Check an IP Address, Domain Name, Subnet, or ASN
5.138.97.127 has a threat confidence score of 86%. This IP address from Russia (AS12389, Rostelecom) has been observed in 11 honeypot sessions targeting RTSP protocols. First observed on March 22, 2026, most recently active March 22, 2026.
Client performs a full RTSP interaction sequence — OPTIONS, DESCRIBE, SETUP, and PLAY — indicating an attempt to initialize and access a media stream. This pattern reflects active interaction with a streaming service rather than simple probing, and is commonly seen when automated tools or unauthorized clients try to view exposed camera or RTSP feeds.
Client requests RTSP OPTIONS followed by DESCRIBE to query supported methods and retrieve stream metadata, but does not proceed to session setup or playback. This pattern is commonly associated with automated scanning or reconnaissance activity checking for exposed cameras or media services.