ip2geo Lookup

Paste any log, netstat output or ticket text. Up to 10,000 IPs, IPv4 and IPv6, pulled out and looked up in seconds.

2-letter ISO codes separated by spaces. Use to filter out non-suspicious IPs.

Contact / Contribute

ip2geo.org is maintained and run by me, Josh. Hi. If this tool was helpful, feel free to say hello, or help cover hosting costs if the free tools saved the day.

About ip2geo.org

Why This Exists

Ever been on the wrong end of a distributed probe hammering away at your email server, SSH port, or some other exposed service? It's chaos. Logs scroll by like a waterfall, and your tools? They're powerful, sure — but not exactly friendly when you're trying to make sense of hundreds of connections in real time.

The Problem

You run a CLI command, grab the output, and paste it into your favorite text editor. You start cleaning it up, extracting IPs manually, only to hit a wall: now you're supposed to copy-paste those addresses into a web form. One by one. Seriously?

When you're facing a flood of suspicious traffic, that's just not going to cut it.

The Fix

I was maintaining an aging email system with no password policies and no support — a perfect storm for account compromises. With no time or budget to overhaul it, I built this tool instead.

ip2geo.org lets you paste raw output from tools like netstat, fail2ban, or anything else that spits out IPs. It automatically extracts valid IPv4 and IPv6 addresses, runs a fast geolocation lookup, and gives you clean, actionable data — instantly. With one glance, I could see login attempts from every corner of the globe and quickly block entire botnets.

What It's Grown Into

The free lookup is still here, and it's the whole tool. Paste a log, get a summary line up front — how much of it is cloud infrastructure, scanning traffic, VPN/proxy exits, or plain residential, plus which ASNs show up the most and how many IPs sit in Spamhaus's DROP list of known-hijacked netblocks.

How It Works

Paste any block of text. ip2geo.org scans it for IPv4 and IPv6 addresses, checks them against a geolocation database, and returns results you can filter by country or infrastructure category — scanning ranges, cloud exit nodes, VPN and proxy infrastructure, or residential traffic. Want to only see scanning infrastructure hits from outside the US? Done. Focus only on what matters.

Why It's Free

This tool was built using free and open-source resources, and it's free because I wish something like this had existed when I needed it most. If it helps you too, consider buying me a coffee or tossing a few bucks toward hosting costs.