Loading...

209.18.47.61 is in , United States

209.18.47.61 is known for DDOS, DNS cache poisoning, firewall alert, fraud, hacking, HTTP fraud, phishing, port scanning, reverse TCP desynchronization, SMTP fraud, sync flood.

The report has been created on Jun 26, 2017 17:29:35
The IP address 209.18.47.61 belongs to Road Runner ISP in (, ), United States (38 and -97). The hostname is dns-cac-lb-01.rr.com.
United States (United States of America, USA) is a High income: OECD country in North America. The currency is U.S. dollar.
As of Jun 26, 2017 17:29:35 we have 32 complaint(s) about 209.18.47.61. Based on our records, the 209.18.47.61 has been involved in DDOS, DNS cache poisoning, firewall alert, fraud, hacking, HTTP fraud, phishing, port scanning, reverse TCP desynchronization, SMTP fraud, sync flood, etc.

209.18.47.61

IP Address Country:  United States (US)
IP Address Region:
IP Address City:
IP Postal Code
IP Address Area Code0
IP Metro Code0
IP Address Latitude:38
IP Address Longitude:-97
IP Address ISP: Road Runner
Organisation:
IP Address Proxy:
IP Address Host:dns-cac-lb-01.rr.com
Map is loading...

If 209.18.47.61 is causing you trouble (doing SPAM, brute-force, DOS attack, phishing, or other fraud), you can report the abuser right here!



We have 32 complaints about 209.18.47.61


Anonymous user from 70.95.129.253 in United States
1 days  agoi think its someone in oregon or michigan - in Hacking
"if anyone can add to this . does there name start with matthew?
i am consstantly being attacked iteven shows my email was intruded on a certain date that exact date is when my computer was being keyworded and being desktop capture for months"

Anonymous user from 76.90.189.155 in United States
11 days  agoip address is fraudulant - in Fraud
"The hacker jacked my dvr,modem,phone line bundle with TWCable & past month my geolocation is being shown as being at address 319 S Belle Ave., Corona, CA. which I am not at. They have accessed all my accounts and remotely listening too so my security tool"
22 days  agoDNS 209.18.47.61 - in Hacking
"Has complete access over my router's homepage. I am constantly booted from the internet, firewall options are changed, etc. F@#k the @55Wholes"
>1 month agoDoS service attack and tcp-udp port scan from this ip address - in DDOS
"over the last 2 days I have had several attack from the ip address 209.18.47.61:53 my firewall logs the attack as a DoS attack and port scan of my router/modem. What can I do to get this stopped or have the person that is causing this arrested?"

Anonymous user from 173.88.16.3 in United States
>7 months agoPlease help - in SMTP Fraud
"This up has ruined 3 iPhones since April 2016. Please I'm tired of being stalked, take this website down. Why would timewarner allow this??"

Anonymous user from 74.76.197.221 in United States
>11 months agoET TROJAN DNS Reply Sinkhole - Anubis - 195.22.26.192/26 - in DNS Cache Poisoning
"209.18.47.61:53 kept trying to send me ET TROJAN DNS Reply Sinkhole - Anubis - 195.22.26.192/26. After this I had to change DNS's just to be able to get abck on the Internet. I temporarily used the 8.8.8.8.and 4.4.4.4 . "
>1 year agoTime Warner Cable Snooping on its Customers - in Port Scanning
"Everytime I get online. i notice dns-cac-lb-01.rr.com scanning my ports, slowing down data speeds, Slowing down my broadband and worst of all trying to access personal files on my pc. "
>1 year agoTWC - in Hacking
"TWC is snooping on my pc & slowing down data speeds!?????????


"
>1 year agoDNS Cache Poisoning - in DNS Cache Poisoning
"Think this guy(s) work through twitter. Noticed by DNS was being routed through this IP and 209.18.47.62, so it is the same group of people that are doing this. "
>1 year agoCreate sync flood alert - in Sync Flood
"It sent to my router report, slow down internet web site loading. Yet it kept its mormal speed when did the speed test"

Anonymous user from 45.48.177.20 in United States
>1 year agoin my router logs - in DDOS
"when i am not home it looks as if this address tried to access our info with out us there, or use us as a gateway some how"

Anonymous user from 74.137.139.69 in United States
>2 years agohelp - in Fraud
"how come it says my primary dns is this number, I don't know nothing about computers and cant get off this server. and I haven't had anything changed since a time warner guy come out and changed the modem and stuff"

Anonymous user from 174.108.30.16 in United States
>2 years agoddoser - in DDOS
"TCP- or UDP-based Port Scan over 1000 times in 1 day . if you see this guys ip address be warned he is using your computer to ddos people."

