Identicon of IP address 104.253.90.40

104.253.90.40

IP Risk Score: 79 / 100

This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.

What is this IP address?
IP Address: 104.253.90.40
Country: Italy flag Italy (IT)
Region Name: Lombardy (25)
City: Milan
ISP: EGIHosting
Organization: Sagota Networks
Threat level: 79 / 100
Conf. level: 100 / 100
Properties
ASN: AS64445
AS Name: NetJoin srl
Timezone: Europe/Rome
Status: Critical
Proxy

Observed Client Profile
  • OS: macOS (100%)
  • Device Type: Desktop (100%)
  • Browser Family: Chrome (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP address exhibits suspicious behavior, including the use of a malformed user-agent and lack of JavaScript support, indicating potential bot activity. Additionally, it is associated with a proxy and has no reverse DNS, raising further concerns about its legitimacy.

The supernet (104.253.0.0/16), which this IP belongs to, exhibits coordinated behavior characterized by repetitive, low-interaction visits to specific pages, suggesting potential automation or scraping activities. The use of identical user agents across multiple IPs, combined with DNS mismatches, raises concerns about the legitimacy of the traffic, indicating possible misuse of infrastructure.

JavaScript Support
โš ๏ธ No
User-Agent Samples
  • Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36

IP Location

Region: Lombardy, Italy

City: Milan

Local time: 2026-06-22 18:07:45