Welcome to the new IP check page! We're rolling it out gradually and would love your input. Spot a bug, or have a suggestion?
Share feedback
2a02:4780:13:1052:0:3522:9596:1
Neutral Activity
There is no recent abuse activity, or the IP address is whitelisted.
IPv6 SLAAC Note
Public IPv6 addresses may implement the SLAAC
privacy extension. With SLAAC, the interface identifier is randomly generated. SLAAC also implements a
configurable time out, so that the original IPv6 interface addresses will be discarded in favor of a new
interface identifier.
Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
2a02:4780:13:1052:0:3522:9596:1 has been reported 32
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 2a02:4780:13:1052:0:3522:9596:1:
This IP address has been reported a total of
32
times from
16 distinct
sources.
2a02:4780:13:1052:0:3522:9596:1 was first reported on
, and the most recent report was
.
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
ketovoila.pl web app secret/repository scan: hits=12; unique_paths=12; sample_paths=/.env,/.env.save ...
show moreketovoila.pl web app secret/repository scan: hits=12; unique_paths=12; sample_paths=/.env,/.env.save,/admin/.env; UA="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"; window=2026-06-08T12:22:44Z..2026-06-08T12:22:44Z
show less
[MonJun0812:43:00.8003312026][security2:error][pid1094635:tid1094813][client2a02:4780:13:1052:0:3522 ...
show more[MonJun0812:43:00.8003312026][security2:error][pid1094635:tid1094813][client2a02:4780:13:1052:0:3522:9596:1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"gustotondo.ch\"][uri\"/dev/.env\"][unique_id\"aiactOW8mkFX_G3_vO5QSwAAARM\"]
show less
(modsecurity) srv104 ModSecurity 2a02:4780:13:1052:0:3522:9596:1 (BR/Brazil/-): 10 in the last 3600 ...
show more(modsecurity) srv104 ModSecurity 2a02:4780:13:1052:0:3522:9596:1 (BR/Brazil/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less