This IP was reported 283 times. Confidence of
Abuse
is 100%: ?
100%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
283
times from
71 distinct
sources.
2602:80d:1007::30 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Malformed or malicious web request
2602:80d:1007::30 - - [17/Apr/2026:11:59:22 +0200] "PRI * HTTP/2. ...
show moreMalformed or malicious web request
2602:80d:1007::30 - - [17/Apr/2026:11:59:22 +0200] "PRI * HTTP/2.0" 400 157 "-" "-"
show less
[FriApr1709:08:22.9582922026][security2:error][pid1773044:tid1773224][client2602:80d:1007::30:0]ModS ...
show more[FriApr1709:08:22.9582922026][security2:error][pid1773044:tid1773224][client2602:80d:1007::30:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.scuolaviva.ch\"][uri\"/\"][unique_id\"aeHcZqwKo8O0HGL0pHcUMAAAAFg\"]
show less
2602:80d:1007::30 has been banned for triggering http-bad-user-agent (2 events over 829.803625ms). T ...
show more2602:80d:1007::30 has been banned for triggering http-bad-user-agent (2 events over 829.803625ms). The user-agent http_access-log is not allowed.
show less
[MonApr1303:51:07.0609022026][security2:error][pid83537:tid83575][client2602:80d:1007::30:0]ModSecur ...
show more[MonApr1303:51:07.0609022026][security2:error][pid83537:tid83575][client2602:80d:1007::30:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"esengineering.ch\"][uri\"/\"][unique_id\"adxMCzBErEdWUE3wSrwXfwAAAII\"]
show less
[SunApr1217:12:10.9069792026][security2:error][pid1846806:tid1846810][client2602:80d:1007::30:0]ModS ...
show more[SunApr1217:12:10.9069792026][security2:error][pid1846806:tid1846810][client2602:80d:1007::30:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a02:29b8:dc01:545::625:de4f\"][uri\"/\"][unique_id\"adu2Sl5w4RKPMvNRJn-l_wAAAQE\"]
show less
Hacking
Web App Attack
Anonymous
89-nginx-x00
...
Bad Web Bot
Web App Attack
Anonymous
Scenarios: http-bad-user-agent
Total requests: 4
[11/Apr/2026:23:50:46 +0000] [Client: 2602:80d:1007 ...
show moreScenarios: http-bad-user-agent
Total requests: 4
[11/Apr/2026:23:50:46 +0000] [Client: 2602:80d:1007::30] GET [200] "/ HTTP/1.1" User-Agent: "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
[11/Apr/2026:23:50:46 +0000] [Client: 2602:80d:1007::30] GET [200] "/favicon.ico HTTP/1.1" User-Agent: "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
show less
[SatApr1103:26:55.9323402026][security2:error][pid1787852:tid1787958][client2602:80d:1007::30:0]ModS ...
show more[SatApr1103:26:55.9323402026][security2:error][pid1787852:tid1787958][client2602:80d:1007::30:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"gustotondo.ch\"][uri\"/\"][unique_id\"admjX1zI875_twXqY5jkzQAAAII\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 241 to
255
of 283 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