abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 30
- Unique targets hit
- 3
- Unique paths probed
- 470
- Detection count
- 11
- First seen
- 2026-06-29 03:10:30 UTC
- Last seen
- 2026-06-29 03:16:00 UTC
- Block expires
- 2026-06-30 04:09:44 UTC
Sample paths probed
- /account
- /cgi-bin/stats
- /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/upload.cfm
- /CTCWebService/CTCWebServiceBean?wsdl
- /cgi-bin/status
- /cgi-bin/test
- /KaseyaCwWebService/ManagedIT.asmx
- /test.cgi
- /crowd/admin/uploadplugin.action
- /cgi-bin/status/status.cgi
- /cgi-bin/test.cgi
- /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/f5-release
- /
- /debug.cgi
- /cgi-bin/test-cgi
- /users/sign_in
- /invoker/JMXInvokerServlet/
- /cgi/ping.cgi?pinghost=127.0.0.1;echo%203FnEr7RFUeJjKtHMwEwEbGdHXDu&pingsize=3
- /ui/h5-vsan/rest/proxy/service/com.vmware.vsan.client.services.capability.VsanCapabilityProvider/getClusterCapabilityData
- /soap.cgi?service=whatever-control;curl
Sample User-Agents
- RootEvidence/1.0
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.