IP Report
192.159.99.56
1337 Services GmbH · AS210558 · New York, United States
Score 90 of 100, in the high risk band. Bands run 0 to 19 minimal, 20 to 49 low, 50 to 79 medium, 80 to 100 high.
Its risk score of 90/100 is high: multiple strong signals stack up here, and most sites that screen traffic would challenge or block requests from this address.
Detection signals
Not detected: Tor, VPN, Proxy, Crawler
Summary
192.159.99.56 is a server address in commercial hosting space, not a home or mobile connection. Traffic from it is almost always software rather than a person browsing.
The address is announced by 1337 Services GmbH (AS210558) and geolocates to New York, United States.
Why this address scores 90
It sits in datacenter address space, where automated traffic vastly outnumbers human visitors.
Together these produce the score of 90/100 shown above.
Observation history
This address has been looked up through Predax once, on September 5, 2026.
Network & location
- ASN
- AS210558
- Country
- United States (US)
- Provider
- 1337 Services GmbH
- Region
- New York
- CIDR
- 192.159.99.0/24
- City
- New York
- Network type
- hosting
- First seen
- 9/5/2026, 7:08:39 AM
- Last seen
- 9/5/2026, 7:08:39 AM
- Times seen
- 1
Network context
We have observed 21 addresses on 1337 Services GmbH (AS210558); 100% of them carried a threat flag or a notable risk score when last checked.
That is a high concentration — on this network, an unfamiliar address deserves more caution than its individual score alone would suggest.
What to do with this
If you run a site and this address showed up
Traffic from server space is rarely a person on a browser. If this address hit your site, it was most likely a bot, a monitor, or a scripted client.
Unblocking it is only worth doing if you can tie it to a service you actually use — an uptime monitor, a payment webhook, an integration. Otherwise a block costs you nothing.
For a store, an address scoring 90/100 matters most at checkout — the WooCommerce fraud plugin screens every order against this data before the payment provider is contacted, so a blocked attempt never becomes a chargeback.
If you found this address in your logs
In your logs this address is almost certainly automation. Check the user agent and the request pattern before attributing its traffic to a human.
If you operate this address yourself and it is being blocked elsewhere, this datacenter classification is why — hosting IPs start from a lower trust position everywhere.
Loading map...
Detection sources
- maliciousVerified · 100%
hijacked_netblock.