This IP presents a moderate risk and may be associated with automated activity. Moderate behavioral signals suggest possible automated probing or scanning. This assessment is backed by strong and consistent detection signals. The combined signals place this IP in a moderate risk category. Monitoring is recommended, with defensive action considered if activity continues.
The IP shows signs of automated behavior with a single access event from an AWS EC2 instance. The user-agent appears to be a mobile device but lacks JavaScript support, which raises concerns about its authenticity. The access pattern is limited, but the infrastructure and user-agent characteristics suggest potential scraping activity.
The supernet (98.89.0.0/16), which this IP belongs to, exhibits a pattern of low-interaction, repetitive visits primarily using a single user agent associated with a known bot, suggesting potential automated scraping behavior. However, the presence of legitimate DNS resolution and a lack of honeypot hits across most IPs indicates that the activity may be benign or misconfigured rather than overtly malicious.
Region: Virginia, United States
City: Ashburn
Local time: 2026-06-22 08:45:50