This IP presents a moderate risk and may be associated with automated activity. Moderate behavioral signals suggest possible automated probing or scanning. This assessment is backed by strong and consistent detection signals. The combined signals place this IP in a moderate risk category. Monitoring is recommended, with defensive action considered if activity continues.
The IP address exhibits behavior consistent with scanning activity, including access to sensitive files. It originates from an AWS EC2 instance, which raises concerns about potential automation. The user-agent appears generic and does not provide clear evidence of human interaction.
The supernet (18.117.0.0/16), which this IP belongs to, exhibits a mix of benign and suspicious behaviors, with a significant number of IPs showing signs of automated scraping and scanning activities. While some IPs appear to be legitimate bots, the presence of repeated low-value requests and honeypot hits suggests potential misuse of the infrastructure.
Region: Ohio, United States
City: Dublin
Local time: 2026-06-22 09:30:30