Significant Threat
IP 87.106.206.249 is a high-risk German address with a threat level of 8/10 that has generated 399 abuse reports, predominantly linked to VoIP fraud activity detected by automated honeypot sensors operating across a 20-source network.
The address resides on AS8560 (IONOS SE) infrastructure in Germany and was first reported in May 2026 with sustained activity through the same month. Of the recent threat reports, Fraud VoIP dominates with 19 instances, while 3 reports reference general Hacking activity. The Suricata intrusion-detection sensors flagging this address recorded STREAM spurious retransmission anomalies, a pattern consistent with VoIP protocol manipulation and credential-harvesting attempts. With an activity frequency score of 8/10 and a 92% confidence rating, the sustained volume of reports from multiple independent honeypot sources indicates persistent, deliberate exploitation rather than incidental scanning.
VoIP fraud exploits telephone systems to route unauthorized calls, frequently through premium-rate numbers, generating direct financial gain for threat actors while inflating costs for the victim organization. The spurious retransmission behavior suggests the attacker is probing for vulnerabilities in exposed VoIP endpoints or attempting to establish fraudulent call-routing tunnels. This pattern poses material financial and operational risk to any organization running unprotected Session Initiation Protocol services or legacy PBX systems on this network segment.
Network defenders should implement dynamic blocking tools such as fail2ban to automatically drop connections from addresses exhibiting this behavioral fingerprint. Organizations with VoIP infrastructure should enforce strong authentication on all telephony endpoints, restrict premium-rate and international dialing permissions, and monitor call-detail records for anomalous usage spikes. Deploying Web Application Firewalls or intrusion-detection systems with rules tuned to VoIP protocol anomalies provides an additional hardening layer against this threat category.