This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.
The IP shows signs of potential automated behavior, including a single access event with a suspicious user-agent that mimics an outdated browser. The lack of JavaScript support and the use of a proxy further raise concerns about the legitimacy of the traffic. While there are no honeypot hits, the overall pattern suggests possible reconnaissance or scraping activity.
The supernet (103.248.0.0/16), which this IP belongs to, exhibits suspicious behavior characterized by repetitive, low-interaction visits across multiple IPs, with a lack of legitimate RDNS and forward DNS matches. The presence of identical user agents and the absence of human-like interaction patterns suggest potential automated scraping or bot activity.
Region: Telangana, India
City: Hyderabad
Local time: 2026-07-05 15:37:36