abuseip.org
Public registry of IP addresses currently blocked by the redirs.com anycast edge for automated abuse — credential scanning, WordPress/PHP exploit probing, and mass-domain enumeration.
- Blocked IPs
- 878
- Total recent hits
- 348,497
- Last refresh
- 2026-07-31 05:21:46 UTC
- Block duration
- 24 hours from last detection
How to look up an IP
Visit https://abuseip.org/ip/<address>. For example: https://abuseip.org/ip/172.69.166.86.
The full list of blocked IPs is in the sitemap.
Bulk export
Machine-readable feeds, regenerated hourly:
/blocklist.txt— one IP per line, suitable for firewalls / fail2ban / ipset/blocklist.json— full structured records (reason, hits, timestamps, sample paths)/blocklist.xml— same data as XML
Customer hostnames are intentionally omitted from all exports.
Recent detections
20.104.18.253— scanning 181 domains (6,853 hits)20.104.16.169— scanning 123 domains (6,044 hits)191.232.199.39— scanning 46 domains (2,672 hits)20.226.5.174— scanning 178 domains (6,156 hits)20.113.56.22— scanning 26 domains (980 hits)20.63.98.115— scanning 18 domains (5,976 hits)91.92.241.196— scanning 133 domains (200 hits)45.148.10.120— scanning 82 domains (82 hits)159.65.1.163— suspicious paths across 25 domains (1,921 hits)20.203.133.142— scanning 34 domains (1,064 hits)158.158.32.229— scanning 22 domains (447 hits)138.246.253.24— scanning 81 domains (81 hits)4.223.71.149— scanning 25 domains (925 hits)51.120.79.193— scanning 31 domains (927 hits)91.134.35.95— scanning 21 domains (75 hits)185.93.89.167— scanning 21 domains (697 hits)94.154.43.229— scanning 18 domains (18 hits)52.165.196.84— scanning 63 domains (11,158 hits)20.9.4.9— scanning 62 domains (6,428 hits)20.197.178.120— scanning 56 domains (10,094 hits)34.148.249.196— suspicious paths across 12 domains (318 hits)85.204.70.104— scanning 30 domains (329 hits)20.48.234.177— scanning 62 domains (11,408 hits)74.248.24.145— scanning 35 domains (3,641 hits)193.47.62.167— scanning 190 domains (190 hits)
Removal & contact
Blocks expire automatically 24 hours after the last detected hit. For false-positive reports email [email protected] with the IP and the relevant timestamps.