Check an IP Address, Domain Name, Subnet, or ASN
52.242.17.182 has a threat confidence score of 66%. This IP address from Canada (AS8075, Microsoft Corporation) has been observed in 13 honeypot sessions targeting HTTP, HTTPS protocols. Detected attack patterns include http goform webslogin probe and auth attempt. First observed on March 12, 2026, most recently active March 19, 2026.
Sequence of requests including probing activity and access to /goform/websLogin, followed by a credential submission (user_name and password), indicating an authentication attempt against a router or embedded device login endpoint.
Identifies HTTP GET requests directly targeting the /bad-request path, indicating automated or manual probing of application error-handling routes rather than legitimate navigation flow.