We have insert in the TXT-Record of the RBLDNS now the unix Timestamp of the last Attack which we received.
We listen IPs 48 Hours along in our Lists, but dynamically Addresses will be changed from some Provider after 12 Hours.
Now you can see when blocklist.de received the last Attack from the queried IP.
For example for the IP 18.104.22.168:
#dig 22.214.171.124.apache.bl.blocklist.de TXT
;; ANSWER SECTION:
126.96.36.199.apache.bl.blocklist.de. 2467 IN TXT "Infected System (Service: apacheddos, Last-Attack: 1369828413), see http://www.blocklist.de/en/view.html?ip=188.8.131.52"
You can parse between Last-Attack: and ), the Unix Timestamp.
A other way was to add the age of last Attack in the A-Record in Hours like this:
127.0.0.x for last Attack was under one Hour old
127.0.2.x the last Attack was older between 2 hours
Please wrote into the comments about the second Way to inser the age in the A-Record.