This IP was reported 513 times. Confidence of
Abuse
is 11%: ?
11%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
513
times from
171 distinct
sources.
2602:fb54:99a:: was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
[WedJun1714:48:42.1684032026][security2:error][pid2757563:tid2757622][client2602:fb54:99a:::0]ModSec ...
show more[WedJun1714:48:42.1684032026][security2:error][pid2757563:tid2757622][client2602:fb54:99a:::0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.gmint.ch\"][uri\"/wp-content/debug.log\"][unique_id\"ajKXqp9mPifo32Ffn49cigAAAI0\"]
show less
Attempted access to sensitive endpoint (/config/credentials.json) detected. Automated scan or unauth ...
show moreAttempted access to sensitive endpoint (/config/credentials.json) detected. Automated scan or unauthorized probing.
show less
(mod_security) mod_security (id:210730) triggered by 2602:fb54:99a:: (Unknown): 1 in the last 300 se ...
show more(mod_security) mod_security (id:210730) triggered by 2602:fb54:99a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 04:53:22.039054 2026] [security2:error] [pid 22257:tid 22257] [client 2602:fb54:99a:::0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kidswithcamerasmovie.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kidswithcamerasmovie.com"] [uri "/wp-content/debug.log"] [unique_id "ajJggsTgbUzi-98Fjgq7DAAAAAo"]
show less
(modsecurity) srv102 ModSecurity 2602:fb54:99a:: (US/United States/-): 10 in the last 3600 secs; Por ...
show more(modsecurity) srv102 ModSecurity 2602:fb54:99a:: (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
[ISILIA Protection v2.1] Tentative d'accès: /laravel/.env | Pays: US | UA: Mozilla/5.0 (Macintosh; I ...
show more[ISILIA Protection v2.1] Tentative d'accès: /laravel/.env | Pays: US | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.
show less
Hacking
Web App Attack
Anonymous
(NGINX) Security rule triggered from 2602:fb54:99a:: (Unknown): 5 in the last 3600 secs
(modsecurity) srv103 ModSecurity 2602:fb54:99a:: (US/United States/-): 10 in the last 3600 secs; Por ...
show more(modsecurity) srv103 ModSecurity 2602:fb54:99a:: (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less