Public threat snapshot

SSH attack activity
observed by Sarang.

This public portal uses daily JSON updates for fast situational awareness, regional context, and accessible IoC discovery.

Daily generated datasetsMalaysia-based visibilityStatic public reporting
SSH Events—

Observed over the last 31 days.

Unique Attacker IPs—

Distinct sources in the reporting window.

Successful Honeypot Logins—

Sessions progressing beyond failed attempts.

Command Activity Events—

Interactive commands captured after access.

Payload Download Events—

Observed payload delivery activity.

Unique Hashes Observed—

Distinct hashes from download activity.

Attack activity

SSH Attacks Trend Yesterday

Hourly view

Attack activity

SSH Attacks Trend

Last 31 days

Global focus

Global Source Context

Last 31 days

Global Countries by Unique IPs

Top 10 countries by unique source IPs.

Attack Volume by Global Countries

Top 10 countries by total observed activity.

Regional focus · Southeast Asia

Regional Source Context

Last 31 days

SEA Countries by Unique IPs

Regional countries ranked by unique source IPs.

Attack Volume by Regional Countries

Regional countries ranked by total observed activity.

Top observables

Top 10 Attacker IPs

Last 31 days

Higher event counts indicate more observed activity, not confirmed attribution to one actor.

Loading published observations…

Top observables

Top 10 Malicious Score IPs

Last 31 days

The score is a behaviour-based proxy weighted from observed Cowrie activity. It is not a native threat-intelligence reputation score.

Loading published observations…

Interpretation notice

Public indicators reflect activity seen by Sarang only.

Observed IP addresses and hashes support threat awareness but should not be treated as identity attribution on their own. Evaluate indicators in context before using them for automated blocking.