What SIP scanners reveal about themselves

In the first article, I described the SIP honeypot and the broad traffic volumes: 48,721,111 requests, 12,634,617 signatures, and 57,970 distinct IPs between November 2021 and September 2026.

This second part looks at behavior. The numbers do not attribute an attack to a person or organization, but they do reveal the strategies being used: broad exploration, insistent repetition, misleading User-Agents, identifier bruteforce, and recognizable probes.

A small minority of IPs produces a lot of traffic

Addresses are replaced by their rank. This ranking is stable only inside this dataset snapshot.

Anonymized IPRequestsSignaturesFirst activityLast activity
IP-01656,027159,3202022-01-062022-10-11
IP-02542,0625,6302026-06-182026-09-07
IP-03524,73382,0562022-01-062022-01-13
IP-04436,238378,7882023-08-292023-10-08
IP-05432,1109,9902022-09-282022-10-28
IP-06380,30036,4512024-08-092026-06-16
IP-07363,626153,8452022-02-272022-04-12
IP-08327,28415,2962022-04-152022-04-23
IP-09323,7564,1612026-08-162026-08-31
IP-10321,91437,7282024-07-192026-02-01
The ten most active IPs The ten most active IPs Observed requests per anonymized source IP-01656,027 IP-02542,062 IP-03524,733 IP-04436,238 IP-05432,110 IP-06380,300 IP-07363,626 IP-08327,284 IP-09323,756 IP-10321,914

The top ten IPs total 4,308,050 requests, or 8.84% of all traffic. Their profiles differ significantly: IP-04 generates almost one signature per request, while IP-05 repeats a small set of signatures many times. The former looks like broad exploration; the latter looks like an insistent campaign over a more limited set of combinations.

This is behavioral interpretation, not attribution. An IP can be a compromised machine, a relay, a VPN, a reassigned address, or shared infrastructure.

/24 subnets

Grouping sources by /24 mostly helps check whether a large volume comes from a whole block or from one machine. In this snapshot, the most active prefix exceeds 1.32 million requests spread across 147 IPs, while another exceeds 542,000 requests with only one active IP.

High /24 volume does not always mean a distributed botnet. It can indicate a truly active range, but also a single very noisy source inside an otherwise quiet block.

How long does an IP remain visible?

For each IP, I calculated the difference between its first and last observation. It is better to call this an observation span rather than an activity duration: two requests separated by four years do not prove continuous activity between them.

Time between first and last observationIPsShare
Same calendar day26,22345.24%
1 to 7 days6,06010.45%
8 to 30 days5,2419.04%
31 to 90 days8,16914.09%
91 to 365 days10,53018.16%
1 to 2 years7691.33%
2 to 3 years7611.31%
3 to 4 years1780.31%
More than 4 years390.07%
Observation span of source IPs Observation span of source IPs Number of IPs by time range Same day26,223 1-7d6,060 8-30d5,241 31-90d8,169 91-365d10,530 1-2y769 2-3y761 3-4y178 4y+39

The contrast is clear: many addresses only pass through, but the long tail is real. Volumes become low after one year, yet they never fully drop to zero.

The oldest IPs are revealing. They mostly sent spaced-out OPTIONS requests. This looks like a stable probe or periodic check, but several explanations remain possible: a misconfigured legitimate service, a recurring scanner, equipment keeping a fixed IP, shared NAT, or reassignment of the same address to several machines.

User-Agents often lie

The User-Agent field looks tempting as an attribution source, but it is entirely controlled by the sender. A scanner can announce the name of a real softphone, use a fabricated string, or change identity for each campaign.

It should therefore be treated as a campaign indicator, not as a software identity. Its real value appears when it is crossed with the method, target, frequency, and time period.

The top ten strings together represent 34.4 million requests, about 70.6% of all observed traffic.

