This IP was reported 10 times. Confidence of
Abuse
is 52%: ?
52%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
10
times from
8 distinct
sources.
2a02:c202:2265:6241::1 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Enumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-08 ...
show moreEnumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-08-31 01:41 UTC
show less
{"ClientAddr":"172.70.247.139:9394","ClientHost":"2a02:c202:2265:6241::1","ClientPort":"9394","Clien ...
show more{"ClientAddr":"172.70.247.139:9394","ClientHost":"2a02:c202:2265:6241::1","ClientPort":"9394","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":403,"Duration":19253737,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":19253737,"RequestAddr":"ha.timvdberg.dev","RequestContentSize":0,"RequestCount":259828,"RequestHost":"ha.timvdberg.dev","RequestMethod":"GET","RequestPath":"/","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"ha@file","StartLocal":"2026-08-31T00:15:03.28009195Z","StartUTC":"2026-08-31T00:15:03.28009195Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"2a02:c202:2265:6241::1","request_X-Forwarded-For":"2a02:c202:2265:6241::1","request_X-Real-Ip":"172.70.247.139","time":"2026-08-31T00:15:03Z"}
{"ClientAddr":"172.70.246.20:13628","ClientHost":"2a02:c202:2265:6241::1","ClientPort":"13628","ClientUsername"
...
show less
Enumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-08 ...
show moreEnumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-08-30 19:45 UTC
show less
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 51167 (Contabo GmbH)
Pro ...
show moreTriggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 51167 (Contabo GmbH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-08-30T07:28:29Z
Ray ID: a332143abf25db0a
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Blocked abusive HTTP application-layer DoS / botnet traffic from 2a02:c202:2265:6241::1: traffic fro ...
show moreBlocked abusive HTTP application-layer DoS / botnet traffic from 2a02:c202:2265:6241::1: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /wp-json/batch/v1 | 2026-08-28 08:57 UTC
show less
Hacking
Web App Attack
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