Abuse intelligence, cleaned for public use.
Collector signals are normalized into a public-safe feed with source details, usernames, hostnames, and raw logs removed.
The Abuse Radar Threat Feed publishes sanitized SSH abuse, mail brute force, credential guessing, and leak trap signals for defenders who need current IP threat intelligence without exposing private infrastructure logs. IP context can be checked against the AbuseIPDB reference while this page keeps bulk IP lookup links out of the table to avoid noisy external-link counts.
Use the sections below to check an IP, review active signals, download blocklists, and integrate the public JSON API.
Attack Mix
Active detections grouped by public-safe category.
This mix helps separate SSH attacks, mail authentication abuse, leak trap hits, and other abuse patterns before reviewing individual IP records.
Country Signal Map
Approximate country placement from IP geolocation. Point size follows detection volume.
The map is a quick geographic view of current threat feed activity and should be treated as operational context, not attribution.
Collector Health
- Leak Trap Sensor 012026-08-12 02:40 GMT+8Live
- Mail Sensor 012026-08-11 19:55 GMT+8Warm
- Mail Sensor 022026-08-11 19:55 GMT+8Warm
- SSH Sensor 012026-08-11 16:58 GMT+8Warm
- SSH Sensor 022026-08-11 12:48 GMT+8Warm
- SSH Sensor 032026-08-11 10:49 GMT+8Warm
- SSH Sensor 042026-08-11 10:45 GMT+8Warm
Latest Geo Signals
27.188.184.13China CNLeak trap address contacted · 2026-08-12 02:40 GMT+8124.149.237.63Australia AULeak trap address contacted · 2026-08-12 02:10 GMT+868.227.32.120United States USLeak trap address contacted · 2026-08-12 02:10 GMT+8101.13.4.119Taiwan TWLeak trap address contacted · 2026-08-12 00:55 GMT+8201.28.237.90Brazil BRLeak trap address contacted · 2026-08-12 00:45 GMT+8202.84.34.85Bangladesh BDLeak trap address contacted · 2026-08-11 21:40 GMT+8
- ChinaCN790
- South KoreaKR453
- IndiaIN414
- United StatesUS301
- Russian FederationRU299
- BrazilBR228
- NetherlandsNL180
- TaiwanTW150
- SwedenSE102
- IndonesiaID85
Plain IP Blocklists
One IP per line, no reason, source, username, or raw log details.
Choose shorter windows for aggressive blocking or longer windows when you want broader coverage from the active Abuse Radar feed.
Signal Ledger
The signal ledger lists the latest active and archived records with reason, country context, first seen time, last seen time, and blocklist eligibility.
| IP | Reason | Severity | IP Detail | Last Seen | Detections | Feed |
|---|---|---|---|---|---|---|
| Leak trap address contacted | Medium | Brazil (BR)FIBERLINK TELECOM LTDA | 2026-07-17 09:45 GMT+825 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Cox Communications Inc. | 2026-07-17 09:45 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)China Unicom China169 Backbone | 2026-07-17 09:45 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Italy (IT)Fastweb SPA | 2026-07-17 09:45 GMT+825 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Cablevision Systems Corp. | 2026-07-17 09:45 GMT+825 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Malaysia (MY)Digi Telecommunications Sdn Bhd., Digi Internet Exchange | 2026-07-17 09:45 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)CHINANET BACKBONE | 2026-07-17 09:45 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | South Korea (KR)Korea Telecom | 2026-07-17 08:30 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Brazil (BR)TELEFÔNICA BRASIL S.A | 2026-07-17 08:30 GMT+825 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)China Mobile | 2026-07-17 08:15 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)The Procter And Gamble Company | 2026-07-17 08:15 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Brazil (BR)Fronteira Internet | 2026-07-17 08:15 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Central Utah Telephone, Inc. | 2026-07-17 08:15 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)Bharti Airtel Limited | 2026-07-17 08:15 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Norway (NO)Austevoll Kraftlag Ba | 2026-07-17 08:15 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Canada (CA)Execulink Telecom Inc. | 2026-07-17 08:15 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)China Mobile Communications Corporation | 2026-07-17 08:15 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Russian Federation (RU)Pjsc Megafon | 2026-07-17 08:15 GMT+825 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Ethiopia (ET)Ethio Telecom | 2026-07-17 08:15 GMT+825 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)CHINANET BACKBONE | 2026-07-17 07:10 GMT+825 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | South Korea (KR)Korea Telecom | 2026-07-17 07:00 GMT+825 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Italy (IT)Telecom Italia S.P.A. | 2026-07-17 07:00 GMT+825 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | India (IN)Reliance Jio Infocomm Limited | 2026-07-16 23:16 GMT+826 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)Chinanet Guangdong Province Shenzhen Man Network | 2026-07-16 18:59 GMT+826 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | United States (US)Digitalocean, LLC | 2026-07-16 18:10 GMT+826 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)China Unicom China169 Backbone | 2026-07-16 14:35 GMT+826 days ago | 6 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)CHINANET BACKBONE | 2026-07-16 12:27 GMT+826 days ago | 5 | 30d list only | |
| Leak trap address contacted | Medium | Netherlands (NL)Worldstream B.V. | 2026-07-16 08:15 GMT+826 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | High | China (CN)CHINANET BACKBONE | 2026-07-16 03:05 GMT+826 days ago | 6 | 30d list only | |
| Leak trap address contacted | Medium | Malaysia (MY)Datacamp Limited | 2026-07-16 03:00 GMT+826 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Malaysia (MY)Datacamp Limited | 2026-07-16 02:45 GMT+827 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Germany (DE)Ecomdata GmbH | 2026-07-16 02:45 GMT+827 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Taiwan (TW)Mobile Business Group | 2026-07-16 01:25 GMT+827 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Medium | China (CN)China Unicom Shenzen Network | 2026-07-15 23:43 GMT+827 days ago | 4 | 30d list only | |
| Suspicious SSH authentication attempts | High | Indonesia (ID)Pt Bali Towerindo Sentra | 2026-07-15 23:13 GMT+827 days ago | 7 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)CHINANET BACKBONE | 2026-07-15 23:07 GMT+827 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | Indonesia (ID)PT Telekomunikasi Indonesia | 2026-07-15 16:30 GMT+827 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)CHINANET BACKBONE | 2026-07-15 14:00 GMT+827 days ago | 1 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)CHINANET BACKBONE | 2026-07-15 12:39 GMT+827 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Brazil (BR)V Tal | 2026-07-15 05:30 GMT+827 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | United Kingdom (GB)Community Fibre Limited | 2026-07-15 05:30 GMT+827 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Taiwan (TW)Mobile Business Group | 2026-07-15 05:15 GMT+827 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)Satellite Netcom Private Limited | 2026-07-15 05:00 GMT+827 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)CHINANET BACKBONE | 2026-07-15 04:55 GMT+827 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | India (IN)Bharti Airtel Limited | 2026-07-15 04:55 GMT+827 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | China (CN)CHINANET BACKBONE | 2026-07-15 04:55 GMT+827 days ago | 2 | 30d list only | |
| Suspicious SSH authentication attempts | Low | China (CN)China Unicom Shenzen Network | 2026-07-15 04:47 GMT+827 days ago | 1 | 30d list only | |
| Leak trap address contacted | Medium | Sweden (SE)Bredband2 Stockholms Stadsnaet Ab | 2026-07-15 04:20 GMT+827 days ago | 2 | 30d list only | |
| Leak trap address contacted | Medium | Finland (FI)Pyhanet Oy | 2026-07-15 04:20 GMT+827 days ago | 3 | 30d list only | |
| Leak trap address contacted | Medium | Malaysia (MY)Digi Telecommunications Sdn Bhd., Digi Internet Exchange | 2026-07-15 04:20 GMT+827 days ago | 1 | 30d list only |