Design preview — Design 3. Same live data as the board; vote here.

The Watchtower

A live view of the addresses attacking our servers: who they are, what they tried, and a free signed block list you can use on your own firewall. How this works →

LIVE SENSOR FEED 11m since last attack
24 hours
26,223events
503addresses
307blocked
7 days
152,441events
2,204addresses
307blocked
all time
174,533events
3,402addresses
307blocked

Is my IP here?

Live feed

TimeAddressWhat happenedOutcome
2026-10-04T22:53:56Z213.209.159.13332 requests on 32 distinct paths — requested a .env file, hoping to find API keys or database credentials (×18); fuzzed a short, random filename looking for a forgotten script that responds (×5); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×3); +5 more kinds
2026-10-04T22:52:53Z–2026-10-04T22:52:54Z185.95.156.1824 requests on 2 distinct paths — requested wp-login.php to check whether this site runs WordPress (×2); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×2)
2026-10-04T22:52:41Z94.154.43.31requested an absolute URL instead of a path, testing whether this server behaves as an open forward proxy
2026-10-04T22:52:18Z–2026-10-04T22:52:27Z35.201.174.12692 requests on 85 distinct paths — requested a .env file, hoping to find API keys or database credentials (×37); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×27); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×13); +6 more kinds
2026-10-04T22:20:00Z–2026-10-04T22:52:24Z195.178.110.1594 requests on 4 distinct paths — probed for an exposed .svn directory to read the site's version-control metadata (×2); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1)
2026-10-04T22:51:54Z–2026-10-04T22:52:06Z104.208.73.22750 requests on 50 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds
2026-10-04T22:45:13Z–2026-10-04T22:45:16Z74.161.160.333 requests on 3 distinct paths — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×1); requested wp-login.php to check whether this site runs WordPress (×1)
2026-10-04T22:44:53Z161.118.226.254read a WordPress plugin's readme.txt to fingerprint its exact version for a known vulnerability
2026-10-04T22:41:29Z–2026-10-04T22:41:30Z203.159.90.9018 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1)
2026-10-04T22:40:33Z–2026-10-04T22:40:36Z192.227.203.22818 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1)
2026-10-04T22:38:26Z93.123.109.16716 requests on 8 distinct paths — requested wp-login.php to check whether this site runs WordPress
2026-10-04T22:35:19Z–2026-10-04T22:36:32Z20.214.109.6811 requests on 11 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×3); probed wp-includes/PHPMailer/, a WordPress core library directory commonly used to drop a webshell after a prior compromise (×3); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×3); +2 more kinds
2026-10-04T22:31:16Z–2026-10-04T22:31:34Z20.210.186.18636 requests on 36 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×31); requested wp-login.php to check whether this site runs WordPress (×3); fuzzed a common filename under /cgi-bin/, looking for a forgotten legacy CGI script (×2)
2026-10-04T22:24:53Z–2026-10-04T22:30:26Z213.209.159.223156 requests on 154 distinct paths — requested a .env file, hoping to find API keys or database credentials (×118); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×12); requested a database dump or site archive by its common backup filename (×6); +10 more kinds
2026-10-04T22:29:36Z–2026-10-04T22:29:53Z20.204.16.11369 requests on 69 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×63); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×4); requested a filename commonly used by web shells left behind by a previous compromise (×1); +1 more kind
2026-10-04T22:28:13Z–2026-10-04T22:28:34Z20.210.128.12537 requests on 37 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×33); requested a WordPress core file used to fingerprint the installed version and active plugins (×1); requested wp-config.php or a backup copy of it, hoping to read the database password in clear text (×1); +2 more kinds
2026-10-04T22:27:08Z–2026-10-04T22:27:18Z20.194.30.10720 requests on 20 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×19); checked for a known-vulnerable or backdoored WordPress plugin path (×1)
2026-10-04T22:17:03Z–2026-10-04T22:17:40Z20.194.96.11483 requests on 83 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×61); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×13); requested a filename commonly used by web shells left behind by a previous compromise (×2); +6 more kinds
2026-10-04T22:15:32Z54.202.51.12probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface
2026-10-04T22:05:32Z–2026-10-04T22:14:17Z136.110.31.111437 requests across 2 sites, 160 distinct paths — requested a .env file, hoping to find API keys or database credentials (×169); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×88); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×52); +21 more kindsblock
2026-10-04T22:11:46Z–2026-10-04T22:11:47Z185.19.40.20218 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1)
2026-10-04T22:07:13Z–2026-10-04T22:10:50Z45.194.37.66 requests — probed a list of common site paths looking for an unprotected admin panel or staging copy
2026-10-04T22:08:19Z–2026-10-04T22:08:57Z130.12.180.11756 requests on 19 distinct paths — requested a .env file, hoping to find API keys or database credentials (×50); requested the .git directory itself, hoping it is exposed and browsable (×3); probed for an exposed .git directory to download the site's source history and config (×3)
2026-10-04T22:08:20Z–2026-10-04T22:08:45Z20.58.177.9875 requests on 75 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×74); checked for a known-vulnerable or backdoored WordPress plugin path (×1)
2026-10-04T22:08:32Z–2026-10-04T22:08:36Z45.138.12.163 requests on 3 distinct paths — requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×1); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1)
2026-10-04T22:07:49Z–2026-10-04T22:07:50Z134.122.120.1755 requests on 5 distinct paths — probed a list of common site paths looking for an unprotected admin panel or staging copy
2026-10-04T22:05:51Z150.241.203.217attempted to relay mail through this server and was rejected (open-relay/spam probe)
2026-10-04T22:04:08Z–2026-10-04T22:04:18Z8.231.206.27204 requests on 161 distinct paths — requested a .env file, hoping to find API keys or database credentials (×79); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×24); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×20); +23 more kindsblock
2026-10-04T22:03:39Z2804:1128:bcc0:9300:f4e5:d81c:38b7:cbf4requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods
2026-10-04T22:03:03Z–2026-10-04T22:03:15Z20.219.11.1640 requests on 40 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×37); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×2); checked for a known-vulnerable or backdoored WordPress plugin path (×1)
2026-10-04T22:01:43Z–2026-10-04T22:01:45Z34.147.108.214189 requests on 159 distinct paths — requested a .env file, hoping to find API keys or database credentials (×64); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×36); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×22); +21 more kinds
2026-10-04T22:00:06Z–2026-10-04T22:01:10Z34.97.233.3191 requests on 190 distinct paths — requested a .env file, hoping to find API keys or database credentials (×188); requested the .git directory itself, hoping it is exposed and browsable (×2); requested phpinfo.php, which dumps the full PHP configuration and environment if left in place (×1)
2026-10-04T22:00:18Z178.211.139.240fuzzed a short, random filename looking for a forgotten script that responds
2026-10-04T21:49:37Z81.171.72.93requested wp-config.php or a backup copy of it, hoping to read the database password in clear textblock
2026-10-04T21:38:50Z–2026-10-04T21:39:03Z34.159.8.403 requests on 3 distinct paths — triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attemptblock
2026-10-04T21:30:43Z–2026-10-04T21:30:58Z34.94.159.1314 requests on 14 distinct paths — requested a .env file, hoping to find API keys or database credentials (×11); was blocked at the edge without matching any specific attack signature (×3)block
2026-10-04T21:24:08Z34.32.78.193 requests — triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attemptblock
2026-10-04T21:08:41Z–2026-10-04T21:22:24Z102.201.253.23677 requests — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floodsblock
2026-10-04T21:11:33Z18.145.72.193triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attemptblock
2026-10-04T21:06:30Z–2026-10-04T21:10:23Z154.64.37.5522 requests — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floodsblock

