Check an IP Address, Domain Name, Subnet, or ASN
195.96.138.231 has a threat confidence score of 97%. This IP address from United Kingdom (AS210924, ssd networks limited) has been observed in 52 honeypot sessions targeting SIP protocols. Detected attack patterns include sip call id high entropy hex 32. First observed on April 18, 2026, most recently active April 18, 2026.
SIP activity where Call-ID values exhibit high entropy and fixed 32-character hexadecimal format, indicating automated generation typically associated with scanning tools, fuzzing frameworks, or SIP enumeration activity.
Represents an unsolicited SIP INVITE request targeting a long numeric destination, with the request accepted for processing by the SIP server (100 Trying). While the Call-ID format appears consistent with legitimate SIP implementations, the absence of prior registration and the use of a PSTN-style numeric target indicate probing of call routing or gateway behavior rather than normal call setup. This behavior is commonly observed during early-stage toll-fraud reconnaissance or PBX routing validation.