AR

Abuse Radar Threat Feed

Sanitized threat intelligence from monitored infrastructure.

Abuse intelligence, cleaned for public use.

Collector signals are normalized into a public-safe feed with source details, usernames, hostnames, and raw logs removed.

The Abuse Radar Threat Feed publishes sanitized SSH abuse, mail brute force, credential guessing, and leak trap signals for defenders who need current IP threat intelligence without exposing private infrastructure logs. IP context can be checked against the AbuseIPDB reference while this page keeps bulk IP lookup links out of the table to avoid noisy external-link counts.

Use the sections below to check an IP, review active signals, download blocklists, and integrate the public JSON API.

Latest signal2026-08-12 03:45 GMT+8
Unique records4496
Total detections7844
Active records1829
Last 24h163
Leak signals3776
Geo pending0
Total visitors1151
Current visitors2
3995Active signals

Attack Mix

Active detections grouped by public-safe category.

This mix helps separate SSH attacks, mail authentication abuse, leak trap hits, and other abuse patterns before reviewing individual IP records.

SSH attacks408
Mail brute/auth272
Leak trap3315
Other0

Country Signal Map

Approximate country placement from IP geolocation. Point size follows detection volume.

The map is a quick geographic view of current threat feed activity and should be treated as operational context, not attribution.

Live Threat Flow

Collector Health

  • Leak Trap Sensor 012026-08-12 03:45 GMT+8Live
  • Mail Sensor 012026-08-11 19:55 GMT+8Warm
  • Mail Sensor 022026-08-11 19:55 GMT+8Warm
  • SSH Sensor 012026-08-11 16:58 GMT+8Warm
  • SSH Sensor 022026-08-11 12:48 GMT+8Warm
  • SSH Sensor 032026-08-11 10:49 GMT+8Warm
  • SSH Sensor 042026-08-11 10:45 GMT+8Warm

Latest Geo Signals

  • 111.70.9.235Taiwan TWLeak trap address contacted · 2026-08-12 03:45 GMT+8
  • 27.188.184.13China CNLeak trap address contacted · 2026-08-12 02:40 GMT+8
  • 124.149.237.63Australia AULeak trap address contacted · 2026-08-12 02:10 GMT+8
  • 68.227.32.120United States USLeak trap address contacted · 2026-08-12 02:10 GMT+8
  • 101.13.4.119Taiwan TWLeak trap address contacted · 2026-08-12 00:55 GMT+8
  • 201.28.237.90Brazil BRLeak trap address contacted · 2026-08-12 00:45 GMT+8
  1. ChinaCN790
  2. South KoreaKR453
  3. IndiaIN414
  4. United StatesUS301
  5. Russian FederationRU299
  6. BrazilBR228
  7. NetherlandsNL180
  8. TaiwanTW151
  9. SwedenSE102
  10. IndonesiaID85

Plain IP Blocklists

One IP per line, no reason, source, username, or raw log details.

Choose shorter windows for aggressive blocking or longer windows when you want broader coverage from the active Abuse Radar feed.

Signal Ledger

The signal ledger lists the latest active and archived records with reason, country context, first seen time, last seen time, and blocklist eligibility.

