The Watchtower
A live view of the addresses attacking our servers: who they are, what they tried, and a free signed block list you can use on your own firewall. How this works →
LIVE SENSOR FEED 11m since last attack
24 hours
26,223events
503addresses
307blocked
7 days
152,441events
2,204addresses
307blocked
all time
174,533events
3,402addresses
307blocked
Is my IP here?
Live feed
| Time | Address | What happened | Outcome |
|---|---|---|---|
| 2026-10-04T22:53:56Z | 213.209.159.133 | 32 requests on 32 distinct paths — requested a .env file, hoping to find API keys or database credentials (×18); fuzzed a short, random filename looking for a forgotten script that responds (×5); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×3); +5 more kinds | |
| 2026-10-04T22:52:53Z–2026-10-04T22:52:54Z | 185.95.156.182 | 4 requests on 2 distinct paths — requested wp-login.php to check whether this site runs WordPress (×2); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×2) | |
| 2026-10-04T22:52:41Z | 94.154.43.31 | requested an absolute URL instead of a path, testing whether this server behaves as an open forward proxy | |
| 2026-10-04T22:52:18Z–2026-10-04T22:52:27Z | 35.201.174.126 | 92 requests on 85 distinct paths — requested a .env file, hoping to find API keys or database credentials (×37); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×27); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×13); +6 more kinds | |
| 2026-10-04T22:20:00Z–2026-10-04T22:52:24Z | 195.178.110.159 | 4 requests on 4 distinct paths — probed for an exposed .svn directory to read the site's version-control metadata (×2); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1) | |
| 2026-10-04T22:51:54Z–2026-10-04T22:52:06Z | 104.208.73.227 | 50 requests on 50 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds | |
| 2026-10-04T22:45:13Z–2026-10-04T22:45:16Z | 74.161.160.33 | 3 requests on 3 distinct paths — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×1); requested wp-login.php to check whether this site runs WordPress (×1) | |
| 2026-10-04T22:44:53Z | 161.118.226.254 | read a WordPress plugin's readme.txt to fingerprint its exact version for a known vulnerability | |
| 2026-10-04T22:41:29Z–2026-10-04T22:41:30Z | 203.159.90.90 | 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1) | |
| 2026-10-04T22:40:33Z–2026-10-04T22:40:36Z | 192.227.203.228 | 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1) | |
| 2026-10-04T22:38:26Z | 93.123.109.167 | 16 requests on 8 distinct paths — requested wp-login.php to check whether this site runs WordPress | |
| 2026-10-04T22:35:19Z–2026-10-04T22:36:32Z | 20.214.109.68 | 11 requests on 11 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×3); probed wp-includes/PHPMailer/, a WordPress core library directory commonly used to drop a webshell after a prior compromise (×3); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×3); +2 more kinds | |
| 2026-10-04T22:31:16Z–2026-10-04T22:31:34Z | 20.210.186.186 | 36 requests on 36 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×31); requested wp-login.php to check whether this site runs WordPress (×3); fuzzed a common filename under /cgi-bin/, looking for a forgotten legacy CGI script (×2) | |
| 2026-10-04T22:24:53Z–2026-10-04T22:30:26Z | 213.209.159.223 | 156 requests on 154 distinct paths — requested a .env file, hoping to find API keys or database credentials (×118); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×12); requested a database dump or site archive by its common backup filename (×6); +10 more kinds | |
| 2026-10-04T22:29:36Z–2026-10-04T22:29:53Z | 20.204.16.113 | 69 requests on 69 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×63); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×4); requested a filename commonly used by web shells left behind by a previous compromise (×1); +1 more kind | |
