IP Report
45.13.186.15
LeaseWeb Netherlands B.V. · AS60781 · Frankfurt am Main, Germany
Score 90 of 100, in the high risk band. Bands run 0 to 19 minimal, 20 to 49 low, 50 to 79 medium, 80 to 100 high.
Its risk score of 90/100 is high: multiple strong signals stack up here, and most sites that screen traffic would challenge or block requests from this address.
Detection signals
Not detected: Tor, VPN, Proxy, Crawler
Summary
45.13.186.15 is a server address in commercial hosting space, not a home or mobile connection. Traffic from it is almost always software rather than a person browsing.
The address is announced by LeaseWeb Netherlands B.V. (AS60781) and geolocates to Frankfurt am Main, Hesse, Germany.
Why this address scores 90
It sits in datacenter address space, where automated traffic vastly outnumbers human visitors.
Together these produce the score of 90/100 shown above.
Observation history
This address has been looked up through Predax once, on September 2, 2026.
Network & location
- ASN
- AS60781
- Country
- Germany (DE)
- Provider
- LeaseWeb Netherlands B.V.
- Region
- Hesse
- CIDR
- 45.13.186.0/23
- City
- Frankfurt am Main
- Network type
- hosting
- First seen
- 9/2/2026, 8:32:47 AM
- Last seen
- 9/2/2026, 8:32:47 AM
- Times seen
- 1
Network context
We have observed 57 addresses on LeaseWeb Netherlands B.V. (AS60781); 100% of them carried a threat flag or a notable risk score when last checked.
That is a high concentration — on this network, an unfamiliar address deserves more caution than its individual score alone would suggest.
What to do with this
If you run a site and this address showed up
Traffic from server space is rarely a person on a browser. If this address hit your site, it was most likely a bot, a monitor, or a scripted client.
Unblocking it is only worth doing if you can tie it to a service you actually use — an uptime monitor, a payment webhook, an integration. Otherwise a block costs you nothing.
You do not have to watch for addresses like this one yourself — the Predax Security plugin for WordPress checks every visitor against this same scoring in real time, and the WooCommerce fraud plugin does it for orders.
If you found this address in your logs
In your logs this address is almost certainly automation. Check the user agent and the request pattern before attributing its traffic to a human.
If you operate this address yourself and it is being blocked elsewhere, this datacenter classification is why — hosting IPs start from a lower trust position everywhere.
Loading map...
Detection sources
- maliciousVerified · 100%
hijacked_netblock.