Flytrap: Live Cyber Attack Map
A network telescope. Nothing is legitimately hosted on this router, so every connection here is a scan, probe, or bot.
Public data · stats refresh hourly · Last 5 Min delayed by 5 minStats last computed: 2026-07-29 16:00:02 UTC
Overview
Average per 5 min
62.4
Last hour (live)
637
Last 24 hours
17,977
Last 30 days
90,753
Top Sources (last 24 hours)
Top 10 Ports
Top 10 Networks
Top 10 IPs
Suspicious /24 Subnets excludes known-benign scanners (Modat, Censys, etc)
| Subnet | Unique IPs | Total Hits | Network(s) |
|---|---|---|---|
| 69.5.169.0/24 | 181 | 487 | Hydra Communications Ltd |
| 198.235.24.0/24 | 117 | 171 | Google LLC |
| 147.185.132.0/24 | 113 | 156 | Google LLC |
| 205.210.31.0/24 | 110 | 176 | Google LLC |
| 64.62.156.0/24 | 101 | 129 | Hurricane Electric LLC |
| 35.203.210.0/24 | 76 | 96 | Google LLC |
| 65.49.1.0/24 | 75 | 100 | Hurricane Electric LLC |
| 35.203.211.0/24 | 73 | 86 | Google LLC |
| 147.185.133.0/24 | 73 | 85 | Google LLC |
| 162.216.150.0/24 | 67 | 87 | Google LLC |
| 162.216.149.0/24 | 62 | 74 | Google LLC |
| 64.62.197.0/24 | 52 | 62 | Hurricane Electric LLC |
| 216.25.89.0/24 | 47 | 80 | Google LLC |
| 194.88.98.0/24 | 37 | 108 | Hydra Communications Ltd |
| 45.82.76.0/24 | 35 | 65 | Detai Prosperous Technologies Limited |
Suspicious IPv6 /48 Blocks excludes known-benign scanners
Map
Probes by Country
Last 30 days
Search
Search by IP (1.2.3.4), CIDR (1.2.3.0/24), ASN (AS64512, 64512, or 3.2213), or country code (US, CA, BE).
Last 5 Minutes delayed 5 min
Source IP, ASN, country, and destination port only. Our own infrastructure is never shown. Not auto-updating — use Refresh.
Refresh| Time (UTC) | Source IP | Country | ASN / Org | Port / Service |
|---|---|---|---|---|
| 2026-07-29 16:50:47 | 67.220.180.114 | United States | AS55081 24 SHELLS | 23/tcp (telnet) |
| 2026-07-29 16:50:43 | 85.217.140.41 | France | AS209334 Modat B.V. | 16656/tcp |
| 2026-07-29 16:50:30 | 69.5.169.16 | Germany | AS25369 Hydra Communications Ltd | 25748/tcp |
| 2026-07-29 16:50:27 | 85.217.140.10 | France | AS209334 Modat B.V. | 42703/tcp |
| 2026-07-29 16:50:26 | 85.217.140.15 | France | AS209334 Modat B.V. | 17546/tcp |
| 2026-07-29 16:50:21 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:50:19 | 216.226.76.10 | United States | AS50219 Valence Technology Co. | 4343/tcp (unicall) |
| 2026-07-29 16:50:12 | 5.226.140.123 | United Kingdom | AS25369 Hydra Communications Ltd | 26030/tcp |
| 2026-07-29 16:50:06 | 182.253.14.140 | Indonesia | AS17451 BIZNET NETWORKS | 23/tcp (telnet) |
| 2026-07-29 16:50:00 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:49:53 | 134.122.106.248 | United Kingdom | AS14061 DigitalOcean, LLC | 32768/tcp (filenet-tms) |
| 2026-07-29 16:49:47 | 85.217.140.31 | France | AS209334 Modat B.V. | 10217/tcp |
| 2026-07-29 16:49:41 | 20.168.123.0 | United States | AS8075 Microsoft Corporation | 6066/tcp (ewctsp) |
| 2026-07-29 16:49:35 | 193.124.20.227 | Germany | AS25369 Hydra Communications Ltd | 777/tcp (multiling-http) |
| 2026-07-29 16:49:24 | 66.132.186.128 | United States | AS398324 Censys, Inc. | 11807/tcp |
| 2026-07-29 16:49:21 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:49:18 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:49:14 | 45.82.76.107 | Germany | AS212512 Detai Prosperous Technologies Limited | 111/tcp (sunrpc) |
| 2026-07-29 16:49:12 | 193.163.125.141 | United Kingdom | AS211298 Driftnet Ltd | 3190/tcp (csvr-proxy) |
| 2026-07-29 16:49:08 | 118.193.64.235 | United Kingdom | AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | 3893/tcp (cgi-starapi) |
| 2026-07-29 16:49:05 | 93.113.10.194 | Romania | AS8751 Media Sat Srl | 23/tcp (telnet) |
| 2026-07-29 16:48:58 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:48:52 | 91.231.89.149 | France | AS213412 ONYPHE SAS | 1157/tcp (iascontrol) |
| 2026-07-29 16:48:24 | 162.217.100.196 | United States | AS32475 Internap Holding LLC | 14/tcp |
| 2026-07-29 16:48:22 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:48:22 | 151.243.11.52 | United Arab Emirates | AS209630 LLC Vash Kredit Bank | 3478/udp (stun-behavior) |
| 2026-07-29 16:48:16 | 195.182.16.23 | Germany | AS206264 Amarutu Technology Ltd | 8081/tcp (sunproxyadmin) |
| 2026-07-29 16:48:15 | 69.5.169.125 | Germany | AS25369 Hydra Communications Ltd | 55484/tcp |
| 2026-07-29 16:48:15 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:48:09 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:48:09 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:48:04 | 8.209.111.212 | Germany | AS45102 Alibaba (US) Technology Co., Ltd. | 1962/tcp (biap-mp) |
| 2026-07-29 16:48:02 | 45.148.10.230 | The Netherlands | AS48090 Techoff Srv Limited | 2222/tcp (EtherNet/IP-1) |
| 2026-07-29 16:48:01 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:47:58 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:47:57 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:47:48 | 77.110.114.66 | United States | AS203273 NetCrafters OU | 8443/tcp (pcsync-https) |
| 2026-07-29 16:47:48 | 193.163.125.144 | United Kingdom | AS211298 Driftnet Ltd | 1005/tcp |