| 2026-10-04T22:28:13Z–2026-10-04T22:28:34Z | 20.210.128.125 | 37 requests on 37 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×33); requested a WordPress core file used to fingerprint the installed version and active plugins (×1); requested wp-config.php or a backup copy of it, hoping to read the database password in clear text (×1); +2 more kinds | |
| 2026-10-04T22:27:08Z–2026-10-04T22:27:18Z | 20.194.30.107 | 20 requests on 20 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×19); checked for a known-vulnerable or backdoored WordPress plugin path (×1) | |
| 2026-10-04T22:17:03Z–2026-10-04T22:17:40Z | 20.194.96.114 | 83 requests on 83 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×61); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×13); requested a filename commonly used by web shells left behind by a previous compromise (×2); +6 more kinds | |
| 2026-10-04T22:15:32Z | 54.202.51.12 | probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | |
| 2026-10-04T22:05:32Z–2026-10-04T22:14:17Z | 136.110.31.111 | 437 requests across 2 sites, 160 distinct paths — requested a .env file, hoping to find API keys or database credentials (×169); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×88); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×52); +21 more kinds | block |
| 2026-10-04T22:11:46Z–2026-10-04T22:11:47Z | 185.19.40.202 | 18 requests on 18 distinct paths — requested a WordPress core file used to fingerprint the installed version and active plugins (×17); requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods (×1) | |
| 2026-10-04T22:07:13Z–2026-10-04T22:10:50Z | 45.194.37.6 | 6 requests — probed a list of common site paths looking for an unprotected admin panel or staging copy | |
| 2026-10-04T22:08:19Z–2026-10-04T22:08:57Z | 130.12.180.117 | 56 requests on 19 distinct paths — requested a .env file, hoping to find API keys or database credentials (×50); requested the .git directory itself, hoping it is exposed and browsable (×3); probed for an exposed .git directory to download the site's source history and config (×3) | |
| 2026-10-04T22:08:20Z–2026-10-04T22:08:45Z | 20.58.177.98 | 75 requests on 75 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×74); checked for a known-vulnerable or backdoored WordPress plugin path (×1) | |
| 2026-10-04T22:08:32Z–2026-10-04T22:08:36Z | 45.138.12.16 | 3 requests on 3 distinct paths — requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×1); requested the .git directory itself, hoping it is exposed and browsable (×1); probed for an exposed .git directory to download the site's source history and config (×1) | |
| 2026-10-04T22:07:49Z–2026-10-04T22:07:50Z | 134.122.120.175 | 5 requests on 5 distinct paths — probed a list of common site paths looking for an unprotected admin panel or staging copy | |
| 2026-10-04T22:05:51Z | 150.241.203.217 | attempted to relay mail through this server and was rejected (open-relay/spam probe) | |
| 2026-10-04T22:04:08Z–2026-10-04T22:04:18Z | 8.231.206.27 | 204 requests on 161 distinct paths — requested a .env file, hoping to find API keys or database credentials (×79); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×24); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×20); +23 more kinds | block |
| 2026-10-04T22:03:39Z | 2804:1128:bcc0:9300:f4e5:d81c:38b7:cbf4 | requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | |
| 2026-10-04T22:03:03Z–2026-10-04T22:03:15Z | 20.219.11.16 | 40 requests on 40 distinct paths — fuzzed a short, random filename looking for a forgotten script that responds (×37); probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface (×2); checked for a known-vulnerable or backdoored WordPress plugin path (×1) | |
