Threat feed
Phishing Database: IPs
Last fetched
Phishing · refreshed hourly · last verified
Phishing Database: IPs is a Phishing threat-intelligence feed, refreshed hourly, indexed by WhisperGraph. WhisperGraph currently records 3,800 indicators listed by it.
What is Phishing Database: IPs
Phishing Database: IPs is the standalone IP-address export from the Phishing.Database project, covering hosts observed serving phishing content independent of any specific domain mapping. This is the export most directly comparable to a traditional IP reputation list, useful for firewall-level blocking where a domain-level or DNS-level control is not available. It shares the project's aggregation methodology, drawing on OpenPhish, PhishTank, and other public phishing-tracking sources. It is indexed here as the IP-specific export of one of the most widely re-used open phishing aggregators.
- Refresh cadence
- hourly
Category drift. The curated category for this feed is Phishing, while WhisperGraph currently files it under phishing.
Indicators currently listed
3,800 indicators across 2 node types.
PREFIX · 2
Related pages
Pivot from Phishing Database: IPs into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.