I have written a letter to the people in charge of the SIP scanning and owner of the network. I have now sent it to several IP responsible for those IP addresses.
——-
Dear support personnel
We have repeatedly been scanned for open SIP (VoIP) access from IP
adresses: 113.105.152.101, 113.105.152.102 and 113.105.152.104.
The last time was February 27th 2010, but this scanning has been going
on for a long time, first reported back in December 2009.
http://www.usken.no/2010/02/and-the-scanning-just-keeps-on-coming/
http://pbxinaflash.com/forum/showthread.php?t=6223
http://www.freepbx.org/forum/freepbx/users/call-log-with-asterisk-in-both-source-and-clid-columns
We believe this is fraudulent activity to scan for open SIP gateways to
route traffic towards the telephony network.
Please inform the owners of these servers that this activity is not
tolerated and seen as an attack on our servers.
regards
sjur