115.89.24.180 is from Korea, Republic of

An Internet Protocol address (IP address 115.89.24.180) is a numerical label that is allocated to a computer (can be any electronic device) which is part of a network (LG DACOM Corporation) that utilises the Internet Protocol. Every IP address does the following: (1) location addressing and (2) host or network interface identification.


e.g. 209.62.45.34 IPv4/IPv6 format for an IP Address, or maxmind.com for a website

Compare to another IP
IP Address:115.89.24.180
IP Address Country:  Korea, Republic of (KR)
IP Address Region:11 Seoul-t'ukpyolsi
IP Address City:Seoul
IP Postal Code
IP Address Area Code0
IP Metro Code0
IP Address Latitude:37.5663986206
IP Address Longitude:126.999702454
IP Address ISP: LG DACOM Corporation
Organisation: LG DACOM Corporation
IP Address Proxy:
IP Address Host:115.89.24.180
Map is loading...

We have 17 complaints about 115.89.24.180

Is 115.89.24.180 misbehaving (engaging in SPAM, brute-force, DOS attack, phishing, or other fraud? Report the abuser now!

"Previous Post Mistake" - filed under Firewall Alert
>2 months ago
My Immediately preceding post is meant for another IP, Sorry bout that! No current problems with 115.89.24.180 Thanks! And in closing I'd just like to say it's a jungle out there!
"Gang of Thieves" - filed under Firewall Alert
>2 months ago
Security alert type : IP Subnet Broadcast Amplification
IP source address : 218.18.232.218
IP destination address : 76.227.65.191
Number of attempts : 3
Time at last attempt : 2/27/12 03:26:20 AM
IP broadcast address : 76.227.65.191

This Prick is working with 211.195.199.49
I'm issuing SYN Floods on 115.89.24.180 - filed under Firewall Alert
>2 years ago
HPING 115.89.24.180 (eth1 115.89.24.180): S set, 40 headers + 0 data bytes
len=46 ip=115.89.24.180 ttl=111 DF id=31286 sport=443 flags=SA seq=0 win=16616 rtt=295.5 ms
DUP! len=46 ip=115.89.24.180 ttl=255 DF id=59866 sport=443 flags=RA seq=0 win=0 rtt=16136.7 ms my email is $clintburford@gmail.com$ I have also submitted data to US-CERT but they are not doing anything about this matter. If anyone wants to team up on designing a firewall I'm working on. Please get a hold of me. I also might be purchasing a sonicwall, watchguard, or a prosafe.
IP Subnet Broadcast Amplification - filed under Firewall Alert
>2 years ago
Security alert type
IP Subnet Broadcast Amplification
IP source address 115.89.24.180

Number of attempts 61
Time at last attempt 3/21/10 12:48:06 AM
trying to attack through firewall - filed under Port Scanning
>2 years ago
=>Found attack from 115.89.24.180.
Source port is 12200 and destination port is 3246 which use the TCP protocol.
=>Found attack from 115.89.24.180.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
attacks frequesnt = every few mionutes
115.89.24.180 - filed under Port Scanning
>2 years ago
115.89.24.180
port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180 - filed under Firewall Alert
>2 years ago
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180
port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180 - filed under Firewall Alert
>2 years ago
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180
port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180 - filed under Firewall Alert
>2 years ago
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180
port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180 - filed under Firewall Alert
>2 years ago
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180
port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180 - filed under Firewall Alert
>2 years ago
Firewall log report: port 3246 & 8085 Blocked incoming TCP connection request from 115.89.24.180
scanner - filed under Port Scanning
>2 years ago
Found attack from 115.89.24.180.
Source port is 12200 and destination port is 8085 which use the TCP protocol.
atemp phising - filed under Phishing
>2 years ago
http://114-141-193-121.dedsvrs.net/signin.fr/index.html.html
34 Times - filed under Brute Force
>2 years ago
amplitude
scans every 10-15 seconds - filed under Firewall Alert
>2 years ago
port 3246 & 8085
Blocked incoming TCP connection request from 115.89.24.180:12200
Asian MONKEY MONKEY MONKEY MONKEY - filed under Port Scanning
>2 years ago
Firewall log:
Sun Mar 7 21:53:16 2010 =>Found attack from 115.89.24.180. Source port is 12200 and destination port is 3246 which use the TCP protocol.
Asian MONKEY MONKEY MONKEY MONKEY - filed under Port Scanning
>2 years ago
Firewall log:
Sat Mar 6 23:05:23 2010 =>Found attack from 115.89.24.180. Source port is 12200 and destination port is 8085 which use the TCP protocol. Sat Mar 6 23:05:23 2010 =>Found attack from 115.89.24.180. Source port is 12200 and destination port is 3246 which use the TCP protocol.
View WHOIS information for 115.89.24.180
[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[Redirected to whois.nic.or.kr]
[Querying whois.nic.or.kr]
[whois.nic.or.kr]
query: 115.89.24.180

