ThreatListPro vs Free IP Blocklists: Do They Stop VPN Brute Force?

We checked the attacker IPs on today's ThreatListPro list against 10 popular free blocklists. Almost none of them were there.

By ThreatListPro Security Team ยท Measured and published October 5, 2026
2,019
Attacker IPs checked
10
Free blocklists compared
2
Found on any of them (0.1%)

Short answer: free blocklists are good at what they were built for, but VPN brute force is not one of those things. On October 5, 2026 the ThreatListPro list held 2,019 individual attacker IPs. Only 2 of them (0.1%) were on any of the 10 free lists below, even with all 10 merged together.

So if your firewall runs only free lists, almost none of the IPs on our VPN brute force list would be blocked by them.

The results, list by list

The ThreatListPro list holds two kinds of entries: 2,019 individual attacker IPs, and 332 CIDR ranges where attacks come from many neighbouring addresses. We report them separately. A range counts as "touched" if the free list blocks even one address inside it.

Free listWhat it's built forSizeOur attacker IPs it listsOur ranges it touches
Spamhaus DROPNetblocks Spamhaus has identified as hijacked or run by spam and cybercrime operations1,641 entries1 of 2,01929 of 332
FireHOL level 1Aggregate of Spamhaus DROP, DShield, Feodo and full bogons4,642 entries1 of 2,01932 of 332
FireHOL level 2Aggregate of attack reports from roughly the last 48 hours4,994 entries1 of 2,01932 of 332
FireHOL level 3Aggregate of attack, spyware and malware reports from roughly the last 30 days12,818 entries0 of 2,01926 of 332
blocklist.de (all)Attack reports from servers running fail2ban and similar tools (SSH, mail, FTP, web)13,328 entries1 of 2,01917 of 332
blocklist.de brute-force loginBrute-force logins on web apps such as WordPress and Joomla205 entries0 of 2,0192 of 332
CINS ArmyPoor-reputation IPs from CINS Sentinel IPS network sensors15,000 entries0 of 2,01921 of 332
Emerging Threats compromisedKnown compromised hosts (Proofpoint Emerging Threats)621 entries0 of 2,0194 of 332
IPsum (level 3+)IPs that appear on 3 or more of 30+ public lists16,812 entries0 of 2,01922 of 332
DShield top 20The 20 /24 subnets reporting the most attacks to DShield20 entries0 of 2,0191 of 332
All 10 combinedEvery list above, merged—2 of 2,01973 of 332 (4 fully)
Bigger is not better here. FireHOL level 1 covers more than 600 million addresses, yet it lists 1 of the 2,019 attacker IPs on the ThreatListPro list.

Why free lists miss VPN attackers

None of these lists is built from VPN login attempts. Each one answers a different question:

VPN password attacks also tend to come from residential proxy networks: thousands of home connections that each try a few passwords and move on. That pattern is hard to catch with reputation lists unless the list is built from VPN attack traffic itself, which is what ThreatListPro is.

Use them together

This is not a reason to remove your free lists. Spamhaus DROP is still one of the best things to block at a perimeter. The point is that they solve a different problem. Most firewalls accept several External Dynamic Lists, so a sensible setup is:

The ThreatListPro list is a few thousand entries, small enough to fit within the EDL limits of any supported firewall (see Palo Alto and FortiGate limits).

How we measured

What this does and doesn't show: it shows that the free lists almost never contain the addresses on ThreatListPro's list. It is a snapshot of one day. It does not count blocked traffic on a real firewall, and it does not measure false positives on either side. Want to check it on your own firewall? Paste the free 200-entry sample into an EDL and compare its hits with your current lists.

Frequently asked questions

Can a free blocklist stop VPN brute force attacks?

Not on its own. On October 5, 2026 we checked the 2,019 individual attacker IPs on the ThreatListPro list against 10 popular free blocklists. Only 2 of them were on any of the 10, even with all the lists combined. None of these free lists is built from VPN login attempts, so the addresses guessing passwords on VPN portals mostly don't appear on them.

Should I stop using Spamhaus DROP or FireHOL?

No. They do their own jobs well: Spamhaus DROP blocks hijacked netblocks and FireHOL level 1 blocks bogons and known criminal ranges. Keep them for that. They just don't cover VPN login attacks, so run ThreatListPro as a separate EDL alongside them.

Why are VPN brute force sources missing from free lists?

Each free list answers a different question: which netblocks are run by criminals, which hosts attacked SSH, mail or web servers, or which IPs already appear on several other lists. VPN password attacks target GlobalProtect, FortiGate SSL-VPN, AnyConnect and similar portals, often from residential proxy addresses that try a few passwords each and move on, so they rarely show up in that data.

More comparisons: ThreatListPro vs FireHOL, vs AbuseIPDB, vs CrowdSec, and every EDL source compared.

Block the attackers free lists miss

Paste one URL into your firewall's EDL and start blocking VPN brute force sources in about 5 minutes. 30 days free, then $9.99/month. Cancel anytime.

Start Free Trial