Loading threats
Identifies SIP scanning or probing activity where an attacker sends INVITE requests directly to a target IP address using randomly generated Call-ID tokens. This pattern is commonly associated with VoIP reconnaissance, SIP endpoint discovery, and automated dialer or PBX attack tooling attempting to enumerate reachable SIP services.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 212.227.28.50 | 97% | 17,002 | 8,104 | 🇫🇷 FR | AS8560 | 2026-03-07 |
| 172.110.223.45 | 92% | 15,550 | 15,550 | 🇭🇰 HK | AS23470 | 2026-03-06 |
| 172.110.223.47 | 97% | 9,813 | 9,813 | 🇭🇰 HK | AS23470 | 2026-03-02 |
| 172.110.223.62 | 98% | 5,106 | 5,106 | 🇭🇰 HK | AS23470 | 2026-03-21 |
| 172.110.223.103 | 87% | 4,800 | 4,686 | 🇭🇰 HK | AS23470 | 2026-03-18 |
| 172.110.223.64 | 98% | 4,166 | 4,166 | 🇭🇰 HK | AS23470 | 2026-03-21 |
| 5.182.209.68 | 90% | 1,916 | 1,220 | 🇳🇱 NL | AS62068 | 2026-03-21 |
| 172.110.223.60 | 93% | 1,780 | 1,780 | 🇭🇰 HK | AS23470 | 2026-03-19 |
| 172.110.223.107 | 78% | 1,434 | 1,434 | 🇭🇰 HK | AS23470 | 2026-03-06 |
| 172.110.223.68 | 89% | 1,317 | 1,317 | 🇭🇰 HK | AS23470 | 2026-03-21 |
| 172.110.223.102 | 91% | 1,310 | 1,310 | 🇭🇰 HK | AS23470 | 2026-02-18 |
| 172.110.223.105 | 83% | 992 | 992 | 🇭🇰 HK | AS23470 | 2026-03-06 |
| 109.199.103.252 | 80% | 481 | 481 | 🇫🇷 FR | AS51167 | 2026-03-12 |
| 109.123.255.228 | 81% | 359 | 359 | 🇫🇷 FR | AS51167 | 2026-03-14 |
| 172.110.223.76 | 69% | 293 | 286 | 🇭🇰 HK | AS23470 | 2026-03-06 |
| 89.163.146.64 | 86% | 291 | 291 | 🇩🇪 DE | AS24961 | 2026-03-05 |
| 172.110.223.80 | 69% | 289 | 286 | 🇭🇰 HK | AS23470 | 2026-03-06 |
| 172.110.223.91 | 66% | 166 | 166 | 🇭🇰 HK | AS23470 | 2026-03-06 |
| 185.82.72.173 | 81% | 135 | 135 | 🇳🇱 NL | AS206092 | 2026-03-21 |
| 172.110.223.77 | 60% | 121 | 121 | 🇭🇰 HK | AS23470 | 2026-03-06 |