Abuse intelligence, cleaned for public use.
Collector signals are normalized into a public-safe feed with source details, usernames, hostnames, and raw logs removed.
The Abuse Radar Threat Feed publishes sanitized SSH abuse, mail brute force, credential guessing, and leak trap signals for defenders who need current IP threat intelligence without exposing private infrastructure logs. IP context can be checked against the AbuseIPDB reference while this page keeps bulk IP lookup links out of the table to avoid noisy external-link counts.
Use the sections below to check an IP, review active signals, download blocklists, and integrate the public JSON API.
Attack Mix
Active detections grouped by public-safe category.
This mix helps separate SSH attacks, mail authentication abuse, leak trap hits, and other abuse patterns before reviewing individual IP records.
Country Signal Map
Approximate country placement from IP geolocation. Point size follows detection volume.
The map is a quick geographic view of current threat feed activity and should be treated as operational context, not attribution.
Collector Health
- Leak Trap Sensor 012026-08-11 20:35 GMT+8Live
- Mail Sensor 012026-08-11 19:55 GMT+8Live
- Mail Sensor 022026-08-11 19:55 GMT+8Live
- SSH Sensor 012026-08-11 16:58 GMT+8Live
- SSH Sensor 022026-08-11 12:48 GMT+8Warm
- SSH Sensor 032026-08-11 10:49 GMT+8Warm
- SSH Sensor 042026-08-11 10:45 GMT+8Warm
Latest Geo Signals
2.55.126.88Israel ILLeak trap address contacted · 2026-08-11 20:35 GMT+865.20.198.159Iraq IQLeak trap address contacted · 2026-08-11 20:25 GMT+8182.151.45.136China CNLeak trap address contacted · 2026-08-11 20:25 GMT+8103.112.224.81India INLeak trap address contacted · 2026-08-11 20:25 GMT+8211.43.100.92South Korea KRLeak trap address contacted · 2026-08-11 20:15 GMT+882.65.140.218France FRLeak trap address contacted · 2026-08-11 20:15 GMT+8
- ChinaCN792
- South KoreaKR453
- IndiaIN413
- United StatesUS300
- Russian FederationRU299
- BrazilBR226
- NetherlandsNL180
- TaiwanTW148
- SwedenSE102
- IndonesiaID85
Plain IP Blocklists
One IP per line, no reason, source, username, or raw log details.
Choose shorter windows for aggressive blocking or longer windows when you want broader coverage from the active Abuse Radar feed.
Signal Ledger
The signal ledger lists the latest active and archived records with reason, country context, first seen time, last seen time, and blocklist eligibility.
| IP | Reason | Severity | IP Detail | Last Seen | Detections | Feed |
|---|---|---|---|---|---|---|
| Leak trap address contacted | Medium | Netherlands (NL)Omegatech LTD | 2026-07-22 07:30 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Germany (DE)HOSTKEY B.V. | 2026-07-22 07:30 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)CHINA169-Backbone - CHINA UNICOM China169 Backbone | 2026-07-22 07:07 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Pakistan (PK)Pakistan Telecommunication Company Limited | 2026-07-22 06:10 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)No.31,Jin-rong Street | 2026-07-22 06:05 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)InfiniaHost.com | 2026-07-22 05:25 GMT+820 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-22 02:59 GMT+820 days ago | 3 | 30d list only | |
| Suspicious mail authentication attempts | Low | Viet Nam (VN)NhanHoa Software company | 2026-07-22 00:25 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | Germany (DE)IONOS SE | 2026-07-22 00:25 GMT+820 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)No.31,Jin-rong Street | 2026-07-22 00:20 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | United States (US)Contabo Inc. | 2026-07-22 00:20 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | Netherlands (NL)Limited Network LTD | 2026-07-22 00:20 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | India (IN)DigitalOcean, LLC | 2026-07-22 00:05 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | France (FR)Contabo GmbH | 2026-07-22 00:05 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | United States (US)Oracle Corporation | 2026-07-22 00:00 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | United States (US)Alibaba US Technology Co., Ltd. | 2026-07-21 23:55 GMT+820 days ago | 1 | 30d list only | |
| Suspicious mail authentication attempts | Low | Singapore (SG)Alibaba US Technology Co., Ltd. | 2026-07-21 23:50 GMT+820 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)No.31,Jin-rong Street | 2026-07-21 23:00 GMT+820 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Optimum | 2026-07-21 23:00 GMT+820 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Thailand (TH)Ministry of education | 2026-07-21 23:00 GMT+820 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-21 22:24 GMT+820 days ago | 5 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-21 16:54 GMT+821 days ago | 3 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-21 15:30 GMT+821 days ago | 4 | 30d list only | |
| Suspicious SSH authentication attempts | Low | Indonesia (ID)telkomnet-as-ap - PT Telekomunikasi Indonesia | 2026-07-21 14:49 GMT+821 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)CHINA169-Backbone - CHINA UNICOM China169 Backbone | 2026-07-21 13:40 GMT+821 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)No.31,Jin-rong Street | 2026-07-21 12:41 GMT+821 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | Russian Federation (RU)PJSC MegaFon | 2026-07-21 12:23 GMT+821 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Charter Communications LLC | 2026-07-21 01:15 GMT+821 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Australia (AU)TPG Telecom Limited | 2026-07-21 01:15 GMT+821 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Spain (ES)IONOS SE | 2026-07-20 23:30 GMT+821 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | High | China (CN)No.31,Jin-rong Street | 2026-07-20 19:46 GMT+822 days ago | 6 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)China Mobile Group JiLin communications corporation | 2026-07-20 18:25 GMT+822 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)China Mobile Communications Group Co., Ltd. | 2026-07-20 18:25 GMT+822 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)CHINA169-Backbone - CHINA UNICOM China169 Backbone | 2026-07-20 15:38 GMT+822 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | United Arab Emirates (AE)Microsoft Corporation | 2026-07-20 13:00 GMT+822 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | Spain (ES)VODAFONE ES VODAFONE ESPANA S.A.U. | 2026-07-20 10:42 GMT+822 days ago | 3 | 30d list only | |
| Suspicious SSH authentication attempts | Low | Thailand (TH)Triple T Broadband Public Company Limited | 2026-07-20 10:19 GMT+822 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Sweden (SE)PatrikWeb-Core Patrik Lagerman | 2026-07-20 03:30 GMT+822 days ago | 2 | 30d list only | |
| Suspicious mail authentication attempts | Low | Netherlands (NL)KPRONET KPROHOST LLC | 2026-07-19 23:50 GMT+822 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)SMART NET INDIA PVT LTD | 2026-07-19 21:20 GMT+822 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Singapore (SG)DigitalOcean, LLC | 2026-07-19 21:20 GMT+822 days ago | 2 | 30d list only | |
| Suspicious mail authentication attempts | Medium | Germany (DE)IONOS SE | 2026-07-19 19:55 GMT+823 days ago | 4 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)BHARTI Airtel Ltd. | 2026-07-19 18:30 GMT+823 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)National Internet Backbone | 2026-07-19 18:30 GMT+823 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Russian Federation (RU)PJSC Rostelecom | 2026-07-19 18:30 GMT+823 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Germany (DE)Microsoft Corporation | 2026-07-19 18:30 GMT+823 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Cox Communications Inc. | 2026-07-19 18:30 GMT+823 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Israel (IL)Pelephone Communications Ltd. | 2026-07-19 18:30 GMT+823 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | South Korea (KR)Korea Telecom | 2026-07-19 17:25 GMT+823 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)China Telecom Group | 2026-07-19 17:10 GMT+823 days ago | 1 | 30d list only |