198.51.100.13
01.10 19:22
198.51.100.14
11.10 15:02
198.51.100.15
08.10 05:46
198.51.100.31
29.09 19:22
198.51.100.32
11.10 14:22
198.51.100.22
28.09 19:22
198.51.100.23
11.10 11:21
198.51.100.24
10.10 17:46
198.51.100.18
05.10 14:39
198.51.100.19
27.09 19:22
198.51.100.20
11.10 11:06
198.51.100.21
04.10 22:57
198.51.100.29
11.10 15:28
198.51.100.30
05.10 02:08
198.51.100.11
11.10 01:24
198.51.100.12
07.10 06:54
198.51.100.33
09.10 07:58
198.51.100.34
29.09 19:22
198.51.100.16
28.09 19:22
198.51.100.25
27.09 19:22
198.51.100.26
11.10 03:29
198.51.100.27
09.10 14:33
198.51.100.28
02.10 19:22
198.51.100.17
11.10 11:54
198.51.100.35
11.10 14:37
The map plots addresses your own server has banned, resolved to countries and drawn by volume. It is not a feed of somebody else's threat data — every point on it is traffic that reached this machine and was turned away.
Attack maps have a reputation as decoration, and used as a wall display they earn it. They become useful when you watch them over weeks rather than seconds, because the shape of the traffic is stable and changes to it mean something. A sudden concentration from one country or one network usually indicates a single actor working through a list, and that is worth a wider block than Fail2ban applies on its own. A broad, even spread is ordinary internet background and needs no action at all.
Geolocation is approximate by nature, so treat country attribution as a hint rather than an identification — VPNs, proxies and compromised hosts all place attackers somewhere other than where they are.