This IP was reported 246 times. Confidence of
Abuse
is 67%: ?
67%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
246
times from
72 distinct
sources.
2602:80d:1003::2b was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Requests sent with a known malicious or scanner user-agent | req: / | UA: Mozilla/5.0 (compatible; C ...
show moreRequests sent with a known malicious or scanner user-agent | req: / | UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
show less
[MonAug1708:58:44.7170602026][security2:error][pid2351844:tid2352028][client2602:80d:1003::2b:0]ModS ...
show more[MonAug1708:58:44.7170602026][security2:error][pid2351844:tid2352028][client2602:80d:1003::2b:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"leonitraslochi.ch\"][uri\"/\"][unique_id\"aoKxJPCcqwT1mCR7iqxX8wAAAQ0\"]
show less
Requests sent with a known malicious or scanner user-agent | req: / | UA: Mozilla/5.0 (compatible; C ...
show moreRequests sent with a known malicious or scanner user-agent | req: / | UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: /
show less
Requests sent with a known malicious or scanner user-agent | req: / | 2 distinct paths | UA: Mozilla ...
show moreRequests sent with a known malicious or scanner user-agent | req: / | 2 distinct paths | UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
show less
[ThuAug1316:39:59.5716292026][security2:error][pid535920:tid535947][client2602:80d:1003::2b:0]ModSec ...
show more[ThuAug1316:39:59.5716292026][security2:error][pid535920:tid535947][client2602:80d:1003::2b:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"an3XP5zuV7pCYtvCczEZzwAAAJg\"]
show less
Triggered crowdsecurity/http-bad-user-agent. More information at: https://app.crowdsec.net/cti/2602: ...
show moreTriggered crowdsecurity/http-bad-user-agent. More information at: https://app.crowdsec.net/cti/2602:80d:1003::2b
show less
[MonAug1022:13:24.1563322026][security2:error][pid1057135:tid1057340][client2602:80d:1003::2b:0]ModS ...
show more[MonAug1022:13:24.1563322026][security2:error][pid1057135:tid1057340][client2602:80d:1003::2b:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"hosting-dominio.ch\"][uri\"/\"][unique_id\"anow5ApfwgxTE3XUVzvByQAAABg\"]
show less