Anonymous user from 174.96.103.87 in United States
>2 years agoTCP- or UDP-based Port Scan - in DNS Cache Poisoning
"Probes a couple ports on PC over 6000 times. Often I get booted offline. Apparently its my own internet company doing this (Time Warner)"

Anonymous user from 66.87.64.213 in United States
>3 years agoI dnt know what's going on - in DNS Cache Poisoning
"Any help something wrong with my internet why is showing that my DNS has spam hacking I don't what's going on I need to find out
"

Anonymous user from 66.57.183.24 in United States
>3 years agoHacker - in Phishing
"The firewall has blocked internet access to 209.18.47.61 (DNS) from your computer. This has been going on for a month. The first time and several more it was inbound. Now it is outbound. Full Header
[Querying whois.arin.net]
[Redirected to ipmt.rr.com:4321]
[Querying ipmt.rr.com]
[ipmt.rr.com]
%rwhois V-1.5:0020b0:00 ipmt.rr.com (by Time Warner Cable, Inc. V-1.0)
network:Class-Name:network
network:ID:NETBLK-ISRR-209.18.32.0-20
network:Auth-Area:209.18.32.0/20
network:Org-Name:Road Runner
network:Tech-Contact:ipaddreg@rr.com
network:Updated:2013-07-23 10:44:10
network:IP-Network:209.18.32.0/20
network:Admin-Contact:IPADD-ARIN
network:IP-Network-Range:209.18.32.0 - 209.18.47.255

organization:Class-Name:organization
organization:ID:NETBLK-ISRR-209.18.32.0-20
organization:Auth-Area:209.18.32.0/20
organization:Org-Name:Road Runner
organization:Tech-Contact:ipaddreg@rr.com
organization:Street-Address:13820 Sunrise Valley Drive
organization:City:Herndon
organization:State:VA
organization:Postal-Code:20171
organization:Country-Code:US
organization:Phone:703-345-3151
organization:Updated:2013-07-23 10:44:10
organization:Created:2013-07-23 10:44:10
organization:Admin-Contact:IPADD-ARIN
"

Anonymous user from 72.51.203.173 in United States
>4 years agoSteelHead::SteelHead - in DDOS
"Pittsburg Steelers Fan obviously.

DDOS against Amazon EC2 -> Strutta.com
(SYN Flood 6 Thu Nov 08 15:34:47 2012 50.16.226.190:80 : site down)

LAN-side UDP Flood 7 Thu Nov 08 15:51:17 2012 239.255.255.250:1900
...
and so on... "

Anonymous user from 68.95.255.15 in United States
>4 years agohacking me? - in DNS Cache Poisoning
"Firewall ESET detected DNS cache poisoning attack from this ip address. please help! i dont want to get hacked. and put this person behind bars.209.18.47.61"

Anonymous user from 107.10.39.164 in United States
>4 years ago
"209.18.47.61 is the default Time Warner neowpa DNS server.

this is not what is causing your problem but it could be someone asking as that DNS server"

Anonymous user from 68.95.255.15 in United States
>4 years agohacking me? - in DNS Cache Poisoning
"Firewall ESET detected DNS cache poisoning attack from this ip address. please help! i dont want to get hacked. and put this person behind bars."

Anonymous user from 74.67.182.72 in United States
>4 years agotried hacking my system - in Firewall Alert
"No.001 Nov 5 05:05:49 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.002 Nov 5 05:05:49 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.003 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.004 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.005 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.006 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.007 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.008 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.009 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.010 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.011 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.012 Nov 5 05:05:50 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.61 --> 74.67.182.72
No.013 Nov 5 05:05:51 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.014 Nov 5 05:05:51 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.015 Nov 5 05:05:51 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.016 Nov 5 05:05:51 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.017 Nov 5 05:05:51 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.018 Nov 5 05:05:51 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.019 Nov 5 05:05:52 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
No.020 Nov 5 05:05:52 - [Firewall Log-PORT SCAN] UDP Packet - 209.18.47.62 --> 74.67.182.72
"

Anonymous user from 74.64.81.133 in United States
>4 years agoThis IP keeps trying to connect to my machine - in Port Scanning
"This IP keeps trying stealth connection attempts to my machine. Hundreds of times, trying many different ports

This is illegal activity and needs to be stopped. This has been going on for weeks. "

Anonymous user from 209.18.47.61 in United States
>4 years ago
"maybe someone with the knowhow should identify these people at TWC (personally) and report them to authorities."
>4 years agoport scan detected - in Hacking
"When on e-mail, the security every 20-30 sec. blocks a port scan. IP addresss 209.18.47.61
Port Allegany, PA
IP postal code 16743
IP address ISP: Road Runner
Organization: Road Runner
IP address host: dns-cac-lb-01.rr.com"
>4 years agoport scan - in Hacking
"When logged on to e-mail, every minute my security system blocks port scan detected, listing isp remote 209.18.47.61. How do I get this stopped?"

