Identicon of IP address 31.58.22.173

31.58.22.173

IP Risk Score: 100 / 100

This IP is considered potentially malicious and poses a serious security threat. Activity from this IP is consistent with active and malicious behavior. This assessment is backed by strong and consistent detection signals. The IP represents a severe and confirmed security risk. Immediate blocking or mitigation is strongly recommended.

What is this IP address?
IP Address: 31.58.22.173
Country: United Kingdom flag United Kingdom (GB)
Region Name: England (ENG)
City: London
ISP: Leaseweb UK Limited
Threat level: 100 / 100
Conf. level: 100 / 100
Properties
ASN: AS205544
AS Name: Leaseweb UK Limited
Timezone: Europe/London
Status: Critical
Hosting
Proxy

Observed Client Profile
  • OS: Linux (100%)
  • Device Type: Desktop (100%)
  • Browser Family: Chrome (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP shows signs of suspicious activity, including a honeypot hit and access from a known hosting provider. The absence of JavaScript support and the use of a potentially spoofed user-agent further indicate automated behavior. This raises significant concerns about malicious intent.

The supernet (31.58.0.0/16), which this IP belongs to, exhibits coordinated behavior with multiple IPs accessing the same site using similar user agents, suggesting the presence of automated scraping or bot activity. The high frequency of low-interaction, one-page visits, combined with the use of proxies and mismatched DNS records, raises concerns about potential misuse of legitimate infrastructure.

๐Ÿฏ
Honeypot Hit
JavaScript Support
โš ๏ธ No
User-Agent Samples
  • Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36

IP Location

Region: England, United Kingdom

City: London

Local time: 2026-07-03 23:37:39