This IP was reported 367 times. Confidence of
Abuse
is 24%: ?
24%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
367
times from
38 distinct
sources.
2001:470:1:fb5::9b was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2001:0470:0001:0fb5:0000:0000:0000:009b was recorded attempting unexpectedly to open an IPv6 Protoco ...
show more2001:0470:0001:0fb5:0000:0000:0000:009b was recorded attempting unexpectedly to open an IPv6 Protocol 41 tunnel.
show less
Blocked by UFW (TCP on 5443)
Source port: 56257
Packet length: 60
This report (for 2001:0470:0001:0 ...
show moreBlocked by UFW (TCP on 5443)
Source port: 56257
Packet length: 60
This report (for 2001:0470:0001:0fb5:0000:0000:0000:009b) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show moreTriggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Confirmed malicious activity observed via T-Pot honeypot Observed 2 events on port 8090 (flow) from ...
show moreConfirmed malicious activity observed via T-Pot honeypot Observed 2 events on port 8090 (flow) from 2026-01-03T15:20:34.326000+00:00 to 2026-01-03T18:02:44.256000+00:00. Sample: {"src_port": 39773, "dest_port": 8090, "event_type": "flow", "src_ip": "2001:0470:0001:0fb5:0000:0000:0000:009b"}
show less
Exploited Host
Showing 1 to
15
of 367 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