This IP address has been reported a total of
31
times from
26 distinct
sources.
43.250.53.42 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Automated exploitation attempt of WordPress CVE-2026-87902 (unauthenticated path traversal in page-t ...
show moreAutomated exploitation attempt of WordPress CVE-2026-87902 (unauthenticated path traversal in page-template resolution, GHSA-7hp8-65ch-5whp) against a self-hosted nginx web service. Double-encoded pagename traversal probes targeting local PHP file inclusion (pearcmd.php oracle variants included). Self-hosted service; no site identifiers included.
show less
Automated mass web-app vuln scan across multiple hosts behind Akamai WAF in ~5 min window. Observed: ...
show moreAutomated mass web-app vuln scan across multiple hosts behind Akamai WAF in ~5 min window. Observed: time-based blind SQLi (SLEEP(6)) on wp-admin/admin-ajax.php and chopslider plugin; LFI/path traversal (../../etc/passwd) on several endpoints; OS command injection (cat /etc/passwd) on pandora_console/ajax.php; Apache Struts2 OGNL RCE attempts (Runtime.exec sh -c id) on index.action/login.action; SSRF/RCE probe via soap.cgi using wget/curl to an oast.pro collaborator domain; PHP pearcmd LFI-to-RCE probe. All requests blocked by Akamai WAF (403 SQL-INJECTION-ANOMALY/LFI-ANOMALY/CMD-INJECTION-ANOMALY/WAT-ANOMALY rules) or 404. IP is hosting/datacenter range already reported by multiple independent parties for identical scanning against unrelated third-party sites in the same time window, confirming broad internet-wide automated scanning rather than a targeted attack.
show less
unauthorized rest api call [22/Sep/2026:23:17:58 "GET /index.php?rest_route=/wp/v2/pages&per_page=3& ...
show moreunauthorized rest api call [22/Sep/2026:23:17:58 "GET /index.php?rest_route=/wp/v2/pages&per_page=3&_fields=id,template"]
show less
Attack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on www.ideaviihde.fi (Dir ...
show moreAttack attempt against Interwebbi servers; (WPNINJA) Ninja Firewall attack on www.ideaviihde.fi (Directory traversal #1) 43.250.53.42 (-): 1 in the last 3600 secs (CF_ENABLE); IP: 43.250.53.42; Ports: *; Direction: 0; Trigger: LF_CUSTOMTRIGGER;
show less
Web App Attack
Showing 1 to
15
of 31 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