Flytrap: Live Cyber Attack Map

A network telescope. Nothing is legitimately hosted on this router, so every connection here is a scan, probe, or bot.

Public data · stats refresh hourly · Last 5 Min delayed by 5 min

Stats last computed: 2026-07-29 15:00:02 UTC

Overview Top Sources Map Search Last 5 Min About

Overview

Average per 5 min

62.6

Last hour (live)

645

Last 24 hours

18,019

Last 30 days

90,101

Top Sources (last 24 hours)

Top 10 Ports

TELNET / 23
6092
HTTPS / 443
153
WWW-HTTP / 80
141
SSH / 22
139
MS-WBT-SERVER / 3389
134
HTTP-ALT / 8080
130
ETHERNET/IP-1 / 2222
57
PCSYNC-HTTPS / 8443
47
SIP / 5060
46
MICROSOFT-DS / 445
42

Top 10 Networks

DigitalOcean, LLC (AS14…
5006
Hydra Communications Lt…
1853
Modat B.V. (AS209334)
1414
Google LLC (AS396982)
1157
ONYPHE SAS (AS213412)
959
Media Sat Srl (AS8751)
721
UCLOUD INFORMATION TECH…
413
Hurricane Electric LLC …
371
Censys, Inc. (AS398324)
369
Microsoft Corporation (…
363

Top 10 IPs

164.90.148.8/32
4842
93.113.10.194/32
721
27.254.77.155/32
211
2.27.52.79/32
150
2.188.239.51/32
149
172.110.223.179/32
148
194.180.49.219/32
126
5.187.35.26/32
74
45.142.193.169/32
74
67.220.180.114/32
56

Suspicious /24 Subnets excludes known-benign scanners (Modat, Censys, etc)

Subnet Unique IPs Total Hits Network(s)
69.5.169.0/24 181 474 Hydra Communications Ltd
198.235.24.0/24 117 171 Google LLC
147.185.132.0/24 112 157 Google LLC
205.210.31.0/24 110 177 Google LLC
64.62.156.0/24 93 120 Hurricane Electric LLC
147.185.133.0/24 79 95 Google LLC
35.203.210.0/24 78 98 Google LLC
35.203.211.0/24 78 94 Google LLC
65.49.1.0/24 71 94 Hurricane Electric LLC
162.216.149.0/24 69 83 Google LLC
162.216.150.0/24 68 90 Google LLC
64.62.197.0/24 52 62 Hurricane Electric LLC
216.25.89.0/24 48 81 Google LLC
194.88.98.0/24 37 106 Hydra Communications Ltd
45.82.76.0/24 34 63 Detai Prosperous Technologies Limited

Suspicious IPv6 /48 Blocks excludes known-benign scanners

No non-benign IPv6 /48 blocks flagged in this window.

Map

Probes by Country

Last 30 days

90,084 Hits 132 Countries
0

Last 5 Minutes delayed 5 min

Source IP, ASN, country, and destination port only. Our own infrastructure is never shown. Not auto-updating — use Refresh.

