Substantial Risk
IP 217.154.152.137, hosted on IONOS SE infrastructure in Germany (AS8560), presents a high-risk threat profile with a threat level of 8/10 and a 91% confidence score, having accumulated 1,238 abuse reports within a three-month detection window spanning May to July 2026.
Automated honeypot sensors detected the address repeatedly engaging in VoIP fraud activity, generating approximately 62 reports per month during this period. The activity frequency rating of 8/10 indicates sustained, repeated engagement in malicious behavior rather than isolated probing. The AS8560 autonomous system, operated by IONOS SE, is a major European hosting provider whose infrastructure has been observed hosting both legitimate services and, in this specific case, an address associated with systematic VoIP fraud exploitation attempts. All 20 recent threat category reports consistently reference VoIP fraud, establishing this as the dominant and persistent attack vector for this IP address.
VoIP fraud represents a significant financial threat to organizations running exposed voice-over-internet-protocol infrastructure. Attackers leverage compromised or poorly secured telephony systems to route unauthorized calls, particularly to premium-rate international numbers, generating profit at the expense of the system operator who bears the call charges. This IP address has been identified as actively seeking vulnerable VoIP endpoints, likely conducting automated scanning for misconfigured SIP servers or weak authentication on voice platforms. The sustained report volume and high activity frequency suggest this address is part of an organized campaign rather than opportunistic probing.
Site operators with exposed VoIP or telephony services should immediately block or rate-limit traffic originating from this IP range on SIP ports (UDP 5060) and related voice protocols. Hardening authentication on all administrative and SIP interfaces with strong, unique credentials and implementing call admission controls can prevent unauthorized call routing. Regular monitoring of call detail records for anomalous patterns such as unexpected international or premium-rate destinations will help detect compromise. Deploying defensive tools such as fail2ban to automatically ban IPs exhibiting brute-force authentication behavior provides an additional layer of protection against this type of threat.