{"schemaVersion":1,"meta":{"total30d":370,"windowDays":30,"crawlerTotal30d":357,"probesPerCrawler":1.04,"lastUpdated":"2026-07-25T18:48:17.357Z"},"whosDriving":{"total":371,"aiDriven":0,"aiDrivenPct":0,"byActor":[{"key":"scripted","label":"Scripted / commodity","blurb":"Wordlist replay. No comprehension, no adaptation, free to run.","count":370,"sharePct":99.7},{"key":"declared_platform","label":"Declared platform","blurb":"A named AI crawler behaving normally.","count":1,"sharePct":0.3}],"byCanaryChannel":[{"channel":"sitemap.xml","count":1}],"coercions":[],"caveat":"Actor classes combine request behaviour with a network-identity check. A user-agent is forgeable, so a platform claim is only reported as verified when the source IP falls inside that company's own published crawler ranges, and only as an impostor when the company publishes ranges and the IP is in none of them. Where we hold no ranges the verdict stays \"unverified\" and is never reported as impersonation. Verified coercion means the company's infrastructure was used, not that the company did anything wrong: the whole point is that someone else pointed it here."},"context":{"internetWide":{"source":"SANS Internet Storm Center","sourceUrl":"https://isc.sans.edu/","windowDays":8,"records":123542713,"avgDailyRecords":15442839,"peakDailySources":175072,"from":"2026-07-17","to":"2026-07-24"},"exploited":{"source":"CISA Known Exploited Vulnerabilities catalogue","sourceUrl":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","catalogVersion":"2026.07.24","total":1653,"buckets":[{"key":"ivanti","label":"Ivanti","surface":"enterprise edge","count":35},{"key":"fortinet","label":"Fortinet","surface":"enterprise edge","count":28},{"key":"citrix","label":"Citrix","surface":"enterprise edge","count":22},{"key":"atlassian","label":"Atlassian","surface":"enterprise app","count":13},{"key":"php","label":"PHP (general)","surface":"website","count":9},{"key":"wordpress","label":"WordPress","surface":"website","count":6}]},"refreshedAt":"2026-07-25T18:25:14.055Z","ourDailyAverage":12.3,"note":"Our sample is one small website. These public reference points exist so you can see how small, and judge the numbers accordingly."},"byCategory":[{"key":"secrets","label":"Secrets & credentials","blurb":"Environment files and key material. The highest-value miss on this list.","count":167,"sharePct":45.1},{"key":"wordpress","label":"WordPress & CMS","blurb":"By far the loudest category, and the one we are least able to satisfy.","count":162,"sharePct":43.8},{"key":"webshell","label":"Web shell / RCE","blurb":"Looking for an already-compromised host, or somewhere to drop code.","count":16,"sharePct":4.3},{"key":"source_exposure","label":"Source & config exposure","blurb":"Repository metadata and config left in the web root.","count":13,"sharePct":3.5},{"key":"admin_panel","label":"Admin panels","blurb":"Management interfaces that should never face the internet.","count":7,"sharePct":1.9},{"key":"other","label":"Everything else","blurb":"Paths that fit no common pattern.","count":5,"sharePct":1.4}],"impliedStacks":[{"stack":"WordPress","count":181,"sharePct":48.9},{"stack":"PHP (generic)","count":11,"sharePct":3},{"stack":"Git-deployed app","count":6,"sharePct":1.6},{"stack":"Laravel","count":1,"sharePct":0.3}],"topPaths":[{"path":"/wp-login.php","count":15,"category":"wordpress"},{"path":"/.env","count":15,"category":"secrets"},{"path":"//xmlrpc.php","count":10,"category":"wordpress"},{"path":"//wp/wp-includes/wlwmanifest.xml","count":10,"category":"wordpress"},{"path":"//shop/wp-includes/wlwmanifest.xml","count":10,"category":"wordpress"},{"path":"//test/wp-includes/wlwmanifest.xml","count":10,"category":"wordpress"},{"path":"//cms/wp-includes/wlwmanifest.xml","count":10,"category":"wordpress"},{"path":"/wp-content/themes/seotheme/db.php","count":10,"category":"webshell"},{"path":"//wp-includes/ID3/license.txt","count":7,"category":"wordpress"},{"path":"//web/wp-includes/wlwmanifest.xml","count":7,"category":"wordpress"},{"path":"//2019/wp-includes/wlwmanifest.xml","count":7,"category":"wordpress"},{"path":"/wp-content/plugins/fix/up.php","count":6,"category":"webshell"},{"path":"/wp-cron.php","count":5,"category":"wordpress"},{"path":"/ss.php","count":5,"category":"other"},{"path":"/api/.env","count":3,"category":"secrets"},{"path":"/.env.production","count":3,"category":"secrets"},{"path":"//blog/wp-includes/wlwmanifest.xml","count":3,"category":"wordpress"},{"path":"//wordpress/wp-includes/wlwmanifest.xml","count":3,"category":"wordpress"},{"path":"//2018/wp-includes/wlwmanifest.xml","count":3,"category":"wordpress"},{"path":"//wp2/wp-includes/wlwmanifest.xml","count":3,"category":"wordpress"}],"topAgents":[{"ua":"curl/8.7.1","count":134,"identifies":true},{"ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36","count":56,"identifies":false},{"ua":"Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36","count":29,"identifies":false},{"ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36","count":27,"identifies":false},{"ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36","count":24,"identifies":false},{"ua":"Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36","count":10,"identifies":false},{"ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36","count":7,"identifies":false},{"ua":"cache-probe-test/1.0","count":5,"identifies":false},{"ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36","count":5,"identifies":false},{"ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36","count":5,"identifies":false}],"daily":[{"day":"2026-07-16","count":160},{"day":"2026-07-17","count":34},{"day":"2026-07-18","count":29},{"day":"2026-07-19","count":12},{"day":"2026-07-20","count":45},{"day":"2026-07-21","count":3},{"day":"2026-07-22","count":6},{"day":"2026-07-23","count":42},{"day":"2026-07-24","count":26},{"day":"2026-07-25","count":13}],"newPaths":[{"path":"/wp-admin/css/","firstSeen":"2026-07-24","category":"wordpress","count":1},{"path":"/administrator/","firstSeen":"2026-07-24","category":"admin_panel","count":2},{"path":"/wp-admin/user/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/network/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/maint/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/js/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/includes/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/images/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/css/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-content/themes/Divi/404.php","firstSeen":"2026-07-23","category":"wordpress","count":1},{"path":"/wp-admin/index.php","firstSeen":"2026-07-23","category":"wordpress","count":2},{"path":"/wp-content/uploads/index.php","firstSeen":"2026-07-23","category":"wordpress","count":1}],"identification":{"identified":166,"anonymous":204,"identifiedPct":44.9},"notes":{"whatThisIs":"Every request to a path this site does not have and never had. Nobody is targeting us specifically, so this is the internet's ambient hostile background, not a targeted campaign.","whyItMatters":"The implied-stack breakdown shows what attackers believe is exploitable at scale right now. It is consistently years behind the security conversation.","limits":"One small site, one 30-day window. Volumes are not comparable to an enterprise perimeter. Paths are classified by pattern, so a novel technique lands in \"everything else\" until we teach the classifier."},"attribution":"Project Wrecked Threat Ledger, https://projectwrecked.com/threat-ledger/"}