Report for IP: 45.88.186.30

Threat LevelHIGH62/1002 rule types across 2 attack categories
3 incidents on record · 2 rule types · active attacker + blocklisted · last seen 44d ago
PTR N/A
Org / ASN 1337 Services GmbH
Country 🇺🇸 United States
City Miami, Florida
Timezone America/New_York

Attack Analysis

IDS: Blocklist — Spamhaus DROP
This IP is on the Spamhaus DROP list — a dataset of netblocks hijacked or leased by professional spam and cybercrime operations with no legitimate users. Traffic from DROP-listed ranges is considered hostile by design. Blocking is unconditional.
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.

Reports (3)

Date Severity Description
17 Aug 2026 - 07:28 high IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 6
17 Aug 2026 - 00:02 high Web: Webshell scan — 3+ unknown PHP probes in 60s
16 Aug 2026 - 23:51 high IDS: Blocklist — Spamhaus DROP listed IP — ET DROP Spamhaus DROP Listed Traffic Inbound group 6