Identicon of IP address 109.196.154.29

109.196.154.29

IP Risk Score: 70 / 100

This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.

What is this IP address?
IP Address: 109.196.154.29
Country: Poland flag Poland (PL)
Region Name: Łódź Voivodeship (10)
City: Lowicz
ISP: ITV Media Sp. z o.o.
Organization: ITV MEDIA Sp. z o.o
Threat level: 70 / 100
Conf. level: 100 / 100
Properties
ASN: AS50411
AS Name: Timplus sp. z o.o.
Timezone: Europe/Warsaw
Reverse DNS: 29-154-196-109.itvmedia.pl
Status: Critical

Observed Client Profile
  • OS: Android (100%)
  • Device Type: Mobile (100%)
  • Browser Family: Chrome (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP shows signs of botnet activity with a suspicious user-agent that lacks JavaScript support. The access pattern indicates potential automated probing behavior, particularly targeting an external IP. The presence of botnet detection further raises concerns about malicious intent.

The supernet (109.196.0.0/16), which this IP belongs to, exhibits suspicious behavior characterized by repetitive, low-interaction visits and a high number of honeypot hits, indicating potential automated scraping or bot activity. The presence of multiple IPs using similar user agents and the lack of legitimate RDNS matching further suggest coordinated stealth automation.

🕞
Botnet Node
JavaScript Support
⚠ No
User-Agent Samples
  • Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.8065.1066 Mobile Safari/537.36

IP Location

Region: Łódź Voivodeship, Poland

City: Lowicz

Local time: 2026-06-22 14:30:56