abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 16
- Unique targets hit
- 3
- Unique paths probed
- 393
- Detection count
- 8
- First seen
- 2026-09-08 22:57:40 UTC
- Last seen
- 2026-09-08 23:30:19 UTC
- Block expires
- 2026-09-09 23:57:43 UTC
Sample paths probed
- /xmlrpc
- /wp-content/plugins/backupbuddy/readme.txt
- /api/content/
- /fileupload/toolsAny
- /mgmt/tm/util/bash
- /_ignition/execute-solution
- /sap/admin/public/default.html
- /3J46DtomMNPxsGVaY9LpB1ub9bY.jsp
- /goanywhere/lic/accept
- /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22whoami%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D/
- /
- /zimbraAdmin/0MVzAe6pgwe5go1D.jsp
- /wp-content/plugins/backupbuddy/backupbuddy.php
- /service/extension/backup/mboximport?account-name=admin&account-status=1&ow=cmd
- /api/v2/cmdb/system/admin
- /aspera/faspex/package_relay/relay_package
- /sap/public/bc/ur/Login/assets/corbu/sap_logo.png
- /authenticationendpoint/3j46dsll1i4bkayda4pstbxdazz.jsp
- /service/extension/backup/mboximport?account-name=admin&ow=2&no-switch=1&append=1
- /login.zul
Sample User-Agents
- RootEvidence/1.0
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.