High Risk
IP address 31.70.78.114 is a high-risk threat actor located in Germany and operating within the IONOS SE network (ASN AS8560), primarily associated with VoIP fraud activity detected by automated honeypot sensors. With 1,160 total abuse reports and a threat level of 8 out of 10, this address has demonstrated persistent, high-frequency malicious behavior over a three-month observation window from May to July 2026, yielding a 91 percent confidence rating that the activity is intentional and hostile rather than coincidental.
The detection profile for this IP shows sustained engagement with honeypot infrastructure, producing 20 recorded threat reports specifically documenting VoIP fraud patterns. The automated honeypot sensor network identified the malicious activity consistently across the reporting period, indicating that this address is not a transient or opportunist visitor but rather an actively managed asset conducting systematic VoIP-related exploitation attempts against exposed telephone systems.
VoIP fraud represents a concrete financial threat to organizations running exposed phone systems, as attackers exploit these platforms to route unauthorized calls—typically to premium-rate or international numbers—generating illicit revenue while victimizing the account holder with inflated telecom bills. The activity detected against IP 31.70.78.114 suggests systematic scanning or probing of VoIP services for registration hijacking, toll fraud, or unauthorized call origination, posing direct monetary risk to any organization with inadequately secured Session Initiation Protocol endpoints.
Site operators should implement call authentication mechanisms such as STIR/SHAKEN to verify calling party legitimacy, enforce strict rules restricting premium-rate and international dial destinations, and continuously monitor call detail records for anomalous patterns indicative of compromise. Deploying fail2ban or equivalent intrusion-prevention tools to automatically block repeated hostile connection attempts, alongside geographic or ASN-based firewall restrictions, provides layered defense against continued probing from this address.