This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.
The IP address has exhibited highly suspicious behavior, including multiple hits to admin paths and a significant number of honeypot interactions. The use of automation indicators, such as the 'Go-http-client/1.1' user-agent, combined with the absence of reverse DNS and hosting from a known provider, suggests malicious intent. The traffic pattern indicates a focused scraping or probing activity.
The supernet (172.96.0.0/16), which this IP belongs to, exhibits suspicious behavior characterized by repetitive low-interaction visits, a mix of user agents, and instances of potential automation. Several IPs show signs of being proxies or hosting services, with some using identical user agents that could indicate coordinated scraping activity.
Region: California, United States
City: Los Angeles
Local time: 2026-06-25 15:23:31