High Risk
217.160.24.49 is a high-risk address with a threat level of 8/10 that has generated 263 reports, primarily for VoIP fraud, indicating sustained abuse originating from IONOS SE infrastructure in Germany.
The IP, allocated to AS8560 (IONOS SE) in Germany, was first reported in May 2026 with consistent activity through the same month, drawing 263 total reports from 20 automated honeypot sensors. The high confidence score of 92% and activity frequency rating of 8/10 reflect reliable, repeated detection of the suspicious behavior over a concentrated timeframe. Detection patterns included Suricata stream spurious retransmission alerts, suggesting ongoing reconnaissance or exploitation attempts against telephony infrastructure.
VoIP fraud represents a significant financial threat, where attackers exploit phone systems to route unauthorized calls—often to premium-rate numbers—generating illicit revenue. The combination of VoIP fraud reports alongside general hacking indicators suggests this address may be engaged in coordinated scanning or exploitation of Voice over IP deployments rather than opportunistic activity. Stream spurious retransmission detection points to potential attempts at session hijacking or traffic manipulation targeting VoIP protocols. Organizations running exposed telephony systems face direct financial exposure if such attempts succeed.
Site operators should implement call authentication standards such as STIR/SHAKEN to verify caller legitimacy, and restrict international and premium-rate dialing unless explicitly required. Deploying automated blocking tools like fail2ban can mitigate repeated hostile attempts. Keeping intrusion detection signatures current and reviewing honeypot-style alerts for the detected patterns will strengthen situational awareness. Continuous monitoring of call records for anomalous volume spikes or unexpected destination numbers provides an additional layer of defense against the fraud techniques this address has demonstrated.