Malicious IPs in United States
IPv4 networks located in United States that are currently flagged for malicious activity, aggregated from multiple external and internal threat intelligence sources. Snapshot of (UTC), updated daily.
United States at a glance
The United States had 2,611 flagged IPv4 networks in the snapshot of 2026-10-11, rank #1 of 179 countries by absolute count. Relative to its allocated IPv4 space that is 1.62 flagged networks per million addresses, rank #74 of 76, well below the median of 9.38 across all rated countries. The largest category is brute force sources with 49% of the flagged networks, followed by other malicious networks (23%). The three networks (ASNs) with the most flagged IPs hold 30% of them, led by GOOGLE-CLOUD-PLATFORM - Google LLC (AS396982). Another 28 flagged IPv6 networks are located in the United States.
Malicious activity in United States by category
A network listed in several categories counts once, in the most specific one. Also flagged: 28 IPv6 networks.
Brute force sources in United States
1,282 (49%)1,282 flagged networks, #2 of 162 countries for brute force sources. Sources of password guessing against SSH, mail, FTP and web logins. Brute Force Sources by Country
Other malicious networks in United States
589 (23%)589 flagged networks, #1 of 143 countries for other malicious networks. Addresses and ranges reported as malicious without a more specific category. Other Malicious Networks by Country
Botnet hosts in United States
240 (9%)240 flagged networks, #2 of 122 countries for botnet hosts. Infected hosts taking part in a botnet. Botnet Hosts by Country
Scanners in United States
211 (8%)211 flagged networks, #1 of 40 countries for scanners. Hosts scanning or probing services on the internet. Scanners by Country
Spam sources in United States
163 (6%)163 flagged networks, #2 of 89 countries for spam sources. Sources of email spam. Spam Sources by Country
C2 servers in United States
126 (5%)126 flagged networks, #1 of 51 countries for C2 servers. Command-and-control servers, payload hosts and other attacker-run infrastructure. C2 Servers by Country
Networks with the most flagged IPs in United States
Autonomous systems announcing the flagged networks located in United States.
| # | Network | Flagged networks |
|---|---|---|
| 1 | AS396982GOOGLE-CLOUD-PLATFORM - Google LLC | 394 |
| 2 | AS22773ASN-CXA-ALL-CCI-22773-RDC - Cox Communications Inc. | 193 |
| 3 | AS14061DIGITALOCEAN-ASN - DigitalOcean, LLC | 186 |
| 4 | AS8075MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation | 145 |
| 5 | AS63949AKAMAI-LINODE-AP Akamai Connected Cloud | 94 |
| 6 | AS7922COMCAST-7922 - Comcast Cable Communications, LLC | 63 |
| 7 | AS31898ORACLE-BMC-31898 - Oracle Corporation | 62 |
| 8 | AS132203TENCENT-NET-AP-CN Tencent Building, Kejizhongyi Avenue | 55 |
| 9 | AS7018ATT-INTERNET4 - AT&T Enterprises, LLC | 54 |
| 10 | AS14618AMAZON-AES - Amazon.com, Inc. | 51 |
Compare United States with other countries
Ranked by flagged networks per million allocated IPv4 addresses.
Countries ranked next to the United States by rate
| # | Country | Networks | Per million |
|---|---|---|---|
| 71 | United Kingdom | 320 | 2.26 |
| 72 | Switzerland | 52 | 2.23 |
| 73 | Austria | 21 | 1.88 |
| 74 | United States | 2,611 | 1.62 |
| 75 | Norway | 23 | 1.47 |
| 76 | Japan | 264 | 1.40 |
Other countries in the ARIN region
| # | Country | Networks | Per million |
|---|---|---|---|
| 63 | Canada | 247 | 3.61 |
Questions about United States
- How many malicious IP addresses are there in the United States?
- On 2026-10-11, 2,611 IPv4 networks (/24 blocks) located in the United States were flagged for malicious activity, with 65,607 listed IPv4 addresses and 28 IPv6 networks. Each /24 counts once, however many of its addresses are listed.
- Which networks in the United States host the most flagged IPs?
- GOOGLE-CLOUD-PLATFORM - Google LLC (AS396982, 394 networks), ASN-CXA-ALL-CCI-22773-RDC - Cox Communications Inc. (AS22773, 193 networks), DIGITALOCEAN-ASN - DigitalOcean, LLC (AS14061, 186 networks). Large hosting providers appear because attackers rent their servers, not necessarily because of the operator.
Query this data per IP via the API
Look up threat categories, reputation score, ASN and geolocation for any address in United States or anywhere else with one API call.