Collection LIVE
Snapshot age19 minutes ago
Sensor fleet10/10 healthy
Connecting

Threat picture

Signals from monitored SSH, mail and leak-trap infrastructure, normalised into a public-safe feed.

Geography

Global source activity

country aggregate · source → hub flow
Live arcs fire only when an indicator is newly observed.
Map details

3,159 active indicators in 699 one-degree cells · placed at reported coordinates, never snapped onto land · 221 indicators withheld from the map in 42 cells because the reported coordinates do not resolve to drawn land; they remain included in all totals

A country disc marks the country. It is drawn at a fixed anchor inside that country's land and is not the location of any address or event.

1 source not plotted: HK (no outline drawn for this territory).

World map: 3,159 active indicators are drawn as small marks in 699 one-degree cells, each placed at the mean of the coordinates its members reported and coloured by signal type; larger discs are country aggregates. Some indicators are withheld from the map, in 42 cells, where coordinates cannot be represented reliably at this map resolution - the outline is simplified and omits small islands, and a few coordinates fall outside the country they resolved to. They remain included in all totals. 11 source countries, each drawn with one route to the Malaysia hub. A country disc is drawn at a fixed anchor inside that country, chosen so the marker sits on the country's land; it marks the country only and is not the location of any address or event. The ranked list beside the map carries the same data as text.
Source countryActive indicatorsDetections
United States6182,941
Belgium972,238
Germany691,584
Netherlands1121,497
China4791,481
India2831,013
South Korea348961
Canada55788
Russian Federation185596
Brazil122511
Taiwan123460
Global activity Open Global Ops

Top source countries by detections

Map nodes sit at a country-level mean of observed coordinates, not at an attack origin. Ranked lists are ordered by detections; the per-category panel below ranks the same countries by active indicators, so the two orders differ.

Activity & classification

Timeline

Threat activity

derived from indicator first & last seen

Last 7 days · Asia/Kuala_Lumpur

Active signals949
Unique IPs904
New IPs327
High risk415
Active indicators Newly observed IPs

Derived from indicator first-seen and last-seen times. Per-observation counts are cumulative in this schema, so a detections-per-bucket series is not available.

Threat activity per time bucket, Asia/Kuala_Lumpur
Bucket startActive indicatorsUnique IPs New IPsHigh risk
2026-10-02T23:00:00+08:00191766
2026-10-03T05:00:00+08:002321612
2026-10-03T11:00:00+08:002020411
2026-10-03T17:00:00+08:0038381417
2026-10-03T23:00:00+08:0044411620
2026-10-04T05:00:00+08:0042421616
2026-10-04T11:00:00+08:0062612525
2026-10-04T17:00:00+08:0045441422
2026-10-04T23:00:00+08:0046461514
2026-10-05T05:00:00+08:0052491522
2026-10-05T11:00:00+08:0069672928
2026-10-05T17:00:00+08:0056542417
2026-10-05T23:00:00+08:0054521922
2026-10-06T05:00:00+08:0029271111
2026-10-06T11:00:00+08:0044421819
2026-10-06T17:00:00+08:0040401318
2026-10-06T23:00:00+08:0048422215
2026-10-07T05:00:00+08:0042411219
2026-10-07T11:00:00+08:0038361415
2026-10-07T17:00:00+08:002119610
2026-10-07T23:00:00+08:00131338
2026-10-08T05:00:00+08:00181647
2026-10-08T11:00:00+08:009935
2026-10-08T17:00:00+08:00121137
2026-10-08T23:00:00+08:002120615
2026-10-09T05:00:00+08:002218716
2026-10-09T11:00:00+08:001716314
2026-10-09T17:00:00+08:005414
Platform

System status

Snapshot built270.7ms to compute this view
Readers online1distinct visitors in the last hour
API reads19,781requests in the last 7 days
Delist queue0requests awaiting review
Platform telemetry, not threat data. Counts describe this service's own operation.
Classification

Attack mix

active detections by category
SSH abuse1020.6% · 29 IP records
Mail / credential abuse700.4% · 11 IP records
Leak trap7,72942.5% · 2,776 IP records
Web attack10,27356.5% · 564 IP records
Other patterns00.0% · 0 IP records
Active detections by category
CategoryDetectionsShare
SSH abuse1020.6%
Mail / credential abuse700.4%
Leak trap7,72942.5%
Web attack10,27356.5%
Other patterns00.0%
18,174 active detections across 4 categories.

