Threat picture
Signals from monitored SSH, mail and leak-trap infrastructure, normalised into a public-safe feed.
Global source activity
Map details
3,159 active indicators in 699 one-degree cells · placed at reported coordinates, never snapped onto land · 221 indicators withheld from the map in 42 cells because the reported coordinates do not resolve to drawn land; they remain included in all totals
A country disc marks the country. It is drawn at a fixed anchor inside that country's land and is not the location of any address or event.
1 source not plotted: HK (no outline drawn for this territory).
| Source country | Active indicators | Detections |
|---|---|---|
| United States | 618 | 2,941 |
| Belgium | 97 | 2,238 |
| Germany | 69 | 1,584 |
| Netherlands | 112 | 1,497 |
| China | 479 | 1,481 |
| India | 283 | 1,013 |
| South Korea | 348 | 961 |
| Canada | 55 | 788 |
| Russian Federation | 185 | 596 |
| Brazil | 122 | 511 |
| Taiwan | 123 | 460 |
Top source countries by detections
- United StatesUS2,941
- BelgiumBE2,238
- GermanyDE1,584
- NetherlandsNL1,497
- ChinaCN1,481
- IndiaIN1,013
- South KoreaKR961
- Hong KongHK806
Top networks by detections
- Avago Technologies U.S. Inc.AS3969825,167
- TECHOFF SRV LIMITEDAS48090790
- FEO PREST SRLAS208137768
- Infraly, LLCAS400529724
- BUSAN EDUCATION RESEARCH & INFORMATION INSTITUTEAS4766704
- TC DATACENTER LIMITEDAS218785589
- CHINANET Anhui province networkAS4134525
- ALBATROSS PROJECTS RF TECHNOLOGY INDIA PRIVATE LIMITEDAS9498523
Activity & classification
Threat activity
Last 7 days · Asia/Kuala_Lumpur
Derived from indicator first-seen and last-seen times. Per-observation counts are cumulative in this schema, so a detections-per-bucket series is not available.
| Bucket start | Active indicators | Unique IPs | New IPs | High risk |
|---|---|---|---|---|
| 2026-10-02T23:00:00+08:00 | 19 | 17 | 6 | 6 |
| 2026-10-03T05:00:00+08:00 | 23 | 21 | 6 | 12 |
| 2026-10-03T11:00:00+08:00 | 20 | 20 | 4 | 11 |
| 2026-10-03T17:00:00+08:00 | 38 | 38 | 14 | 17 |
| 2026-10-03T23:00:00+08:00 | 44 | 41 | 16 | 20 |
| 2026-10-04T05:00:00+08:00 | 42 | 42 | 16 | 16 |
| 2026-10-04T11:00:00+08:00 | 62 | 61 | 25 | 25 |
| 2026-10-04T17:00:00+08:00 | 45 | 44 | 14 | 22 |
| 2026-10-04T23:00:00+08:00 | 46 | 46 | 15 | 14 |
| 2026-10-05T05:00:00+08:00 | 52 | 49 | 15 | 22 |
| 2026-10-05T11:00:00+08:00 | 69 | 67 | 29 | 28 |
| 2026-10-05T17:00:00+08:00 | 56 | 54 | 24 | 17 |
| 2026-10-05T23:00:00+08:00 | 54 | 52 | 19 | 22 |
| 2026-10-06T05:00:00+08:00 | 29 | 27 | 11 | 11 |
| 2026-10-06T11:00:00+08:00 | 44 | 42 | 18 | 19 |
| 2026-10-06T17:00:00+08:00 | 40 | 40 | 13 | 18 |
| 2026-10-06T23:00:00+08:00 | 48 | 42 | 22 | 15 |
| 2026-10-07T05:00:00+08:00 | 42 | 41 | 12 | 19 |
| 2026-10-07T11:00:00+08:00 | 38 | 36 | 14 | 15 |
| 2026-10-07T17:00:00+08:00 | 21 | 19 | 6 | 10 |
| 2026-10-07T23:00:00+08:00 | 13 | 13 | 3 | 8 |
| 2026-10-08T05:00:00+08:00 | 18 | 16 | 4 | 7 |
| 2026-10-08T11:00:00+08:00 | 9 | 9 | 3 | 5 |
| 2026-10-08T17:00:00+08:00 | 12 | 11 | 3 | 7 |
| 2026-10-08T23:00:00+08:00 | 21 | 20 | 6 | 15 |
| 2026-10-09T05:00:00+08:00 | 22 | 18 | 7 | 16 |
| 2026-10-09T11:00:00+08:00 | 17 | 16 | 3 | 14 |
| 2026-10-09T17:00:00+08:00 | 5 | 4 | 1 | 4 |
System status
Attack mix
| Category | Detections | Share |
|---|---|---|
