Substantial Risk
IP 31.70.66.9 is a high-risk address operated through IONOS SE (AS8560) in Germany that has been repeatedly flagged for VoIP fraud activity, accumulating 1,802 abuse reports from automated honeypot sensors between May and July 2026 with a confidence score of 91 percent. The volume of reports and sustained activity frequency of 8 out of 10 indicate persistent, deliberate targeting of voice-over-internet-protocol infrastructure rather than opportunistic scanning. The IP's placement within a commercial hosting environment operated by a major European ISP suggests the compromised or abuser-controlled device is likely a customer-hosted endpoint being leveraged for fraudulent calling operations. The geographic origin in Germany does not imply legitimate use — threat actors routinely deploy infrastructure across borders to obscure attribution and exploit jurisdictional complexity. With an 8 out of 10 threat rating and near-perfect confidence, the evidence strongly supports blocking or heavily restricting traffic from this address on any exposed telephony-facing system. Organizations running VoIP services should treat any inbound connection from 31.70.66.9 as a known threat vector and implement immediate mitigations to prevent financial losses associated with unauthorized premium-rate calling. Call authentication protocols such as STIR/SHAKEN should be enforced to verify caller legitimacy, and call-detail record monitoring should flag any unusual patterns such as rapid dialing sequences, after-hours activity or calls to premium and international numbers. Restricting premium-rate and international dialing on untrusted extensions significantly reduces the attack surface for financial exploitation. Deploying adaptive rate limiting and anomaly detection on SIP ports — potentially leveraging tools such as fail2ban or equivalent intrusion-prevention systems — can automatically block repeated fraudulent attempts in real time. Regular auditing of dial-plan configurations and access controls ensures that even if an initial compromise occurs, the blast radius remains limited. Continuous monitoring of abuse feeds and maintaining updated blocklists derived from community-driven threat intelligence remain essential practices for defending telephony infrastructure against evolving VoIP fraud campaigns.