This IP was reported 94 times. Confidence of
Abuse
is 67%: ?
67%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
94
times from
29 distinct
sources.
2602:80d:1007::ba was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[FriJul3101:53:53.1518652026][security2:error][pid3596120:tid3596239][client2602:80d:1007::ba:0]ModS ...
show more[FriJul3101:53:53.1518652026][security2:error][pid3596120:tid3596239][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"amvkEZDV_z8wQsY2uDC4JAAAAQU\"]
show less
[SunJul2601:45:10.3324782026][security2:error][pid1748707:tid1748726][client2602:80d:1007::ba:0]ModS ...
show more[SunJul2601:45:10.3324782026][security2:error][pid1748707:tid1748726][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"swiss-web-hosting.ch\"][uri\"/\"][unique_id\"amVKhmdj_1c3mibLO2cQ2gAAAAA\"]
show less
[MonJul2015:25:10.5792422026][security2:error][pid1445814:tid1445853][client2602:80d:1007::ba:0]ModS ...
show more[MonJul2015:25:10.5792422026][security2:error][pid1445814:tid1445853][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.lascalasagl.ch\"][uri\"/\"][unique_id\"al4htqUlZSP-4kwoRsiEoAAAAMU\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
15
of 94 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