Substantial Risk
IP 31.70.75.122 is a high-risk German address with a threat level of 8/10 that has been linked to 174 reported incidents of suspicious activity, with automated honeypot sensors flagging it primarily for VoIP fraud activity in May 2026.
Evidence shows 91% confidence in malicious intent across 20 recent reports specifically documenting Fraud VoIP patterns. The address originates from IONOS SE's network (AS8560), a major European hosting provider, which explains its active involvement in telecommunications fraud operations. Detection occurred solely through automated honeypot sensors without community reporting, suggesting automated exploitation attempts rather than opportunistic scanning. The address was first and last reported within the same month, indicating a concentrated but significant burst of malicious activity against exposed VoIP infrastructure.
VoIP fraud exploits telephone systems to make unauthorized calls, often routing through compromised systems to premium rate numbers for financial gain. This activity poses direct financial risk to organizations with inadequately secured phone infrastructure, potentially generating substantial unauthorized charges in a short timeframe. The high activity frequency of 8/10 indicates persistent automated probing rather than casual reconnaissance, meaning the operator behind this address is systematically hunting for vulnerable VoIP deployments.
Site operators should immediately audit VoIP systems for weak or default credentials and enforce strong multi-factor authentication across all telephony access points. Implementing call pattern monitoring and alerting can detect anomalies indicative of compromise, while restricting international and premium-rate dialing limits the financial impact of any successful exploitation. Deploying rate-limiting tools such as fail2ban on authentication interfaces and blocking known scanning infrastructure at the network perimeter provides additional layers of defence against this persistent threat actor.