This IP is considered safe and does not pose a threat. Only minimal and non-threatening activity has been observed from this IP. This assessment is backed by strong and consistent detection signals. Overall risk is negligible when threat severity and confidence are considered together. No action is required.
The IP address is associated with Telegram's infrastructure and has triggered a honeypot hit, indicating potential malicious intent. The user-agent suggests automated behavior, and the lack of JavaScript support raises further concerns. Overall, this activity is suspicious and warrants close monitoring.
The supernet (149.154.0.0/16), which this IP belongs to, exhibits behavior consistent with automated bot activity, primarily from Telegram's infrastructure, with repetitive low-interaction visits and a common user agent. However, the presence of multiple IPs without matching RDNS and forward DNS raises concerns about potential misuse or spoofing.
Region: England, United Kingdom
City: London
Local time: 2026-06-29 15:31:13