Attack map

IPset (ipsum)
118,295
3.32 MB — Preventive protection
Fail2ban
54,171
26 jail — reactive protection
Total blocked
172,466
IPset + Fail2ban
Geographic attack map
Top source countries
25 unique IPs in 14 countries
China 136
apache-auth: 1vsftpd: 2phpmyadmin-syslog: 1nginx-limit-req: 1
198.51.100.13 01.10 19:22
198.51.100.14 11.10 15:02
198.51.100.15 08.10 05:46
198.51.100.31 29.09 19:22
198.51.100.32 11.10 14:22
United States 69
apache-badbots: 1nginx-http-auth: 1postfix-sasl: 1
198.51.100.22 28.09 19:22
198.51.100.23 11.10 11:21
198.51.100.24 10.10 17:46
Romania 52
exim: 1pam-generic: 1
198.51.100.18 05.10 14:39
198.51.100.19 27.09 19:22
India 48
apache-nohome: 1exim-spam: 1
198.51.100.20 11.10 11:06
198.51.100.21 04.10 22:57
Singapore 41
recidive: 1apache-badbots: 1
198.51.100.29 11.10 15:28
198.51.100.30 05.10 02:08
Russian Federation 33
nginx-botsearch: 1apache-botsearch: 1
198.51.100.11 11.10 01:24
198.51.100.12 07.10 06:54
Moldova 33
apache-badbots: 1
198.51.100.33 09.10 07:58
Indonesia 25
mysqld-auth: 1
198.51.100.34 29.09 19:22
Germany 25
apache-botsearch: 1
198.51.100.16 28.09 19:22
Vietnam 18
exim: 1apache-badbots: 1
198.51.100.25 27.09 19:22
198.51.100.26 11.10 03:29
Bulgaria 16
postfix-sasl: 1
198.51.100.27 09.10 14:33
Latvia 9
recidive-permanent: 1
198.51.100.28 02.10 19:22
Netherlands 8
apache-overflows: 1
198.51.100.17 11.10 11:54
Brazil 6
nginx-limit-req: 1
198.51.100.35 11.10 14:37

An attack map built from your own Fail2ban bans

The map plots addresses your own server has banned, resolved to countries and drawn by volume. It is not a feed of somebody else's threat data — every point on it is traffic that reached this machine and was turned away.

Attack maps have a reputation as decoration, and used as a wall display they earn it. They become useful when you watch them over weeks rather than seconds, because the shape of the traffic is stable and changes to it mean something. A sudden concentration from one country or one network usually indicates a single actor working through a list, and that is worth a wider block than Fail2ban applies on its own. A broad, even spread is ordinary internet background and needs no action at all.

Geolocation is approximate by nature, so treat country attribution as a hint rather than an identification — VPNs, proxies and compromised hosts all place attackers somewhere other than where they are.