# KOREAN

Á¶È¸ÇϽŠIPv4ÁÖ¼Ò´Â Çѱ¹ÀÎÅͳÝÁøÈï¿øÀ¸·ÎºÎÅÍ ¾Æ·¡ÀÇ °ü¸®´ëÇàÀÚ¿¡°Ô ÇÒ´çµÇ¾úÀ¸¸ç, ÇÒ´ç Á¤º¸´Â ´ÙÀ½°ú °°½À´Ï´Ù.

[ ³×Æ®¿öÅ© ÇÒ´ç Á¤º¸ ]
IPv4ÁÖ¼Ò : 115.88.0.0 - 115.95.255.255 (/13)
¼­ºñ½º¸í : BORANET
±â°ü¸í : (ÁÖ)¿¤ÁöÀ¯Ç÷¯½º
±â°ü°íÀ¯¹øÈ£ : ORG572
ÁÖ¼Ò : ¼­¿ï °­³²±¸ ¿ª»ïµ¿ 706-1
¿ìÆí¹øÈ£ : 135-080
ÇÒ´çÀÏÀÚ : 20080725

[ IPv4ÁÖ¼Ò Ã¥ÀÓÀÚ Á¤º¸ ]
À̸§ : IPÁÖ¼Ò°ü¸®ÀÚ
ÀüÈ­¹øÈ£ : +82-2-2089-7755
ÀüÀÚ¿ìÆí : ipadm@lguplus.co.kr

[ IPv4ÁÖ¼Ò ´ã´çÀÚ Á¤º¸ ]
À̸§ : IPÁÖ¼Ò°ü¸®ÀÚ
ÀüÈ­¹øÈ£ : +82-2-2089-7755
ÀüÀÚ¿ìÆí : ipadm@lguplus.co.kr

[ ½ºÆÔ ÇØÅ· ´ã´çÀÚ Á¤º¸ ]
À̸§ : Network Abuse ´ã´çÀÚ
ÀüÈ­¹øÈ£ : +82-2-2089-0101
ÀüÀÚ¿ìÆí : security@bora.net

--------------------------------------------------------------------------------

Á¶È¸ÇϽŠIPv4ÁÖ¼Ò´Â À§ÀÇ °ü¸®´ëÇàÀڷκÎÅÍ ¾Æ·¡ÀÇ »ç¿ëÀÚ¿¡°Ô ÇÒ´çµÇ¾úÀ¸¸ç, ÇÒ´ç Á¤º¸´Â ´ÙÀ½°ú °°½À´Ï´Ù.

[ ³×Æ®¿öÅ© ÇÒ´ç Á¤º¸ ]
IPv4ÁÖ¼Ò : 115.89.16.0 - 115.89.31.255 (/20)
³×Æ®¿öÅ© À̸§ : BORANET-INFRA
±â°ü¸í : (ÁÖ)¿¤ÁöÀ¯Ç÷¯½º
±â°ü°íÀ¯¹øÈ£ : ORG572
ÁÖ¼Ò : ¼­¿ï °­³²±¸ ¿ª»ïµ¿ 706-1
¿ìÆí¹øÈ£ : 135-080
ÇÒ´ç³»¿ª µî·ÏÀÏ : 20110207
°ø°³¿©ºÎ : Y

[ ³×Æ®¿öÅ© ´ã´çÀÚ Á¤º¸ ]
À̸§ : IPÁÖ¼Ò°ü¸®ÀÚ
±â°ü¸í : (ÁÖ)¿¤ÁöÀ¯Ç÷¯½º
ÁÖ¼Ò : ¼­¿ï °­³²±¸ ¿ª»ïµ¿ 706-1
¿ìÆí¹øÈ£ : 135-080
ÀüÈ­¹øÈ£ : +82-2-2089-7755
ÀüÀÚ¿ìÆí : ipadm@lguplus.co.kr


# ENGLISH

KRNIC is not an ISP but a National Internet Registry similar to APNIC.

