The Watchtower

Our own sensors — on this host, our mail host and one friend's origin — record what attacks them. This is the live result: addresses, scores, evidence, and a free signed feed. How this works →

Last 24 hours
22821 events457 addresses303 blocked
Last 7 days
144627 events2143 addresses303 blocked
All time
166368 events3318 addresses303 blocked

Time since last attack: 4m

Attack weather

Blocked at the door

Since 4 Oct: 63 packets dropped at the kernel/firewall level on 2 of 3 hosts (never counted against address scoring — these are packets that never reached the application).

firewalld 1.3.4 attaches no counter to any rule it manages on this host, and its nftables table is netlink-owned (flags owner,persist) -- a manual nft counter was refused live (confirmed 2026-10-04)

Is my IP here?

Live feed

TimeAddressWhat happenedOutcome
2026-10-04T18:23:47Z195.178.110.106fuzzed a short, random filename looking for a forgotten script that responds
2026-10-04T18:23:47Z195.178.110.106requested the .git directory itself, hoping it is exposed and browsable
2026-10-04T18:21:34Z139.59.158.43requested the .git directory itself, hoping it is exposed and browsable
2026-10-04T18:21:12Z134.199.160.115requested the .git directory itself, hoping it is exposed and browsable
2026-10-04T18:21:06Z195.178.110.199requested the .git directory itself, hoping it is exposed and browsable
2026-10-04T18:23:11Z216.150.187.9requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods
2026-10-04T18:22:06Z41.105.48.43requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods
2026-10-04T18:21:16Z209.61.59.36requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods
2026-10-04T18:23:47Z195.178.110.106probed for an exposed .git directory to download the site's source history and config
2026-10-04T18:20:18Z – 2026-10-04T18:20:28Z20.194.30.10719 × fuzzed a short, random filename looking for a forgotten script that responds (19 distinct paths)
2026-10-04T18:20:17Z20.194.30.107checked for a known-vulnerable or backdoored WordPress plugin path
2026-10-04T18:21:34Z139.59.158.43probed for an exposed .git directory to download the site's source history and config
2026-10-04T18:21:12Z134.199.160.115probed for an exposed .git directory to download the site's source history and config
2026-10-04T18:21:13Z195.178.110.199requested docker-compose.yml, which often contains embedded passwords and connection strings
2026-10-04T18:21:13Z195.178.110.199requested .htaccess or .htpasswd, which can leak access rules or password hashes
2026-10-04T18:21:09Z – 2026-10-04T18:21:12Z195.178.110.1994 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (4 distinct paths)
2026-10-04T18:21:09Z195.178.110.199requested an AWS credentials file left in a web-accessible path by mistake
2026-10-04T18:21:09Z – 2026-10-04T18:21:09Z195.178.110.1992 × fuzzed a short, random filename looking for a forgotten script that responds (2 distinct paths)
2026-10-04T18:21:09Z195.178.110.199requested phpinfo.php, which dumps the full PHP configuration and environment if left in place
2026-10-04T18:21:07Z – 2026-10-04T18:21:07Z195.178.110.1992 × requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (2 distinct paths)
2026-10-04T18:21:07Z195.178.110.199requested a config.json file, hoping it exposes API keys or internal settings
2026-10-04T18:21:07Z195.178.110.199requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot
2026-10-04T18:21:06Z195.178.110.199probed for an exposed .git directory to download the site's source history and config
2026-10-04T18:21:06Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:06Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:05Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:05Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:05Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:05Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:05Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:05Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:04Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:04Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:21:04Z195.178.110.199requested a .env file, hoping to find API keys or database credentials
2026-10-04T18:18:23Z153.0.158.115requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot
2026-10-04T18:18:26Z – 2026-10-04T18:18:36Z104.208.73.22744 × fuzzed a short, random filename looking for a forgotten script that responds (42 distinct paths)
2026-10-04T18:19:31Z – 2026-10-04T18:19:41Z20.197.26.4637 × fuzzed a short, random filename looking for a forgotten script that responds (37 distinct paths)
2026-10-04T18:19:31Z20.197.26.46probed for an exposed Adminer database-management script
2026-10-04T18:19:25Z – 2026-10-04T18:19:30Z20.197.26.4622 × fuzzed a short, random filename looking for a forgotten script that responds (22 distinct paths)
2026-10-04T18:19:24Z20.197.26.46requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods
2026-10-04T18:19:22Z – 2026-10-04T18:19:24Z20.197.26.467 × fuzzed a short, random filename looking for a forgotten script that responds (7 distinct paths)
2026-10-04T18:19:22Z20.197.26.46requested wp-config.php or a backup copy of it, hoping to read the database password in clear text
2026-10-04T18:19:21Z – 2026-10-04T18:19:22Z20.197.26.464 × fuzzed a short, random filename looking for a forgotten script that responds (4 distinct paths)
2026-10-04T18:19:21Z20.197.26.46requested wp-login.php to check whether this site runs WordPress
2026-10-04T18:19:20Z – 2026-10-04T18:19:20Z20.197.26.462 × fuzzed a short, random filename looking for a forgotten script that responds (2 distinct paths)
2026-10-04T18:19:20Z20.197.26.46requested wp-config.php or a backup copy of it, hoping to read the database password in clear text
2026-10-04T18:19:18Z – 2026-10-04T18:19:20Z20.197.26.467 × fuzzed a short, random filename looking for a forgotten script that responds (7 distinct paths)
2026-10-04T18:19:18Z20.197.26.46requested a filename commonly used by web shells left behind by a previous compromise
2026-10-04T18:19:18Z20.197.26.46fuzzed a short, random filename looking for a forgotten script that responds
2026-10-04T18:19:18Z20.197.26.46probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface

