This IP is considered high risk and shows signs of malicious behavior. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.
The supernet (185.239.0.0/16), which this IP belongs to, exhibits behavior indicative of automated scraping or bot activity, with multiple IPs utilizing similar user agents and engaging in repetitive, low-interaction visits to the same target. The presence of DNS mismatches and a lack of legitimate forward DNS resolution further raises suspicions of coordinated stealth automation.
Region: North Rhine-Westphalia, Germany
City: Münster
Local time: 2026-07-03 22:43:37