This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.
The IP exhibits signs of automated behavior, including missing JavaScript support and access to a specific path with multiple requests in a short time frame. The user-agent appears structured but may be spoofed, and the lack of RDNS raises concerns about its legitimacy.
The supernet (104.164.0.0/16), which this IP belongs to, exhibits coordinated behavior characterized by repetitive, low-interaction visits to specific sites, primarily using identical user agents across multiple IPs. This suggests the presence of automated scraping or bot activity, particularly given the high number of honeypot hits and the lack of legitimate user interaction.
Region: Ontario, Canada
City: Toronto
Local time: 2026-06-23 06:06:28