Visible events are replayed from a local generator seeded with Cloudflare Radar L3 and L7 aggregate telemetry captured during the latest static build.
03:28:00Low
L7 Malware activity from 🇲🇽 Mexico targeting 🇬🇧 United Kingdom
Application-layer telemetry mapped 0.24% of mitigated request pressure to this corridor, with IP Reputation absorbing the primary load during Patch request spikes sourced through AS8075 (Microsoft Corporation).
L7IP ReputationAS80750.24% shareTCP:445
03:26:00Critical
L7 Botnet activity from 🇳🇱 Netherlands targeting 🇺🇸 United States
Cloudflare observed 6.50% of the active L7 pair mix on this route, with Bot Management engaging across abnormal Get traffic and repeat visibility from AS24940 (Hetzner Online GmbH).
L7Bot ManagementAS249406.50% shareTCP:23
03:24:00Medium
L3 Exploit activity from 🇺🇸 United States targeting ðŸ‡ðŸ‡° Hong Kong
Volumetric edge sampling attributed 0.65% of high-noise route pressure to Other associated with AS16509 (Amazon.com, Inc.).
L3OtherAS165090.65% shareHTTPS:22
03:22:00Low
L7 Phishing activity from 🇺🇸 United States targeting 🇫🇷 France
Cloudflare observed 1.22% of the active L7 pair mix on this route, with Access Rules engaging across abnormal Post traffic and repeat visibility from AS31898 (Oracle Corporation).
L7Access RulesAS318981.22% shareHTTPS:443
03:20:00Medium
L3 Botnet activity from 🇷🇺 Russia targeting 🇨🇦 Canada
Cloudflare network telemetry shows Mirai (udp) flood pressure accounting for 0.30% of the current path mix and recurring visibility from AS211590 (Bucklog SARL).
L3Mirai (udp) floodAS2115900.30% shareUDP:443
03:18:00Critical
L7 Exploit activity from 🇨🇳 China targeting 🇺🇸 United States
Cloudflare observed 13.01% of the active L7 pair mix on this route, with WAF engaging across abnormal Get traffic and repeat visibility from AS8075 (Microsoft Corporation).
L7WAFAS807513.01% shareHTTPS:443
03:12:00Low
L7 Malware activity from 🇹🇷 Turkey targeting 🇸🇬 Singapore
Application-layer telemetry mapped 0.24% of mitigated request pressure to this corridor, with IP Reputation absorbing the primary load during Get request spikes sourced through AS14061 (DigitalOcean, LLC).
L7IP ReputationAS140610.24% shareHTTPS:443
03:08:00Low
L7 Botnet activity from 🇫🇷 France targeting 🇨🇳 China
Application-layer telemetry mapped 0.24% of mitigated request pressure to this corridor, with Bot Management absorbing the primary load during Get request spikes sourced through AS45102 (Alibaba (US) Technology Co., Ltd.).
L7Bot ManagementAS451020.24% shareUDP:6667
03:06:00Medium
L3 DDoS activity from 🇷🇺 Russia targeting ðŸ‡ðŸ‡° Hong Kong
Layer 3 Udp flood activity contributed 0.39% of the top Cloudflare-observed path mix with origin concentration in AS211590 (Bucklog SARL).
L3Udp floodAS2115900.39% shareUDP:53
02:58:00Low
L7 Exploit activity from 🇮🇩 Indonesia targeting 🇩🇪 Germany
Application-layer telemetry mapped 0.24% of mitigated request pressure to this corridor, with WAF absorbing the primary load during Get request spikes sourced through AS13335 (Cloudflare, Inc.).
L7WAFAS133350.24% shareHTTPS:22
02:54:00Medium
L3 DDoS activity from 🇮🇳 India targeting 🇸🇬 Singapore
Cloudflare network telemetry shows Ack flood pressure accounting for 0.24% of the current path mix and recurring visibility from AS16509 (Amazon.com, Inc.).
L3Ack floodAS165090.24% shareTCP:8443
02:52:00Low
L7 Malware activity from 🇸🇬 Singapore targeting 🇨🇦 Canada
Cloudflare observed 1.40% of the active L7 pair mix on this route, with IP Reputation engaging across abnormal Get traffic and repeat visibility from AS48090 (TECHOFF SRV LIMITED).
L7IP ReputationAS480901.40% shareTCP:443