Identicon of IP address 103.154.138.108

103.154.138.108

IP Risk Score: 82 / 100

This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.

What is this IP address?
IP Address: 103.154.138.108
Country: Indonesia flag Indonesia (ID)
Region Name: Jakarta (JK)
City: Jakarta
ISP: MORATELINDONAP
Threat level: 82 / 100
Conf. level: 100 / 100
Properties
ASN: AS131111
AS Name: PT Mora Telematika Indonesia
Timezone: Asia/Jakarta
Reverse DNS: ip-103-154-138-108.moratelindo.net.id
Status: Critical

Observed Client Profile
  • OS: Android (100%)
  • Device Type: Mobile (100%)
  • Browser Family: Chrome (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP shows signs of botnet activity with a suspicious user-agent and no JavaScript support. The access pattern indicates potential automated probing behavior, particularly targeting an external IP. The RDNS does not point to a known cloud provider, but the overall context raises significant concerns.

The supernet (103.154.0.0/16), which this IP belongs to, exhibits coordinated behavior characterized by repetitive, low-interaction visits to a specific domain, with multiple IPs using similar user agents. The lack of forward DNS matches and the presence of crawler-like user agents across different IPs suggest potential automation and scraping activities, raising concerns about analytics pollution and possible misuse of legitimate infrastructure.

πŸ•ΈοΈ
Botnet Node
JavaScript Support
⚠️ No
User-Agent Samples
  • Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.9994.1456 Mobile Safari/537.36

IP Location

Region: Jakarta, Indonesia

City: Jakarta

Local time: 2026-06-28 13:48:18