๐ฉ๐ช
updown.io
2026-09-03 19:36:58
(39 minutes ago)
{"level":"info","ts":1788464213.6915424,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1788464213.6915424,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"52.90.150.115","remote_port":"64734","client_ip":"52.90.150.115","proto":"HTTP/1.1","method":"GET","host":"status.api.keyclic.com","uri":"/","headers":{"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7"],"Priority":["u=0, i"],"Sec-Ch-Ua":["\"Not:A-Brand\";v=\"99\", \"Google Chrome\";v=\"145\", \"Chromium\";v=\"145\""],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"],"Sec-Fetch-Mode":["navigate"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept-Language":["en-US;q=1.0, en;q=0.9"],"Sec-Fetch-User":["?1"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-Dest":["document"],"Sec-Fetch-Site":["none"]},"tls":{"resumed":false,"version":772
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-03 19:36:28
(40 minutes ago)
Malware host detected by rbl.malware.expert. RBL lookup of 115.150.90.52.rbl.malware.expert succeede ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 115.150.90.52.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-1)
show less
Hacking
๐บ๐ธ
sandra361
2026-09-03 19:25:03
(51 minutes ago)
Cloudflare WAF: 1 request from AS14618/US | Action: managed_challenge | GET HTTP/1.1 | Path: / | Use ...
show more
Cloudflare WAF: 1 request from AS14618/US | Action: managed_challenge | GET HTTP/1.1 | Path: / | User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-03 18:17:02
(1 hour ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [mx01,mx03]
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-03 18:01:36
(2 hours ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14618 (Amazon.com, ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14618 (Amazon.com, Inc.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-03T17:32:35Z
Ray ID: a3567ea069120715
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ญ๐บ
kranem
2026-09-03 18:00:25
(2 hours ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 14618 (Amazon.com, Inc.)
Protocol: HTTP/1 ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 14618 (Amazon.com, Inc.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-03T16:53:16Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ง๐ท
dominioz
2026-09-03 16:45:47
(3 hours ago)
2026-09-03 13:57:55 GET / - - 52.90.150.115 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7) ...
show more
2026-09-03 13:57:55 GET / - - 52.90.150.115 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/146.0.0.0+Safari/537.36 - 404 5327
2026-09-03 16:28:35 POST / rest_route=/batch/v1&_w2s=21b795b0 - 52.90.150.115 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/146.0.0.0+Safari/537.36 - 403 539
2026-09-03 16:28:35 POST / rest_route=/batch/v1&_w2s=9e967303 - 52.90.150.115 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/146.0.0.0+Safari/537.36 - 403 539
2026-09-03 16:45:37 GET /err/ 404;https://clinicadurand.com.br:443/readme.html - 52.90.150.115 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/144.0.0.0+Safari/537.36 - 403 226
...
show less
Web App Attack
๐บ๐ธ
LotPhantom
2026-09-03 16:16:38
(4 hours ago)
52.90.150.115 - - [03/Sep/2026:16:16:12 +0000] "GET / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
52.90.150.115 - - [03/Sep/2026:16:16:12 +0000] "GET / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-03 15:54:25
(4 hours ago)
Reported from Nginx log analysis 19. Log: 52.90.150.115 - - [03/Sep/2026:xx:xx:xx 0200] "GET / HTTP ...
show more
Reported from Nginx log analysis 19. Log: 52.90.150.115 - - [03/Sep/2026:xx:xx:xx 0200] "GET / HTTP/1.1" xxx xxx "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36" "-" "US United States Ashburn" "AS14618" "Amazon.com, Inc."
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
Rip
2026-09-03 15:53:13
(4 hours ago)
403 Errors: Access Forbidden
Brute-Force
๐ง๐ช
cmbplf
2026-09-03 13:04:47
(7 hours ago)
5.348 requests from abuseipdb.com blacklisted IP (10mos4w1d)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Ike57
2026-09-03 12:20:56
(7 hours ago)
Detected activity: Proxycheck.io Risk score: 100%; Multiple WAF violations; Malicious activity detec ...
show more
Detected activity: Proxycheck.io Risk score: 100%; Multiple WAF violations; Malicious activity detected; Abuse Confidence score over set treshold; Blocked by web application firewall; VPN server detected; Datacenter IP detected; Anonymous Network detected; Compromised/Hacked server activity | User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
Exploited Host
VPN IP
๐ณ๐ฑ
DrLex0
2026-09-03 12:06:03
(8 hours ago)
POST on root path. Another stupid Amazon range to nuke.
52.90.150.115 443 - [03/Sep/2026:10:26:30 + ...
show more
POST on root path. Another stupid Amazon range to nuke.
52.90.150.115 443 - [03/Sep/2026:10:26:30 +0000] "GET / HTTP/1.1" 301 5435 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36"
52.90.150.115 443 - [03/Sep/2026:10:26:30 +0000] "GET / HTTP/1.1" 200 6991 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36"
52.90.150.115 443 - [03/Sep/2026:12:06:03 +0000] "GET / HTTP/1.1" 301 5443 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
52.90.150.115 443 - [03/Sep/2026:12:06:03 +0000] "GET / HTTP/1.1" 200 6991 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-03 11:24:33
(8 hours ago)
tcp/443 (2 or more attempts)
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-09-03 10:44:44
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack