The Watchtower
Our own sensors — on this host, our mail host and one friend's origin — record what attacks them. This is the live result: addresses, scores, evidence, and a free signed feed. How this works →
Time since last attack: 4m
Attack weather
- web: 18.2× the 30-day median, dominated by recon from AS8075 (Microsoft Corporation)
- ssh: history too short (6 days of data since 2026-09-28)
- mail: history too short (5 days of data since 2026-09-29)
- panel: history too short (5 days of data since 2026-09-29)
Blocked at the door
Since 4 Oct: 63 packets dropped at the kernel/firewall level on 2 of 3 hosts (never counted against address scoring — these are packets that never reached the application).
- NL4: 60 packets
- 4emx: 3 packets
- .19: counter not available
firewalld 1.3.4 attaches no counter to any rule it manages on this host, and its nftables table is netlink-owned (flags owner,persist) -- a manual nft counter was refused live (confirmed 2026-10-04)
Is my IP here?
Live feed
| Time | Address | What happened | Outcome |
|---|---|---|---|
| 2026-10-04T18:23:47Z | 195.178.110.106 | fuzzed a short, random filename looking for a forgotten script that responds | |
| 2026-10-04T18:23:47Z | 195.178.110.106 | requested the .git directory itself, hoping it is exposed and browsable | |
| 2026-10-04T18:21:34Z | 139.59.158.43 | requested the .git directory itself, hoping it is exposed and browsable | |
| 2026-10-04T18:21:12Z | 134.199.160.115 | requested the .git directory itself, hoping it is exposed and browsable | |
| 2026-10-04T18:21:06Z | 195.178.110.199 | requested the .git directory itself, hoping it is exposed and browsable | |
| 2026-10-04T18:23:11Z | 216.150.187.9 | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | |
| 2026-10-04T18:22:06Z | 41.105.48.43 | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | |
| 2026-10-04T18:21:16Z | 209.61.59.36 | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | |
| 2026-10-04T18:23:47Z | 195.178.110.106 | probed for an exposed .git directory to download the site's source history and config | |
| 2026-10-04T18:20:18Z – 2026-10-04T18:20:28Z | 20.194.30.107 | 19 × fuzzed a short, random filename looking for a forgotten script that responds (19 distinct paths) | |
| 2026-10-04T18:20:17Z | 20.194.30.107 | checked for a known-vulnerable or backdoored WordPress plugin path | |
| 2026-10-04T18:21:34Z | 139.59.158.43 | probed for an exposed .git directory to download the site's source history and config | |
| 2026-10-04T18:21:12Z | 134.199.160.115 | probed for an exposed .git directory to download the site's source history and config | |
| 2026-10-04T18:21:13Z | 195.178.110.199 | requested docker-compose.yml, which often contains embedded passwords and connection strings | |
| 2026-10-04T18:21:13Z | 195.178.110.199 | requested .htaccess or .htpasswd, which can leak access rules or password hashes | |
| 2026-10-04T18:21:09Z – 2026-10-04T18:21:12Z | 195.178.110.199 | 4 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (4 distinct paths) | |
| 2026-10-04T18:21:09Z | 195.178.110.199 | requested an AWS credentials file left in a web-accessible path by mistake | |
