Significant Threat
IP address 87.106.105.253 is a high-risk German address with a threat level of 8/10 that has been linked to 245 abuse reports, predominantly VoIP fraud activity detected through automated honeypot sensors. With an activity frequency rated 8/10 and a confidence score of 91%, this IP presents a concrete and ongoing risk to telecommunications infrastructure.
The aggregate data shows sustained malicious behavior concentrated in May 2026, with all 20 most recent reports attributing the activity to VoIP fraud. The IP is registered to IONOS SE (ASN AS8560), a major German hosting provider, which means the address belongs to a commercial server environment rather than a residential connection. This hosting context is significant because compromised servers or abuse-friendly infrastructure within such networks frequently serve as launch points for telephony abuse. The consistent volume of reports over a compressed timeframe indicates deliberate, automated targeting rather than incidental scanning.
VoIP fraud represents a financial threat vector that exploits phone systems to place unauthorized calls, often to premium-rate or international numbers, generating revenue for attackers at the victim's expense. For organizations operating SIP-based systems, session border controllers, or any VoIP-enabled services exposed to this IP, the concrete risk includes unauthorized call routing, service degradation from resource exhaustion, and substantial telecommunications charges. The high activity frequency suggests the IP is part of an active campaign rather than opportunistic probing.
Site operators should block this IP at the network perimeter and implement geo-based or prefix-based restrictions on VoIP signaling and media ports. Deploying call authentication mechanisms such as STIR/SHAKEN and establishing strict dial-plan controls that prohibit premium-rate and international routing without explicit authorization will reduce exposure. Continuous monitoring of call detail records for anomalies and rate-limiting failed SIP authentication attempts using tools like fail2ban provide additional defensive layers against similar threats.