Refresh
Time (UTC) Source IP Country ASN / Org Port / Service
2026-07-29 15:46:32 66.132.186.252 United States AS398324 Censys, Inc. 6008/tcp
2026-07-29 15:46:27 193.163.125.110 United Kingdom AS211298 Driftnet Ltd 9903/tcp
2026-07-29 15:46:16 157.20.144.241 Indonesia AS150279 PT Lintas Network Solusi 5577/tcp
2026-07-29 15:46:09 81.19.216.82 The Netherlands AS25369 Hydra Communications Ltd 8767/tcp (core-of-source)
2026-07-29 15:46:08 5.187.35.26 The Netherlands AS206264 Amarutu Technology Ltd 3795/tcp (myblast)
2026-07-29 15:46:04 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:45:53 47.250.185.143 Malaysia AS45102 Alibaba (US) Technology Co., Ltd. 8023/tcp (arca-api)
2026-07-29 15:45:51 156.225.1.87 Hong Kong AS9465 AGOTOZ PTE. LTD. 9134/tcp
2026-07-29 15:45:47 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:45:42 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:45:28 66.132.195.15 United States AS398324 Censys, Inc. 1367/tcp (dcs)
2026-07-29 15:45:24 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:45:23 156.225.1.10 Hong Kong AS9465 AGOTOZ PTE. LTD. 22/tcp (ssh)
2026-07-29 15:45:21 27.254.77.155 Thailand AS4750 CS LOXINFO PUBLIC COMPANY LIMITED 23/tcp (telnet)
2026-07-29 15:45:20 188.240.59.29 United Kingdom AS25369 Hydra Communications Ltd 24571/tcp
2026-07-29 15:45:17 176.65.148.58 The Netherlands AS51396 Pfcloud UG (haftungsbeschrankt) 443/tcp (https)
2026-07-29 15:45:17 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 5939/tcp
2026-07-29 15:45:14 203.156.108.68 Thailand AS55423 JasTel Network 7744/tcp (raqmon-pdu)
2026-07-29 15:45:12 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 6060/tcp
2026-07-29 15:45:12 27.254.77.155 Thailand AS4750 CS LOXINFO PUBLIC COMPANY LIMITED 23/tcp (telnet)
2026-07-29 15:45:12 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:44:50 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:44:49 20.65.194.68 United States AS8075 Microsoft Corporation 79/tcp (finger)
2026-07-29 15:44:45 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:44:45 207.90.244.19 United States AS174 Cogent Communications, LLC 3190/tcp (csvr-proxy)
2026-07-29 15:44:41 69.5.169.215 Germany AS25369 Hydra Communications Ltd 56961/tcp
2026-07-29 15:44:35 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:44:29 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 6633/tcp
2026-07-29 15:44:28 106.75.174.165 China AS58466 CHINANET Guangdong province network 49167/tcp
2026-07-29 15:44:13 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 5966/tcp
2026-07-29 15:44:11 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 5941/tcp
2026-07-29 15:44:05 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:43:46 154.16.44.134 United Kingdom AS25369 Hydra Communications Ltd 17904/tcp
2026-07-29 15:43:43 107.155.116.46 United States AS29802 HIVELOCITY, Inc. 5060/udp (sip)
2026-07-29 15:43:38 216.218.206.108 United States AS6939 Hurricane Electric LLC 2101/tcp (rtcm-sc104)
2026-07-29 15:43:37 45.79.153.51 United States AS63949 Akamai Connected Cloud 8443/tcp (pcsync-https)
2026-07-29 15:43:27 80.87.206.20 Russia AS16276 OVH SAS 4125/tcp (opsview-envoy)
2026-07-29 15:43:07 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 5980/tcp
2026-07-29 15:43:04 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:43:03 85.11.167.7 The Netherlands AS197170 TechTies Inc. 5433/tcp (pyrrho)
2026-07-29 15:42:59 91.231.89.189 France AS213412 ONYPHE SAS 3299/tcp (pdrncs)
2026-07-29 15:42:54 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:49 185.242.3.226 The Netherlands AS401626 Netiface America, Inc. 498/tcp (siam)
2026-07-29 15:42:48 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:47 184.105.139.95 United States AS6939 Hurricane Electric LLC 789/tcp
2026-07-29 15:42:46 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:33 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:32 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:31 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:29 66.132.186.252 United States AS398324 Censys, Inc. 5902/tcp
2026-07-29 15:42:26 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:23 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:42:18 37.10.113.220 United Kingdom AS25369 Hydra Communications Ltd 41911/tcp
2026-07-29 15:42:15 94.183.218.216 United Arab Emirates AS58232 Parsun Network Solutions PTY LTD 5936/tcp
2026-07-29 15:42:12 195.140.214.21 United Kingdom AS25369 Hydra Communications Ltd 53751/tcp
2026-07-29 15:42:11 185.242.226.95 United States AS202425 IP Volume inc 8569/tcp
2026-07-29 15:42:09 20.119.74.72 United States AS8075 Microsoft Corporation 7222/tcp
2026-07-29 15:42:08 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)
2026-07-29 15:41:55 193.163.125.125 United Kingdom AS211298 Driftnet Ltd 27019/tcp
2026-07-29 15:41:54 205.210.31.249 United States AS396982 Google LLC 2455/tcp (wago-io-system)
2026-07-29 15:41:39 124.29.226.124 Pakistan AS9541 Cyber Internet Services (Pvt) Ltd. 23/tcp (telnet)
2026-07-29 15:41:35 164.90.148.8 United States AS14061 DigitalOcean, LLC 23/tcp (telnet)

