This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.
The IP address shows a high level of suspicious activity, including multiple honeypot hits and repeated access to various endpoints with 404 responses. The user-agent appears to be spoofed, and the behavior suggests potential malicious intent. The traffic originates from an AWS EC2 instance, which raises further concerns about automation and evasion tactics.
The supernet (13.212.0.0/16), which this IP belongs to, exhibits coordinated behavior with multiple IPs generating repetitive, low-interaction traffic primarily targeting a single site, indicating potential automated scraping or bot activity. The use of identical user agents and high honeypot hit rates across several IPs raises concerns about stealthy automation and possible analytics pollution.
Region: Central Singapore, Singapore
City: Singapore
Local time: 2026-06-22 20:26:00