Significant Threat
IP address 87.106.189.67 is a high-risk German address with a threat level of 8/10, strongly linked to VoIP fraud activity detected across automated honeypot sensors over a concentrated reporting period in May 2026. With 409 total abuse reports and a confidence score of 92%, this IP demonstrates sustained, deliberate probing behavior that poses a material risk to any exposed phone infrastructure.
The address traces to IONOS SE operating on ASN AS8560, one of Germany's largest hosting providers, and all reported activity originates from automated honeypot sensors. The 8/10 activity frequency indicates repeated, persistent attempts rather than isolated scanning, while the consistent volume of 409 reports across multiple detection points confirms this is not background noise but sustained hostile activity specifically targeting VoIP systems. The dominant threat category of VoIP fraud reflects organized exploitation attempts against phone infrastructure.
VoIP fraud exploits phone systems to make unauthorized calls, often routing through premium rate numbers for direct financial gain. An IP with this reputation engaging your phone infrastructure suggests attempts to enumerate valid extensions, test for default or weak credentials, or establish unauthorized call paths to premium destinations. The sustained frequency and report volume indicate this is likely part of an automated campaign scanning broadly for vulnerable VoIP deployments rather than targeted reconnaissance.
Site operators should immediately block or rate-limit traffic from this IP at the firewall level and monitor for any successful authentication attempts. Implementing call authentication protocols such as STIR/SHAKEN, restricting international and premium rate dialing, and hardening credential requirements for VoIP management interfaces will significantly reduce exposure. Regular review of call detail records for anomalous patterns and consideration of tools like fail2ban for correlating abuse across log sources can help detect and disrupt ongoing exploitation attempts.