Check an IP Address, Domain Name, Subnet, or ASN
134.209.47.152 has a very high threat confidence level of 99%, originating from Clifton, United States, on the DigitalOcean, LLC network (14061). It has been observed across 3,213 sessions targeting SIP, First observed on February 1, 2026, most recently active February 2, 2026.
Represents automated SIP reconnaissance activity characterized by multiple unauthenticated SIP methods (such as REGISTER and INVITE) issued using bot-like Call-ID formats. This behavior indicates an attempt to enumerate valid SIP users, extensions, or call routing behavior by systematically probing a SIP service without establishing legitimate registration or dialog context. The use of a numeric-only, hyphen-delimited Call-ID format across different SIP methods strongly suggests an automated scanner or fraud bot rather than a legitimate user agent.