This IP was reported 176 times. Confidence of
Abuse
is 100%: ?
100%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
176
times from
47 distinct
sources.
2602:80d:1008::21 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[WedAug1916:01:58.3649602026][security2:error][pid2531554:tid2531568][client2602:80d:1008::21:0]ModS ...
show more[WedAug1916:01:58.3649602026][security2:error][pid2531554:tid2531568][client2602:80d:1008::21:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.creazione-siti-web-ticino.ch\"][uri\"/\"][unique_id\"aoW3VnLo74ocH9nQQ4r5fQAAAAM\"]
show less
[TueAug1803:24:44.3017022026][security2:error][pid327250:tid327279][client2602:80d:1008::21:0]ModSec ...
show more[TueAug1803:24:44.3017022026][security2:error][pid327250:tid327279][client2602:80d:1008::21:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"kvsm-blackstone.com\"][uri\"/\"][unique_id\"aoO0XMssjH28DLsrx3TgmQAAAc4\"]
show less
[SunAug1621:09:00.9392832026][security2:error][pid519562:tid519576][client2602:80d:1008::21:0]ModSec ...
show more[SunAug1621:09:00.9392832026][security2:error][pid519562:tid519576][client2602:80d:1008::21:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"www.scrspace.com\"][uri\"/\"][unique_id\"aoIKzFIS9Q6X0LPrqbW1OwAAAIo\"]
show less
Malformed or malicious web request
2602:80d:1008::21 - - [16/Aug/2026:17:38:23 +0200] "\x16\x03\x01\ ...
show moreMalformed or malicious web request
2602:80d:1008::21 - - [16/Aug/2026:17:38:23 +0200] "\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xE9\x91h[\xA9\x5Cj+\xEC\xB7\x1F\xCB\xDF\xAC\x8FS\xF9\x901\xF8R\xD2s\x7F\x86\x14\xE9J\x19\x22\xB3\xFD \xDD\xD4\xFF\xC0\xFC\xD3\xACa4" 400 157 "-" "-"
show less
2602:80d:1008::21 has been banned for triggering http-bad-user-agent (2 events over 6.170841805s). T ...
show more2602:80d:1008::21 has been banned for triggering http-bad-user-agent (2 events over 6.170841805s). The user-agent http_access-log is not allowed.
show less