Signal types the same population, one level finer

  • Automated web path enumerationweb_scanner_enumeration8,125 det157 rec
  • Leak trap address contactedleak_trap_hit7,729 det2,776 rec
  • Sensitive file probing over HTTPweb_sensitive_file_probe1,701 det279 rec
  • Known exploit path probing over HTTPweb_exploit_probe201 det78 rec
  • Suspicious web authentication attemptsweb_auth_abuse168 det18 rec
  • Suspicious SSH authentication attemptsssh_auth_abuse102 det29 rec
  • Path traversal attempted over HTTPweb_path_traversal78 det32 rec
  • Suspicious mail authentication attemptsmail_auth_abuse70 det11 rec

Top sources by category active indicators per country

  • United StatesUS618
  • ChinaCN479
  • South KoreaKR348
  • IndiaIN283
  • Russian FederationRU185
  • TaiwanTW123
  • BrazilBR122
  • NetherlandsNL112
SSH abuseMail / credential abuseLeak trapOther patterns

3,380 of 3,380 active indicators geolocated across 106 countries. Bar length is each country’s share of the busiest.

Active indicators by source country and attack category
CountryTotalSSH abuseMail / credential abuseLeak trapOther patternsUnique IPs
United States61810488129560
China4791804610479
South Korea348103398347
India2831027210282
Russian Federation185001841185
Taiwan123001149117
Brazil122001175120
Netherlands11205258272

Operations & ledger

Fleet

Sensor fleet

10 healthy · 1 retiredAll sensors
  • Leak Trap Sensor 01 (retired)retired · last observed 2026-05-20 · 20 obsRetired
  • SSH Sensor 01Check-in just now
    Last observation 25 days ago · usually within 28 h · 729 obs
    Healthy
  • SSH Sensor 02Check-in 2 minutes ago
    Last observation 25 days ago · usually within 30.5 h · 292 obs
    Healthy
  • SSH Sensor 03Check-in 3 minutes ago
    Last observation 25 days ago · usually within 35.9 h · 198 obs
    Healthy
  • SSH Sensor 04Check-in 2 minutes ago
    Last observation 22 days ago · usually within 32.8 h · 236 obs
    Healthy
  • Mail Sensor 01Check-in 1 minute ago
    Last observation 1 day ago · usually within 5.8 d · 138 obs
    Healthy
  • Leak Trap Sensor 02Check-in just now
    Last observation 20 minutes ago · usually within 1.3 h · 11,963 obs
    Healthy
  • Mail Sensor 02Check-in just now
    Last observation 8 hours ago · usually within 6.1 d · 595 obs
    Healthy

Health is collector liveness, proven by a heartbeat every 5 min; observation activity is reported separately. A collector that has seen no abuse is not an unhealthy collector. Each trace shows indicators the sensor observed for the first time on each of the last 14 days; a flat trace means no new indicators, not no traffic.

Ledger

Most active IPs

by detection volumeSee all
Most active IP addresses by detection volume
IPRiskDetectionsOriginLast seen
45.45.237.65Low547United States AS40052911 days ago
213.209.159.133Low414Germany AS2081373 days ago
34.19.246.187Low330Canada AS39698210 days ago
213.209.159.84Low323Germany AS2081374 days ago
34.19.248.170Low233Canada AS39698210 days ago
Ledger

Newly observed

first seen most recentlySee all
Most recently first-seen threats
IPSignalRiskOrigin First seenGMT+8
31.57.216.50Path traversal attempted over HTTPMediumLjubljana, Slovenia SIAS197769 · VPS Dedicated LLC2026-10-09 17:3719 minutes ago
31.57.216.50Automated web path enumerationHighLjubljana, Slovenia SIAS197769 · VPS Dedicated LLC2026-10-09 17:3619 minutes ago
174.68.45.140Leak trap address contactedMediumLas Vegas, United States USAS22773 · Cox Communications Inc.2026-10-09 16:351 hour ago
35.212.188.111Sensitive file probing over HTTPMediumThe Dalles, United States USGoogle LLC2026-10-09 12:385 hours ago
68.227.77.60Leak trap address contactedMediumSpringdale, United States USAS22773 · Cox Communications Inc.2026-10-09 11:156 hours ago
Dispatch

Plain IP blocklists

one address per line, ready for firewallsUsage & automation
Query

Analyst query