Abuse intelligence, cleaned for public use.
Collector signals are normalized into a public-safe feed with source details, usernames, hostnames, and raw logs removed.
The Abuse Radar Threat Feed publishes sanitized SSH abuse, mail brute force, credential guessing, and leak trap signals for defenders who need current IP threat intelligence without exposing private infrastructure logs. IP context can be checked against the AbuseIPDB reference while this page keeps bulk IP lookup links out of the table to avoid noisy external-link counts.
Use the sections below to check an IP, review active signals, download blocklists, and integrate the public JSON API.
Attack Mix
Active detections grouped by public-safe category.
This mix helps separate SSH attacks, mail authentication abuse, leak trap hits, and other abuse patterns before reviewing individual IP records.
Country Signal Map
Approximate country placement from IP geolocation. Point size follows detection volume.
The map is a quick geographic view of current threat feed activity and should be treated as operational context, not attribution.
Collector Health
- Leak Trap Sensor 012026-08-11 19:10 GMT+8Live
- Mail Sensor 012026-08-11 17:05 GMT+8Live
- Mail Sensor 022026-08-11 17:05 GMT+8Live
- SSH Sensor 012026-08-11 16:58 GMT+8Live
- SSH Sensor 022026-08-11 12:48 GMT+8Warm
- SSH Sensor 032026-08-11 10:49 GMT+8Warm
- SSH Sensor 042026-08-11 10:45 GMT+8Warm
Latest Geo Signals
124.153.166.170South Korea KRLeak trap address contacted · 2026-08-11 19:10 GMT+8123.210.137.163Australia AULeak trap address contacted · 2026-08-11 19:10 GMT+8122.187.227.152India INLeak trap address contacted · 2026-08-11 18:45 GMT+8192.34.164.13United States USLeak trap address contacted · 2026-08-11 17:40 GMT+8213.176.26.54Netherlands NLSuspicious mail authentication attempts · 2026-08-11 17:05 GMT+8213.176.26.94Netherlands NLSuspicious mail authentication attempts · 2026-08-11 17:05 GMT+8
- ChinaCN791
- South KoreaKR452
- IndiaIN412
- United StatesUS300
- Russian FederationRU299
- BrazilBR226
- NetherlandsNL165
- TaiwanTW148
- SwedenSE102
- IranIR94
Plain IP Blocklists
One IP per line, no reason, source, username, or raw log details.
Choose shorter windows for aggressive blocking or longer windows when you want broader coverage from the active Abuse Radar feed.
Signal Ledger
The signal ledger lists the latest active and archived records with reason, country context, first seen time, last seen time, and blocklist eligibility.
| IP | Reason | Severity | IP Detail | Last Seen | Detections | Feed |
|---|---|---|---|---|---|---|
| Leak trap address contacted | Medium | South Korea (KR)SK Broadband Co Ltd | 2026-07-24 09:15 GMT+818 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)BHARTI Airtel Ltd. | 2026-07-24 07:55 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)BHARTI Airtel Ltd. | 2026-07-24 05:55 GMT+818 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Russian Federation (RU)Kom lan Ltd | 2026-07-24 03:05 GMT+818 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Israel (IL)Cellcom Fixed Line Communication L.P | 2026-07-24 02:00 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)National Internet Backbone | 2026-07-24 01:20 GMT+818 days ago | 4 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | Indonesia (ID)telkomnet-as-ap - PT Telekomunikasi Indonesia | 2026-07-24 00:34 GMT+818 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Brazil (BR)AS18881 - TELEFONICA BRASIL S.A | 2026-07-24 00:20 GMT+818 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Taiwan (TW)taiwanmobile-as - Taiwan Mobile Co., Ltd. | 2026-07-24 00:20 GMT+818 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Russian Federation (RU)INSYS LLC | 2026-07-23 23:45 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Türkiye (TR)TURKCELL ILETISIM HIZMETLERI A.S. | 2026-07-23 23:45 GMT+818 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Israel (IL)Partner Communications Ltd. | 2026-07-23 23:45 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)UPNET | 2026-07-23 22:35 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Canada (CA)OVH SAS | 2026-07-23 21:30 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Kazakhstan (KZ)JSC Transtelecom | 2026-07-23 20:55 GMT+818 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Russian Federation (RU)PJSC Moscow city telephone network | 2026-07-23 20:55 GMT+818 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | South Korea (KR)LG HelloVision Corp. | 2026-07-23 19:10 GMT+819 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | South Korea (KR)Korea Telecom | 2026-07-23 19:10 GMT+819 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Low | Indonesia (ID)Neuviz Net | 2026-07-23 17:37 GMT+819 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | High | Viet Nam (VN)Sai gon Postel Corporation | 2026-07-23 11:50 GMT+819 days ago | 13 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)Hangzhou Alibaba Advertising Co.,Ltd. | 2026-07-23 11:35 GMT+819 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | Germany (DE)Omegatech LTD | 2026-07-23 10:10 GMT+819 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | High | South Korea (KR)Korea Telecom | 2026-07-23 10:06 GMT+819 days ago | 10 | 30d list only | |
| Leak trap address contacted | Medium | Hong Kong (HK)Tencent Building, Kejizhongyi Avenue | 2026-07-23 08:10 GMT+819 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Brazil (BR)AS18881 - TELEFONICA BRASIL S.A | 2026-07-23 06:35 GMT+819 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | High | China (CN)No.31,Jin-rong Street | 2026-07-23 05:35 GMT+819 days ago | 7 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)China Unicom Beijing Province Network | 2026-07-23 04:46 GMT+819 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)No.31,Jin-rong Street | 2026-07-23 03:01 GMT+819 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)Oracle Corporation | 2026-07-23 00:25 GMT+819 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Russian Federation (RU)PJSC Moscow city telephone network | 2026-07-22 23:20 GMT+819 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)China Mobile Communications Group Co., Ltd. | 2026-07-22 21:09 GMT+819 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)National Internet Backbone | 2026-07-22 18:45 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Netherlands (NL)Omegatech LTD | 2026-07-22 18:00 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | Indonesia (ID)telkomnet-as-ap - PT Telekomunikasi Indonesia | 2026-07-22 15:13 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)China Mobile Communicaitons Corporation | 2026-07-22 14:34 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)CHINA169-Backbone - CHINA UNICOM China169 Backbone | 2026-07-22 13:34 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)Hangzhou Alibaba Advertising Co.,Ltd. | 2026-07-22 13:05 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-22 12:05 GMT+820 days ago | 5 | 30d list only | |
| Suspicious SSH authentication attempts | Low | United Kingdom (GB)Hutchison 3G UK Limited | 2026-07-22 11:09 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | United Kingdom (GB)Hutchison 3G UK Limited | 2026-07-22 11:05 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | High | China (CN)No.31,Jin-rong Street | 2026-07-22 10:51 GMT+820 days ago | 7 | 30d list only | |
| Suspicious SSH authentication attempts | Low | Indonesia (ID)telkomnet-as-ap - PT Telekomunikasi Indonesia | 2026-07-22 10:36 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Taiwan (TW)Mobile Business Group | 2026-07-22 09:25 GMT+820 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Mozambique (MZ)Movitel, SA - Movitel, SA | 2026-07-22 09:25 GMT+820 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Netherlands (NL)Omegatech LTD | 2026-07-22 09:20 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-22 08:01 GMT+820 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Netherlands (NL)Omegatech LTD | 2026-07-22 07:30 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Germany (DE)HOSTKEY B.V. | 2026-07-22 07:30 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)CHINA169-Backbone - CHINA UNICOM China169 Backbone | 2026-07-22 07:07 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Pakistan (PK)Pakistan Telecommunication Company Limited | 2026-07-22 06:10 GMT+820 days ago | 1 | 30d list only |