Identicon of IP address 149.154.26.230

149.154.26.230

IP Risk Score: 37 / 100

This IP presents a moderate risk and may be associated with automated activity. Moderate behavioral signals suggest possible automated probing or scanning. This assessment is backed by strong and consistent detection signals. The combined signals place this IP in a moderate risk category. Monitoring is recommended, with defensive action considered if activity continues.

What is this IP address?
IP Address: 149.154.26.230
Country: United States flag United States (US)
Region Name: North Carolina (NC)
City: Wilmington
ISP: Metronet
Organization: Metronet
Threat level: 37 / 100
Conf. level: 100 / 100
Properties
ASN: AS30600
AS Name: Metronet
Timezone: America/New_York
Status: Suspicious

Observed Client Profile
  • OS: macOS (100%)
  • Device Type: Bot (100%)
  • Browser Family: Safari (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP shows signs of automated behavior with multiple requests in a short time frame and varying user-agents. However, the presence of JavaScript support and the user-agent resembling a legitimate mobile browser suggest it may not be malicious.

The supernet (149.154.0.0/16), which this IP belongs to, exhibits behavior consistent with automated bot activity, primarily from Telegram's infrastructure, with repetitive low-interaction visits and a common user agent. However, the presence of multiple IPs without matching RDNS and forward DNS raises concerns about potential misuse or spoofing.

๐Ÿ•ท๏ธ
Spider
JavaScript Support
โœ“ Yes
User-Agent Samples
  • Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.4 (KHTML, like Gecko) Version/9.0.1 Safari/601.2.4 facebookexternalhit/1.1 Facebot Twitterbot/1.0

IP Location

Region: North Carolina, United States

City: Wilmington

Local time: 2026-06-28 01:48:37