This IP presents a moderate risk and may be associated with automated activity. Moderate behavioral signals suggest possible automated probing or scanning. This assessment is backed by strong and consistent detection signals. The combined signals place this IP in a moderate risk category. Monitoring is recommended, with defensive action considered if activity continues.
The IP shows signs of automated behavior with multiple requests in a short time frame and varying user-agents. However, the presence of JavaScript support and the user-agent resembling a legitimate mobile browser suggest it may not be malicious.
The supernet (149.154.0.0/16), which this IP belongs to, exhibits behavior consistent with automated bot activity, primarily from Telegram's infrastructure, with repetitive low-interaction visits and a common user agent. However, the presence of multiple IPs without matching RDNS and forward DNS raises concerns about potential misuse or spoofing.
Region: North Carolina, United States
City: Wilmington
Local time: 2026-06-28 01:48:37