Significant Threat
31.70.86.142 is a high-risk IP address registered in Germany and operated by IONOS SE that presents a concrete threat to VoIP infrastructure, accumulating 1308 total abuse reports with a dominant pattern of VoIP fraud activity across automated honeypot detection systems over a three-month observation window.
The address, spanning the AS8560 autonomous system operated by the major European hosting provider IONOS SE, was first flagged in May 2026 and remained active through July 2026, generating reports at an elevated frequency rated 8 out of 10. Of the recent report batch, 20 instances specifically identified fraudulent VoIP activity as the threat category, placing this vector as the dominant concern. All 20 contributing sources were automated honeypot sensors distributed across the threat intelligence network, yielding a 91 percent confidence score in the assessment. The volume of reports relative to the relatively short activity window indicates sustained, deliberate engagement rather than opportunistic scanning.
VoIP fraud exploits phone systems to route unauthorized calls, typically to premium-rate or international numbers, generating illicit revenue for threat actors at the expense of the compromised system's owner. For organizations running exposed Session Initiation Protocol services, unauthorized access can result in significant financial losses through inflated telephony bills and potential regulatory complications. The sustained reporting pattern observed from 31.70.86.142 suggests an active attempt to compromise or abuse VoIP resources rather than incidental reconnaissance activity.
Site operators should immediately block or restrict access from this address at the network perimeter and implement call authentication protocols such as STIR/SHAKEN on VoIP endpoints. Organizations running exposed phone systems should monitor call detail records for anomalies, particularly premium-rate or international dialing patterns, and enforce strict rate limiting on outbound call initiation. Deploying adaptive authentication and reviewing access logs for repeated authentication failures will further reduce exposure to this threat vector.