| 2026-10-04T22:01:43Z–2026-10-04T22:01:45Z | 34.147.108.214 | 189 requests on 159 distinct paths — requested a .env file, hoping to find API keys or database credentials (×64); used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root (×36); requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot (×22); +21 more kinds | |
| 2026-10-04T22:00:06Z–2026-10-04T22:01:10Z | 34.97.233.3 | 191 requests on 190 distinct paths — requested a .env file, hoping to find API keys or database credentials (×188); requested the .git directory itself, hoping it is exposed and browsable (×2); requested phpinfo.php, which dumps the full PHP configuration and environment if left in place (×1) | |
| 2026-10-04T22:00:18Z | 178.211.139.240 | fuzzed a short, random filename looking for a forgotten script that responds | |
| 2026-10-04T21:49:37Z | 81.171.72.93 | requested wp-config.php or a backup copy of it, hoping to read the database password in clear text | block |
| 2026-10-04T21:38:50Z–2026-10-04T21:39:03Z | 34.159.8.40 | 3 requests on 3 distinct paths — triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | block |
| 2026-10-04T21:30:43Z–2026-10-04T21:30:58Z | 34.94.159.13 | 14 requests on 14 distinct paths — requested a .env file, hoping to find API keys or database credentials (×11); was blocked at the edge without matching any specific attack signature (×3) | block |
| 2026-10-04T21:24:08Z | 34.32.78.19 | 3 requests — triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | block |
| 2026-10-04T21:08:41Z–2026-10-04T21:22:24Z | 102.201.253.236 | 77 requests — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | block |
| 2026-10-04T21:11:33Z | 18.145.72.193 | triggered Cloudflare's managed rule for a Next.js server-action request-smuggling/RCE attempt | block |
| 2026-10-04T21:06:30Z–2026-10-04T21:10:23Z | 154.64.37.55 | 22 requests — requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | block |
Breakdowns
Events per hour (7 days)
View as table (168 hourly buckets)
| Hour | Events |
|---|---|
| 2026-10-02T23:00:00Z | 385 |
| 2026-10-03T00:00:00Z | 897 |
| 2026-10-03T01:00:00Z | 688 |
| 2026-10-03T02:00:00Z | 469 |
| 2026-10-03T03:00:00Z | 371 |
| 2026-10-03T04:00:00Z | 856 |
| 2026-10-03T05:00:00Z | 876 |
| 2026-10-03T06:00:00Z | 923 |
| 2026-10-03T07:00:00Z | 1115 |
| 2026-10-03T08:00:00Z | 1187 |
| 2026-10-03T09:00:00Z | 673 |
| 2026-10-03T10:00:00Z | 933 |
| 2026-10-03T11:00:00Z | 909 |
| 2026-10-03T12:00:00Z | 756 |
| 2026-10-03T13:00:00Z | 1043 |
| 2026-10-03T14:00:00Z | 353 |
| 2026-10-03T15:00:00Z | 1076 |
| 2026-10-03T16:00:00Z | 727 |
| 2026-10-03T17:00:00Z | 435 |
| 2026-10-03T18:00:00Z | 1590 |
| 2026-10-03T19:00:00Z | 905 |
| 2026-10-03T20:00:00Z | 1062 |
| 2026-10-03T21:00:00Z | 802 |
| 2026-10-03T22:00:00Z | 1376 |
| 2026-10-03T23:00:00Z | 832 |
| 2026-10-04T00:00:00Z | 618 |
| 2026-10-04T01:00:00Z | 661 |
| 2026-10-04T02:00:00Z | 1146 |
| 2026-10-04T03:00:00Z | 1365 |
| 2026-10-04T04:00:00Z | 507 |
| 2026-10-04T05:00:00Z | 887 |
| 2026-10-04T06:00:00Z | 890 |
| 2026-10-04T07:00:00Z | 787 |
| 2026-10-04T08:00:00Z | 723 |
| 2026-10-04T09:00:00Z | 1784 |
| 2026-10-04T10:00:00Z | 1183 |
| 2026-10-04T11:00:00Z | 949 |
| 2026-10-04T12:00:00Z | 550 |
| 2026-10-04T13:00:00Z | 567 |
| 2026-10-04T14:00:00Z | 1263 |
| 2026-10-04T15:00:00Z | 1049 |
| 2026-10-04T16:00:00Z | 745 |
| 2026-10-04T17:00:00Z | 1068 |
| 2026-10-04T18:00:00Z | 1080 |
| 2026-10-04T19:00:00Z | 1715 |
| 2026-10-04T20:00:00Z | 2199 |
| 2026-10-04T21:00:00Z | 1759 |
| 2026-10-04T22:00:00Z | 1896 |
Surface × attack type (7 days)
View as table
| Surface | Attack type | Count |
|---|---|---|
| web-app | recon | 74813 |
| web-app | secrets-hunt | 56160 |
| web-app | credential-spray | 6583 |
| web-app | scanner-tool | 5905 |
| web-app | injection | 4662 |
| web-app | unknown | 2602 |
| web-app | cve-exploit | 852 |
| panel | secrets-hunt | 329 |
| mail-smtp | credential-brute | 207 |
| mail-smtp | spam-relay-probe | 126 |
| web-app | bot-impersonation | 68 |
| panel | scanner-tool | 38 |
| panel | recon | 26 |
| ssh | scanner-tool | 18 |
| ftp | credential-brute | 17 |
| panel | credential-brute | 12 |
| panel | injection | 8 |
| panel | open-proxy-probe | 8 |
| ssh | recon | 5 |
| web-app | dos-pattern | 2 |
Top ASNs
View as table
| ASN | Organisation | Addresses |
|---|---|---|
| AS396982 | Google LLC | 1201 |
| AS14061 | DigitalOcean, LLC | 353 |
| AS8075 | Microsoft Corporation | 151 |
| AS48090 | Techoff Srv Limited | 66 |
| AS206092 | F.n.s. Holdings Limited | 58 |
| AS16509 | Amazon.com, Inc. | 53 |
| AS63949 | Akamai Connected Cloud | 50 |
| AS218785 | Tc Datacenter Limited | 39 |
| AS31898 | Oracle Corporation | 38 |
| AS197170 | TechTies Inc. | 37 |
Top 10 countries
View as table
| Country | Addresses |
|---|---|
| United States | 1145 |
| Singapore | 194 |
| India | 184 |
| The Netherlands | 177 |
| Germany | 170 |
| France | 130 |
| Belgium | 123 |
| United Kingdom | 94 |
| Taiwan | 86 |
| Brazil | 82 |
Most Wanted
Hosting/cloud-ASN addresses only — a residential or mobile address never appears here, whatever its score.
144.172.97.202
93.3
blockedWantedRegular
RouterHosting LLC
last seen 2026-10-04T17:25:56Z
45.138.12.28
92.0
blockedWantedRegularNight OwlToolkit
Tc Datacenter Limited
last seen 2026-10-02T13:30:55Z
213.209.159.223
90.0
blockedWantedRegularToolkit
Feo Prest SRL
last seen 2026-10-04T22:30:26Z
207.175.220.59
89.6
blockedWantedRegularToolkit
Google LLC
last seen 2026-10-01T20:09:51Z
45.148.10.120
89.0
blockedWantedRegularToolkitRepeat Offender
Techoff Srv Limited
last seen 2026-10-04T15:06:47Z
20.204.42.136
84.5
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T18:19:55Z
45.138.12.26
83.0
blockedRelentlessRegularToolkit
Tc Datacenter Limited
last seen 2026-10-02T14:56:32Z
35.241.202.92
82.7
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T12:16:32Z
34.156.121.46
82.3
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T09:18:16Z
35.240.100.200
82.2
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T08:21:32Z
213.209.159.133
80.7
blockedRelentlessRegularToolkit
Feo Prest SRL
last seen 2026-10-04T22:53:56Z
34.62.116.145
80.2
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T14:46:53Z
34.140.234.80
80.0
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T13:12:39Z
34.14.99.143
79.9
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T12:07:53Z
34.156.206.32
79.4
blockedRelentlessRegularToolkit
Google LLC
last seen 2026-10-02T08:07:37Z
34.62.82.165
79.1
blockedRelentlessRegularNight OwlToolkit
Google LLC
last seen 2026-10-02T05:46:48Z
20.219.185.206
78.8
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T20:48:58Z
13.70.107.184
78.8
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T20:37:39Z
20.58.177.98
77.9
blockedRelentlessRegularToolkit
Microsoft Corporation
last seen 2026-10-04T22:08:45Z
45.138.12.16
77.9
blockedRelentlessRegularToolkit
Tc Datacenter Limited
last seen 2026-10-04T22:08:36Z
Feeds
Free, signed, updated every 10 minutes. See /threats/about for the full terms.
- feed.txt — one address per line, hosting and cloud networks (CSF/Cloudflare-list compatible)
- feed-residential.txt — opt-in: residential, mobile and unknown networks (30-day windows)
- feed-listed.txt — lower confidence: listed and blocked, not enforced by us
- feed-v6.txt — blocked IPv6 as /64 prefixes
- feed.json — full detail, with
expiresper address - feed-web.txt, feed-ssh.txt, feed-mail.txt, feed-panel.txt — per-surface
- vocab-v1.json — the surface/attack-type vocabulary
- pubkey.minisig — signing public key