Notable Threat
IP address 31.70.75.104 is a high-risk address associated with VoIP fraud activity, exhibiting a threat level of 8 out of 10 with a 91 percent confidence score based on 1,439 total abuse reports submitted through automated honeypot sensors over a three-month window between May 2026 and July 2026.
Located in Germany and routed through AS8560, operated by IONOS SE, this IP demonstrated an activity frequency rating of 8 out of 10, indicating sustained and repeated malicious behavior rather than isolated probes. The concentration of 20 recent reports categorizing the activity as fraud involving Voice over Internet Protocol systems suggests systematic exploitation of telecommunications infrastructure rather than opportunistic scanning. Community reports and honeypot detections together paint a consistent picture of an actor leveraging this address specifically for unauthorized VoIP-related fraud operations.
VoIP fraud represents a financially motivated threat vector where compromised or abuseable telephony infrastructure is weaponized to route unauthorized calls, particularly to premium-rate numbers that generate illicit revenue for the attacker. For organizations running exposed SIP endpoints, session border controllers or open telephony services, an IP with this abuse history poses a direct risk of becoming a vector for fraudulent call routing, potentially resulting in unexpected charges, service degradation or legal liability. The frequency and volume of reports against 31.70.75.104 indicate persistent targeting rather than transient scanning.
Operators should block this IP at the network perimeter and implement fail2ban or similar dynamic blocking tools to automatically mitigate repeated abuse. Restricting international and premium-rate dialing on any exposed VoIP endpoints, enforcing strong SIP authentication, monitoring call detail records for anomalous patterns and deploying call admission control policies will substantially reduce exposure to this threat category.