[ Network Information ]
IPv4 Address : 115.88.0.0 - 115.95.255.255 (/13)
Service Name : BORANET
Organization Name : LG DACOM Corporation
Organization ID : ORG572
Address : 706-1, Seoul Gangnam-gu Yeoksam-dong
Zip Code : 135-080
Registration Date : 20080725

[ Admin Contact Information ]
Name : IP Administrator
Phone : +82-2-2089-7755
E-Mail : ipadm@lguplus.co.kr

[ Tech Contact Information ]
Name : IP ADMIN
Phone : +82-2-2089-7755
E-Mail : ipadm@lguplus.co.kr

[ Network Abuse Contact Information ]
Name : Network Abuse
Phone : +82-2-2089-0101
E-Mail : security@bora.net

--------------------------------------------------------------------------------

More specific assignment information is as follows.

[ Network Information ]
IPv4 Address : 115.89.16.0 - 115.89.31.255 (/20)
Network Name : BORANET-INFRA
Organization Name : LG DACOM Corporation
Organization ID : ORG572
Address : 706-1, Seoul Gangnam-gu Yeoksam-dong
Zip Code : 135-080
Registration Date : 20110207
Publishes : Y

[ Technical Contact Information ]
Name : IP ADMIN
Organization Name : LG DACOM Corporation
Address : 706-1, Seoul Gangnam-gu Yeoksam-dong
Zip Code : 135-080
Phone : +82-2-2089-7755
E-Mail : ipadm@lguplus.co.kr


