Substantial Risk
IP 31.70.75.109 is a high-risk address originating from Germany that has been definitively linked to VoIP fraud, accumulating 2,202 total abuse reports with a threat level of 8/10 and a confidence score of 91 percent. The IP was actively reported between May 2026 and July 2026, indicating sustained malicious activity over approximately three months. Its activity frequency rating of 8/10 confirms consistent engagement in hostile behavior rather than isolated incidents.
Detection data from automated honeypot sensors shows 20 recent reports specifically categorizing this address under VoIP fraud activity. The IP operates within AS8560, the autonomous system administered by IONOS SE, one of Germany's largest hosting and cloud infrastructure providers. The sheer volume of reports, combined with the concentrated timeframe of detection, paints a picture of systematic abuse rather than opportunistic scanning. The 91 percent confidence score reflects the unambiguous pattern matching across multiple detection points, leaving little doubt about the malicious nature of this address's traffic.
VoIP fraud represents a direct financial threat to organizations running exposed telephony infrastructure. Attackers leveraging addresses like 31.70.75.109 typically probe SIP endpoints and telephony gateways to establish unauthorized call sessions, often routing calls through the victim's systems to premium-rate or international numbers. This abuse can result in substantial unauthorized charges appearing on corporate telephony accounts within hours of initial compromise. The infrastructure supporting this activity, including the AS8560 network, is frequently repurposed by threat actors due to its scalability and relative anonymity.
Organizations operating VoIP services should immediately block or rate-limit traffic from 31.70.75.109 at network boundaries and session border controllers. Implement call authentication protocols such as STIR/SHAKEN to verify calling party legitimacy. Restrict international and premium-rate dialing permissions by default and monitor call records for sudden spikes in anomalous destinations. Deploy intrusion detection systems to alert on repeated SIP authentication failures, and consider using defensive tools such as fail2ban to automatically ban addresses exhibiting brute-force behavior against telephony ports.