| 2026-07-29 16:47:24 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:47:23 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:47:16 | 193.3.53.4 | United States | AS211607 Securitytrails, LLC | 5001/tcp (commplex-link) |
| 2026-07-29 16:47:15 | 213.166.84.47 | United Kingdom | AS25369 Hydra Communications Ltd | 855/tcp |
| 2026-07-29 16:47:08 | 180.167.128.202 | China | AS4812 China Telecom (Group) | 22/tcp (ssh) |
| 2026-07-29 16:47:04 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:46:56 | 27.254.77.155 | Thailand | AS4750 CS LOXINFO PUBLIC COMPANY LIMITED | 23/tcp (telnet) |
| 2026-07-29 16:46:45 | 185.200.118.46 | United Kingdom | AS9009 M247 Europe SRL | 443/udp (https) |
| 2026-07-29 16:46:43 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:46:35 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:46:29 | 45.82.76.106 | Germany | AS212512 Detai Prosperous Technologies Limited | 616/tcp (sco-sysmgr) |
| 2026-07-29 16:46:28 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:46:25 | 89.37.172.150 | United Kingdom | AS25369 Hydra Communications Ltd | 34779/tcp |
| 2026-07-29 16:46:19 | 164.90.148.8 | United States | AS14061 DigitalOcean, LLC | 23/tcp (telnet) |
| 2026-07-29 16:46:14 | 195.184.76.195 | United States | AS213412 ONYPHE SAS | 4738/tcp (solera-lpn) |
| 2026-07-29 16:46:13 | 45.133.173.241 | United Kingdom | AS25369 Hydra Communications Ltd | 60941/tcp |
| 2026-07-29 16:46:01 | 85.217.140.36 | France | AS209334 Modat B.V. | 63472/tcp |
What this data actually shows
We run a public IP with nothing on it. No website, no mail server, no anything a real visitor would ever want. Anything that connects to it wasn't invited, which makes it a clean way to watch what the internet actually does when nobody's looking.
Right now we're seeing a steady mix of TCP scanning and a smaller, quieter stream of UDP probes. TCP dominates because it's cheap and unambiguous for an attacker to run at scale, a single SYN packet tells you in one round trip whether something's listening. SSH, RDP and Telnet show up constantly, along with SMB, all the classic access points botnets and credential-stuffing tools go after first. We've also watched the same source IP retry an SMTP connection six times in five seconds, which is what an automated relay-hunting script looks like when it doesn't get an answer.
UDP tells a different story. SIP shows up a lot, VoIP infrastructure gets probed heavily and consistently. SNMP and NTP appear too, often from sources checking whether they've found an open amplification target rather than anything aimed at us specifically. SSDP and mDNS point at IoT and device discovery scans. We've seen BACnet, which is a building automation protocol, meaning someone out there is specifically hunting for exposed industrial and facilities control systems. Port 1434 still gets hit occasionally, decades after the Slammer worm made it infamous.
IPv6 barely registers by comparison. Out of everything we log, IPv6 traffic is a tiny fraction of the total, and that gap is really the whole story of why IPv4 gets hammered and IPv6 doesn't. IPv4's address space is small enough that scanning all of it is a weekend project for anyone with a botnet. IPv6 per subnet alone has more addresses than anyone could ever brute-force, so attackers rely on DNS records, certificate transparency logs and leaked lists instead of blind scanning. A telescope with nothing pointing at it from either protocol makes that difference obvious in a way a live production server never would.
None of this is unique to us. Every unused IP on the internet sees roughly this shape of traffic, which is the actual point, this is what the background noise looks like everywhere, all the time, whether anyone's watching or not.
How we get this data
Every connection attempt that reaches this IP gets logged before it's dropped. We whitelist our own management access and infrastructure so we're not counting ourselves, everything else that shows up is unsolicited by definition. Each source IP gets enriched against MaxMind's databases for network ownership, ASN and rough geography, and destination ports get matched against IANA's official service name registry so a hit on port 1433 shows up as MS-SQL rather than a bare number.
We also maintain a manual allowlist for networks we've confirmed belong to legitimate internet research, companies like Censys and Onyphe run continuous scanning as their actual business, cataloguing what's reachable rather than trying to break into it. We exclude those from anything we flag as suspicious, since lumping a research crawler in with a credential-stuffing botnet would make the data less useful, not more. This is the same anonymized, aggregated approach behind our Global Analytics data, just pointed at unsolicited traffic instead of site performance.
Questions, feedback, or a benign network request
If you run scanning infrastructure and want your network excluded from anything we publish as suspicious, email us at [email protected]. We'll check that the ASN in question is actually used for security research or similar legitimate scanning, not just a hosting provider with mixed traffic, before adding it. Same address for anything else, questions about the data, requests, or general feedback.