| 2026-10-04T18:21:09Z – 2026-10-04T18:21:09Z | 195.178.110.199 | 2 × fuzzed a short, random filename looking for a forgotten script that responds (2 distinct paths) | |
| 2026-10-04T18:21:09Z | 195.178.110.199 | requested phpinfo.php, which dumps the full PHP configuration and environment if left in place | |
| 2026-10-04T18:21:07Z – 2026-10-04T18:21:07Z | 195.178.110.199 | 2 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths) | |
| 2026-10-04T18:21:07Z | 195.178.110.199 | requested a config.json file, hoping it exposes API keys or internal settings | |
| 2026-10-04T18:21:07Z | 195.178.110.199 | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | |
| 2026-10-04T18:21:06Z | 195.178.110.199 | probed for an exposed .git directory to download the site's source history and config | |
| 2026-10-04T18:21:06Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:06Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:05Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:05Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:05Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:05Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:05Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:05Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:04Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:04Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:21:04Z | 195.178.110.199 | requested a .env file, hoping to find API keys or database credentials | |
| 2026-10-04T18:18:23Z | 153.0.158.115 | requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | |
| 2026-10-04T18:18:26Z – 2026-10-04T18:18:36Z | 104.208.73.227 | 44 × fuzzed a short, random filename looking for a forgotten script that responds (42 distinct paths) | |
| 2026-10-04T18:19:31Z – 2026-10-04T18:19:41Z | 20.197.26.46 | 37 × fuzzed a short, random filename looking for a forgotten script that responds (37 distinct paths) | |
| 2026-10-04T18:19:31Z | 20.197.26.46 | probed for an exposed Adminer database-management script | |
| 2026-10-04T18:19:25Z – 2026-10-04T18:19:30Z | 20.197.26.46 | 22 × fuzzed a short, random filename looking for a forgotten script that responds (22 distinct paths) | |
| 2026-10-04T18:19:24Z | 20.197.26.46 | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | |
| 2026-10-04T18:19:22Z – 2026-10-04T18:19:24Z | 20.197.26.46 | 7 × fuzzed a short, random filename looking for a forgotten script that responds (7 distinct paths) | |
| 2026-10-04T18:19:22Z | 20.197.26.46 | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | |
| 2026-10-04T18:19:21Z – 2026-10-04T18:19:22Z | 20.197.26.46 | 4 × fuzzed a short, random filename looking for a forgotten script that responds (4 distinct paths) | |
| 2026-10-04T18:19:21Z | 20.197.26.46 | requested wp-login.php to check whether this site runs WordPress | |
| 2026-10-04T18:19:20Z – 2026-10-04T18:19:20Z | 20.197.26.46 | 2 × fuzzed a short, random filename looking for a forgotten script that responds (2 distinct paths) | |
| 2026-10-04T18:19:20Z | 20.197.26.46 | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | |
| 2026-10-04T18:19:18Z – 2026-10-04T18:19:20Z | 20.197.26.46 | 7 × fuzzed a short, random filename looking for a forgotten script that responds (7 distinct paths) | |
