Substantial Risk
IP 31.70.75.118 is a high-risk address operating from IONOS SE infrastructure in Germany, with 370 abuse reports and a threat level of 8/10 indicating significant malicious activity concentrated in the VoIP fraud category.
Automated honeypot sensors and community reports have documented 370 incidents attributed to this IP since first appearing in May 2026, with consistent activity through the same month. The dominant threat category driving these reports is VoIP fraud, representing 20 confirmed detection events. With an activity frequency rating of 8/10 and a 91% confidence score, the data paints a clear picture of sustained, deliberate abuse originating from this address. The network is operated by AS8560 (IONOS SE), a major European hosting provider, which means the hostile activity is traversing commercial infrastructure rather than a residential connection.
VoIP fraud exploits telecommunications systems to route unauthorized calls, typically targeting premium-rate numbers or international destinations to generate illicit revenue. The concrete risk to any organization running an exposed VoIP service is unauthorized call routing at the victim's expense, potentially resulting in substantial financial losses within hours. Attackers scanning for open SIP ports or misconfigured telephony equipment can rapidly scale such attacks, making prompt detection critical for limiting exposure.
Site operators should implement call authentication protocols such as STIR/SHAKEN, enforce strict dial-plan restrictions to block premium-rate and international destinations unless explicitly authorized, and deploy rate-limiting on SIP ports to throttle rapid call attempts. Monitoring call detail records for anomalous patterns and leveraging defensive tools like fail2ban to automatically block repeated offenders will further reduce exposure to this threat vector.