Elevated Risk
IP 31.70.75.117 is a German address operated by IONOS SE (AS8560) that presents a moderate-to-high threat profile with a 7/10 threat level and 91% confidence based on 289 total abuse reports. The dominant activity detected against this address is VoIP fraud, consistent with exploitation patterns targeting voice-over-internet-protocol infrastructure to generate unauthorized premium-rate calls for financial gain. The address was first and last reported in May 2026, with activity frequency rated 8/10, indicating persistent scanning or probing behavior rather than isolated opportunistic contact.
The report volume of 289 submissions over a compressed timeframe, sourced exclusively from automated honeypot sensors, signals coordinated automated exploitation attempts rather than manual probing. All 20 of the most recent categorized reports specifically flag Fraud VoIP activity, establishing this as the primary threat vector associated with the address. Its placement within IONOS SE's German network infrastructure means traffic originating from this IP passes through a major commercial hosting and cloud provider, which is frequently leveraged by threat actors due to the volume of customers and relative reputation of IP space.
VoIP fraud represents a direct financial risk to organizations running telephony infrastructure, as attackers leverage compromised or misconfigured systems to route expensive international or premium-rate calls while the victim absorbs the cost. Sites exposing SIP ports, administrative telephony interfaces or session-border controllers without strong authentication face the highest exposure. Even when an organization does not operate VoIP services directly, the scanning activity documented against this IP confirms it is actively probing internet-facing telephony assets across numerous targets simultaneously.
Site operators should block or throttle traffic from this address at the network edge firewall and implement fail2ban or equivalent log-analysis tools to auto-ban sources generating repeated SIP or VoIP authentication failures. Organizations running VoIP infrastructure should enforce strong session authentication, disable unused SIP ports, monitor call-detail records for anomalous patterns such as sudden spikes in outbound calls to premium or international numbers, and restrict premium-rate dialing by default. Continuous abuse-log monitoring and integration of IP reputation feeds will help contextualize and block repeat offenders like 31.70.75.117 proactively.