AbuseIPDB » 2605:7980:0:22a1::1
2605:7980:0:22a1::1 was found in our database!
This IP was reported 8 times. Confidence of
Abuse
is 31% : ?
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
ISP
RouterHosting LLC
Usage Type
Data Center/Web Hosting/Transit
ASN
AS14956
Domain Name
cloudzy.com
Country
๐บ๐ธ
United States of America
City
Dallas, Texas
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 2605:7980:0:22a1::1 :
This IP address has been reported a total of
8
times from
6 distinct
sources.
2605:7980:0:22a1::1 was first reported on
July 19th 2026 , and the most recent report was
2 days ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-08-28 08:15:29
(2 days ago)
GET swagger.json | UA: BigHunter/1.5 | Time: 2026-08-28 08:15:29 UTC
Web App Attack
๐ฉ๐ช
conseilgouz
2026-08-25 10:05:59
(5 days ago)
ece- 404 : Too many 404 errors
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-08-22 12:08:00
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐ฌ๐ง
pinguin
2026-08-12 09:43:19
(2 weeks ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Go-http-client/1.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-07-24 13:22:39
(1 month ago)
[Fri Jul 24 15:22:36.936866 2026] [access_compat:error] [pid 764240:tid 136234282251968] [client 260 ...
show more
[Fri Jul 24 15:22:36.936866 2026] [access_compat:error] [pid 764240:tid 136234282251968] [client 2605:7980:0:22a1::1:52529] AH01797: client denied by server configuration: /var/www/nextcloud/config/stripe.php
[Fri Jul 24 15:22:36.961492 2026] [access_compat:error] [pid 194026:tid 136234114463424] [client 2605:7980:0:22a1::1:52547] AH01797: client denied by server configuration: /var/www/nextcloud/config/stripe.php
[Fri Jul 24 15:22:38.206856 2026] [access_compat:error] [pid 828092:tid 136233745381056] [client 2605:7980:0:22a1::1:52556] AH01797: client denied by server configuration: /var/www/nextcloud/config/.env
[Fri Jul 24 15:22:39.146766 2026] [access_compat:error] [pid 828244:tid 136233627915968] [client 2605:7980:0:22a1::1:52589] AH01797: client denied by server configuration: /var/www/nextcloud/config/secrets.env
[Fri Jul 24 15:22:39.156405 2026] [access_compat:error] [pid 828244:tid 136234513221312] [client 2605:7980:0:22a1::1:52601] AH01797: client denied by server configuratio
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-23 00:49:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2605:7980:0:22a1::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2605:7980:0:22a1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:49:18.597926 2026] [security2:error] [pid 1748806:tid 1748806] [client 2605:7980:0:22a1::1:59644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibermar.info"] [uri "/.git/HEAD"] [unique_id "amFlDhRW8PoGLMFGzjo6JgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 03:03:54
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2605:7980:0:22a1::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2605:7980:0:22a1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 23:03:37.145683 2026] [security2:error] [pid 2090:tid 2090] [client 2605:7980:0:22a1::1:57302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalnova.com.sprektech.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalnova.com.sprektech.com"] [uri "/elmah.axd"] [unique_id "alw-iQmP-pmwjgCdNiAAtQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 02:29:47
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2605:7980:0:22a1::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2605:7980:0:22a1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 22:29:32.245238 2026] [security2:error] [pid 10232:tid 10232] [client 2605:7980:0:22a1::1:59247] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.roughexports.velvetculture.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.roughexports.velvetculture.com"] [uri "/elmah.axd"] [unique_id "alw2jLYN8leJS0lH8GyF-AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Showing 1 to
8
of 8 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: