Elevated Risk
IP 31.70.75.115, allocated to IONOS SE in Germany, is a high-risk address associated with VoIP fraud activity, accumulating 247 abuse reports with a threat level rating of 8 out of 10 and a confidence score of 91 percent, indicating highly reliable attribution to malicious behavior.
Automated honeypot sensors logged 20 confirmed instances of fraudulent VoIP activity against this IP during May 2026, representing the dominant threat category across all submissions. The high activity frequency score of 8 out of 10 and the substantial report volume demonstrate persistent engagement with target systems throughout the reporting window. Operating from AS8560 (IONOS SE), a major German hosting provider, this address sits within infrastructure commonly used for both legitimate and malicious services, making it a credible source of telecommunications fraud. The remaining reports in the 247-total figure likely capture secondary detection signatures consistent with the same fraud campaign.
VoIP fraud exploits phone systems and session initiation protocol endpoints to route unauthorized calls, typically to premium-rate or international numbers for financial gain. For organizations running exposed VoIP infrastructure, an IP engaging in this behavior could indicate compromise of dial plans, registration hijacking, or unauthorized trunking. The real-world risk extends beyond mere nuisance: compromised VoIP systems can generate massive bills, damage carrier relationships, and serve as conduits for further network intrusion. The abstract attack pattern observed suggests probing for open SIP ports and misconfigured PBX systems.
Site operators should immediately block or challenge traffic from this IP at the firewall level and monitor for any active VoIP registrations originating from this address. Implementing call authentication standards such as STIR/SHAKEN can verify caller legitimacy, while restricting international and premium-rate dialing curtails the financial impact of any successful compromise. Tools such as fail2ban can automatically ban repeated scanning patterns targeting SIP ports, and regular audits of VoIP dial plans will limit unauthorized call routing. Continuous logging of SIP registration attempts and call setup attempts from unknown sources is strongly advised.