This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.
The IP shows signs of automated behavior with a mobile user-agent that lacks JavaScript support. The request to a potentially sensitive path and the absence of RDNS raise concerns about the intent behind the access. The botnet detection signal further indicates possible malicious activity.
The supernet (130.180.0.0/16), which this IP belongs to, exhibits highly repetitive behavior with low interaction, characterized by multiple IPs making one-page visits with a lack of RDNS and forward DNS matches. This suggests potential automated scraping or bot activity, particularly given the absence of legitimate user agent diversity and the consistent use of non-matching DNS records.
Region: District of Columbia, United States
City: Washington
Local time: 2026-06-25 17:23:20