High Risk
IP 172.110.223.33 is a high-risk address operating from Hong Kong via ASN AS23470 (RELIABLESITE) that has accumulated 6,995 abuse reports between February and June 2026, indicating sustained involvement in VoIP fraud activity with a threat level of 8/10 and an 88% confidence score from automated honeypot sensors.
The volume of reports and activity frequency of 8/10 both underscore persistent malicious behavior rather than incidental scanning. All 20 recent threat reports consistently cite Fraud VoIP as the category, suggesting a specialized and financially motivated operation rather than generalized exploitation. The IP's association with RELIABLESITE places it within a network operator that has generated significant abuse history. Detection has been driven entirely by automated honeypot sensors, which collected reliable telemetry over a four-month window, lending high confidence to the characterization. Geographic positioning in Hong Kong provides convenient transit for international VoIP fraud schemes targeting premium-rate destinations.
VoIP fraud exploits phone systems and voice infrastructure to route unauthorized calls, typically toward premium-rate or international numbers that generate illicit revenue for the attacker. For organizations running exposed SIP endpoints, session border controllers, or open telephony services, an IP with this profile represents a direct pathway to financial losses through toll fraud, as well as potential service degradation from resource exhaustion. The sustained report volume indicates this IP has successfully leveraged such infrastructure in the past and continues probing for vulnerable targets.
Site operators should immediately block or rate-limit traffic from this IP at the firewall or edge device level, particularly for SIP ports and VoIP signaling channels. Enabling call authentication mechanisms such as STIR/SHAKEN can help verify call origin legitimacy. Restricting international and premium-rate dialing features, monitoring call detail records for anomalous patterns, and deploying defensive tools like fail2ban to automatically ban repeated offenders will substantially reduce exposure to this threat vector.