Identicon of IP address 109.199.102.175

109.199.102.175

IP Risk Score: 63 / 100

This IP presents a moderate risk and may be associated with automated activity. Moderate behavioral signals suggest possible automated probing or scanning. This assessment is backed by strong and consistent detection signals. The combined signals place this IP in a moderate risk category. Monitoring is recommended, with defensive action considered if activity continues.

What is this IP address?
IP Address: 109.199.102.175
Country: Germany flag Germany (DE)
Region Name: North Rhine-Westphalia (NW)
City: Düsseldorf
ISP: Contabo GmbH
Threat level: 63 / 100
Conf. level: 100 / 100
Properties
ASN: AS51167
AS Name: Contabo GmbH
Timezone: Europe/Berlin
Reverse DNS: vmi2829869.contaboserver.net
Status: Suspicious
Hosting

Observed Client Profile
  • OS: macOS (50%)
  • Device Type: Desktop (100%)
  • Browser Family: Safari (50%)
  • Rendering Engine: Gecko (100%)
Variability
Behavioral Indicators

The IP shows signs of potential automated behavior with multiple requests from a cloud hosting provider. The lack of JavaScript support and the use of distinct user agents raise concerns about the authenticity of the traffic. While there are no honeypot hits, the overall pattern suggests possible scraping activity.

The supernet (109.199.0.0/16), which this IP belongs to, exhibits coordinated behavior with repetitive low-interaction visits and a mix of user agents, suggesting potential automated scraping activities. The presence of multiple IPs with similar patterns and some DNS mismatches raises concerns about stealth automation and possible misuse of legitimate infrastructure.

JavaScript Support
⚠️ No
User-Agent Samples
  • Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15
  • Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/114.0

IP Location

Region: North Rhine-Westphalia, Germany

City: Düsseldorf

Local time: 2026-06-24 04:01:54