This paper addresses the challenge of automatically extracting and classifying malicious IP addresses reported in security forums. The proposed method, RIPEx, uses a cross-forum learning approach to identify IP addresses from other numerical data and classify them as benign or malicious. RIPEx achieves high accuracy, with 95% precision and over 93% recall in distinguishing IP addresses from other numeric data, and an average of 88% precision and over 78% recall in identifying malicious IPs. The method leverages knowledge transfer across forums, requiring no new training data for each forum, and demonstrates significant potential for extracting useful information from security forums.