Declared User-AgentRequestsSignaturesSource IPsMain methods
pplsip11,495,6871,672,5248964 methods
PolycomSoundPointIP SPIP_550 UA 3.3.2.04133,440,1731,246,67123,785REGISTER, INVITE
Avaya IP Phone 1120E3,039,929321,2373,1533 methods
friendly-scanner2,866,965660,8453,23223 methods
<null>2,842,9041,489,9966,23616 methods
erafsadfasfa2,658,511175,908124REGISTER, INVITE
PBX2,560,384894,6846175 methods
Linksys/SPA9422,432,036303,396106REGISTER, INVITE, ACK
ims1,630,132256,4211893 methods
Z 3.14.38765 rv2.8.31,454,4081,064,255951 method
Requests by declared User-Agent Requests by declared User-Agent Top 10 by request volume pplsip11,495,687 Polycom3,440,173 Avaya3,039,929 friendly-scanner2,866,965 <null>2,842,904 erafsadfasfa2,658,511 PBX2,560,384 Linksys2,432,036 ims1,630,132 Z 3.14...1,454,408

The hierarchy is very asymmetric: pplsip dominates, followed by a group of strings between 2.4 and 3.4 million requests. This ranking mainly says something about campaign families and tool configurations, not directly about operators.

These names do not mean that 3.4 million requests truly came from Polycom phones or that 3 million came from Avaya phones. In a SIP request, the scanner freely chooses its User-Agent. Reusing the name of common equipment may help mimic an endpoint, test specific rules, or simply reflect a tool default.

pplsip is the default User-Agent value in SIPPTS, Pepelux’s SIP tool suite. The string does not prove that every packet came from the official repository, because the -ua option is configurable and the code can be reused or modified, but it explains why this label appears massively in automated campaigns. friendly-scanner remains associated with SIPVicious, while strings such as erafsadfasfa look deliberately artificial. PBX and ims are more generic.

Large REGISTER volumes

REGISTER accounts for almost 33.4 million requests in the database. On this honeypot without user accounts, very large volumes are compatible with identifier discovery or automated bruteforce.

IPs are replaced with REG-01, REG-02, and so on. The “tested identifiers” column is the number of distinct caller values; the number of recipients is identical or almost identical here.

Anonymized sourceREGISTER requestsSignaturesTested identifiersUser-AgentsPeriod
REG-01656,021159,319159,31912022-01-06 -> 2022-01-25
REG-02542,0625,6305,62322026-06-18 -> 2026-09-07
REG-03524,73382,05682,05612022-01-06 -> 2022-01-13
REG-04432,1109,9909,99012022-09-28 -> 2022-10-28
REG-05380,30036,45110,06162024-08-09 -> 2026-06-16
REG-06323,7564,1614,16122026-08-16 -> 2026-08-31
REG-07321,91437,72818,32362024-07-19 -> 2026-02-01
REG-08309,40625,11625,10512022-01-08 -> 2022-03-24
REG-09309,0014,7294,72722026-04-01 -> 2026-08-23
REG-10307,09613,91013,90912026-06-19 -> 2026-06-20
REGISTER volumes for the ten most active sources REGISTER volumes for the ten most active sources Sources anonymized by REGISTER volume REG-01656,021 REG-02542,062 REG-03524,733 REG-04432,110 REG-05380,300 REG-06323,756 REG-07321,914 REG-08309,406 REG-09309,001 REG-10307,096

REG-01 and REG-03 combine high volume, one User-Agent, and tens of thousands of distinct identifiers over a short period. REG-10 concentrates more than 307,000 requests in less than a day. These profiles are strongly compatible with automated enumeration or bruteforce campaigns.

REG-05 and REG-07 are different: several User-Agents and activity spread over nearly two years. A single public IP may be shared, reassigned, or used by several machines; persistence alone is therefore not enough to conclude that there is one actor.

A few recognizable probes

Some traffic looks neither like REGISTER bruteforce nor like INVITE call attempts. There are also very occasional OPTIONS requests, often sent without a User-Agent, that are closer to service discovery for exposed SIP.

I keep the detailed analysis of these signatures for the next article, because it depends more on the From, To, Call-ID, and CSeq fields than on raw source volume. The important point here is simply that the corpus mixes insistent campaigns and much lighter probes.

What I take away

SIP traffic exposed on the Internet mixes several behaviors. Some look like very broad scanning, with few requests per IP. Others are far more insistent, with hundreds of thousands of REGISTER or INVITE attempts. User-Agents help group families of behavior, but they do not prove the identity of a tool or actor.

This behavioral reading is useful, but it still says little about the identifiers placed in SIP headers. That is the subject of the third article: What SIP identifiers reveal about scanners.


Methodological notes