Check an IP Address, Domain Name, Subnet, or ASN
154.23.185.197 has a threat confidence score of 49%. This IP address from Hong Kong (AS140227, Hong Kong Communications International Co., Limited) has been observed in 2 honeypot sessions targeting SIP protocols. First observed on March 7, 2026, most recently active March 7, 2026.
Represents an automated SIP INVITE request likely generated by a scanner or bot rather than a legitimate user agent. The behavior is inferred from a combination of a numeric-only SIP Call-ID format and a direct INVITE to a long numeric target without prior registration or dialog context. This pattern is commonly associated with SIP service probing, extension discovery, or early-stage toll-fraud reconnaissance. This behavior indicates reconnaissance activity against a SIP service but does not, by itself, confirm successful call setup or financial abuse.