Identicon of IP address 104.238.32.25

104.238.32.25

IP Risk Score: 86 / 100

This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.

What is this IP address?
IP Address: 104.238.32.25
Country: United States flag United States (US)
Region Name: Virginia (VA)
City: Ashburn
ISP: GTT Communications Inc.
Organization: Web2Objects LLC
Threat level: 86 / 100
Conf. level: 100 / 100
Properties
ASN: AS3257
AS Name: GTT Communications Inc.
Timezone: America/New_York
Status: Critical
Proxy

Observed Client Profile
  • OS: macOS (100%)
  • Device Type: Desktop (100%)
  • Browser Family: Chrome (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP address exhibits strong indicators of automated behavior, including the absence of JavaScript support and use of a suspicious user-agent. It is associated with a proxy and lacks reverse DNS, suggesting potential evasion tactics. The single access event raises concerns about probing activity.

The supernet (104.238.0.0/16), which this IP belongs to, exhibits behavior indicative of coordinated automation, with multiple IPs utilizing similar user agents and engaging in repetitive, low-interaction requests to the same target. The presence of proxies and hosting services, along with mismatched forward DNS, raises concerns about potential scraping or botnet activity.

JavaScript Support
โš ๏ธ No
User-Agent Samples
  • Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36

IP Location

Region: Virginia, United States

City: Ashburn

Local time: 2026-06-23 06:06:28