Flytrap: Live Cyber Attack Map

A network telescope. Nothing is legitimately hosted on this router, so every connection here is a scan, probe, or bot.

Public data · stats refresh hourly · Last 5 Min delayed by 5 min

Stats last computed: 2026-08-17 20:00:04 UTC

Overview Top Sources Map Search Last 5 Min About

Overview

Average per 5 min

49.7

Last hour (live)

637

Last 24 hours

14,300

Last 30 days

371,068

Top Sources (last 24 hours)

Top 10 Ports

TELNET / 23
946
SSH / 22
523
WWW-HTTP / 80
224
HTTPS / 443
136
MS-WBT-SERVER / 3389
110
HTTP-ALT / 8080
91
SIP / 5060
87
SIP / 5060
74
PCSYNC-HTTPS / 8443
61
RFB / 5900
55

Top 10 Networks

Modat B.V. (AS209334)
2391
Google LLC (AS396982)
1725
Hydra Communications Lt…
1474
ONYPHE SAS (AS213412)
723
ReliableSite.Net LLC (A…
649
Pfcloud UG (haftungsbes…
564
Hurricane Electric LLC …
371
Censys, Inc. (AS398324)
331
Amazon.com, Inc. (AS146…
303
Microsoft Corporation (…
285

Top 10 IPs

136.65.37.142/32
716
172.110.223.179/32
564
204.76.203.226/32
399
198.46.134.48/32
94
85.217.149.68/32
60
85.217.140.48/32
55
195.182.16.23/32
55
5.61.209.44/32
55
85.217.140.53/32
53
85.217.140.10/32
53

Suspicious /24 Subnets excludes known-benign scanners (Modat, Censys, etc)

Subnet Unique IPs Total Hits Network(s)
69.5.169.0/24 165 371 Hydra Communications Ltd
205.210.31.0/24 108 155 Google LLC
198.235.24.0/24 104 159 Google LLC
147.185.132.0/24 103 138 Google LLC
65.49.1.0/24 78 94 Hurricane Electric LLC
64.62.156.0/24 77 99 Hurricane Electric LLC
35.203.210.0/24 73 87 Google LLC
147.185.133.0/24 71 83 Google LLC
162.216.150.0/24 71 82 Google LLC
162.216.149.0/24 71 81 Google LLC
35.203.211.0/24 62 73 Google LLC
64.62.197.0/24 57 64 Hurricane Electric LLC
216.25.89.0/24 47 71 Google LLC
194.88.98.0/24 34 82 Hydra Communications Ltd
81.19.216.0/24 30 88 Hydra Communications Ltd

Suspicious IPv6 /48 Blocks excludes known-benign scanners

No non-benign IPv6 /48 blocks flagged in this window.

Map

Probes by Country

Last 30 days

370,982 Hits 169 Countries
0
delayed 5 min

Last 5 Minutes

Source IP, ASN, country, and destination port only. Our own infrastructure is never shown. Not auto-updating — use Refresh.

