Abuse intelligence, cleaned for public use.
Collector signals are normalized into a public-safe feed with source details, usernames, hostnames, and raw logs removed.
The Abuse Radar Threat Feed publishes sanitized SSH abuse, mail brute force, credential guessing, and leak trap signals for defenders who need current IP threat intelligence without exposing private infrastructure logs. IP context can be checked against the AbuseIPDB reference while this page keeps bulk IP lookup links out of the table to avoid noisy external-link counts.
Use the sections below to check an IP, review active signals, download blocklists, and integrate the public JSON API.
Attack Mix
Active detections grouped by public-safe category.
This mix helps separate SSH attacks, mail authentication abuse, leak trap hits, and other abuse patterns before reviewing individual IP records.
Country Signal Map
Approximate country placement from IP geolocation. Point size follows detection volume.
The map is a quick geographic view of current threat feed activity and should be treated as operational context, not attribution.
Collector Health
- SSH Sensor 012026-06-11 20:22 GMT+8Live
- Leak Trap Sensor 012026-06-11 18:55 GMT+8Live
- SSH Sensor 022026-06-11 12:13 GMT+8Warm
- Mail Sensor 012026-06-11 10:15 GMT+8Warm
- SSH Sensor 032026-06-11 09:54 GMT+8Warm
- SSH Sensor 042026-06-11 07:39 GMT+8Warm
- Mail Sensor 022026-06-10 12:55 GMT+8Quiet
Latest Geo Signals
221.159.21.88Republic of Korea KRSuspicious SSH authentication attempts · 2026-06-11 20:22 GMT+845.80.185.112Costa Rica CRLeak trap address contacted · 2026-06-11 18:55 GMT+8167.71.239.213India INSuspicious SSH authentication attempts · 2026-06-11 13:45 GMT+8114.247.140.114China CNSuspicious SSH authentication attempts · 2026-06-11 13:37 GMT+8114.35.183.71Taiwan TWSuspicious SSH authentication attempts · 2026-06-11 12:13 GMT+845.80.185.37Costa Rica CRLeak trap address contacted · 2026-06-11 12:00 GMT+8
- ChinaCN922
- IndiaIN642
- Republic of KoreaKR327
- RussiaRU235
- United StatesUS215
- BrazilBR171
- NetherlandsNL113
- TaiwanTW112
- MalaysiaMY100
- SwedenSE78
Plain IP Blocklists
One IP per line, no reason, source, username, or raw log details.
Choose shorter windows for aggressive blocking or longer windows when you want broader coverage from the active Abuse Radar feed.
Signal Ledger
The signal ledger lists the latest active and archived records with reason, country context, first seen time, last seen time, and blocklist eligibility.
| IP | Reason | Severity | IP Detail | Last Seen | Detections | Feed |
|---|---|---|---|---|---|---|
| Leak trap address contacted | Medium | India (IN)Bharti Airtel Limited | 2026-06-06 09:15 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Germany (DE)Ambyre LLC | 2026-06-06 08:40 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Singapore (SG)M1 LIMITED | 2026-06-06 08:20 GMT+85 days ago | 2 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | Medium | China (CN)Chinanet | 2026-06-06 08:00 GMT+85 days ago | 3 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Japan (JP)CYBERVERSE LLC | 2026-06-06 07:10 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Hong Kong (HK)Pccw Ims Limited | 2026-06-06 07:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | United States (US)Frontier Communications of America, Inc. | 2026-06-06 07:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Uzbekistan (UZ)RUBICON WIRELESS COMMUNICATION LLC | 2026-06-06 07:10 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | United Kingdom (GB)Zen Internet LTD | 2026-06-06 07:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Republic of Korea (KR)Korea Telecom | 2026-06-06 06:55 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Japan (JP)Optage Inc. | 2026-06-06 06:15 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Republic of Korea (KR)Korea Telecom | 2026-06-06 06:15 GMT+85 days ago | 1 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | High | China (CN)Chinanet | 2026-06-06 06:14 GMT+85 days ago | 5 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Netherlands (NL)Church of Cyberology | 2026-06-06 06:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | India (IN)Bharti Airtel Limited | 2026-06-06 05:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Brazil (BR)Desktop Sigmanet Comunica o Multim dia SA | 2026-06-06 05:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Malaysia (MY)Digi Telecommunications Sdn Bhd., Digi Internet Exchange | 2026-06-06 05:10 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Republic of Korea (KR)Korea Telecom | 2026-06-06 05:10 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | High | Sweden (SE)Bahnhof Ab | 2026-06-06 05:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Australia (AU)Tpg Internet Pty LTD | 2026-06-06 05:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)Chinanet Sichuan Telecom Internet Data Center | 2026-06-06 05:10 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Vietnam (VN)Viettel Group | 2026-06-06 03:05 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Sweden (SE)Telia Company Ab | 2026-06-06 03:05 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Republic of Korea (KR)Korea Telecom | 2026-06-06 03:05 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)China Telecom group | 2026-06-06 01:00 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Turkey (TR)TURKCELL ILETISIM HIZMETLERI A.S. | 2026-06-06 01:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Taiwan (TW)Mobile Business Group | 2026-06-06 01:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Indonesia (ID)Telekomunikasi Indonesia pt | 2026-06-06 01:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Russia (RU)LLC Cifrovie Seti Urala | 2026-06-06 01:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)Chinanet | 2026-06-06 01:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | Medium | China (CN)CHINANET BACKBONE | 2026-06-06 00:36 GMT+85 days ago | 1 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | Medium | China (CN)CHINANET BACKBONE | 2026-06-06 00:35 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)No. 1,jin rong Street | 2026-06-06 00:05 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)CNC Group CHINA1 Shanxi Province Network | 2026-06-06 00:05 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | India (IN)Bharti Airtel Limited | 2026-06-05 23:00 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Republic of Korea (KR)Korea Telecom | 2026-06-05 22:55 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Colombia (CO)Telmex Colombia S.A. | 2026-06-05 22:55 GMT+85 days ago | 1 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | High | Kazakhstan (KZ)Btcom Infocommunications Ltd. | 2026-06-05 22:27 GMT+85 days ago | 4 | 10/15/30d lists | |
| Leak trap address contacted | Medium | India (IN)Bharti Airtel Limited | 2026-06-05 22:00 GMT+85 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)CERNET | 2026-06-05 21:50 GMT+85 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Brazil (BR)V Tal | 2026-06-05 20:55 GMT+86 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Pakistan (PK)PLAY BROADBAND PRIVATE LIMITED | 2026-06-05 20:55 GMT+86 days ago | 2 | 10/15/30d lists | |
| Leak trap address contacted | Medium | China (CN)No. 1,jin rong Street | 2026-06-05 20:55 GMT+86 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Republic of Korea (KR)Korea Telecom | 2026-06-05 20:55 GMT+86 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Brazil (BR)Vivo | 2026-06-05 20:55 GMT+86 days ago | 2 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | Medium | China (CN)Chinanet | 2026-06-05 20:40 GMT+86 days ago | 2 | 10/15/30d lists | |
| Suspicious SSH authentication attempts | Medium | China (CN)China Mobile Communications Corporation | 2026-06-05 19:22 GMT+86 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Japan (JP)CYBERVERSE LLC | 2026-06-05 18:50 GMT+86 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Israel (IL)Partner Communications Ltd. | 2026-06-05 18:50 GMT+86 days ago | 1 | 10/15/30d lists | |
| Leak trap address contacted | Medium | Afghanistan (AF)Government Communications Network | 2026-06-05 18:50 GMT+86 days ago | 1 | 10/15/30d lists |