Spamhaus DROP malicious netblocks & ASNs, daily
Daily snapshot of the Spamhaus DROP lists (keyless JSON feeds, free of charge per the DROP Fair Use Policy): IPv4/IPv6 netblocks hijacked or wholly controlled by spam and cyber-crime operations (SBL reference, RIR, prefix math) plus ASN-DROP rogue autonomous systems (ASN, name, domain, country), each row carrying its list's own publication timestamp. Advisory drop-all-traffic intelligence for firewalls, routers and SOC triage — join flow logs on CIDR containment or filter BGP announcements by ASN. Terms s.3.2: the 'Spamhaus' name must not appear in marketing or promotional materials.
- Rows
- 2,213
- Columns
- 14
- Source cadence
- Daily
- Last refreshed
- Oct 3, 2026
- Theme
- technology
| Column | Type | Description |
|---|---|---|
| list | string | Which Spamhaus list the row comes from: drop_v4, drop_v6, or asn_drop. |
| network | string | Listed network as CIDR (drop_v4/drop_v6) or autonomous system as AS<number> (asn_drop). |
| ip_version | integer | 4 or 6 for CIDR rows; null for ASN rows. |
| prefix_length | integer | CIDR prefix length; null for ASN rows. (unit: bits) |
| address_count | integer | Number of IPv4 addresses in the CIDR (2**(32-prefix)); null for IPv6 rows (counts overflow int64) and ASN rows. (unit: addresses) |
| sbl_id | string | Spamhaus Blocklist reference (SBLnnnnnn) backing the listing; null for ASN rows. |
| rir | string | Regional Internet Registry that allocated the netblock / ASN. |
| asn | integer | Autonomous system number (asn_drop rows only). |
| as_name | string | AS name (asn_drop rows only). |
| domain | string | Associated domain (asn_drop rows only). |
| country_code | string | ISO-2 country of the ASN (asn_drop rows only). |
| list_timestamp | string | Publication timestamp of the source list this row was taken from (ISO-8601 UTC, from the feed's metadata record). (unit: timestamp) |
| fetch_date | string | Date this snapshot was fetched (ISO date). (unit: date) |
| row_hash | string | Deterministic 12-hex row identity hash (list|network|sbl_id; sbl_id empty on asn_drop rows). |
First 10 sample rows — a preview, not the complete dataset.
| list | network | ip_version | prefix_length | address_count | sbl_id | rir | asn | as_name | domain | country_code | list_timestamp | fetch_date | row_hash |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| drop_v4 | 1.10.16.0/20 | 4 | 20 | 4,096 | SBL256894 | apnic | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | 2b0f00c53f06 |
| drop_v4 | 1.19.0.0/16 | 4 | 16 | 65,536 | SBL434604 | apnic | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | 7350c959c876 |
| drop_v4 | 1.32.128.0/18 | 4 | 18 | 16,384 | SBL286275 | apnic | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | fabe1087d725 |
| drop_v4 | 2.26.75.0/24 | 4 | 24 | 256 | SBL698389 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | e0bcb379b173 |
| drop_v4 | 2.27.5.0/24 | 4 | 24 | 256 | SBL698390 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | cb058d6e3b7f |
| drop_v4 | 2.27.62.0/24 | 4 | 24 | 256 | SBL699649 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | 28743a8e036c |
| drop_v4 | 2.56.192.0/22 | 4 | 22 | 1,024 | SBL459831 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | 0ae5b5e83d52 |
| drop_v4 | 2.57.122.0/24 | 4 | 24 | 256 | SBL636050 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | e96aa6821bfc |
| drop_v4 | 2.57.232.0/23 | 4 | 23 | 512 | SBL538946 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | aa73cca46dea |
| drop_v4 | 2.57.234.0/23 | 4 | 23 | 512 | SBL538947 | ripencc | — | — | — | — | 2026-10-03T22:14:02+00:00 | 2026-10-03 | 8b19638e352d |
- Current
20261003T222611Z-5e8672c239c1 · sha256 5e8672c239c1…
2,213 rows · first snapshot
Point any LLM at the metadata endpoint — the documentation above is machine-readable too (JSON-LD + Croissant).
curl "https://datazimuts.com/v1/datasets/spamhaus_drop_intel/spamhaus_drop_netblocks_daily" | jq '{title, rows, columns_count, license}'import requests
ds = requests.get("https://datazimuts.com/v1/datasets/spamhaus_drop_intel/spamhaus_drop_netblocks_daily").json()
print(ds["title"], ds["rows"], "rows")
# Sample rows for an LLM context window
for row in ds.get("sample_rows", [])[:5]:
print(row)API endpoint: https://datazimuts.com/v1/datasets/spamhaus_drop_intel/spamhaus_drop_netblocks_daily
Tip: fetch /llms.txt for the full machine-readable catalog.
Where this data comes from and what was made from it. Other people's work shows as counts; only shared projects are named.
Cite this snapshot
Pinned to snapshot 20261003T222611Z-5e8672c239c1 and its content hash, so readers get exactly the data you used.
Spamhaus DROP malicious-network intelligence. (2026). Spamhaus DROP malicious netblocks & ASNs, daily [Data set, snapshot 20261003T222611Z-5e8672c239c1, sha256 5e8672c239c1]. Datazimuts. Retrieved 2026-10-05, from https://datazimuts.com/en/datasets/spamhaus_drop_intel/spamhaus_drop_netblocks_daily?snapshot=20261003T222611Z-5e8672c239c1
@misc{dz_spamhaus_drop_intel_spamhaus_drop_netblo_5e8672c2,
title = {{Spamhaus DROP malicious netblocks \& ASNs, daily}},
author = {{Spamhaus DROP malicious-network intelligence}},
year = {2026},
publisher = {Datazimuts},
howpublished = {\url{https://datazimuts.com/en/datasets/spamhaus_drop_intel/spamhaus_drop_netblocks_daily?snapshot=20261003T222611Z-5e8672c239c1}},
note = {Snapshot 20261003T222611Z-5e8672c239c1, sha256 5e8672c239c1215cbaa74764a19a866b5e9c299cab65211e91396c6b9e090771; accessed 2026-10-05}
}Embed a table or a chart
Paste this into any page. The embed is pinned to the same snapshot, follows the reader's light or dark setting, and always shows the source, license and a link back.
<iframe src="https://datazimuts.com/embed/chart?dataset=spamhaus_drop_intel%2Fspamhaus_drop_netblocks_daily&lang=en&theme=auto&snapshot=20261003T222611Z-5e8672c239c1&x=list_timestamp&y=ip_version&agg=avg" title="Spamhaus DROP malicious netblocks & ASNs, daily" width="100%" height="380" style="border:0" loading="lazy"></iframe>
Ask about this dataset. Answers come only from its catalog record, measured profile and change history, and list the facts they used.