Time (UTC) Source IP Country ASN / Org Port / Service
2026-08-17 20:06:00 45.194.67.120 United States AS215925 Vpsvault.host Ltd 1900/udp (ssdp)
2026-08-17 20:05:55 85.217.140.53 France AS209334 Modat B.V. 40003/tcp
2026-08-17 20:05:26 156.225.1.86 Hong Kong AS9465 AGOTOZ PTE. LTD. 995/tcp (pop3s)
2026-08-17 20:05:26 193.46.255.250 Romania AS47890 Unmanaged Ltd 8060/udp (aero)
2026-08-17 20:05:02 52.91.195.196 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:05:00 52.91.195.196 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:04:59 54.226.74.194 United States AS14618 Amazon.com, Inc. 3232/tcp (mdtp)
2026-08-17 20:04:59 52.91.195.196 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:04:58 18.206.38.153 United States AS14618 Amazon.com, Inc. 443/tcp (https)
2026-08-17 20:04:57 54.226.74.194 United States AS14618 Amazon.com, Inc. 3232/tcp (mdtp)
2026-08-17 20:04:56 157.230.188.141 United States AS14061 DigitalOcean, LLC 7443/tcp (oracleas-https)
2026-08-17 20:04:56 54.226.74.194 United States AS14618 Amazon.com, Inc. 3232/tcp (mdtp)
2026-08-17 20:04:56 18.206.38.153 United States AS14618 Amazon.com, Inc. 443/tcp (https)
2026-08-17 20:04:55 18.206.38.153 United States AS14618 Amazon.com, Inc. 443/tcp (https)
2026-08-17 20:04:55 3.83.162.99 United States AS14618 Amazon.com, Inc. 13443/tcp
2026-08-17 20:04:54 50.19.171.136 United States AS14618 Amazon.com, Inc. 12443/tcp
2026-08-17 20:04:54 183.12.164.212 China AS4134 Chinanet 49789/udp
2026-08-17 20:04:53 13.219.99.134 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:04:53 188.232.206.51 Russia AS41843 JSC ER-Telecom Holding 23/tcp (telnet)
2026-08-17 20:04:52 3.83.162.99 United States AS14618 Amazon.com, Inc. 13443/tcp
2026-08-17 20:04:52 188.232.206.51 Russia AS41843 JSC ER-Telecom Holding 23/tcp (telnet)
2026-08-17 20:04:52 50.19.171.136 United States AS14618 Amazon.com, Inc. 12443/tcp
2026-08-17 20:04:52 91.231.89.75 France AS213412 ONYPHE SAS 7365/tcp (lcm-server)
2026-08-17 20:04:51 3.83.162.99 United States AS14618 Amazon.com, Inc. 13443/tcp
2026-08-17 20:04:51 13.219.99.134 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:04:51 50.19.171.136 United States AS14618 Amazon.com, Inc. 12443/tcp
2026-08-17 20:04:50 13.219.99.134 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:04:49 194.187.176.56 Germany AS208843 Alpha Strike Labs GmbH 4117/tcp (hillrserv)
2026-08-17 20:04:47 54.235.52.37 United States AS14618 Amazon.com, Inc. 31337/tcp (eldim)
2026-08-17 20:04:45 54.235.52.37 United States AS14618 Amazon.com, Inc. 31337/tcp (eldim)
2026-08-17 20:04:44 54.235.52.37 United States AS14618 Amazon.com, Inc. 31337/tcp (eldim)
2026-08-17 20:04:35 85.217.149.74 Canada AS209334 Modat B.V. 8022/tcp (oa-system)
2026-08-17 20:04:35 13.222.142.21 United States AS14618 Amazon.com, Inc. 50050/tcp
2026-08-17 20:04:33 13.222.142.21 United States AS14618 Amazon.com, Inc. 50050/tcp
2026-08-17 20:04:32 13.222.142.21 United States AS14618 Amazon.com, Inc. 50050/tcp
2026-08-17 20:04:21 78.113.133.53 France AS15557 Societe Francaise Du Radiotelephone - SFR SA 23303/udp
2026-08-17 20:04:19 99.151.14.85 United States AS7018 AT&T Enterprises, LLC 31553/udp
2026-08-17 20:04:15 66.132.186.219 United States AS398324 Censys, Inc. 9599/tcp (robix)
2026-08-17 20:04:13 85.217.149.63 Canada AS209334 Modat B.V. 62308/tcp
2026-08-17 20:04:06 172.110.223.108 Hong Kong AS23470 ReliableSite.Net LLC 17410/udp
2026-08-17 20:03:41 35.203.210.173 United Kingdom AS396982 Google LLC 10413/tcp
2026-08-17 20:03:40 43.228.157.9 Pakistan AS205759 Ghosty Networks LLC 1620/tcp (faxportwinport)
2026-08-17 20:03:38 45.148.10.230 The Netherlands AS48090 Techoff Srv Limited 60022/tcp
2026-08-17 20:03:29 54.145.20.113 United States AS14618 Amazon.com, Inc. 22/tcp (ssh)
2026-08-17 20:03:25 54.145.20.113 United States AS14618 Amazon.com, Inc. 22/tcp (ssh)
2026-08-17 20:03:24 85.217.140.54 France AS209334 Modat B.V. 1344/tcp (icap)
2026-08-17 20:03:23 54.145.20.113 United States AS14618 Amazon.com, Inc. 22/tcp (ssh)
2026-08-17 20:03:22 54.145.20.113 United States AS14618 Amazon.com, Inc. 22/tcp (ssh)
2026-08-17 20:03:21 44.201.252.11 United States AS14618 Amazon.com, Inc. 21/tcp (ftp)
2026-08-17 20:03:20 193.176.29.29 United Kingdom AS25369 Hydra Communications Ltd 3135/tcp (peerbook-port)
