Is 13.107.6.152 a VPN? Yes.
Ground-truth confirmed VPN/proxy — 5 signals matched across 5 intelligence sources. very high confidence in this reading.
Protocol handshake
Live OpenVPN, IKEv2, WireGuard, SOCKS5, and HTTP-CONNECT probes. Ground truth on positive.
TCP/443 serves a valid cert for www.bing.com when probed with that SNI but a different default cert otherwise; www.bing.com does not resolve to 13.107.6.152 (REALITY masquerade signature)
ASN classification
Team Cymru allocation data + PeeringDB self-declared network type.
PeeringDB classifies ASN AS8068 as "Content" — content/cloud-hosting profile
BGP routing topology
RIPE NCC routing-information service. Single-homed ASes and unannounced prefixes.
ASN AS8068 is single-homed (1 upstream, 1 total neighbours) — lone-wolf BGP footprint common to proxy-operator ASes
IP intelligence
Matches against the Tor exit list, public proxy feeds, curated VPN-provider ranges, and datacenter ASN registries.
Datacenter / hosting ASN AS8068 (Microsoft Corporation)
Shodan observation
Passive ~30-day port fingerprint. VPN/proxy software CPE matches and observed ports.
Shodan has observed 2 open port(s) on this IP
Should I block this IP?
Practical guidance by use case — fraud, ad-ops, streaming, and general websites.
This IP is a confirmed commercial VPN exit. Multiple ground-truth sources agree, and active probing returned a VPN protocol handshake (or it appears in a published relay list).
- Fraud / risk teams
- Block at signup, checkout, password reset, and money-out flows. Pair with device fingerprint to allow trusted users on VPN.
- Ad ops / programmatic
- Filter as non-human traffic. Most commercial VPN traffic on ad surfaces is bot or click-fraud unless your inventory specifically allows VPN.
About IP address 13.107.6.152
13.107.6.152 is an IPv4 address routed via AS8068 (Microsoft Corporation) and geo-located to United States. The verdict above combines six free, no-auth intelligence sources: local db-ip ASN data, the Tor Project exit list, public proxy feeds (TheSpeedX / Proxifly / FireHOL), Team Cymru + PeeringDB for ASN classification, RIPE NCC for BGP topology and abuse contacts, and Shodan InternetDB for ~30-day port observation.
Verdicts are recomputed on every page load and cached for up to one hour upstream. No data about your browser or identity is persisted.