This IP was reported 191 times. Confidence of
Abuse
is 100%: ?
100%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
191
times from
56 distinct
sources.
2602:80d:1008::56 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SunAug2308:56:01.3536212026][security2:error][pid3522696:tid3522787][client2602:80d:1008::56:0]ModS ...
show more[SunAug2308:56:01.3536212026][security2:error][pid3522696:tid3522787][client2602:80d:1008::56:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"aoqZgSXgNWY3WGfI_XPCggAAAQE\"]
show less
[ThuAug2017:08:42.6035202026][security2:error][pid4018669:tid4018707][client2602:80d:1008::56:0]ModS ...
show more[ThuAug2017:08:42.6035202026][security2:error][pid4018669:tid4018707][client2602:80d:1008::56:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"aocYet-U7uzan7-svhavcQAAAII\"]
show less
Blocked by CrowdSec | Scenario: crowdsecurity/http-bad-user-agent | 2602:80d:1008::56 triggered 2 ev ...
show moreBlocked by CrowdSec | Scenario: crowdsecurity/http-bad-user-agent | 2602:80d:1008::56 triggered 2 events | Detected: 2026-08-20T01:57:03.559070127Z
show less
[WedAug1910:35:42.3598972026][security2:error][pid2193802:tid2193904][client2602:80d:1008::56:0]ModS ...
show more[WedAug1910:35:42.3598972026][security2:error][pid2193802:tid2193904][client2602:80d:1008::56:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"hdcadvisory.ch\"][uri\"/\"][unique_id\"aoVq3nC0XHjY7mWGQT1nMgAAAgk\"]
show less
Requests sent with a known malicious or scanner user-agent | req: / | UA: Mozilla/5.0 (compatible; C ...
show moreRequests sent with a known malicious or scanner user-agent | req: / | UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
show less
[SunAug1604:13:40.7897232026][security2:error][pid971059:tid971307][client2602:80d:1008::56:0]ModSec ...
show more[SunAug1604:13:40.7897232026][security2:error][pid971059:tid971307][client2602:80d:1008::56:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"swisservers.com\"][uri\"/\"][unique_id\"aoEc1O6kiHvf6wcW3shIHgAAAVY\"]
show less
Hacking
Web App Attack
Showing 1 to
15
of 191 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