This IP was reported 77 times. Confidence of
Abuse
is 100%: ?
100%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
77
times from
34 distinct
sources.
2602:fb54:1a00::53 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SatJun1314:26:51.0950942026][security2:error][pid1098132:tid1098222][client2602:fb54:1a00::53:0]Mod ...
show more[SatJun1314:26:51.0950942026][security2:error][pid1098132:tid1098222][client2602:fb54:1a00::53:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"gualandi.mood4apps.com\"][uri\"/wp-content/debug.log\"][unique_id\"ai1Mi_ti9RvRKS88bL5BhQAAAJM\"]
show less
{"level":"info","ts":1781347735.9136002,"logger":"http.log.access.log0","msg":"handled request","req ...
show more{"level":"info","ts":1781347735.9136002,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"2602:fb54:1a00::53","remote_port":"21288","client_ip":"2602:fb54:1a00::53","proto":"HTTP/1.1","method":"GET","host":"ygxc.status.updown.io","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000057829,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://ygxc.status.updown.io/"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1781347740.211456,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"2602:fb54:1a00::53","remote_port":"2236","client_ip":"2602:fb54:1a00::53","proto":"HTTP/1.1","method":"GET","host":"ygxc.status.updown.io","uri":"/firebase-service-account.json","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64; rv:150.0) Gecko/20100101 Firefox/
...
show less
134 attacks on VC URLs, too many concurrent requests, config grabbing URLs (type 2), env grabbing UR ...
show more134 attacks on VC URLs, too many concurrent requests, config grabbing URLs (type 2), env grabbing URLs, password grabbing URLs:
GET /.git/config HTTP/1.1
GET /gcp-key.json HTTP/1.1
GET /config/production.json HTTP/1.1
GET /.env.local~ HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
(modsecurity) srv103 ModSecurity 2602:fb54:1a00::53 (US/United States/-): 10 in the last 3600 secs; ...
show more(modsecurity) srv103 ModSecurity 2602:fb54:1a00::53 (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
[FriJun1215:25:02.7532792026][security2:error][pid3771356:tid3771452][client2602:fb54:1a00::53:0]Mod ...
show more[FriJun1215:25:02.7532792026][security2:error][pid3771356:tid3771452][client2602:fb54:1a00::53:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"mail.solaristech.ch\"][uri\"/wp-content/debug.log\"][unique_id\"aiwIrs3kPPF4oJdCCzu0EAAAAMk\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
15
of 77 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