2026-08-17 20:03:17 44.201.252.11 United States AS14618 Amazon.com, Inc. 21/tcp (ftp)
2026-08-17 20:03:15 44.201.252.11 United States AS14618 Amazon.com, Inc. 21/tcp (ftp)
2026-08-17 20:03:14 44.201.252.11 United States AS14618 Amazon.com, Inc. 21/tcp (ftp)
2026-08-17 20:03:09 118.193.57.218 Thailand AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED 1154/tcp (resacommunity)
2026-08-17 20:03:01 100.58.171.235 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:59 100.58.171.235 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:58 34.205.139.179 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:02:58 100.58.171.235 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:56 85.217.140.40 France AS209334 Modat B.V. 83/tcp (mit-ml-dev)
2026-08-17 20:02:56 34.205.139.179 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:02:56 195.184.76.13 United States AS213412 ONYPHE SAS 12326/tcp
2026-08-17 20:02:55 34.205.139.179 United States AS14618 Amazon.com, Inc. 9200/tcp (wap-wsp)
2026-08-17 20:02:52 85.217.140.5 France AS209334 Modat B.V. 7001/tcp (afs3-callback)
2026-08-17 20:02:42 20.64.105.253 United States AS8075 Microsoft Corporation 5984/tcp (couchdb)
2026-08-17 20:02:41 13.218.231.196 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:40 81.19.216.79 The Netherlands AS25369 Hydra Communications Ltd 946/tcp
2026-08-17 20:02:40 79.124.59.182 Bulgaria AS50360 Tamatiya EOOD 2607/tcp (connection)
2026-08-17 20:02:40 18.206.124.95 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:40 13.218.90.220 United States AS14618 Amazon.com, Inc. 7443/tcp (oracleas-https)
2026-08-17 20:02:39 13.218.231.196 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:38 13.218.231.196 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:38 18.206.124.95 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:38 13.218.90.220 United States AS14618 Amazon.com, Inc. 7443/tcp (oracleas-https)
2026-08-17 20:02:37 18.206.124.95 United States AS14618 Amazon.com, Inc. 8443/tcp (pcsync-https)
2026-08-17 20:02:37 13.218.90.220 United States AS14618 Amazon.com, Inc. 7443/tcp (oracleas-https)
2026-08-17 20:02:33 54.242.243.244 United States AS14618 Amazon.com, Inc. 3389/tcp (ms-wbt-server)
2026-08-17 20:02:32 18.215.151.183 United States AS14618 Amazon.com, Inc. 1224/tcp (vpnz)
2026-08-17 20:02:32 194.50.235.136 United Kingdom AS25369 Hydra Communications Ltd 2000/tcp (cisco-sccp)
2026-08-17 20:02:31 54.242.243.244 United States AS14618 Amazon.com, Inc. 3389/tcp (ms-wbt-server)
2026-08-17 20:02:30 18.215.151.183 United States AS14618 Amazon.com, Inc. 1224/tcp (vpnz)
2026-08-17 20:02:30 54.242.243.244 United States AS14618 Amazon.com, Inc. 3389/tcp (ms-wbt-server)
2026-08-17 20:02:29 18.215.151.183 United States AS14618 Amazon.com, Inc. 1224/tcp (vpnz)
2026-08-17 20:02:23 3.89.231.206 United States AS14618 Amazon.com, Inc. 8080/tcp (http-alt)
2026-08-17 20:02:23 91.230.168.131 United States AS213412 ONYPHE SAS 2512/tcp (citrixima)
2026-08-17 20:02:21 3.89.231.206 United States AS14618 Amazon.com, Inc. 8080/tcp (http-alt)
2026-08-17 20:02:20 3.89.231.206 United States AS14618 Amazon.com, Inc. 8080/tcp (http-alt)
2026-08-17 20:02:15 152.32.149.246 United States AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED 2086/tcp (gnunet)
2026-08-17 20:02:03 167.94.145.25 United States AS398705 Censys, Inc. 6667/tcp
2026-08-17 20:02:01 198.235.24.42 United States AS396982 Google LLC 888/tcp (cddbp)
2026-08-17 20:01:54 41.90.172.175 Kenya AS33771 Safaricom Limited 23/tcp (telnet)
2026-08-17 20:01:54 41.90.172.175 Kenya AS33771 Safaricom Limited 22/tcp (ssh)
2026-08-17 20:01:53 41.90.172.175 Kenya AS33771 Safaricom Limited 22/tcp (ssh)
2026-08-17 20:01:53 41.90.172.175 Kenya AS33771 Safaricom Limited 23/tcp (telnet)
2026-08-17 20:01:47 41.90.172.175 Kenya AS33771 Safaricom Limited 22/tcp (ssh)
2026-08-17 20:01:47 41.90.172.175 Kenya AS33771 Safaricom Limited 23/tcp (telnet)
2026-08-17 20:01:41 31.14.254.5 United Kingdom AS25369 Hydra Communications Ltd 5666/tcp (nrpe)
2026-08-17 20:01:24 5.61.209.44 Seychelles AS206264 Amarutu Technology Ltd 84/tcp (ctf)
2026-08-17 20:01:17 188.241.120.4 Switzerland AS25369 Hydra Communications Ltd 3389/tcp (ms-wbt-server)

