Identicon of IP address 38.41.188.252

38.41.188.252

IP Risk Score: 78 / 100

This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.

What is this IP address?
IP Address: 38.41.188.252
Country: Venezuela flag Venezuela (VE)
Region Name: Zulia (V)
City: Cabimas
ISP: IT PRONETWORK C.A
Organization: IT PRONETWORK
Threat level: 78 / 100
Conf. level: 100 / 100
Properties
ASN: AS271951
AS Name: 4 EVER PLUG,C.A.
Timezone: America/Caracas
Status: Critical

Observed Client Profile
  • OS: Android (100%)
  • Device Type: Mobile (100%)
  • Browser Family: Chrome (100%)
  • Rendering Engine: Gecko (100%)
Behavioral Indicators

The IP shows signs of botnet activity with a suspicious user-agent and no JavaScript support. The access pattern indicates potential probing behavior, particularly targeting an external IP. The lack of RDNS further raises concerns about the legitimacy of the traffic.

The supernet (38.41.0.0/16), which this IP belongs to, exhibits a pattern of low-interaction, repetitive traffic with a significant number of IPs utilizing identical user agents, suggesting potential automated scraping or bot activity. However, the presence of legitimate RDNS and forward DNS matches for many IPs indicates that this infrastructure may be misused rather than inherently malicious.

πŸ•ΈοΈ
Botnet Node
JavaScript Support
⚠️ No
User-Agent Samples
  • Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.3670.1338 Mobile Safari/537.36

IP Location

Region: Zulia, Venezuela

City: Cabimas

Local time: 2026-06-22 11:02:49