Notable Threat
IP 195.96.138.179, registered to ssd networks limited in the United Kingdom and operating on AS210924, presents a high-risk threat profile with a 7/10 threat level and a 91% confidence score. This address has generated 624 total abuse reports with an activity frequency rated 8/10, indicating sustained and persistent hostile behavior. The dominant threat category driving this assessment is VoIP fraud, detected through 20 recent automated honeypot reports filed over an eight-week window between April and May 2026.
The concentration of recent reports from honeypot sensors confirms that IP 195.96.138.179 is actively engaged in VoIP-related exploitation attempts. With 624 cumulative reports and an activity frequency score of 8/10, this address demonstrates consistent scanning and probing behavior targeting voice-over-internet-protocol infrastructure. The geographic location in the United Kingdom and its association with AS210924 operated by ssd networks limited places this source within a commercial hosting environment that may be leveraged for telephony fraud campaigns. The detection span from April through May 2026 indicates the malicious activity is ongoing and has not subsided, maintaining its threat relevance through the present period.
VoIP fraud represents a serious financial threat vector where attackers exploit internet telephone systems to route unauthorized calls, frequently targeting premium-rate numbers to generate illicit revenue. For organizations running exposed SIP (Session Initiation Protocol) servers, telephony gateways, or soft-switches, an address with this threat profile poses a direct risk of toll fraud, service theft, and unauthorized call origination. Attackers leveraging compromised VoIP infrastructure can accumulate substantial charges within minutes, creating immediate financial liability for the victim while obscuring the attacker's identity through this UK-based intermediate address.
Network operators should immediately block IP 195.96.138.179 at the firewall level and implement geographic or rate-based restrictions on outbound SIP traffic. Deploying fail2ban or equivalent intrusion-prevention tools configured to detect and ban brute-force SIP authentication attempts provides an additional defensive layer. Organizations running VoIP services should enforce strong SIP authentication credentials, enable call-pattern monitoring to flag anomalies such as unusual destination numbers or call volumes, and restrict international and premium-rate dialing by default unless explicitly permitted for specific accounts.