This IP was reported 249 times. Confidence of
Abuse
is 47%: ?
47%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
249
times from
60 distinct
sources.
2602:80d:1005::12 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[ThuSep0320:53:14.3001752026][security2:error][pid3301393:tid3301527][client2602:80d:1005::12:0]ModS ...
show more[ThuSep0320:53:14.3001752026][security2:error][pid3301393:tid3301527][client2602:80d:1005::12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"apnCGiH2xnGIfijHsAWbJQAAARc\"]
show less
[ThuSep0301:05:25.5727002026][security2:error][pid2085005:tid2085092][client2602:80d:1005::12:0]ModS ...
show more[ThuSep0301:05:25.5727002026][security2:error][pid2085005:tid2085092][client2602:80d:1005::12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"apirtZlhEYQr5pTFPbEoVAAAAMA\"]
show less
[WedSep0208:45:09.2358092026][security2:error][pid2658389:tid2658924][client2602:80d:1005::12:0]ModS ...
show more[WedSep0208:45:09.2358092026][security2:error][pid2658389:tid2658924][client2602:80d:1005::12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a02:29b8:dc01:545::625:de4f\"][uri\"/\"][unique_id\"apfF9a7FkhE35073jgdlhQAAAUA\"]
show less
[TueSep0111:50:45.8843382026][security2:error][pid3997086:tid3997175][client2602:80d:1005::12:0]ModS ...
show more[TueSep0111:50:45.8843382026][security2:error][pid3997086:tid3997175][client2602:80d:1005::12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"apaf9XwhUAj86ehMZlthYQAAAMM\"]
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-31 14:30 UTC
show less
[SatAug2910:49:42.0599952026][security2:error][pid3853975:tid3854172][client2602:80d:1005::12:0]ModS ...
show more[SatAug2910:49:42.0599952026][security2:error][pid3853975:tid3854172][client2602:80d:1005::12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"formet.ch\"][uri\"/\"][unique_id\"apKdJqB6W1yzDKYG2OjjTAAAAhc\"]
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-27T01:29:27.917491812Z. Context: http_status=200
show less
[WedAug2614:45:16.1877532026][security2:error][pid3931907:tid3932185][client2602:80d:1005::12:0]ModS ...
show more[WedAug2614:45:16.1877532026][security2:error][pid3931907:tid3932185][client2602:80d:1005::12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"hdcadvisory.ch\"][uri\"/\"][unique_id\"ao7f3Dh7aACD4RGu4s4RdgAAAQQ\"]
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-26 12:20 UTC
show less
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5 ...
show moreAbusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) | path: / (+1 more) | 2026-08-23 13:57 UTC
show less
Bad Web Bot
Showing 1 to
15
of 249 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