This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.
The IP shows signs of automated behavior with a malformed user-agent and no JavaScript support, indicating potential bot activity. The access pattern is suspicious, particularly given the botnet detection signal.
The supernet (200.53.0.0/16), which this IP belongs to, exhibits behavior indicative of coordinated automation, with multiple IPs showing repetitive, low-interaction visits and a variety of user agents, some of which appear to be spoofed. While the RDNS and forward DNS match for most IPs, the presence of distinct user agents and low interaction raises concerns about potential scraping or bot-like activity.
Region: São Paulo, Brazil
City: Guarulhos
Local time: 2026-07-05 08:52:25