What this data actually shows

We run a public IP with nothing on it. No website, no mail server, no anything a real visitor would ever want. Anything that connects to it wasn't invited, which makes it a clean way to watch what the internet actually does when nobody's looking.

Right now we're seeing a steady mix of TCP scanning and a smaller, quieter stream of UDP probes. TCP dominates because it's cheap and unambiguous for an attacker to run at scale, a single SYN packet tells you in one round trip whether something's listening. SSH, RDP and Telnet show up constantly, along with SMB, all the classic access points botnets and credential-stuffing tools go after first. We've also watched the same source IP retry an SMTP connection six times in five seconds, which is what an automated relay-hunting script looks like when it doesn't get an answer.

UDP tells a different story. SIP shows up a lot, VoIP infrastructure gets probed heavily and consistently. SNMP and NTP appear too, often from sources checking whether they've found an open amplification target rather than anything aimed at us specifically. SSDP and mDNS point at IoT and device discovery scans. We've seen BACnet, which is a building automation protocol, meaning someone out there is specifically hunting for exposed industrial and facilities control systems. Port 1434 still gets hit occasionally, decades after the Slammer worm made it infamous.

IPv6 barely registers by comparison. Out of everything we log, IPv6 traffic is a tiny fraction of the total, and that gap is really the whole story of why IPv4 gets hammered and IPv6 doesn't. IPv4's address space is small enough that scanning all of it is a weekend project for anyone with a botnet. IPv6 per subnet alone has more addresses than anyone could ever brute-force, so attackers rely on DNS records, certificate transparency logs and leaked lists instead of blind scanning. A telescope with nothing pointing at it from either protocol makes that difference obvious in a way a live production server never would.

None of this is unique to us. Every unused IP on the internet sees roughly this shape of traffic, which is the actual point, this is what the background noise looks like everywhere, all the time, whether anyone's watching or not.

How we get this data

Every connection attempt that reaches this IP gets logged before it's dropped. We whitelist our own management access and infrastructure so we're not counting ourselves, everything else that shows up is unsolicited by definition. Each source IP gets enriched against MaxMind's databases for network ownership, ASN and rough geography, and destination ports get matched against IANA's official service name registry so a hit on port 1433 shows up as MS-SQL rather than a bare number.

We also maintain a manual allowlist for networks we've confirmed belong to legitimate internet research, companies like Censys and Onyphe run continuous scanning as their actual business, cataloguing what's reachable rather than trying to break into it. We exclude those from anything we flag as suspicious, since lumping a research crawler in with a credential-stuffing botnet would make the data less useful, not more. This is the same anonymized, aggregated approach behind our Global Analytics data, just pointed at unsolicited traffic instead of site performance.

Questions, feedback, or a benign network request

If you run scanning infrastructure and want your network excluded from anything we publish as suspicious, email us at [email protected]. We'll check that the ASN in question is actually used for security research or similar legitimate scanning, not just a hosting provider with mixed traffic, before adding it. Same address for anything else, questions about the data, requests, or general feedback.