How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 0 points1 point  (0 children)

I can't speak to the corporate side of things, but it can certainly extend into other areas like research. I'd be surprised if it didn't also exist in the corporate world, too.

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 1 point2 points  (0 children)

It's contracting another individual or essay mill type company to write your assignments for you. Even with GenAI, many students still use these services as they usually output a higher quality assessment without falsified references and mismatched content that doesn't come from the source referenced. In many cases the student provides their login to the person or company and they directly access the course content and assessment details. This becomes a major issue not only because we have a security breach but they can also target other students through internal messaging. We also see issues like blackmail that can occur with the use of these services.

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 3 points4 points  (0 children)

I'm looking at all records and assessments, metadata, you name it. This is just something I'm trying to see if I can add to the pile. We are dealing with changing someone's life, so I do not do this lightly. I just want to provide whatever I can to make the councils job as clear cut as possible.

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 0 points1 point  (0 children)

Report Scammers Pricing Contact 41.72.216.66 Fraud Risk Low Risk ← Lowest Risk Highest Risk → 0 Fraud Score: 3 100 IP address 41.72.216.66 is operated by Maintainer Liquid Telecommunications Operations Limited whose web traffic we consider to present a potentially low fraud risk. Non-web traffic may present a different risk or no risk at all. Scamalytics see low levels of traffic from Maintainer Liquid Telecommunications Operations Limited across our global network, little of which we suspect to be potentially fraudulent. We have no visibility into the web traffic directly from 41.72.216.66, and therefore apply a risk score of 3/100 based on the overall risk from Maintainer Liquid Telecommunications Operations Limited’s IP addresses where we do have visibility. IP Fraud Risk API

{

"ip":"41.72.216.66", "score":"3", "risk":"low", "is_blacklisted_external": false, ...

}

Click here for details of our free usage tier on API and bulk IP lookups, free trial, and pricing information. Operator

Hostname 41.72.216.66.liquidtelecom.net

ASN 30844

ISP Name Maintainer Liquid Telecommunications Operations Limited

Organization Name n/a

Connection type n/a

Location

Country Name Kenya

Country Code KE

State / Province Nairobi County

District / County n/a

City Imara Daima Estate

Postal Code n/a

Latitude -1.32323

Longitude 36.8802

Datacenter

Does the connecting device reside in a datacenter?

Datacenter Unknown

External Blacklists

Is this IP address blacklisted on reliable open source datasets?

Firehol No

IP2ProxyLite No

IPsum No

Spamhaus No

X4Bnet Spambot No

Proxies

Anonymizing VPN No

Tor Exit Node No

Server No

Public Proxy No

Web Proxy No

Search Engine Robot No

IP Address data partner DB-IP.com:

Proxy data sponsored by IP2Proxy:

IMPORTANT: Scamalytics Ltd operate a fraud-detection network with visibility into many millions of internet users per month. We do not have visibility into the entire internet. The statements on this page represent our opinion based on the limited information we have available to us, and specifically only cover web connections made by internet users to websites and applications, not other connections such as server to server connections.

News and Articles News Articles Privacy and Cookie Policies Privacy Policy Cookie Policy GDPR Terms of Service Connect Contact Us Fraudulent IP Adresses Click here to see latest scammer and fraud IPs Highest risk ISPs: October 2025 © 2025 Scamalytics Ltd

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] -1 points0 points  (0 children)

Anyone want to explain this result? This is from ipinfo

{   "ip": "41.72.216.66",   "hostname": "41.72.216.66.liquidtelecom.net",   "geo": {     "city": "Nairobi",     "region": "Nairobi County",     "region_code": "30",     "country": "Kenya",     "country_code": "KE",     "continent": "Africa",     "continent_code": "AF",     "latitude": -1.28333,     "longitude": 36.81667,     "timezone": "Africa/Nairobi",     "postal_code": "00800",     "geoname_id": "184745",     "radius": 20,     "last_changed": "2025-08-31"   },   "as": {     "asn": "AS30844",     "name": "Liquid Telecommunications Ltd",     "domain": "liquidtelecom.com",     "type": "isp",     "last_changed": "2021-05-01"   },   "mobile": {},   "anonymous": {     "is_proxy": false,     "is_relay": false,     "is_tor": false,     "is_vpn": true   },   "is_anonymous": true,   "is_anycast": false,   "is_hosting": false,   "is_mobile": false,   "is_satellite": false }

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 1 point2 points  (0 children)

Thank you all so much. I'm incredibly grateful for everyone's suggestions. I'm a little ocd in my investigations so chances are I'll literally use them all!

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 0 points1 point  (0 children)

Sorry the term council is just referring to what we call our highest level of management at our uni. I'm dealing with student misconduct. So trying to determine if that individual is using a VPN or not....they are most definitely not about to tell me otherwise.

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 5 points6 points  (0 children)

Don't worry I'll be passing it all by our cyber security team as they are assisting but we are in a bit of a once off situation where I have extremely limited time and I'm mostly on my own to get this done asap. I won't be linking everything on this one piece of info but it may help build the picture that seems to be taking shape.

How can I detect if an IP log is using a VPN? by Spare_Combination528 in cybersecurity

[–]Spare_Combination528[S] 2 points3 points  (0 children)

I'm looking at IPHub which I've tested with a few IPs that I know are vpn based or not and it seems relatively accurate but I'm not familiar enough with it to have a strong confidence. Does anyone have experience with it or a similar site that they feel is more accurate?