This IP was reported 129 times. Confidence of
Abuse
is 58%: ?
58%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
129
times from
34 distinct
sources.
2602:80d:1007::ba was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[FriMay2905:06:52.7772572026][security2:error][pid1587349:tid1587472][client2602:80d:1007::ba:0]ModS ...
show more[FriMay2905:06:52.7772572026][security2:error][pid1587349:tid1587472][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.sisuconsulting.net\"][uri\"/\"][unique_id\"ahkCzMQ4lkpGkDMuEx_RmwAAAQw\"]
show less
[SunMay2414:13:41.6411722026][security2:error][pid3416604:tid3416954][client2602:80d:1007::ba:0]ModS ...
show more[SunMay2414:13:41.6411722026][security2:error][pid3416604:tid3416954][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.mondo-it.ch\"][uri\"/\"][unique_id\"ahLrdSlb9Ry9aCUT0-JXZwAAAEU\"]
show less
[FriMay1501:49:59.3833692026][security2:error][pid4069283:tid4069369][client2602:80d:1007::ba:0]ModS ...
show more[FriMay1501:49:59.3833692026][security2:error][pid4069283:tid4069369][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.pulispina.ch\"][uri\"/\"][unique_id\"agZfp7TeICYengHxYrPE8gAAAQI\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
[SunMay1017:24:56.2531142026][security2:error][pid1146605:tid1146724][client2602:80d:1007::ba:0]ModS ...
show more[SunMay1017:24:56.2531142026][security2:error][pid1146605:tid1146724][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.wildpferde.ch\"][uri\"/favicon.ico\"][unique_id\"agCjSN3VIpzx24XrVOT4AAAAAQc\"]
show less
[SatMay0901:23:41.0915322026][security2:error][pid2712540:tid2712613][client2602:80d:1007::ba:0]ModS ...
show more[SatMay0901:23:41.0915322026][security2:error][pid2712540:tid2712613][client2602:80d:1007::ba:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"fidmeyer.ch\"][uri\"/\"][unique_id\"af5wfZqsYBAZVfdN_F54pQAAAI0\"]
show less