Live threat ranking

Top DDoS Source Networks

The ten networks with the most unique DDoS source IPs observed by Whatoblock honeypots during the last 31 days.

Ranked by unique IPs ASN-level view 31-day activity

Top 10 DDoS Source Networks

Intelligence brief

Understanding DDoS Source Networks

Turn distributed attack observations into network-level intelligence

What this ranking shows

DDoS traffic is distributed across many compromised devices, but grouping those sources by autonomous system reveals which networks contribute the largest populations of attacking IPs.

Whatoblock aggregates observations from its honeypot network over a rolling 31-day window. Each network is ranked by unique source IPs, while observations, geographic reach, active days, and the daily timeline provide the context needed to distinguish concentrated bursts from persistent activity.

An ASN ranking is an indicator of observed abuse volume, not a claim that the network operator is malicious. Large access providers and hosting networks can appear because compromised customers or rented infrastructure generate attack traffic.

Methodology

Data is sourced from Whatoblock's honeypot network and refreshed from the current 31-day observation window. See the API documentation for broader programmatic access.