High Risk
IP 31.70.78.222 is a high-risk address originating from Germany that has been flagged 373 times for VoIP fraud activity, representing a significant threat to unprotected voice-over-internet protocol infrastructure. With a threat level of 8 out of 10 and a confidence score of 91 percent, automated honeypot sensors have consistently detected abusive behavior originating from this IONOS SE-hosted endpoint during May 2026, indicating persistent rather than opportunistic malicious intent.
The abuse pattern centers on VoIP fraud, a threat category that exploits internet telephony systems to make unauthorized calls, frequently directed toward premium-rate numbers for financial profit. All 20 of the most recent reports attribute this specific activity to the address, and the elevated activity frequency rating of 8 out of 10 suggests the host is actively scanning for or directly targeting vulnerable SIP (Session Initiation Protocol) endpoints. The concentration of detection sources within automated honeypot environments confirms that this is not isolated scanning but sustained engagement with telephony attack surfaces.
For organizations operating VoIP systems, exposure to this IP creates a concrete risk of toll fraud, unexpected charges from premium-rate call routing, and resource exhaustion as attacker-controlled sessions consume bandwidth and trunk capacity. The German network origin and hosting on AS8560 (IONOS SE) does not indicate state-sponsored activity but rather suggests the infrastructure may be compromised or a residential proxy being leveraged to obfuscate fraud operations.
Defensive measures should include immediate blocking of this address at the network perimeter firewall and VoIP application layer. Implementing fail2ban or similar dynamic blockade tools to automatically ban repeated SIP registration attempts provides automated protection against credential guessing and scanning. Organizations should enforce strong SIP authentication, disable unused extensions, monitor call detail records for anomalous patterns such as high-volume calls to unknown international numbers, and consider geographic or carrier-based call restrictions to limit exposure to premium-rate destinations.