High Risk
IP 173.245.76.90, an address routed through EGIHOSTING's AS18779 network in the United States, presents a high-risk threat profile with a threat level of 8/10 and a 73% confidence score, primarily linked to VoIP fraud activity detected by automated honeypot sensors. The IP has accumulated 290 total reports in the available dataset, with recent activity concentrated in a single threat category over a reporting window spanning February through April 2026. Despite the substantial report volume, the current activity frequency registers at 0/10, suggesting that while the address carries significant historical weight as a threat indicator, no fresh intrusion attempts have been logged in the most recent monitoring period. The concentration of all recent reports on VoIP fraud reflects a focused exploitation pattern rather than opportunistic scanning behaviour.
The evidence base for this assessment derives entirely from automated honeypot detection systems, which contributed 20 separate reports tagging the address for fraudulent VoIP activity. This methodical focus on a single attack vector distinguishes IP 173.245.76.90 from general-purpose scanning infrastructure, indicating sustained interest in telephony systems rather than broad reconnaissance. The 73% confidence score reflects reasonable certainty that the observed behaviour represents genuine malicious intent rather than misclassification, though roughly a quarter of the analysis carries uncertainty. EGIHOSTING's role as the network operator places this address within a hosting environment commonly associated with commercial cloud and dedicated server offerings, which threat actors frequently abuse as launch points due to the relative anonymity and bandwidth they provide.
VoIP fraud represents a financially motivated threat category that exploits phone system vulnerabilities to place unauthorized calls, frequently targeting premium-rate or international numbers to generate illicit revenue. For organisations operating exposed telephony infrastructure, an IP with this many historical reports against it poses concrete risks including unexpected toll charges, resource exhaustion, and potential compromise of communication systems. The fact that all 20 recent reports centre on this specific category confirms intent to weaponize VoIP services, not merely to probe for open ports or weak credentials. An address with this threat level and reporting history warrants immediate inclusion in blocklists and denial lists for any VoIP-facing assets.