Notable Threat
IP 103.123.226.138, registered to Juweriyah Networks Private Limited in India (ASN AS138296), presents a high-risk threat profile with a severity rating of 8/10 and 93% confidence based on 156 total abuse reports. This address has been actively targeting web applications and phone infrastructure, with a concentrated reporting window spanning May through June 2026 and an activity frequency rated 8/10. The combination of probing honeypot sensors across multiple networks and explicit VoIP fraud indicators makes this IP a versatile threat actor worth blocking on sight.
The detection data draws from 20 separate automated honeypot sensors that logged consistent probing behaviour over approximately two months. Threat categorization breaks down as follows: 15 reports classified as general hacking activity involving intrusion attempts and vulnerability exploitation, 13 reports documenting web application attacks, and 5 reports specifically tied to VoIP fraud schemes. The honeypot logs captured multiple instances of web application probing events alongside Suricata alerts flagging application-layer protocol anomalies, suggesting the actor employs layered reconnaissance before attempting exploitation. The moderate volume of reports combined with sustained activity indicates persistent rather than opportunistic scanning behaviour.
Web application attacks pose the most immediate risk to exposed services, as the honeypot evidence shows repeated probing for application-layer vulnerabilities consistent with OWASP Top 10 issues including injection flaws and misconfiguration exploitation. Meanwhile, the VoIP fraud reports suggest this actor may be monetising compromised phone systems by routing unauthorized calls through targeted infrastructure, either to premium-rate numbers or as part of larger telephony fraud chains. The general hacking activity signals broader scanning for accessible entry points across networked services, making any publicly reachable system a potential target.
Network defenders should immediately block 103.123.226.138 at the firewall level and monitor ingress traffic patterns for similar probing originating from adjacent address space. Deploying a web application firewall with rule sets covering the observed probe patterns will neutralise application-layer attempts, while rate-limiting authentication endpoints reduces brute-force exposure. Implementing fail2ban or equivalent dynamic blocking tools on SSH and VoIP services specifically thwarts repeated intrusion patterns. Regular audit cycles for publicly accessible applications and telephony infrastructure remain essential given the dual threat vector this IP represents.