This IP address has been reported a total of
10
times from
7 distinct
sources.
195.96.138.20 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Brazil
with 1
report;
Switzerland
with 1
report.
The most common categories in these recent reports were:
DDoS Attack
1
time;
Fraud VoIP
1
time;
Hacking
1
time;
Exploited Host
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Inaxas SecureAsterisk has automatically banned 195.96.138.20 after detecting activity against a SIP ...
show moreInaxas SecureAsterisk has automatically banned 195.96.138.20 after detecting activity against a SIP/VoIP infrastructure.
Detected attack behaviour:
- Attempt to use non existing account: 26 event(s) between 2026-10-06 15:04:55 UTC and 2026-10-07 09:45:27 UTC.
show less
Firewall: Within 2026-04-18 15:46:48 - 2026-04-18 16:33:56 CEST(+0200) identified: unallowed access ...
show moreFirewall: Within 2026-04-18 15:46:48 - 2026-04-18 16:33:56 CEST(+0200) identified: unallowed access from 195.96.138.20 on port 5060(sip) (1 trial)
Fail2ban: Within 2026-04-18 15:46:48 - 2026-04-18 16:33:56 CEST(+0200) banned: 6 times by fail2ban[firewall]; 6 times by fail2ban[recidive]
show less
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. D ...
show moreReconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Suricata. Decoy listen port: 5060/tcp. Observed event time: 2026-04-19 09:39:09 UTC. Report from passive honeypot only; no payload or credentials included.
show less
Reconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Sentrypeer. ...
show moreReconnaissance or port-scan activity observed on a honeypot sensor. Honeypot decoy type: Sentrypeer. Decoy listen port: 5060/tcp. Observed event time: 2026-04-19 09:34:08 UTC. Report from passive honeypot only; no payload or credentials included.
show less