Substantial Risk
IP 87.106.149.37 is a Germany-based address that automated honeypot sensors flagged with a threat level of 7 out of 10, driven predominantly by Fraud VoIP activity detected across 20 distinct honeypot sensors over a two-month window. With 1,117 cumulative abuse reports and an activity frequency rating of 8 out of 10, this address presents a moderate-to-high risk to exposed telephony and VoIP infrastructure.
The detection data places 87.106.149.37 within network AS8560, operated by IONOS SE, a major European hosting and cloud-services provider headquartered in Germany. Reports first emerged in June 2026 and continued through July 2026, indicating sustained malicious behavior spanning at least two months. The concentration of recent reports specifically citing Fraud VoIP as the threat category, combined with the high confidence score of 91 percent, suggests this IP is actively involved in telephony fraud rather than incidentally scanning or probing for vulnerabilities.
VoIP fraud exploits internet-connected phone systems to initiate unauthorized calls, typically routing through premium-rate numbers to generate illicit revenue. An IP with this activity profile likely operates compromised VoIP hardware or a SIP server configured to dial out to paid-call destinations without authorization. For organizations running SIP endpoints, session-border controllers or poorly secured VoIP gateways, exposure to this address could result in unauthorized toll charges, service degradation or credential harvesting attempts.
Defensive measures include hardening SIP authentication with strong, unique passwords and disabling unused SIP methods, implementing call pattern monitoring to flag anomalous outbound traffic, and using allowlists to restrict which IP addresses can register against VoIP infrastructure. Deploying tools such as fail2ban or comparable intrusion-prevention systems to block repeated authentication failures provides an additional layer of protection against credential-guessing attempts associated with this threat profile.