Check an IP Address, Domain Name, Subnet, or ASN
144.172.88.228 has a threat confidence score of 99%. This IP address from United Arab Emirates (AS14956, RouterHosting LLC) has been observed in 89 honeypot sessions targeting SIP protocols. Detected attack patterns include sip call id high entropy hex 32. First observed on April 27, 2026, most recently active April 27, 2026.
SIP activity where Call-ID values exhibit high entropy and fixed 32-character hexadecimal format, indicating automated generation typically associated with scanning tools, fuzzing frameworks, or SIP enumeration activity.
Identifies SIP scanning or probing activity where an attacker sends INVITE requests directly to a target IP address using randomly generated Call-ID tokens. This pattern is commonly associated with VoIP reconnaissance, SIP endpoint discovery, and automated dialer or PBX attack tooling attempting to enumerate reachable SIP services.