Short answer: free blocklists are good at what they were built for, but VPN brute force is not one of those things. On October 5, 2026 the ThreatListPro list held 2,019 individual attacker IPs. Only 2 of them (0.1%) were on any of the 10 free lists below, even with all 10 merged together.
So if your firewall runs only free lists, almost none of the IPs on our VPN brute force list would be blocked by them.
The results, list by list
The ThreatListPro list holds two kinds of entries: 2,019 individual attacker IPs, and 332 CIDR ranges where attacks come from many neighbouring addresses. We report them separately. A range counts as "touched" if the free list blocks even one address inside it.
| Free list | What it's built for | Size | Our attacker IPs it lists | Our ranges it touches |
|---|---|---|---|---|
| Spamhaus DROP | Netblocks Spamhaus has identified as hijacked or run by spam and cybercrime operations | 1,641 entries | 1 of 2,019 | 29 of 332 |
| FireHOL level 1 | Aggregate of Spamhaus DROP, DShield, Feodo and full bogons | 4,642 entries | 1 of 2,019 | 32 of 332 |
| FireHOL level 2 | Aggregate of attack reports from roughly the last 48 hours | 4,994 entries | 1 of 2,019 | 32 of 332 |
| FireHOL level 3 | Aggregate of attack, spyware and malware reports from roughly the last 30 days | 12,818 entries | 0 of 2,019 | 26 of 332 |
| blocklist.de (all) | Attack reports from servers running fail2ban and similar tools (SSH, mail, FTP, web) | 13,328 entries | 1 of 2,019 | 17 of 332 |
| blocklist.de brute-force login | Brute-force logins on web apps such as WordPress and Joomla | 205 entries | 0 of 2,019 | 2 of 332 |
| CINS Army | Poor-reputation IPs from CINS Sentinel IPS network sensors | 15,000 entries | 0 of 2,019 | 21 of 332 |
| Emerging Threats compromised | Known compromised hosts (Proofpoint Emerging Threats) | 621 entries | 0 of 2,019 | 4 of 332 |
| IPsum (level 3+) | IPs that appear on 3 or more of 30+ public lists | 16,812 entries | 0 of 2,019 | 22 of 332 |
| DShield top 20 | The 20 /24 subnets reporting the most attacks to DShield | 20 entries | 0 of 2,019 | 1 of 332 |
| All 10 combined | Every list above, merged | — | 2 of 2,019 | 73 of 332 (4 fully) |
Why free lists miss VPN attackers
None of these lists is built from VPN login attempts. Each one answers a different question:
- Spamhaus DROP and FireHOL level 1 list whole netblocks that are hijacked or run by spam and crime operations, plus address space that should never appear on the internet. VPN attackers mostly use ordinary addresses.
- blocklist.de collects reports from servers running fail2ban and similar tools, mostly SSH, mail, FTP and web attacks. CINS Army and DShield come from their own network sensors and contributed firewall logs. FireHOL levels 2–3 aggregate feeds like these.
- IPsum only lists addresses that already appear on several other public lists.
VPN password attacks also tend to come from residential proxy networks: thousands of home connections that each try a few passwords and move on. That pattern is hard to catch with reputation lists unless the list is built from VPN attack traffic itself, which is what ThreatListPro is.
Use them together
This is not a reason to remove your free lists. Spamhaus DROP is still one of the best things to block at a perimeter. The point is that they solve a different problem. Most firewalls accept several External Dynamic Lists, so a sensible setup is:
- Spamhaus DROP or FireHOL level 1 for hijacked and bogon ranges.
- ThreatListPro for the addresses attacking your VPN login page.
The ThreatListPro list is a few thousand entries, small enough to fit within the EDL limits of any supported firewall (see Palo Alto and FortiGate limits).
How we measured
- We took the ThreatListPro list as served to customers on October 5, 2026. After normalizing and removing duplicate entries, 2,019 individual IPv4 addresses and 332 CIDR ranges remained.
- We downloaded each free list from its public source the same day (IPsum at level 3 and above) and expanded every entry to address ranges.
- For each free list, and for all 10 merged, we counted which of our IPs it lists and which of our ranges it overlaps.
What this does and doesn't show: it shows that the free lists almost never contain the addresses on ThreatListPro's list. It is a snapshot of one day. It does not count blocked traffic on a real firewall, and it does not measure false positives on either side. Want to check it on your own firewall? Paste the free 200-entry sample into an EDL and compare its hits with your current lists.
Frequently asked questions
Can a free blocklist stop VPN brute force attacks?
Not on its own. On October 5, 2026 we checked the 2,019 individual attacker IPs on the ThreatListPro list against 10 popular free blocklists. Only 2 of them were on any of the 10, even with all the lists combined. None of these free lists is built from VPN login attempts, so the addresses guessing passwords on VPN portals mostly don't appear on them.
Should I stop using Spamhaus DROP or FireHOL?
No. They do their own jobs well: Spamhaus DROP blocks hijacked netblocks and FireHOL level 1 blocks bogons and known criminal ranges. Keep them for that. They just don't cover VPN login attacks, so run ThreatListPro as a separate EDL alongside them.
Why are VPN brute force sources missing from free lists?
Each free list answers a different question: which netblocks are run by criminals, which hosts attacked SSH, mail or web servers, or which IPs already appear on several other lists. VPN password attacks target GlobalProtect, FortiGate SSL-VPN, AnyConnect and similar portals, often from residential proxy addresses that try a few passwords each and move on, so they rarely show up in that data.
More comparisons: ThreatListPro vs FireHOL, vs AbuseIPDB, vs CrowdSec, and every EDL source compared.