| 2026-10-04T18:19:18Z | 20.197.26.46 | requested a filename commonly used by web shells left behind by a previous compromise | |
| 2026-10-04T18:19:18Z | 20.197.26.46 | fuzzed a short, random filename looking for a forgotten script that responds | |
| 2026-10-04T18:19:18Z | 20.197.26.46 | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface |
Events per hour (7 days)
169 hourly buckets
- 2026-10-02T19:00:00Z: 642
- 2026-10-02T20:00:00Z: 402
- 2026-10-02T21:00:00Z: 816
- 2026-10-02T22:00:00Z: 637
- 2026-10-02T23:00:00Z: 385
- 2026-10-03T00:00:00Z: 897
- 2026-10-03T01:00:00Z: 688
- 2026-10-03T02:00:00Z: 469
- 2026-10-03T03:00:00Z: 371
- 2026-10-03T04:00:00Z: 856
- 2026-10-03T05:00:00Z: 876
- 2026-10-03T06:00:00Z: 923
- 2026-10-03T07:00:00Z: 1115
- 2026-10-03T08:00:00Z: 1187
- 2026-10-03T09:00:00Z: 673
- 2026-10-03T10:00:00Z: 933
- 2026-10-03T11:00:00Z: 909
- 2026-10-03T12:00:00Z: 756
- 2026-10-03T13:00:00Z: 1043
- 2026-10-03T14:00:00Z: 353
- 2026-10-03T15:00:00Z: 1076
- 2026-10-03T16:00:00Z: 727
- 2026-10-03T17:00:00Z: 435
- 2026-10-03T18:00:00Z: 1590
- 2026-10-03T19:00:00Z: 905
- 2026-10-03T20:00:00Z: 1062
- 2026-10-03T21:00:00Z: 802
- 2026-10-03T22:00:00Z: 1376
- 2026-10-03T23:00:00Z: 832
- 2026-10-04T00:00:00Z: 618
- 2026-10-04T01:00:00Z: 661
- 2026-10-04T02:00:00Z: 1146
- 2026-10-04T03:00:00Z: 1365
- 2026-10-04T04:00:00Z: 507
- 2026-10-04T05:00:00Z: 887
- 2026-10-04T06:00:00Z: 890
- 2026-10-04T07:00:00Z: 787
- 2026-10-04T08:00:00Z: 723
- 2026-10-04T09:00:00Z: 1784
- 2026-10-04T10:00:00Z: 1183
- 2026-10-04T11:00:00Z: 949
- 2026-10-04T12:00:00Z: 550
- 2026-10-04T13:00:00Z: 567
- 2026-10-04T14:00:00Z: 1263
- 2026-10-04T15:00:00Z: 1049
- 2026-10-04T16:00:00Z: 745
- 2026-10-04T17:00:00Z: 1068
- 2026-10-04T18:00:00Z: 484
Surface × attack type (7 days)
| Surface | Attack type | Count |
|---|---|---|
| ftp | credential-brute | 17 |
| mail-smtp | credential-brute | 200 |
| mail-smtp | spam-relay-probe | 125 |
| panel | credential-brute | 12 |
| panel | injection | 8 |
| panel | open-proxy-probe | 7 |
| panel | recon | 20 |
| panel | scanner-tool | 38 |
| panel | secrets-hunt | 329 |
| ssh | scanner-tool | 17 |
| web-app | bot-impersonation | 66 |
| web-app | credential-spray | 6264 |
| web-app | cve-exploit | 736 |
| web-app | dos-pattern | 2 |
| web-app | injection | 4211 |
| web-app | recon | 71394 |
| web-app | scanner-tool | 5879 |
| web-app | secrets-hunt | 52479 |
| web-app | unknown | 2823 |
Top ASNs
| ASN | Organisation | Addresses |
|---|---|---|
| AS396982 | Google LLC | 1175 |
| AS14061 | DigitalOcean, LLC | 343 |
| AS8075 | Microsoft Corporation | 149 |
| AS48090 | Techoff Srv Limited | 65 |
| AS206092 | F.n.s. Holdings Limited | 58 |
| AS16509 | Amazon.com, Inc. | 50 |
| AS63949 | Akamai Connected Cloud | 49 |
| AS218785 | Tc Datacenter Limited | 39 |
| AS31898 | Oracle Corporation | 38 |
| AS197170 | TechTies Inc. | 37 |
Top 10 countries
| Country | Addresses |
|---|---|
| United States | 1110 |
| Singapore | 192 |
| India | 183 |
| The Netherlands | 173 |
| Germany | 163 |
| France | 128 |
| Belgium | 123 |
| United Kingdom | 94 |
| Taiwan | 82 |
| Brazil | 79 |
AI crawlers (last 30 days)
Requests whose User-Agent claims to be one of these crawlers. "Admin/sensitive path" and "rDNS confirmed" are defined on the about page.