Breakdowns

Events per hour (7 days)

View as table (168 hourly buckets)
HourEvents
2026-10-02T23:00:00Z385
2026-10-03T00:00:00Z897
2026-10-03T01:00:00Z688
2026-10-03T02:00:00Z469
2026-10-03T03:00:00Z371
2026-10-03T04:00:00Z856
2026-10-03T05:00:00Z876
2026-10-03T06:00:00Z923
2026-10-03T07:00:00Z1115
2026-10-03T08:00:00Z1187
2026-10-03T09:00:00Z673
2026-10-03T10:00:00Z933
2026-10-03T11:00:00Z909
2026-10-03T12:00:00Z756
2026-10-03T13:00:00Z1043
2026-10-03T14:00:00Z353
2026-10-03T15:00:00Z1076
2026-10-03T16:00:00Z727
2026-10-03T17:00:00Z435
2026-10-03T18:00:00Z1590
2026-10-03T19:00:00Z905
2026-10-03T20:00:00Z1062
2026-10-03T21:00:00Z802
2026-10-03T22:00:00Z1376
2026-10-03T23:00:00Z832
2026-10-04T00:00:00Z618
2026-10-04T01:00:00Z661
2026-10-04T02:00:00Z1146
2026-10-04T03:00:00Z1365
2026-10-04T04:00:00Z507
2026-10-04T05:00:00Z887
2026-10-04T06:00:00Z890
2026-10-04T07:00:00Z787
2026-10-04T08:00:00Z723
2026-10-04T09:00:00Z1784
2026-10-04T10:00:00Z1183
2026-10-04T11:00:00Z949
2026-10-04T12:00:00Z550
2026-10-04T13:00:00Z567
2026-10-04T14:00:00Z1263
2026-10-04T15:00:00Z1049
2026-10-04T16:00:00Z745
2026-10-04T17:00:00Z1068
2026-10-04T18:00:00Z1080
2026-10-04T19:00:00Z1715
2026-10-04T20:00:00Z2199
2026-10-04T21:00:00Z1759
2026-10-04T22:00:00Z1896

