Check an IP Address, Domain Name, Subnet, or ASN
159.65.199.126 has a threat confidence score of 82%. This IP address from The Netherlands (AS14061, DigitalOcean, LLC) has been observed in 34 honeypot sessions targeting HTTPS, RTSP, HTTP, FTP, SIP and 4 other protocols. First observed on January 22, 2026, most recently active April 19, 2026.
SIP request using sip:nm as the Request-URI, a malformed or placeholder target commonly observed in SIP scanning and fuzzing activity rather than legitimate client behavior.
RTSP DESCRIBE request targeting /Streaming/Channels/101, a default IP camera stream path commonly used in automated scanning and unauthorized access attempts to enumerate or access live video streams.
HTTP GET request to /robots.txt.
HTTPS request to /robots.txt.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.