This IP is considered high risk and shows signs of malicious behavior. Strong indicators point to automated scanning or suspicious access attempts. This assessment is backed by strong and consistent detection signals. The combined indicators suggest a high overall security risk. Defensive measures such as rate limiting or blocking are recommended.
The IP shows signs of automated behavior with a mobile user-agent that lacks JavaScript support. The request to an external IP and the botnet detection signal raise concerns about potential malicious intent. The RDNS indicates a legitimate ISP, but the overall activity is atypical for normal user behavior.
The supernet (49.204.0.0/16), which this IP belongs to, exhibits signs of coordinated scraping behavior, with multiple IPs using identical or crawler-like user agents, low-interaction one-page visits, and a lack of legitimate forward DNS resolution. This suggests potential automation and stealthy traffic patterns that could lead to analytics pollution.
Region: Telangana, India
City: Hyderabad
Local time: 2026-06-30 09:36:46