Identicon of IP address 167.253.18.252

167.253.18.252

IP Risk Score: 86 / 100

This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.

What is this IP address?
IP Address: 167.253.18.252
Country: United States flag United States (US)
Region Name: Virginia (VA)
City: Fairfax
ISP: PureVoltage Hosting Inc.
Organization: VPNVault LLC
Threat level: 86 / 100
Conf. level: 100 / 100
Properties
ASN: AS26548
AS Name: PureVoltage Hosting Inc.
Timezone: America/New_York
Reverse DNS: 167-253-18-252.cloudairone.com
Status: Critical
Proxy

Observed Client Profile
  • OS: Unknown (100%)
  • Device Type: Bot (100%)
  • Browser Family: Unknown (100%)
  • Rendering Engine: Unknown (100%)
Behavioral Indicators

The IP address exhibits suspicious behavior, including a malformed user-agent claiming to be Googlebot while lacking JavaScript support. It is associated with a known hosting provider and is likely using a proxy, indicating potential automated scraping activity.

The supernet (167.253.0.0/16), which this IP belongs to, exhibits signs of coordinated automation with multiple IPs showing repetitive behavior, low interaction, and a lack of legitimate RDNS records. The presence of a proxy IP with a matching forward DNS raises concerns about potential misuse, while the overall lack of identifiable legitimate bot behavior suggests possible scraping or stealth activity.

๐Ÿ•ท๏ธ
Spider
JavaScript Support
โš ๏ธ No
User-Agent Samples
  • Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)

IP Location

Region: Virginia, United States

City: Fairfax

Local time: 2026-06-25 22:32:25