| Crawler | Requests | Admin/sensitive path | Ordinary page | rDNS confirmed | rDNS not confirmed | Blocked at edge | Reached origin |
|---|---|---|---|---|---|---|---|
| ClaudeBot | 3,655 | 2,658 | 997 | 0 | 239 | 151 | 3,504 |
| PerplexityBot | 2,551 | 1,891 | 660 | 0 | 215 | 0 | 2,551 |
| DeepSeekBot | 1,277 | 969 | 308 | 0 | 158 | 0 | 1,277 |
| Google-Extended/GoogleOther | 1,260 | 960 | 300 | 0 | 159 | 2 | 1,258 |
| GPTBot | 1,230 | 885 | 345 | 0 | 173 | 39 | 1,191 |
| Meta-ExternalAgent | 1,222 | 909 | 313 | 0 | 167 | 1 | 1,221 |
| Bytespider | 1,184 | 886 | 298 | 0 | 160 | 6 | 1,178 |
| CCBot | 1,159 | 863 | 296 | 0 | 153 | 10 | 1,149 |
| cohere-ai | 1,145 | 846 | 299 | 0 | 151 | 10 | 1,135 |
| Amazonbot | 1,128 | 855 | 273 | 0 | 167 | 11 | 1,117 |
| PetalBot | 60 | 1 | 59 | 21 | 0 | 38 | 22 |
Most Wanted
Hosting/cloud-ASN addresses only — a residential or mobile address never appears here, whatever its score.
| Address | Score | Level | Organisation | Last seen |
|---|---|---|---|---|
| 144.172.97.202 | 93.9 | Wanted | RouterHosting LLC | 2026-10-04T17:25:56Z |
| 45.138.12.28 | 92.7 | Wanted | Tc Datacenter Limited | 2026-10-02T13:30:55Z |
| 207.175.220.59 | 90.3 | Wanted | Google LLC | 2026-10-01T20:09:51Z |
| 45.148.10.120 | 89.6 | Wanted | Techoff Srv Limited | 2026-10-04T15:06:47Z |
| 20.204.42.136 | 85.0 | Relentless | Microsoft Corporation | 2026-10-04T18:19:55Z |
| 45.138.12.26 | 83.6 | Relentless | Tc Datacenter Limited | 2026-10-02T14:56:32Z |
| 35.241.202.92 | 83.2 | Relentless | Google LLC | 2026-10-02T12:16:32Z |
| 34.156.121.46 | 82.9 | Relentless | Google LLC | 2026-10-02T09:18:16Z |
| 35.240.100.200 | 82.8 | Relentless | Google LLC | 2026-10-02T08:21:32Z |
| 34.62.116.145 | 80.8 | Relentless | Google LLC | 2026-10-02T14:46:53Z |
| 34.140.234.80 | 80.6 | Relentless | Google LLC | 2026-10-02T13:12:39Z |
| 34.14.99.143 | 80.5 | Relentless | Google LLC | 2026-10-02T12:07:53Z |
| 34.156.206.32 | 80.0 | Relentless | Google LLC | 2026-10-02T08:07:37Z |
| 34.62.82.165 | 79.7 | Relentless | Google LLC | 2026-10-02T05:46:48Z |
| 13.70.107.184 | 78.9 | Relentless | Microsoft Corporation | 2026-10-04T17:33:45Z |
| 20.219.185.206 | 78.8 | Relentless | Microsoft Corporation | 2026-10-04T16:40:56Z |
| 213.209.159.223 | 78.5 | Relentless | Feo Prest SRL | 2026-09-30T22:41:31Z |
| 102.220.161.64 | 78.3 | Relentless | VPS Dedicated LLC | 2026-10-04T12:07:43Z |
| 45.138.12.30 | 77.6 | Relentless | Tc Datacenter Limited | 2026-10-02T11:37:11Z |
| 45.138.12.16 | 77.6 | Relentless | Tc Datacenter Limited | 2026-10-04T14:37:56Z |
Hoster responses
No abuse reports sent yet — the reporting pipeline ships in phase 3.
Credentials board
From our own honeypots only — aggregate counts, never tied to an address.
No honeypot data yet.
Weekly digest archive
No digests published yet.
Feeds
Free, signed, updated every 10 minutes. See /threats/about for the full terms.
- feed.txt — one address per line (CSF/Cloudflare-list compatible)
- feed.json — full detail, with
expiresper address - feed-web.txt, feed-ssh.txt, feed-mail.txt, feed-panel.txt — per-surface
- vocab-v1.json — the surface/attack-type vocabulary
- pubkey.minisig — signing public key