This IP address has been reported a total of
149
times from
132 distinct
sources.
20.63.63.224 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show moreTriggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /fm.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
263 requests with url.path */wp.php
242 requests with url.path */wp-content/plugins/hellopress/wp_ ...
show more263 requests with url.path */wp.php
242 requests with url.path */wp-content/plugins/hellopress/wp_filemanager.php
show less
Bot / scanning and/or hacking attempts: GET /mini.php HTTP/1.1, GET /wp-admin/includes/index.php HTT ...
show moreBot / scanning and/or hacking attempts: GET /mini.php HTTP/1.1, GET /wp-admin/includes/index.php HTTP/1.1, GET /init.php HTTP/1.1, GET /wp-info.php HTTP/1.1, GET /100.php HTTP/1.1, GET /fm.php HTTP/1.1, GET /plugins.php HTTP/1.1, GET / HTTP/1.1, GET /z.ph HTTP/1.1, GET /xroot7.php HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
Multiple web server 400 error codes from same source ip
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 20.63.63.224 (CA/Canada/-): 1 in the last 360 ...
show more(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 20.63.63.224 (CA/Canada/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.63.63.224 - - [31/May/2026:18:17:40 +0200] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/1.1" 301 162 "-" "-" "-" host=ip96.ip-51-89-2.eu
show less