IPReasonSeverityIP DetailFirst SeenLast SeenDetectionsFeed
Leak trap address contacted Medium China (CN)China Unicom China169 Backbone 2026-05-18 20:50 GMT+82 months ago 2026-07-15 04:20 GMT+827 days ago 2 30d list only
Leak trap address contacted Medium United States (US)Fabulous Fiber LLC 2026-05-24 17:45 GMT+82 months ago 2026-07-15 04:20 GMT+827 days ago 3 30d list only
Leak trap address contacted Medium South Korea (KR)Korea Telecom 2026-07-15 03:50 GMT+828 days ago 2026-07-15 03:50 GMT+828 days ago 1 30d list only
Leak trap address contacted Medium Bolivia (BO)AXS Bolivia S. A. 2026-05-24 03:05 GMT+82 months ago 2026-07-15 03:05 GMT+828 days ago 2 30d list only
Leak trap address contacted Medium Russian Federation (RU)PJSC Rostelecom 2026-05-27 20:10 GMT+82 months ago 2026-07-15 02:35 GMT+828 days ago 3 30d list only
Leak trap address contacted Medium China (CN)No.31,Jin-rong Street 2026-05-25 19:20 GMT+82 months ago 2026-07-15 02:35 GMT+828 days ago 2 30d list only
Leak trap address contacted Medium China (CN)CHINA169-Backbone - CHINA UNICOM China169 Backbone 2026-05-27 04:25 GMT+82 months ago 2026-07-15 02:35 GMT+828 days ago 2 30d list only
Leak trap address contacted Medium Finland (FI)TSF-IP-Core Telia Finland Oyj 2026-05-25 03:00 GMT+82 months ago 2026-07-15 02:35 GMT+828 days ago 2 30d list only
Leak trap address contacted Medium Taiwan (TW)Mobile Business Group 2026-07-15 02:35 GMT+828 days ago 2026-07-15 02:35 GMT+828 days ago 1 30d list only
Leak trap address contacted Medium Bosnia and Herzegovina (BA)BH Telecom d.d. Sarajevo 2026-05-25 01:00 GMT+82 months ago 2026-07-15 02:00 GMT+828 days ago 2 30d list only
Suspicious mail authentication attempts Medium Belgium (BE)Datacamp Limited 2026-07-15 00:15 GMT+828 days ago 2026-07-15 00:15 GMT+828 days ago 4 30d list only
Suspicious SSH authentication attempts Medium Indonesia (ID)PT Netciti Persada 2026-06-06 12:16 GMT+82 months ago 2026-07-14 20:40 GMT+828 days ago 5 30d list only
Leak trap address contacted Medium Hong Kong (HK)Antbox Networks Limited 2026-07-14 18:10 GMT+828 days ago 2026-07-14 18:10 GMT+828 days ago 1 30d list only
Suspicious SSH authentication attempts Low China (CN)China Telecom Group 2026-07-14 15:17 GMT+828 days ago 2026-07-14 15:17 GMT+828 days ago 1 30d list only
Suspicious SSH authentication attempts Medium China (CN)CMNET-Jiangsu-AP - China Mobile communications corporation 2026-07-14 14:23 GMT+828 days ago 2026-07-14 14:23 GMT+828 days ago 3 30d list only
Suspicious SSH authentication attempts High China (CN)China Mobile Communications Group Co., Ltd. 2026-06-28 23:15 GMT+81 month ago 2026-07-14 14:03 GMT+828 days ago 7 30d list only
Suspicious SSH authentication attempts Medium China (CN)No.31,Jin-rong Street 2026-06-22 03:05 GMT+81 month ago 2026-07-14 08:47 GMT+828 days ago 4 30d list only
Suspicious SSH authentication attempts Medium China (CN)No.31,Jin-rong Street 2026-07-14 01:52 GMT+829 days ago 2026-07-14 01:52 GMT+829 days ago 3 30d list only
Suspicious SSH authentication attempts Medium China (CN)CMNET-Jiangsu-AP - China Mobile communications corporation 2026-07-13 23:06 GMT+829 days ago 2026-07-13 23:06 GMT+829 days ago 3 30d list only
Suspicious SSH authentication attempts Low China (CN)China Unicom Guangzhou network 2026-07-13 22:24 GMT+829 days ago 2026-07-13 22:24 GMT+829 days ago 1 30d list only
Leak trap address contacted Medium Viet Nam (VN)Viettel Group 2026-07-13 21:40 GMT+829 days ago 2026-07-13 21:40 GMT+829 days ago 1 30d list only
Suspicious SSH authentication attempts Low China (CN)No.31,Jin-rong Street 2026-07-13 20:57 GMT+829 days ago 2026-07-13 20:57 GMT+829 days ago 1 30d list only
Leak trap address contacted Medium Morocco (MA)MEDITELECOM 2026-07-13 19:55 GMT+829 days ago 2026-07-13 19:55 GMT+829 days ago 1 30d list only
Suspicious SSH authentication attempts High China (CN)CMNET-Zhejiang-AP - China Mobile communications corporation 2026-05-26 19:07 GMT+82 months ago 2026-07-13 18:48 GMT+829 days ago 6 30d list only
Suspicious SSH authentication attempts High China (CN)No.31,Jin-rong Street 2026-07-09 05:34 GMT+81 month ago 2026-07-13 16:55 GMT+829 days ago 6 30d list only
Leak trap address contacted Medium United States (US)Riseup Networks 2026-07-13 12:55 GMT+829 days ago 2026-07-13 12:55 GMT+829 days ago 1 30d list only
Suspicious SSH authentication attempts Medium Indonesia (ID)PT Mora Telematika Indonesia 2026-07-04 02:08 GMT+81 month ago 2026-07-13 10:21 GMT+829 days ago 2 30d list only
Suspicious SSH authentication attempts Low China (CN)China Unicom Shenzen network 2026-07-13 04:56 GMT+829 days ago 2026-07-13 04:56 GMT+829 days ago 1 30d list only
Suspicious SSH authentication attempts Medium China (CN)CMNET-Hunan-AP - China Mobile communications corporation 2026-06-09 02:23 GMT+82 months ago 2026-07-13 04:50 GMT+829 days ago 5 30d list only
Showing 29 of 1829 matched records. Page 37 of 37.