Events per hour (7 days)

169 hourly buckets
  • 2026-10-02T19:00:00Z: 642
  • 2026-10-02T20:00:00Z: 402
  • 2026-10-02T21:00:00Z: 816
  • 2026-10-02T22:00:00Z: 637
  • 2026-10-02T23:00:00Z: 385
  • 2026-10-03T00:00:00Z: 897
  • 2026-10-03T01:00:00Z: 688
  • 2026-10-03T02:00:00Z: 469
  • 2026-10-03T03:00:00Z: 371
  • 2026-10-03T04:00:00Z: 856
  • 2026-10-03T05:00:00Z: 876
  • 2026-10-03T06:00:00Z: 923
  • 2026-10-03T07:00:00Z: 1115
  • 2026-10-03T08:00:00Z: 1187
  • 2026-10-03T09:00:00Z: 673
  • 2026-10-03T10:00:00Z: 933
  • 2026-10-03T11:00:00Z: 909
  • 2026-10-03T12:00:00Z: 756
  • 2026-10-03T13:00:00Z: 1043
  • 2026-10-03T14:00:00Z: 353
  • 2026-10-03T15:00:00Z: 1076
  • 2026-10-03T16:00:00Z: 727
  • 2026-10-03T17:00:00Z: 435
  • 2026-10-03T18:00:00Z: 1590
  • 2026-10-03T19:00:00Z: 905
  • 2026-10-03T20:00:00Z: 1062
  • 2026-10-03T21:00:00Z: 802
  • 2026-10-03T22:00:00Z: 1376
  • 2026-10-03T23:00:00Z: 832
  • 2026-10-04T00:00:00Z: 618
  • 2026-10-04T01:00:00Z: 661
  • 2026-10-04T02:00:00Z: 1146
  • 2026-10-04T03:00:00Z: 1365
  • 2026-10-04T04:00:00Z: 507
  • 2026-10-04T05:00:00Z: 887
  • 2026-10-04T06:00:00Z: 890
  • 2026-10-04T07:00:00Z: 787
  • 2026-10-04T08:00:00Z: 723
  • 2026-10-04T09:00:00Z: 1784
  • 2026-10-04T10:00:00Z: 1183
  • 2026-10-04T11:00:00Z: 949
  • 2026-10-04T12:00:00Z: 550
  • 2026-10-04T13:00:00Z: 567
  • 2026-10-04T14:00:00Z: 1263
  • 2026-10-04T15:00:00Z: 1049
  • 2026-10-04T16:00:00Z: 745
  • 2026-10-04T17:00:00Z: 1068
  • 2026-10-04T18:00:00Z: 484

Surface × attack type (7 days)

