The Watchtower — Live Ops
A live view of the addresses attacking our servers: who they are, what they tried, and a free signed block list you can use on your own firewall. How this works →
Time since last attack
12m
Last 24h
26223 ev
/ 503 ip / 307 blk
Last 7d
152441 ev
/ 2204 ip / 307 blk
All time
174533 ev
/ 3402 ip / 307 blk
Is my IP here?
IPv4 or IPv6 address, e.g. 203.0.113.7Events per hour — 7 days
Live feed
- 213.209.159.133 32 requests on 32 distinct paths — requested a .env file, hoping to find API keys or database credentials (×18); fuzzed a short, random filename looking for a forgotten script that responds (×5); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×3); +5 more kinds
- 185.95.156.182 4 requests on 2 distinct paths — requested wp-login.php to check whether this site runs WordPress (×2); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×2)
- 94.154.43.31 requested an absolute URL instead of a path, testing whether this server behaves as an open forward proxy
- 35.201.174.126 92 requests on 85 distinct paths — requested a .env file, hoping to find API keys or database credentials (×37); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×27); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×13); +6 more kinds
- 195.178.110.159 4 requests on 4 distinct paths — probed for an exposed .svn directory to read the site's version-control metadata (×2); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1)
- 104.208.73.227 50 requests on 50 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds
- 74.161.160.33 3 requests on 3 distinct paths — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×1); requested wp-login.php to check whether this site runs WordPress (×1)
- 161.118.226.254 read a WordPress plugin's readme.txt to fingerprint its exact version for a known vulnerability
- 203.159.90.90 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1)
- 192.227.203.228 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1)
- 93.123.109.167 16 requests on 8 distinct paths — requested wp-login.php to check whether this site runs WordPress
- 20.214.109.68 11 requests on 11 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×3); probed wp-includes/PHPMailer/, a WordPress core library directory commonly used to drop a webshell after a prior compromise (×3); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×3); +2 more kinds
- 20.210.186.186 36 requests on 36 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×31); requested wp-login.php to check whether this site runs WordPress (×3); fuzzed a common filename under /cgi-bin/, looking for a forgotten legacy CGI script (×2)
- 213.209.159.223 156 requests on 154 distinct paths — requested a .env file, hoping to find API keys or database credentials (×118); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×12); requested a database dump or site archive by its common backup filename (×6); +10 more kinds
- 20.204.16.113 69 requests on 69 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×63); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×4); requested a filename commonly used by web shells left behind by a previous compromise (×1); +1 more kind
Top ASNs
Top 10 countries
Surface × attack type — 7 days
Most Wanted
Hosting/cloud-ASN addresses only — a residential or mobile address never appears here, whatever its score.
| Address | Tier | Score | Level | Organisation | Last seen |
|---|---|---|---|---|---|
| 144.172.97.202 | blocked | 93.3 | Wanted | RouterHosting LLC | 2026-10-04T17:25:56Z |
| 45.138.12.28 | blocked | 92.0 | Wanted | Tc Datacenter Limited | 2026-10-02T13:30:55Z |
| 213.209.159.223 | blocked | 90.0 | Wanted | Feo Prest SRL | 2026-10-04T22:30:26Z |
| 207.175.220.59 | blocked | 89.6 | Wanted | Google LLC | 2026-10-01T20:09:51Z |
| 45.148.10.120 | blocked | 89.0 | Wanted | Techoff Srv Limited | 2026-10-04T15:06:47Z |
| 20.204.42.136 | blocked | 84.5 | Relentless | Microsoft Corporation | 2026-10-04T18:19:55Z |
| 45.138.12.26 | blocked | 83.0 | Relentless | Tc Datacenter Limited | 2026-10-02T14:56:32Z |
| 35.241.202.92 | blocked | 82.7 | Relentless | Google LLC | 2026-10-02T12:16:32Z |
| 34.156.121.46 | blocked | 82.3 | Relentless | Google LLC | 2026-10-02T09:18:16Z |
| 35.240.100.200 | blocked | 82.2 | Relentless | Google LLC | 2026-10-02T08:21:32Z |
| 213.209.159.133 | blocked | 80.7 | Relentless | Feo Prest SRL | 2026-10-04T22:53:56Z |
| 34.62.116.145 | blocked | 80.2 | Relentless | Google LLC | 2026-10-02T14:46:53Z |
| 34.140.234.80 | blocked | 80.0 | Relentless | Google LLC | 2026-10-02T13:12:39Z |
| 34.14.99.143 | blocked | 79.9 | Relentless | Google LLC | 2026-10-02T12:07:53Z |
| 34.156.206.32 | blocked | 79.4 | Relentless | Google LLC | 2026-10-02T08:07:37Z |
| 34.62.82.165 | blocked | 79.1 | Relentless | Google LLC | 2026-10-02T05:46:48Z |
| 20.219.185.206 | blocked | 78.8 | Relentless | Microsoft Corporation | 2026-10-04T20:48:58Z |
| 13.70.107.184 | blocked | 78.8 | Relentless | Microsoft Corporation | 2026-10-04T20:37:39Z |
| 20.58.177.98 | blocked | 77.9 | Relentless | Microsoft Corporation | 2026-10-04T22:08:45Z |
| 45.138.12.16 | blocked | 77.9 | Relentless | Tc Datacenter Limited | 2026-10-04T22:08:36Z |
Feeds
Free, signed, updated every 10 minutes. See /threats/about for the full terms.
- feed.txt — one address per line
- feed.json — full detail, with
expiresper address - feed-web.txt, feed-ssh.txt, feed-mail.txt, feed-panel.txt — per-surface
- vocab-v1.json — the surface/attack-type vocabulary
- pubkey.minisig — signing public key