Anonymous user from 24.94.233.7 in United States
>4 years agodetected by ESET - in DNS Cache Poisoning
"Firewall ESET detected DNS cache poisoning attack... Firewall ESET detected DNS cache poisoning attack...Firewall ESET detected DNS cache poisoning attack...Firewall ESET detected DNS cache poisoning attack...Firewall ESET detected DNS cache poisoning attack..."
>5 years agoDNS Cache Poisoning - in DNS Cache Poisoning
"DNS Cache Poisoning attack from 209.18.47.61 reported by Eset NOD32.
Rather pointless to have a minimum word counts for a simple report, would you not agree?"

Anonymous user from 75.81.192.220 in United States
>5 years agodns problems - in Reverse TCP Desynchronization
"dns causing multiple problems. reverse dns searches don't work, dns cache poisoning, etc..... Much slower internet browsing. dns servers are issued by time warner cable"

Anonymous user from 76.188.1.208 in United States
>5 years agoPort scans followed by syn-flood attacks - in Port Scanning
"This person port scans my pc all day and all night and when ever I open a browser syn-floods my pc and uses all the stack space till my pc or browser become non responsive crashes. the syn flood packets always come from diffrent ip addresses cause he is editing the packets time/date and using a proxy to cover the fact its him. (currently working on echo request denial and just blocked proxy address connections we will see)

"

Anonymous user from 72.178.215.33 in United States
>5 years agotried to connect - in Firewall Alert
"just adding to the report on this ip. my zone alarm keeps hitting on it once in a while jn;awioghgh3oighhjpjfpijgjgjdjg[jagj9ugoptjgpug9rugjrpo"
>5 years agoPort Scanning - in Port Scanning
"This IP has been running a continuous port scan on my current IP for days now. I presume this is not standard protocol for any legitimate services."

Anonymous user from 76.169.17.59 in United States
>5 years agoDNS Cache Poisoning - in DNS Cache Poisoning
"My firewall / antivirus reported a DNS Cache Poisoning attack from 209.18.47.61 That's pretty much it. I don't know why does a complain need to have at least 20 words."

Anonymous user from 71.66.106.44 in United States
>5 years agomy computer - in Hacking
"does not respond, please stop hacking into my computer. all windows are at a stand still for quiet a long time, also the computer is fighting off virus. this is a problem and i don't have the money to fix this. i use my computer for school and this is a problem."
>5 years agoFake DNS - in HTTP Fraud
"This is a fake DNS provided by Time Warner Cable on new Road Runner accounts. All traffic gets redirected to https://registration.rr.com/welcome

TWC want you to agree to a 12 page EULA as well as a Privacy Waiver.

The workaround is to change the dns setting at the router to use opendns 208.67.222.222 or 208.67.220.220"

WHOIS for 209.18.47.61

[Querying whois.arin.net]
[whois.arin.net]
#
# Query terms are ambiguous. The query is assumed to be:
# "n 209.18.47.61"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=209.18.47.61?showDetails=true&showARIN=true
#

Road Runner HoldCo LLC COUDERSPORTBB-1 (NET-209-18-32-0-1) 209.18.32.0 - 209.18.47.255
American Registry for Internet Numbers NET209 (NET-209-0-0-0-0) 209.0.0.0 - 209.255.255.255


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Abusing IP Addresses from the same C block

IP AddressAbuseComplaints
209.18.47.62DDOS:DNS cache poisoning:hacking:port scanning:5 complaints

Other DDOS, DNS Cache Poisoning, Firewall Alert, Fraud, Hacking, HTTP Fraud, Phishing, Port Scanning, Reverse TCP Desynchronization, SMTP Fraud, Sync Flood Complaints

4 hr 11 min  ago United States138.68.101.87"email received with your ip"
1 days  ago United States209.18.47.61"i think its someone in oregon or michigan"
1 days  ago United States209.18.47.62"i think it may be someone from oregon"
8 days  ago United States68.105.51.178"Overflowing webserver Ram/CPU until complete shut down."
11 days  ago United States64.94.1.137"Receiving multiple firewall alerts"
11 days  ago United States209.18.47.61"ip address is fraudulant"
17 days  ago Finland88.114.45.66"LOAN OFFER"
17 days  ago China182.100.67.252"Constant attack against public facing IPs"
22 days  ago United States209.18.47.61"DNS 209.18.47.61"
23 days  ago China183.131.83.53"Netgear Modem reports a port scan by this IP"