Significant Threat
IP 31.70.86.142 is a high-risk address operated by IONOS SE (AS8560) in Germany that has generated 1,545 abuse reports with a dominant threat pattern centred on VoIP fraud, representing a persistent and active threat to telecommunications infrastructure worldwide. With a threat level of 7/10 and an activity frequency rated 8/10, this IP has demonstrated consistent malicious behaviour across automated honeypot sensors from its first appearance in May 2026 through August 2026. The 91% confidence score indicates a highly reliable assessment that the observed activity matches known fraud signatures rather than anomalous legitimate traffic. The concentration of recent reports specifically targeting VoIP systems underscores this IP's established role in an abuse ecosystem focused on exploiting phone infrastructure for financial gain.
The volume of reports—1,545 total over approximately four months—reflects sustained, high-frequency malicious activity rather than isolated scanning or opportunistic probing. All 20 of the most recent reports attribute the threat exclusively to VoIP fraud, suggesting the IP has been repurposed or specialised within this attack category. The detection network comprising automated honeypot sensors has consistently flagged this address across multiple monitoring points, and the absence of diversification into other threat types indicates a focused, financially motivated operation. Geographically anchored to Germany through IONOS SE's infrastructure, this address may be operating through compromised endpoints, residential broadband used as a proxy, or directly provisioned resources facilitating fraudulent call routing.
VoIP fraud exploits telephone systems to route unauthorised calls—typically to premium-rate or international numbers—generating illicit revenue for attackers while accumulating substantial costs for targeted organisations. For any entity operating SIP-based telephony, an IP with this profile poses a concrete risk of being used as a call origination point, a relay for fraudulent traffic, or a scanning platform seeking vulnerable VoIP endpoints. The pattern observed here suggests the address is actively engaged in enumerating or abusing SIP credentials, registering with malicious proxies, or generating high-volume call attempts designed to bypass detection thresholds. This is not theoretical: organisations with exposed VoIP infrastructure receiving connections from such addresses face immediate financial exposure through fraudulent toll fraud, regulatory scrutiny, and service degradation.