Check an IP Address, Domain Name, Subnet, or ASN
185.82.72.173 has a threat confidence score of 81%. This IP address from The Netherlands (AS206092, F.n.s. Holdings Limited) has been observed in 135 honeypot sessions targeting MYSQL, SIP, HTTP, HTTPS protocols. First observed on February 23, 2026, most recently active March 21, 2026.
Identifies SIP scanning or probing activity where an attacker sends INVITE requests directly to a target IP address using randomly generated Call-ID tokens. This pattern is commonly associated with VoIP reconnaissance, SIP endpoint discovery, and automated dialer or PBX attack tooling attempting to enumerate reachable SIP services.
Identifies HTTP requests targeting the web server root path ("/"), typically used for initial service discovery, host validation, or baseline content inspection prior to deeper enumeration.