This IP was reported 327 times. Confidence of
Abuse
is 90%: ?
90%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
327
times from
79 distinct
sources.
2602:80d:1007::31 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-30T00:48:02.019565103Z. Context: http_status=200, http_status=302
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-29T19:05:23.900059457Z. Context: http_status=200, http_status=302
show less
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show moreCrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-08-29T02:14:06.634248503Z. Context: http_status=200
show less
[AUTORAVALT][[28/08/2026 - 10:53:13 -03:00 UTC]
Attack from [Censys, Inc.]
[2602:80d:1007::31] Actio ...
show more[AUTORAVALT][[28/08/2026 - 10:53:13 -03:00 UTC]
Attack from [Censys, Inc.]
[2602:80d:1007::31] Action: BLocKed
Bad Web Bot -> Webpage scraping (email extraction, content, etc.) crawlers that do not respect robots.txt. Excessive requests and user agent spoofing.
]
...
show less
[FriAug2815:45:35.6488672026][security2:error][pid2722793:tid2722841][client2602:80d:1007::31:0]ModS ...
show more[FriAug2815:45:35.6488672026][security2:error][pid2722793:tid2722841][client2602:80d:1007::31:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.fidmeyer.ch\"][uri\"/images/favicon.ico\"][unique_id\"apGQ_wLyYgpmKi75HT-M-AAAAEQ\"]
show less
[FriAug2802:37:50.6104392026][security2:error][pid3183019:tid3183290][client2602:80d:1007::31:0]ModS ...
show more[FriAug2802:37:50.6104392026][security2:error][pid3183019:tid3183290][client2602:80d:1007::31:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"whatsdecor.ch\"][uri\"/wp-content/uploads/2018/11/cropped-Logo-WD-sito-1-32x32.jpg\"][unique_id\"apDYXloI1dfk130MxVnX_gAAAQc\"]
show less
2602:80d:1007::31 has been banned for triggering http-bad-user-agent (2 events over 2.704449254s). T ...
show more2602:80d:1007::31 has been banned for triggering http-bad-user-agent (2 events over 2.704449254s). The user-agent http_access-log is not allowed.
show less
Bad Web Bot
Showing 31 to
45
of 327 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