This IP was reported 247 times. Confidence of
Abuse
is 91%: ?
91%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
247
times from
78 distinct
sources.
2602:80d:1003::2f was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-25 07:54 UTC
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-25T03:59:01.530582662Z. Context: http_status=200
show less
[SunAug2309:16:26.6636202026][security2:error][pid3537682:tid3537819][client2602:80d:1003::2f:0]ModS ...
show more[SunAug2309:16:26.6636202026][security2:error][pid3537682:tid3537819][client2602:80d:1003::2f:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"aoqeShvBzxTYkWrEYGsmvQAAAVg\"]
show less
CrowdSec local HTTP alert
scenario: crowdsecurity/http-bad-user-agent
alert_id: 4759
events: 2
creat ...
show moreCrowdSec local HTTP alert
scenario: crowdsecurity/http-bad-user-agent
alert_id: 4759
events: 2
created_at: 2026-08-23T00:38:42Z
message: Ip 2602:80d:1003::2f performed 'crowdsecurity/http-bad-user-agent' (2 events over 3.699239886s) at 2026-08-23 00:38:41.71019204 +0000 UTC
target_uri: ["/","/favicon.ico"]
method: ["GET"]
status: ["200","404"]
user_agent: ["Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"]
show less
[SatAug2217:07:55.9493502026][security2:error][pid2938984:tid2939242][client2602:80d:1003::2f:0]ModS ...
show more[SatAug2217:07:55.9493502026][security2:error][pid2938984:tid2939242][client2602:80d:1003::2f:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a02:29b8:dc01:545::625:de4f\"][uri\"/\"][unique_id\"aom7S-mpxvHYyTYyHZ-YhwAAABc\"]
show less
[ThuAug2008:23:26.1291042026][security2:error][pid3478318:tid3478453][client2602:80d:1003::2f:0]ModS ...
show more[ThuAug2008:23:26.1291042026][security2:error][pid3478318:tid3478453][client2602:80d:1003::2f:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.gmint.ch\"][uri\"/\"][unique_id\"aoadXtaOH7stERJDPohY7gAAARg\"]
show less
[MonAug1708:19:18.7718122026][security2:error][pid2213420:tid2213458][client2602:80d:1003::2f:0]ModS ...
show more[MonAug1708:19:18.7718122026][security2:error][pid2213420:tid2213458][client2602:80d:1003::2f:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a02:29b8:dc01:545::625:de4f\"][uri\"/\"][unique_id\"aoKn5uU7XJseSEuDWHbYfgAAAA8\"]
show less
Hacking
Web App Attack
Showing 1 to
15
of 247 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