| SSH abuse | 102 | 0.6% |
| Mail / credential abuse | 70 | 0.4% |
| Leak trap | 7,729 | 42.5% |
| Web attack | 10,273 | 56.5% |
| Other patterns | 0 | 0.0% |
Signal types the same population, one level finer
- Automated web path enumerationweb_scanner_enumeration8,125 det157 rec
- Leak trap address contactedleak_trap_hit7,729 det2,776 rec
- Sensitive file probing over HTTPweb_sensitive_file_probe1,701 det279 rec
- Known exploit path probing over HTTPweb_exploit_probe201 det78 rec
- Suspicious web authentication attemptsweb_auth_abuse168 det18 rec
- Suspicious SSH authentication attemptsssh_auth_abuse102 det29 rec
- Path traversal attempted over HTTPweb_path_traversal78 det32 rec
- Suspicious mail authentication attemptsmail_auth_abuse70 det11 rec
Top sources by category active indicators per country
- United StatesUS618
- ChinaCN479
- South KoreaKR348
- IndiaIN283
- Russian FederationRU185
- TaiwanTW123
- BrazilBR122
- NetherlandsNL112
3,380 of 3,380 active indicators geolocated across 106 countries. Bar length is each country’s share of the busiest.
| Country | Total | SSH abuse | Mail / credential abuse | Leak trap | Other patterns | Unique IPs |
|---|---|---|---|---|---|---|
| United States | 618 | 1 | 0 | 488 | 129 | 560 |
| China | 479 | 18 | 0 | 461 | 0 | 479 |
| South Korea | 348 | 1 | 0 | 339 | 8 | 347 |
| India | 283 | 1 | 0 | 272 | 10 | 282 |
| Russian Federation | 185 | 0 | 0 | 184 | 1 | 185 |
| Taiwan | 123 | 0 | 0 | 114 | 9 | 117 |
| Brazil | 122 | 0 | 0 | 117 | 5 | 120 |
| Netherlands | 112 | 0 | 5 | 25 | 82 | 72 |
Operations & ledger
- Leak Trap Sensor 01 (retired)Retired
- SSH Sensor 01Healthy
- SSH Sensor 02Healthy
- SSH Sensor 03Healthy
- SSH Sensor 04Healthy
- Mail Sensor 01Healthy
- Leak Trap Sensor 02Healthy
- Mail Sensor 02Healthy
Health is collector liveness, proven by a heartbeat every 5 min; observation activity is reported separately. A collector that has seen no abuse is not an unhealthy collector. Each trace shows indicators the sensor observed for the first time on each of the last 14 days; a flat trace means no new indicators, not no traffic.
| IP | Risk | Detections | Origin | Last seen |
|---|---|---|---|---|
| 45.45.237.65 | Low | 547 | United States AS400529 | 11 days ago |
| 213.209.159.133 | Low | 414 | Germany AS208137 | 3 days ago |
| 34.19.246.187 | Low | 330 | Canada AS396982 | 10 days ago |
| 213.209.159.84 | Low | 323 | Germany AS208137 | 4 days ago |
| 34.19.248.170 | Low | 233 | Canada AS396982 | 10 days ago |
| IP | Signal | Risk | Origin | First seenGMT+8 |
|---|---|---|---|---|
| 31.57.216.50 | Path traversal attempted over HTTP | Medium | Ljubljana, Slovenia SIAS197769 · VPS Dedicated LLC | 2026-10-09 17:3719 minutes ago |
| 31.57.216.50 | Automated web path enumeration | High | Ljubljana, Slovenia SIAS197769 · VPS Dedicated LLC | 2026-10-09 17:3619 minutes ago |
| 174.68.45.140 | Leak trap address contacted | Medium | Las Vegas, United States USAS22773 · Cox Communications Inc. | 2026-10-09 16:351 hour ago |
| 35.212.188.111 | Sensitive file probing over HTTP | Medium | The Dalles, United States USGoogle LLC | 2026-10-09 12:385 hours ago |
| 68.227.77.60 | Leak trap address contacted | Medium | Springdale, United States USAS22773 · Cox Communications Inc. | 2026-10-09 11:156 hours ago |