What this data actually shows

We run a public IP with nothing on it. No website, no mail server, no anything a real visitor would ever want. Anything that connects to it wasn't invited, which makes it a clean way to watch what the internet actually does when nobody's looking.

Right now we're seeing a steady mix of TCP scanning and a smaller, quieter stream of UDP probes. TCP dominates because it's cheap and unambiguous for an attacker to run at scale, a single SYN packet tells you in one round trip whether something's listening. SSH, RDP and Telnet show up constantly, along with SMB, all the classic access points botnets and credential-stuffing tools go after first. We've also watched the same source IP retry an SMTP connection six times in five seconds, which is what an automated relay-hunting script looks like when it doesn't get an answer.

UDP tells a different story. SIP shows up a lot, VoIP infrastructure gets probed heavily and consistently. SNMP and NTP appear too, often from sources checking whether they've found an open amplification target rather than anything aimed at us specifically. SSDP and mDNS point at IoT and device discovery scans. We've seen BACnet, which is a building automation protocol, meaning someone out there is specifically hunting for exposed industrial and facilities control systems. Port 1434 still gets hit occasionally, decades after the Slammer worm made it infamous.

IPv6 barely registers by comparison. Out of everything we log, IPv6 traffic is a tiny fraction of the total, and that gap is really the whole story of why IPv4 gets hammered and IPv6 doesn't. IPv4's address space is small enough that scanning all of it is a weekend project for anyone with a botnet. IPv6 per subnet alone has more addresses than anyone could ever brute-force, so attackers rely on DNS records, certificate transparency logs and leaked lists instead of blind scanning. A telescope with nothing pointing at it from either protocol makes that difference obvious in a way a live production server never would.

None of this is unique to us. Every unused IP on the internet sees roughly this shape of traffic, which is the actual point, this is what the background noise looks like everywhere, all the time, whether anyone's watching or not.

How we get this data

Every connection attempt that reaches this IP gets logged before it's dropped. We whitelist our own management access and infrastructure so we're not counting ourselves, everything else that shows up is unsolicited by definition. Each source IP gets enriched against MaxMind's databases for network ownership, ASN and rough geography, and destination ports get matched against IANA's official service name registry so a hit on port 1433 shows up as MS-SQL rather than a bare number.

We also maintain a manual allowlist for networks we've confirmed belong to legitimate internet research, companies like Censys and Onyphe run continuous scanning as their actual business, cataloguing what's reachable rather than trying to break into it. We exclude those from anything we flag as suspicious, since lumping a research crawler in with a credential-stuffing botnet would make the data less useful, not more. This is the same anonymized, aggregated approach behind our Global Analytics data, just pointed at unsolicited traffic instead of site performance.

Questions, feedback, or a benign network request

If you run scanning infrastructure and want your network excluded from anything we publish as suspicious, email us at [email protected]. We'll check that the ASN in question is actually used for security research or similar legitimate scanning, not just a hosting provider with mixed traffic, before adding it. Same address for anything else, questions about the data, requests, or general feedback.