MIRAGE
Threat IntelligenceServices › SIP

SIP attacks & scanning (port 5060)

VoIP signalling — toll-fraud dialling and PBX registration abuse.

Observed by OffSeq honeypot sensors · last 7 days · #2 most-attacked service · last seen just now

586,080
Attacks
436
Distinct source IPs
5060
Port · udp

The #2 most-attacked service across the fleet in the last 7 days.

OffSeq honeypots emulating SIP recorded 586,080 attacks from 436 distinct source IPs over the last 7 days. VoIP signalling — toll-fraud dialling and PBX registration abuse.

Top CVEs exploited across the fleet (last 7 days)

Fleet-wide, not scoped to SIP.

Other attacked services

Open the live SIP view →