This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.
The IP address exhibits strong indicators of automated behavior, including lack of JavaScript support and use of a proxy. The user-agent appears to be a standard browser UA but is likely spoofed given the context. The access pattern is limited but suspicious due to the proxy nature and missing RDNS.
The supernet (104.238.0.0/16), which this IP belongs to, exhibits behavior indicative of coordinated automation, with multiple IPs utilizing similar user agents and engaging in repetitive, low-interaction requests to the same target. The presence of proxies and hosting services, along with mismatched forward DNS, raises concerns about potential scraping or botnet activity.
Region: North Holland, Netherlands
City: Amsterdam
Local time: 2026-06-23 12:06:23