This IP was reported 39 times. Confidence of
Abuse
is 100%: ?
100%
Important Note: Public IPv6 addresses may implement the SLAAC
privacy extension. With this, the interface identifier is randomly generated. The SLAAC
privacy extension also implements a time out, which is configurable, so that the IPv6
interface addresses will be discarded and a new interface identifier is generated.
This IP address has been reported a total of
39
times from
20 distinct
sources.
2a04:c300:400::1cf was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
99 attacks on too many concurrent requests, password grabbing URLs, env grabbing URLs, config grabbi ...
show more99 attacks on too many concurrent requests, password grabbing URLs, env grabbing URLs, config grabbing URLs (type 2), VC URLs:
GET /key.json HTTP/1.1
GET /.aws/credentials HTTP/1.1
GET /.env.local~ HTTP/1.1
GET /config/default.json HTTP/1.1
GET /.git/config HTTP/1.1
show less
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-21.
show less
(modsecurity) srv103 ModSecurity 2a04:c300:400::1cf (DE/Germany/-): 10 in the last 3600 secs; Ports: ...
show more(modsecurity) srv103 ModSecurity 2a04:c300:400::1cf (DE/Germany/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -65.282 (Bad < -10 / Very Bad < -20 ...
show moreBot/Spam/Scrapper attack detected on www.handytreff.de - Score: -65.282 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa
show less
Web App Attack
Bad Web Bot
Anonymous
(mod_security) mod_security triggered on hostname [redacted] 2a04:c300:400::1cf (Unknown): (CF_ENAB ...
show more(mod_security) mod_security triggered on hostname [redacted] 2a04:c300:400::1cf (Unknown): (CF_ENABLE)
show less
(modsecurity) srv104 ModSecurity 2a04:c300:400::1cf (DE/Germany/-): 10 in the last 3600 secs; Ports: ...
show more(modsecurity) srv104 ModSecurity 2a04:c300:400::1cf (DE/Germany/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Showing 1 to
15
of 39 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