Live attack traffic

normandale.net — one small Minnesota website 12:49 AM CT
1,094
attacks caught in the last 24 hours
5,695
visits in the last 24 hours
97%
confirmed automated in the last 24 hours
72,763
visits counted lower bound since Jul 18

Happening now 1 person · 42 machines in the last hour · 2 watching this page · newest first

12:49 AM US Opened this dashboard /ktsp likely you watching
12:46 AM IN WordPress break-in attempt (unlisted path) ×10 attack probe
12:46 AM US · DigitalOcean WordPress break-in attempt (unlisted path) attack probe
12:46 AM ID WordPress break-in attempt (trap: WordPress user list) attack probe
12:46 AM DE · Cloudflare WordPress break-in attempt (trap: WordPress installer) attack probe
12:46 AM SG WordPress break-in attempt (trap: WordPress API) attack probe
12:46 AM US WordPress break-in attempt (trap: WordPress user list) attack probe
12:46 AM IN WordPress break-in attempt (unlisted path) ×6 attack probe
Most recent person on the site
12:41 AM US Person reading the site /why/ person

Requests per hour · last 24 hours

1 AM7 AM1 PM7 PM
automated (bottom of each bar) people (top) unresolved faded bar = still in progress, or only partly recorded · gap = not recorded

What the bots are hunting for every one is a decoy — the real site has none of them

Password file (.env) 1,711
WordPress installer 1,495
Source code folder (.git) 830
WordPress user list 686
Server info page 451
Editor upload settings 344
App config file 336
Hosting control panel 261
Mac folder listing 236
Debug toolbar 233
WordPress API 194
Database admin panel 188
WordPress login page 186
Java admin endpoint 180
Live server status 150
Microsoft Exchange 122
Admin console 120
Cloud account keys 108
Container registry 108
adminer 84
openid-cpanelid 58
owncloud-graphapi-phpinfo 56
env-bak 55
credentials-json 43
Developer server keys 43
index-php 43
Database backup 36
vite-fs 33
AI API — status 33
SSH private key 21
WordPress admin 16
WordPress XML-RPC 13
openapi-json 11
ip-echo 11
Old server test page 9
api-openapi-json 8
gcp-service-account 6
Automated deploy script 5
AI API — chat endpoint 4
api-keys-json 4

Point at any trap — or tap it — to see what it is.

6,728 caught since Aug 17. Read the counts as an order, not exact totals. 3 stolen fake passwords have since been used.

Where the automated traffic arrives from 17 countries in the live window

Iran 179
United States 38
India 25
Hong Kong 13
Singapore 8
Indonesia 7

Where the traffic enters from, not who is behind it — attackers rent machines abroad.

Requests per day

Aug 17Aug 19Aug 21Aug 23Aug 25Aug 27Aug 29

Every day looks like every other day: this is the internet's ordinary background rate against one small site.

97% of this traffic is not people. Machines scan every site on the internet, all day. Being small does not make you safe.
They are looking for unlocked doors — old software, forgotten admin pages, passwords left in a file. None of it is personal.
Simple habits stop almost all of it. Install updates. Use a different, strong password everywhere. Turn on two-factor login.