Surface × attack type (7 days)

View as table
SurfaceAttack typeCount
web-apprecon74813
web-appsecrets-hunt56160
web-appcredential-spray6583
web-appscanner-tool5905
web-appinjection4662
web-appunknown2602
web-appcve-exploit852
panelsecrets-hunt329
mail-smtpcredential-brute207
mail-smtpspam-relay-probe126
web-appbot-impersonation68
panelscanner-tool38
panelrecon26
sshscanner-tool18
ftpcredential-brute17
panelcredential-brute12
panelinjection8
panelopen-proxy-probe8
sshrecon5
web-appdos-pattern2

Top ASNs

View as table
ASNOrganisationAddresses
AS396982Google LLC1201
AS14061DigitalOcean, LLC353
AS8075Microsoft Corporation151
AS48090Techoff Srv Limited66
AS206092F.n.s. Holdings Limited58
AS16509Amazon.com, Inc.53
AS63949Akamai Connected Cloud50
AS218785Tc Datacenter Limited39
AS31898Oracle Corporation38
AS197170TechTies Inc.37

Top 10 countries

View as table
CountryAddresses
United States1145
Singapore194
India184
The Netherlands177
Germany170
France130
Belgium123
United Kingdom94
Taiwan86
Brazil82

Most Wanted

Hosting/cloud-ASN addresses only — a residential or mobile address never appears here, whatever its score.

144.172.97.202
93.3
blockedWantedRegular
RouterHosting LLC
last seen 2026-10-04T17:25:56Z
45.138.12.28
92.0
blockedWantedRegularNight OwlToolkit
Tc Datacenter Limited
last seen 2026-10-02T13:30:55Z
213.209.159.223
90.0
blockedWantedRegularToolkit
Feo Prest SRL
last seen 2026-10-04T22:30:26Z
207.175.220.59
89.6
blockedWantedRegularToolkit
Google LLC
last seen 2026-10-01T20:09:51Z
45.148.10.120
89.0
blockedWantedRegularToolkitRepeat Offender
Techoff Srv Limited
last seen 2026-10-04T15:06:47Z
20.204.42.136
84.5
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T18:19:55Z
45.138.12.26
83.0
blockedRelentlessRegularToolkit
Tc Datacenter Limited
last seen 2026-10-02T14:56:32Z
35.241.202.92
82.7
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T12:16:32Z
34.156.121.46
82.3
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T09:18:16Z
35.240.100.200
82.2
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T08:21:32Z
213.209.159.133
80.7
blockedRelentlessRegularToolkit
Feo Prest SRL
last seen 2026-10-04T22:53:56Z
34.62.116.145
80.2
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T14:46:53Z
34.140.234.80
80.0
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T13:12:39Z
34.14.99.143
79.9
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T12:07:53Z
34.156.206.32
79.4
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T08:07:37Z
34.62.82.165
79.1
blockedRelentlessRegularNight OwlToolkit
Google LLC
last seen 2026-10-02T05:46:48Z
20.219.185.206
78.8
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T20:48:58Z
13.70.107.184
78.8
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T20:37:39Z
20.58.177.98
77.9
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T22:08:45Z
45.138.12.16
77.9
blockedRelentlessRegularToolkit
Tc Datacenter Limited
last seen 2026-10-04T22:08:36Z

Feeds

Free, signed, updated every 10 minutes. See /threats/about for the full terms.

Read the method, thresholds, retention and removal policy →