- KISA/KRNIC Whois Service -

15 Latest Attacks
89.108.127.160 - Site is a scam - filed under Fraud
one of the sites through this host, everingame.com has defrauded hundreds of users. http://www.scamb...
1 hr 39 min  ago
114.36.160.94 - mindless stuff - filed under Spam
Hacking attemps, spaming. He has inserted himeslf into our medical servicesrecipients. It has been r...
2 hr 1 min  ago
205.186.130.61 - email hijacking - filed under Hacking
This person has been logging into my gmail account and sent out spam emails to my entire contact lis...
2 hr 2 min  ago
202.104.197.118 - Attempted login to FTP - filed under Brute Force
Brute force attempts to log into my server FTP with the username "administrator." A sim...
2 hr 31 min  ago
74.128.173.47 - Bet2day casino - filed under Spam
Same as the rest, spam mail every hour now on 3 of my emails. No way to unsubscribe and impossible t...
3 hr 28 min  ago
173.9.198.249 - website was hacked 2 days ago - filed under FTP Hacking
2 days ago from this ip several of our websites we're hacked by logging on to our ftp webhosting ac...
3 hr 40 min  ago
66.147.240.186 - This IP is trying to logon my website - filed under Brute Force
Website: http://www.iphonesp.com.br/ Page: /administrator/index.php Description: There was an unsu...
4 hr 10 min  ago
94.183.53.255 - Attacking Google account - filed under Hacking
Someone recently tried to sign in to your Google Account, XXXXX. We prevented the sign-in attempt in...
4 hr 44 min  ago
67.205.111.248 - 184.107.157.130 - filed under Hacking
this site keeps port scanning my IP addresses. i have him blocked but clearly theres a problem with...
5 hr 14 min  ago
72.21.194.32 - Risky connection blocked - filed under Malware
Looks to me like 72.21.194.32 is a server leased from Amazon's cloud services server farm by someon...
5 hr 47 min  ago
74.128.173.47 - unsubscribe bet2day from Ryan Hardy - filed under Spam
no way to unsubscribe to their unwanted mail about bet2day; looks to me a kind of spam or other non...
6 hr 22 min  ago
[00001] 2012-05-14 18:09:02 [Root]system-critical-00441: ICMP ping id=0! From 178.33.224.175 to 66.2...
6 hr 55 min  ago
Unsolicited spam from webmaster@arclip.ru -user17662 Received: from s6.cishost.ru ([92.38.199.150])...
7 hr 1 min  ago
77.78.228.62 - malware - filed under Malware
2012/05/16 20:18:16 +0300 DEOCAMDATARDS computer IP-BLOCK 77.78.228.62 (Type: incoming) 2012/05/16 2...
8 hr 2 min  ago
200.107.124.36 - spam - filed under Spam
Spam 200.107.124.36 "From rrenat31391@mail.ru Wed May 16 19:06:25 2012 DKIM-Signature: v=1; ...
8 hr 23 min  ago
More Attacks
221.192.199.36 - scanning, mostly port 12200 - filed under Port Scanning
Constantly appears all times of day or night, blocked by firewall. I, too, assume it's automated, ma...
>3 years ago
87.7.117.36 - trying all kinds of HTTP requests - filed under HTTP Fraud
trying all kinds of HTTP requests...
>1 year ago
61.139.105.163 - Port Scanning - filed under Port Scanning
The Chinese authorities should get there act together and stop these criminals....
>3 years ago
91.201.66.6 - casio watch - filed under SQL Injection
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEA...
>1 month ago
221.7.40.47 - Brute force the same as you - filed under FTP Hacking
Banned the IP and stopped for now. Really it is empty not like I care what is on there....
>2 years ago
60.217.229.226 - Attempting to log into FTP server - filed under FTP Hacking
60.217.229.226 is using a brute force attack to find out FTP password for non existent FTP user ADMI...
>2 years ago
fraud@antihotmail.om ----------------------------- http://www.asail.com/paypal.com.au/au/login.acco...
>3 months ago
along with other IP from around the globe...117.199.151.48-117.200.128.46-94.96.35.95-94.96.75.48...
>2 years ago
66.235.120.111 - Is in my router logs section - filed under DDOS
[DoS Attack: RST Scan] from source: 66.235.120.111, port 80, Monday, September 12,2011 09:51:55 this...
>8 months ago
217.207.81.133 - SSH Dictionary attack - filed under Brute Force
Probably another unwitting botnet dupe...
>2 years ago
220.165.28.67 - brute force on port 22 - filed under Brute Force
initially uses the fully qualified name of the attached machine, then moves on to use dictionary bas...
>1 year ago
Suspect this machine might be an unwitting participant in a botnet...
>2 years ago
212.204.48.78 - SSH Dictionary attack - filed under Brute Force
Repeated attempts to login with invented - bogus - credentials. Probably an unwitting participant in...
>2 years ago
218.6.15.138 - IPS Notices in the last 10 Days - filed under DDOS
AttackerNo IP Address Frequency 1 125.65.112.161 50 2 61.160.216.187 42 3 118.123.1...
>2 years ago
85.27.84.117 - WAGE DOS ATTACK - filed under DDOS
Hi there My name is David, I am a WAGE Head Administrator and would like to report a ongoing DDoS a...
>8 months ago
Probably an unwitting participant in a bot net - this type of attack is sometimes referred to as an ...
>2 years ago
117.22.229.187 - Network Attack Intrusion - filed under Hacking
9/17/2010 11:09:12 AM Network Attack Blocker Detected: Intrusion.Win.MSSQL.worm.Helkern Absent ...
>1 year ago
I never visited Brazil and my gmail was accessed from this IP. It sent a lot of spam messages to all...
>4 months ago
221.194.109.238 - SSH Dictionary attack - filed under Brute Force
Probably another unwitting botnet dupe...
>2 years ago
From - Fri Sep 16 09:04:08 2011 X-Account-Key: account11 X-UIDL: 22D51F98-DFEB-11E0-8CAC-001E0BCBB1E...
>8 months ago
Probably an unwitting participant in a Botnet, attempting an SSH dictionary attack...
>2 years ago
96.9.149.86 - attack - filed under SQL Injection
several attacks from this IP - Attention on 5 January 2012 there was an attempt to break my website ...
>4 months ago
60.161.78.155 - Network attack intrusion - filed under Hacking
4/28/2010 2:09:08 PM Detected: Intrusion.Win.MSSQL.worm.Helkern UDP from 60.161.78.155 to local ...
>2 years ago
64.31.89.48 - Report spam - filed under Spam
Hello, Below is a SPAM received by our system. It originated from your site, used an address referen...
>5 months ago
120.5.75.124 - Spam & possible phishing - filed under Spam
Email content: Every inch of your tool will be screaming about your manhood. Have a...
>3 years ago