This IP was reported 262 times. Confidence of
Abuse
is 98%: ?
98%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
262
times from
65 distinct
sources.
2602:80d:1007::5c was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[WedSep1615:20:10.6649962026][security2:error][pid3014670:tid3014763][client2602:80d:1007::5c:0]ModS ...
show more[WedSep1615:20:10.6649962026][security2:error][pid3014670:tid3014763][client2602:80d:1007::5c:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"hosting-e-domini.com\"][uri\"/\"][unique_id\"aqqXiqnXvNKiNbgAUPFJpAAAAQI\"]
show less
[WedSep1601:35:58.1829082026][security2:error][pid3946152:tid3946159][client2602:80d:1007::5c:0]ModS ...
show more[WedSep1601:35:58.1829082026][security2:error][pid3946152:tid3946159][client2602:80d:1007::5c:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"aqnWXrFfCJBSqu6lr2IK-wAAAUQ\"]
show less
[TueSep1510:16:06.3487302026][security2:error][pid2979790:tid2979863][client2602:80d:1007::5c:0]ModS ...
show more[TueSep1510:16:06.3487302026][security2:error][pid2979790:tid2979863][client2602:80d:1007::5c:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.esengineering.ch\"][uri\"/\"][unique_id\"aqj-xjLr3KCE-vN5KxnoAgAAAIE\"]
show less
Keenetic Firewall: Persistent traffic from Blacklisted IP. Blocked via Kernel/NFLOG. (54 hits in 24h ...
show moreKeenetic Firewall: Persistent traffic from Blacklisted IP. Blocked via Kernel/NFLOG. (54 hits in 24h).
show less
CrowdSec: malicious bot / scanner detected (crowdsecurity/http-bad-user-agent) at 2026-09-14T22:49:3 ...
show moreCrowdSec: malicious bot / scanner detected (crowdsecurity/http-bad-user-agent) at 2026-09-14T22:49:30.621Z
show less
[ThuSep1015:16:07.1518642026][security2:error][pid324938:tid325051][client2602:80d:1007::5c:0]ModSec ...
show more[ThuSep1015:16:07.1518642026][security2:error][pid324938:tid325051][client2602:80d:1007::5c:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"manuclean.ch\"][uri\"/\"][unique_id\"aqKtlz6WVxefAR3Bl7a8bQAAAUA\"]
show less
[ThuSep1014:47:02.3398902026][security2:error][pid2683077:tid2683415][client2602:80d:1007::5c:0]ModS ...
show more[ThuSep1014:47:02.3398902026][security2:error][pid2683077:tid2683415][client2602:80d:1007::5c:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a02:29b8:dc01:545::625:de4f\"][uri\"/\"][unique_id\"aqKmxkvmlFzYmI1Cvu50IAAAANY\"]
show less
Hacking
Web App Attack
Showing 1 to
15
of 262 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