Attack origins
Top countries
48-hour timeline failed attempts / hour
Most-tried usernames
vs previous 48h
Top attacking IPs
by attemptsHighlights
When they knock attempts by hour of day
About the data
What counts as an attempt: each SSH connection (one sshd process from one source IP) that logged at least one failed-authentication sign — Invalid user, Failed password/publickey, a PAM authentication failure, too many auth failures, or the connection being closed/reset by an invalid or authenticating user before login. Several log lines from the same connection are counted once. Bare port scans that never try a username are not counted.
What's left out: successful logins and anything about them, every address that has ever logged in successfully, the owners' own addresses, and non-sshd log lines. Real account names are shown as (real account).
Windows: a new map is built every 48 hours from the previous 48 hours; the three most recent are kept for comparison. "vs previous 48h" compares against the 48 hours right before each window. Times are shown in US Eastern (ET) and UTC.
Location: IP geolocation is approximate (city-level at best; VPNs, clouds and proxies often map to data centers). Lookups are done offline with the free DB-IP Lite database, refreshed monthly.