This IP was reported 197 times. Confidence of
Abuse
is 85%: ?
85%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
197
times from
46 distinct
sources.
2602:80d:1008::9e was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatAug2903:21:00.0128172026][security2:error][pid3426807:tid3426831][client2602:80d:1008::9e:0]ModS ...
show more[SatAug2903:21:00.0128172026][security2:error][pid3426807:tid3426831][client2602:80d:1008::9e:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"apIz_OMcThMgKNQBt1NTqQAAAAs\"]
show less
Repeated bad requests to web service - Repeat offender 2602:80d:1008::9e banned at least 2 times in ...
show moreRepeated bad requests to web service - Repeat offender 2602:80d:1008::9e banned at least 2 times in the last 7 days
show less
[WedAug2600:10:29.0374102026][security2:error][pid3053919:tid3053966][client2602:80d:1008::9e:0]ModS ...
show more[WedAug2600:10:29.0374102026][security2:error][pid3053919:tid3053966][client2602:80d:1008::9e:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"ao4S1TOICCI3Zz9I2QiH_gAAAEs\"]
show less
Blocked by UFW (TCP on 443)
Source port: 11352
Packet length: 80
This report (for 2602:080d:1008:00 ...
show moreBlocked by UFW (TCP on 443)
Source port: 11352
Packet length: 80
This report (for 2602:080d:1008:0000:0000:0000:0000:009e) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
2602:80d:1008::9e has been banned for triggering http-bad-user-agent (2 events over 544.87701ms). Th ...
show more2602:80d:1008::9e has been banned for triggering http-bad-user-agent (2 events over 544.87701ms). The user-agent http_access-log is not allowed.
show less
[SunAug2314:30:31.0216362026][security2:error][pid3821995:tid3822084][client2602:80d:1008::9e:0]ModS ...
show more[SunAug2314:30:31.0216362026][security2:error][pid3821995:tid3822084][client2602:80d:1008::9e:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"2a01:4f8:212:1561::8\"][uri\"/\"][unique_id\"aorn50Ndul4TWDhR8LBSUAAAAMM\"]
show less
[WedAug1911:46:01.1709312026][security2:error][pid2274948:tid2275078][client2602:80d:1008::9e:0]ModS ...
show more[WedAug1911:46:01.1709312026][security2:error][pid2274948:tid2275078][client2602:80d:1008::9e:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\bshodan\\\\\\\\b\|\\\\\\\\bcensysinspect\\\\\\\\b\|\\\\\\\\bcensys\\\\\\\\b\|\\\\\\\\bexpanse\\\\\\\\b\|\\\\\\\\bnetsystemsresearch\\\\\\\\b\|\\\\\\\\bnetcraftsurveyagent\\\\\\\\b\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"73\"][id\"338801\"][rev\"1\"][msg\"Atomicorp.comWAFRules:Blockedinternet-widesurveyorUA\"][severity\"ERROR\"][hostname\"mail.specialfood.ch\"][uri\"/\"][unique_id\"aoV7WQCdTbUT8DDBFgcKcQAAAlg\"]
show less
Malformed or malicious web request
2602:80d:1008::9e - - [18/Aug/2026:09:49:31 +0200] "\x16\x03\x01\ ...
show moreMalformed or malicious web request
2602:80d:1008::9e - - [18/Aug/2026:09:49:31 +0200] "\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x91#\xF38\x0F.-\xB1\x91\xF2\x18c8\xAFsry\xB6sd\x16c" 400 157 "-" "-"
show less
Hacking
Web App Attack
Showing 1 to
15
of 197 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