This IP was reported 166 times. Confidence of
Abuse
is 74%: ?
74%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
166
times from
54 distinct
sources.
2602:80d:1007::20 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[ThuJul2309:41:52.8498242026][security2:error][pid1364339:tid1364466][client2602:80d:1007::20:0]ModS ...
show more[ThuJul2309:41:52.8498242026][security2:error][pid1364339:tid1364466][client2602:80d:1007::20:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.scrspace.com\"][uri\"/\"][unique_id\"amHFwMRrFrPySJB8MBdImgAAAVI\"]
show less
[WedJul2209:12:24.9885462026][security2:error][pid1470071:tid1470340][client2602:80d:1007::20:0]ModS ...
show more[WedJul2209:12:24.9885462026][security2:error][pid1470071:tid1470340][client2602:80d:1007::20:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a02:29b8:dc01:545::625:de4f\"][uri\"/\"][unique_id\"amBtWM3oqvPi7eKb4pVOwwAAAI0\"]
show less
CrowdSec: malicious bot / scanner detected (crowdsecurity/http-bad-user-agent) at 2026-07-22T03:44:5 ...
show moreCrowdSec: malicious bot / scanner detected (crowdsecurity/http-bad-user-agent) at 2026-07-22T03:44:59.473Z
show less
CrowdSec local HTTP alert
scenario: crowdsecurity/http-bad-user-agent
alert_id: 1452
events: 2
creat ...
show moreCrowdSec local HTTP alert
scenario: crowdsecurity/http-bad-user-agent
alert_id: 1452
events: 2
created_at: 2026-07-20T23:20:05Z
message: Ip 2602:80d:1007::20 performed 'crowdsecurity/http-bad-user-agent' (2 events over 1.917554729s) at 2026-07-20 23:20:05.469809287 +0000 UTC
target_uri: ["/","/favicon.ico"]
method: ["GET"]
status: ["200","404"]
user_agent: ["Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"]
show less
[MonJul2009:48:35.4316152026][security2:error][pid1445818:tid1445925][client2602:80d:1007::20:0]ModS ...
show more[MonJul2009:48:35.4316152026][security2:error][pid1445818:tid1445925][client2602:80d:1007::20:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.aaaa6877.org\"][uri\"/\"][unique_id\"al3S039oyQcOJpsK-h61AAAAAFc\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 31 to
45
of 166 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