Recent Activity
This IP has received recent abuse reports, which causes the score to increase.
IPv6 SLAAC Note
Public IPv6 addresses may implement the SLAAC
privacy extension. With SLAAC, the interface identifier is randomly generated. SLAAC also implements a
configurable time out, so that the original IPv6 interface addresses will be discarded in favor of a new
interface identifier.
This IP address has been reported a total of
35
times from
22 distinct
sources.
2400:6180:0:d2:0:3:3082:8000 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
United States of America
with 15
reports;
Netherlands
with 7
reports;
Hungary
with 3
reports.
The most common categories in these recent reports were:
Web App Attack
26
times;
Bad Web Bot
18
times;
Brute-Force
12
times;
Hacking
7
times;
Port Scan
1
time;
Other
2
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-30.
show less
Honeypot triggered: /server/.env on ifebridge.com. User-Agent: Mozilla/5.0 (X11; Linux x86_64) Apple ...
show moreHoneypot triggered: /server/.env on ifebridge.com. User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36. Method: GET
show less
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show moreAutomated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/phpinfo via rule ...
show more[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/phpinfo via rule: /config
show less
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show moreTriggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /index.php
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
| [Dangerous/Singapore] Aggressive IP 2400:6180:0:d2:0:3:3082:8000 (~30 hits). Type: DoS Defender- W ...
show more| [Dangerous/Singapore] Aggressive IP 2400:6180:0:d2:0:3:3082:8000 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Honeypot triggered: /.env on ifebridge.com. User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bu ...
show moreHoneypot triggered: /.env on ifebridge.com. User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36. Method: GET
show less