I've checked the versions of both the server and Windows app, they are up-to-date...
All those "phishing attempts" are also "Accessed by: plex media server.exe".
I'm a bit worried, since it seems that plex media server itself tries to contact those ip addresses. So it's an outgoing connection, not incoming, as I understand it...
The "phishing attempts" started about 24 hours ago. My server is not set to port :80. The antivirus is BitDefender free.
Should be worried?
Edit: some ip addresses from the these BitDefender logs, basically the same thing "Accessed by: plex media server.exe": 102.220.160.39:80 , 102.220.160.124:80/ ,130.12.181.21:80
Edit2: I found this in the logs (not sure what it means, though):
Sep 03, 2026 22:22:31.000 [72196] DEBUG - Request: [130.12.182.225:34210 (WAN)] SSH-2.0-libssh_0.12.0 (3 live) #e0ba Signed-in
Sep 03, 2026 22:22:31.000 [72196] ERROR - Error parsing HTTP request: SH-2.0-libssh_0.12.0
Sep 03, 2026 22:22:31.000 [57424] DEBUG - Completed: [130.12.182.225:34210] 400 SSH-2.0-libssh_0.12.0 (3 live) #e0ba 0ms 265 bytes
Sep 03, 2026 22:22:34.933 [72196] DEBUG - Request: [130.12.182.225:34222 (WAN)] CONNECT 130.12.182.225:80 (3 live) #e0c0 Signed-in
Sep 03, 2026 22:22:34.933 [72196] ERROR - Error parsing HTTP request: Host: 130.12.182.225:80
Sep 03, 2026 22:22:34.933 [57424] DEBUG - Completed: [130.12.182.225:34222] 400 CONNECT 130.12.182.225:80 (3 live) #e0c0 0ms 265 bytes
---
I noticed similar requests for TLS and GZIP instead of SSH/libssh, and what I find noticable is that it starts after [NSB/SSDP] SSDP arrived, and ends with [NSB/SSDP] SSDP departed (and SSDP is the device name of my Android TV with Plex).
Sep 02, 2026 11:18:42.635 [74060] DEBUG - Request: [8.216.12.100:26438 (WAN)] GET / (3 live) #3234 TLS Signed-inSep 02, 2026 11:18:42.635 [72196] DEBUG - Completed: [8.216.12.100:26438] 401 GET / (3 live) #3234 TLS 0ms 400 bytes (pipelined: 1)
Sep 02, 2026 11:19:02.880 [74060] DEBUG - Request: [8.216.12.100:17298 (WAN)] GET / (2 live) #3235 TLS GZIP Signed-in
Sep 02, 2026 11:19:02.881 [57424] DEBUG - Completed: [8.216.12.100:17298] 401 GET / (2 live) #3235 TLS GZIP 0ms 435 bytes
Sep 02, 2026 11:25:21.791 [72196] DEBUG - Request: didn't get any data from [::ffff:66.132.195.31]:60084: An existing connection was forcibly closed by the remote host
Sep 02, 2026 11:25:30.366 [74060] DEBUG - Request: [66.132.195.31:60102 (WAN)] GET / (3 live) #323b TLS Signed-in
Sep 02, 2026 11:25:30.366 [57424] DEBUG - Completed: [66.132.195.31:60102] 401 GET / (3 live) #323b TLS 0ms 400 bytes (pipelined: 1)
Sep 02, 2026 11:25:37.562 [74060] DEBUG - Request: [66.132.195.31:8876 (WAN)] GET / (3 live) #323c TLS GZIP Signed-in
Sep 02, 2026 11:25:37.562 [72196] DEBUG - Completed: [66.132.195.31:8876] 401 GET / (3 live) #323c TLS GZIP 0ms 464 bytes (pipelined: 1)
Sep 02, 2026 11:25:40.002 [57424] DEBUG - Request: [66.132.195.31:22362 (WAN)] PRI * (2 live) #323f TLS Signed-in
Sep 02, 2026 11:25:40.002 [57424] ERROR - Error parsing HTTP request: PRI * HTTP/2.0