abuseip.org
- Reason
- suspicious paths across 1 domains
- Hits (last hour)
- 64
- Unique targets hit
- 1
- Unique paths probed
- 3,335
- Detection count
- 44
- First seen
- 2026-09-01 18:33:13 UTC
- Last seen
- 2026-09-01 20:31:09 UTC
- Block expires
- 2026-09-02 20:31:32 UTC
Sample paths probed
- /plugins/captcha/crypt/cryptographp.php?cfg=1%0D%0ASet-Cookie:%20crlfinjection=1
- /redirector.php?do=nodelay&url=https://dns.wt-oob-server.com
- /updating.jsp?url=https://dns.wt-oob-server.com/
- /jobs/?"'><script>alert(document.domain)</script>
- /IntellectMain.jsp?IntellectSystem=https://www.dns.wt-oob-server.com
- /select_project.php?url=http://dns.wt-oob-server.com
- /auth/realms/master/protocol/openid-connect/auth?scope=openid&response_type=code&redirect_uri=valid&state=cfx&nonce=cfx&client_id=security-admin-console&request_uri=http://dabf76p620us6js33bi0jtd35njcec19p.dns.wt-oob-server.com/
- /html/common/forward_js.jsp?FORWARD_URL=http://dns.wt-oob-server.com
- /signin?from=javascript:alert(document.cookie)
- /OA_HTML/lcmServiceController.jsp
- /modules/babel/redirect.php?newurl=http://dns.wt-oob-server.com
- /labkey/__r1/login-login.view?returnUrl=http://dns.wt-oob-server.com
- /web/cgi-bin/hi3510/param.cgi?cmd=setmobilesnapattr&cururl=http%3A%2F%2Fdns.wt-oob-server.com
- /redirector.php?url=https://dns.wt-oob-server.com
- /boafrm/formWlanRedirect?redirect-url=http://dns.wt-oob-server.com&wlan_id=1
- /html/portlet/ext/common/page_preview_popup.jsp?hostname=dns.wt-oob-server.com
- /login?next=http://dns.wt-oob-server.com/?app.scan/
- //www.dns.wt-oob-server.com
- /api/logout?redirect_to=http://dns.wt-oob-server.com/
- /signin?from=https://dns.wt-oob-server.com
Sample User-Agents
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36
What does this mean?
This address sent traffic that the redirs.com edge classified as automated abuse โ typically WordPress/PHP exploit scanning, credential file probing (.env, .git, .aws/), or mass-domain enumeration. The block is automatic and time-limited (24 hours from last detection).
If you believe this is a false positive, contact [email protected] with the IP and the timestamps above.