Substantial Risk
IP 193.104.222.2 is a moderate-to-high-risk address associated with VoIP fraud activity, with 177 abuse reports submitted through automated honeypot sensors between March and May 2026. The IP has been flagged with a threat level of 7/10 and a confidence score of 87%, indicating a reliable correlation between the observed behavior and the reported threat category.
The IP is geolocated to Great Britain and operates within AS42201, administered by PVDataNet AB. Across the two-month reporting window, automated honeypot sensors submitted 20 reports specifically categorizing the activity as Fraud VoIP, representing the dominant threat type among all submissions. The activity frequency has been assessed at 4/10, suggesting persistent but not hyperactive engagement. With 177 total reports and 20 dedicated VoIP fraud reports, this address demonstrates a consistent pattern of abuse that warrants attention from network defenders.
VoIP fraud exploits voice-over-internet-protocol systems to make unauthorized calls, typically to premium-rate numbers or international destinations, generating illicit revenue for threat actors. The concrete risk to an exposed VoIP service includes financial losses from fraudulent call charges, resource consumption by unauthorized traffic, and potential reputational damage if the compromised system is used to relay calls for illegal operations. Organizations with exposed SIP ports, weak authentication on VoIP infrastructure, or unrestricted international/premium dialing routes are particularly vulnerable to this type of exploitation.
Site operators should take immediate defensive action. Implementing strong authentication mechanisms such as SIP ALG-aware credentials, TLS encryption, and IP allowlisting significantly reduces unauthorized access. Configuring fail2ban or similar intrusion-prevention tools to monitor and block repeated authentication failures can disrupt automated attack workflows. Restricting international and premium-rate dialing capabilities, enabling call pattern monitoring for anomalies, and deploying session-border controllers to validate call authorization represent additional layers of protection against this threat vector.