Check an IP Address, Domain Name, Subnet, or ASN
103.123.226.138 has a threat confidence score of 77%. This IP address from India (AS138296, Juweriyah Networks Private Limited) has been observed in 7 honeypot sessions targeting SIP protocols. First observed on April 29, 2026, most recently active April 29, 2026.
Automated SIP INVITE requests initiating direct call setup toward a numeric extension, indicating scripted VoIP interaction rather than passive capability probing. The client attempts to establish a call session (e.g., extension-to-extension dialing such as 100 → 100) using high-entropy Call-ID values, a pattern frequently associated with automated dialers, toll-fraud reconnaissance, or PBX abuse tooling. These interactions validate whether the endpoint accepts call initiation and may precede brute-force registration attempts, relay abuse, or fraudulent outbound call campaigns.