This IP was reported 270 times. Confidence of
Abuse
is 63%: ?
63%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
270
times from
76 distinct
sources.
2602:80d:1003::33 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-27 11:27 UTC
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-27T11:24:31.895357349Z. Context: http_status=200, http_status=404
show less
[WedAug2608:41:44.1908972026][security2:error][pid3551522:tid3551591][client2602:80d:1003::33:0]ModS ...
show more[WedAug2608:41:44.1908972026][security2:error][pid3551522:tid3551591][client2602:80d:1003::33:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.spazi-web-hosting.ch\"][uri\"/\"][unique_id\"ao6KqNZE3iKa8cQq6h-9SQAAAIg\"]
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-25T12:41:06.833265847Z. Context: http_status=304
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-25 02:18 UTC
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-24 09:20 UTC
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more)
show less
[SatAug2222:19:13.1553622026][security2:error][pid2898523:tid2898564][client2602:80d:1003::33:0]ModS ...
show more[SatAug2222:19:13.1553622026][security2:error][pid2898523:tid2898564][client2602:80d:1003::33:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"aooEQVWywnAg5Iu-6iYQaQAAAEQ\"]
show less
[FriAug2118:46:51.0273282026][security2:error][pid1329405:tid1329569][client2602:80d:1003::33:0]ModS ...
show more[FriAug2118:46:51.0273282026][security2:error][pid1329405:tid1329569][client2602:80d:1003::33:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/sitemap.xml\"][unique_id\"aoiA-9pW6IA0k0NK59jKJQAAABE\"]
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-21T11:46:11.589396866Z. Context: http_status=200
show less
[TueAug1810:13:58.8485392026][security2:error][pid769363:tid769501][client2602:80d:1003::33:0]ModSec ...
show more[TueAug1810:13:58.8485392026][security2:error][pid769363:tid769501][client2602:80d:1003::33:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.spazi-web-hosting.ch\"][uri\"/\"][unique_id\"aoQURsFE87iH4ouDN14RxQAAAlQ\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
15
of 270 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