AbuseIPDB » 2a01:4f9:c015:441::1
2a01:4f9:c015:441::1 was found in our database!
This IP was reported 4 times. Confidence of
Abuse
is 0% : ?
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
ISP
Hetzner Online GmbH
Usage Type
Data Center/Web Hosting/Transit
ASN
AS24940
Domain Name
hetzner.com
Country
๐ซ๐ฎ
Finland
City
Helsinki, Uusimaa
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 2a01:4f9:c015:441::1 :
This IP address has been reported a total of
4
times from
4 distinct
sources.
2a01:4f9:c015:441::1 was first reported on
May 4th 2026 , and the most recent report was
2 months ago .
Old Reports:
The most recent abuse report for this IP address is from
2 months ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
๐ช๐ธ
el-brujo
2026-05-05 14:42:00
(2 months ago)
Cloudflare WAF: Request Path: /env.bak Request Query: Host: ns2.elhacker.net userAgent: Go-http-cli ...
show more
Cloudflare WAF: Request Path: /env.bak Request Query: Host: ns2.elhacker.net userAgent: Go-http-client/1.1 Action: block Source: firewallManaged ASN Description: Hetzner Online GmbH Country: FI Method: GET Timestamp: 2026-05-05T14:42:00Z ruleId: c04705c7adee4ce3a763bd5e18135e0c. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-05-05 11:16:57
(2 months ago)
Threat Intelligence via ARMTI, Web Attack: GET /env.txt
Web App Attack
๐ซ๐ท
pocketpark
2026-05-05 09:37:56
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /data.php | UA: Go-http-client/1.1 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-05-04 13:06:07
(2 months ago)
[Mon May 04 15:05:58.389630 2026] [access_compat:error] [pid 851656:tid 124507182323392] [client 2a0 ...
show more
[Mon May 04 15:05:58.389630 2026] [access_compat:error] [pid 851656:tid 124507182323392] [client 2a01:4f9:c015:441::1:50776] AH01797: client denied by server configuration: /var/www/nextcloud/config/api.php, referer: http://2.59.132.52:80/config/api.php
[Mon May 04 15:05:58.659662 2026] [access_compat:error] [pid 851656:tid 124507931006656] [client 2a01:4f9:c015:441::1:50790] AH01797: client denied by server configuration: /var/www/nextcloud/config/stripe.php, referer: http://2.59.132.52:80/config/stripe.php
[Mon May 04 15:06:05.828850 2026] [access_compat:error] [pid 851636:tid 124508168562368] [client 2a01:4f9:c015:441::1:42500] AH01797: client denied by server configuration: /var/www/nextcloud/config/.env, referer: http://2.59.132.52:80/config/.env
[Mon May 04 15:06:06.629061 2026] [access_compat:error] [pid 851636:tid 124507494782656] [client 2a01:4f9:c015:441::1:42532] AH01797: client denied by server configuration: /var/www/nextcloud/config/settings.php, referer: http://2.59.132.
...
show less
Brute-Force
SSH
Showing 1 to
4
of 4 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: