This script allows you to analyze a list of IP addresses using the AbuseIPDB API. It generates reports in CSV and HTML formats and displays a detailed summary in the console with a well-formatted and color-highlighted table. It is particularly useful for handling security incidents when there are many IPs to investigate.
AbuseIPDB provides a free analysis of up to 1,000 IPs per day, allowing users to check multiple addresses without cost.
Additionally, the script groups IPs into three categories depending on their confidence score, which indicates how likely they are to be risky:
🔴 High Risk IPs (>40 confidence)
🟠 Medium Risk IPs (1-39 confidence)
🟢 Informational (0 confidence)
- Queries multiple IP addresses in parallel for efficiency.
- Generates an interactive HTML report: search, filter by risk level or TOR, sort any column, and copy the flagged IPs straight to your clipboard to feed a block list. Every IP links to its AbuseIPDB page.
- Creates a CSV report for running queries, importing into data programs, or generating tables.
- Displays a visual summary in the console with risk categories and TOR nodes.
- Zero dependencies: runs on a clean Python 3.8+ install, nothing to
pip install. - Reports the usage type of each IP (Data Center, Fixed Line ISP, CDN, ...), which helps to quickly separate hosting infrastructure from residential connections.
- Validates the input list: blank lines, comments (
#), duplicates, malformed entries and private/reserved addresses are skipped before spending API quota. - Retries transient failures with exponential backoff and honours the API rate limit, stopping early if the key is rejected or the daily quota runs out.
- Lists every failed lookup and skipped entry in the console and in the HTML report, so no IP disappears silently.
Python 3.8 or newer. Nothing else.
The script uses only the Python standard library, so there is no pip install step, no virtual environment to set up and no third party packages to trust. Clone the repository, add your API key and run it.
- Insert your AbuseIPDB API key in the script before executing it.
- Place the IP addresses to be analyzed in a file named
ips.txt(one IP per line). The repository ships with a small sample list so you can see what the reports look like on a first run, before replacing it with your own IPs. - Run the script:
python IPAbuseChecker0x.py- After execution, the following files will be generated:
report_IPAbuseChecker0x.html: An HTML report with color-coded risk levels for easier interpretation.results_IPAbuseChecker0x.csv: Contains detailed information about the analyzed IPs.- A structured summary table will be displayed in the console.
The input and output files can be changed without editing the script:
-i, --input INPUT file with one IP per line (default: ips.txt)
-c, --csv CSV CSV output file (default: results_IPAbuseChecker0x.csv)
-o, --html HTML HTML output file (default: report_IPAbuseChecker0x.html)
--no-logo do not print the banner
For example, to analyze a different list and write the reports somewhere else:
python IPAbuseChecker0x.py -i incident_ips.txt -c incident.csv -o incident.htmlThe script uses the AbuseIPDB API, so you need an API key. Replace the API_KEY variable in the script with your own key:
API_KEY = 'YOUR_API_KEY'You can get a free key by registering at abuseipdb.com. The free tier allows up to 1,000 IP checks per day.
By default the script only takes into account reports from the last 360 days. You can change it in this line (valid range: 1 to 365):
MAX_AGE_IN_DAYS = 360A visual report is generated with color coding to indicate the risk level of each IP. It is a single self-contained file with no external resources, so it can be attached to a ticket or shared as is, and it works offline.
Beyond the table, the report gives you:
- Overview cards and a risk distribution bar for an immediate read of how bad the batch is.
- Top countries, showing how many addresses each one contributes and how many of those are flagged, to spot the source of an attack at a glance.
- A search box that matches any field: IP, ISP, domain, country or usage type.
- Filters for High, Medium, Informational, TOR and Reported.
- Sortable columns. IPs sort in real numeric order, not alphabetically, and dates sort chronologically.
- Copy shown IPs / Copy flagged IPs buttons that put one IP per line on your clipboard, ready to paste into a firewall rule or a SIEM query.
- A link on every IP to its AbuseIPDB page for the full report history.
- A print stylesheet: the toolbar is hidden and every row is expanded, so
Ctrl+Pproduces a clean PDF.
A structured CSV report is generated containing detailed information about each analyzed IP, including confidence scores, ISP details, domain, country, and whether the IP is associated with TOR nodes.
Note: The CSV file is generated in its traditional format, but the following image displays it as a table to better visualize all columns and data.
If you want to improve the script or add new features, feel free to contribute! Fork the repository and submit a pull request.
This project is licensed under the MIT License. You are free to use and modify it as needed.



