This IP presents a moderate risk and may be associated with automated activity. Moderate behavioral signals suggest possible automated probing or scanning. This assessment is backed by strong and consistent detection signals. The combined signals place this IP in a moderate risk category. Monitoring is recommended, with defensive action considered if activity continues.
The IP shows signs of potential automated activity, including a malformed user-agent and lack of JavaScript support. The access pattern is limited, but the absence of RDNS and the use of a cloud hosting provider raise concerns about the intent behind the request.
The supernet (104.252.0.0/16), which this IP belongs to, exhibits suspicious behavior characterized by repetitive low-interaction visits to a limited number of sites, with multiple IPs using similar user agents and showing high honeypot hit rates. The lack of matching forward DNS records and the presence of hosting and proxy services suggest potential misuse of legitimate infrastructure for automated scraping or bot-like activities.
Region: Virginia, United States
City: Ashburn
Local time: 2026-06-23 05:07:33