:

  • ip
  • hostname
  • timestamp

Below are a few sample rows:

ip,hostname,timestamp
47.254.15.150,,2025-07-04 06:59:20.204578
199.45.154.125,scanner-201.hk2.censys-scanner.com,2025-07-04 21:01:43.186353
88.99.12.16,static.16.12.99.88.clients.your-server.de,2025-07-04 21:10:06.984532
64.62.156.207,scan-88-5.shadowserver.org,2025-07-04 01:17:36.372423
147.185.133.45,,2025-07-04 13:39:18.605161
45.79.137.206,,2025-07-04 08:20:50.267583
20.64.105.237,azpdsg0k59cb.stretchoid.com,2025-07-04 22:26:07.212272
185.200.116.73,no-mans-land.m247.com,2025-07-04 04:59:07.4289

The IPs are identified as scanning the Internet based on activity observed by a honeypot network. If the same IP is seen across several honeypot sensors then it is added to the internet-scanners dataset. This means that if a scanner breaks the IP space into segments and spreads the scanning out across scanners then it is less likely to get labeled by the honeypot network.