SurfaceAttack typeCount
ftpcredential-brute17
mail-smtpcredential-brute200
mail-smtpspam-relay-probe125
panelcredential-brute12
panelinjection8
panelopen-proxy-probe7
panelrecon20
panelscanner-tool38
panelsecrets-hunt329
sshscanner-tool17
web-appbot-impersonation66
web-appcredential-spray6264
web-appcve-exploit736
web-appdos-pattern2
web-appinjection4211
web-apprecon71394
web-appscanner-tool5879
web-appsecrets-hunt52479
web-appunknown2823

Top ASNs

ASNOrganisationAddresses
AS396982Google LLC1175
AS14061DigitalOcean, LLC343
AS8075Microsoft Corporation149
AS48090Techoff Srv Limited65
AS206092F.n.s. Holdings Limited58
AS16509Amazon.com, Inc.50
AS63949Akamai Connected Cloud49
AS218785Tc Datacenter Limited39
AS31898Oracle Corporation38
AS197170TechTies Inc.37

Top 10 countries

CountryAddresses
United States1110
Singapore192
India183
The Netherlands173
Germany163
France128
Belgium123
United Kingdom94
Taiwan82
Brazil79

AI crawlers (last 30 days)

Requests whose User-Agent claims to be one of these crawlers. "Admin/sensitive path" and "rDNS confirmed" are defined on the about page.

CrawlerRequestsAdmin/sensitive pathOrdinary pagerDNS confirmedrDNS not confirmedBlocked at edgeReached origin
ClaudeBot3,6552,65899702391513,504
PerplexityBot2,5511,891660021502,551
DeepSeekBot1,277969308015801,277
Google-Extended/GoogleOther1,260960300015921,258
GPTBot1,2308853450173391,191
Meta-ExternalAgent1,222909313016711,221
Bytespider1,184886298016061,178
CCBot1,1598632960153101,149
cohere-ai1,1458462990151101,135
Amazonbot1,1288552730167111,117
PetalBot601592103822

Most Wanted

Hosting/cloud-ASN addresses only — a residential or mobile address never appears here, whatever its score.

AddressScoreLevelOrganisationLast seen
144.172.97.20293.9WantedRouterHosting LLC2026-10-04T17:25:56Z
45.138.12.2892.7WantedTc Datacenter Limited2026-10-02T13:30:55Z
207.175.220.5990.3WantedGoogle LLC2026-10-01T20:09:51Z
45.148.10.12089.6WantedTechoff Srv Limited2026-10-04T15:06:47Z
20.204.42.13685.0RelentlessMicrosoft Corporation2026-10-04T18:19:55Z
45.138.12.2683.6RelentlessTc Datacenter Limited2026-10-02T14:56:32Z
35.241.202.9283.2RelentlessGoogle LLC2026-10-02T12:16:32Z
34.156.121.4682.9RelentlessGoogle LLC2026-10-02T09:18:16Z
35.240.100.20082.8RelentlessGoogle LLC2026-10-02T08:21:32Z
34.62.116.14580.8RelentlessGoogle LLC2026-10-02T14:46:53Z
34.140.234.8080.6RelentlessGoogle LLC2026-10-02T13:12:39Z
34.14.99.14380.5RelentlessGoogle LLC2026-10-02T12:07:53Z
34.156.206.3280.0RelentlessGoogle LLC2026-10-02T08:07:37Z
34.62.82.16579.7RelentlessGoogle LLC2026-10-02T05:46:48Z
13.70.107.18478.9RelentlessMicrosoft Corporation2026-10-04T17:33:45Z
20.219.185.20678.8RelentlessMicrosoft Corporation2026-10-04T16:40:56Z
213.209.159.22378.5RelentlessFeo Prest SRL2026-09-30T22:41:31Z
102.220.161.6478.3RelentlessVPS Dedicated LLC2026-10-04T12:07:43Z
45.138.12.3077.6RelentlessTc Datacenter Limited2026-10-02T11:37:11Z
45.138.12.1677.6RelentlessTc Datacenter Limited2026-10-04T14:37:56Z

Hoster responses

No abuse reports sent yet — the reporting pipeline ships in phase 3.

Credentials board

From our own honeypots only — aggregate counts, never tied to an address.

No honeypot data yet.

Weekly digest archive

No digests published yet.

Feeds

Free, signed, updated every 10 minutes. See /threats/about for the full terms.

Read the method, thresholds, retention and removal policy →