222.161.2.46 is from China

An Internet Protocol address (IP address 222.161.2.46) is a numerical label that is allocated to a computer (can be any electronic device) which is part of a network (China Unicom Jilin province network) that utilises the Internet Protocol. Every IP address does the following: (1) location addressing and (2) host or network interface identification.


e.g. 209.62.45.34 IPv4/IPv6 format for an IP Address, or maxmind.com for a website

Compare to another IP
IP Address:222.161.2.46
IP Address Country:  China (CN)
IP Address Region:05 Jilin
IP Address City:Jilin
IP Postal Code
IP Address Area Code0
IP Metro Code0
IP Address Latitude:43.8507995605
IP Address Longitude:126.560302734
IP Address ISP: China Unicom Jilin province network
Organisation: China Unicom Jilin province network
IP Address Proxy:
IP Address Host:222.161.2.46
Map is loading...

We have 27 complaints about 222.161.2.46

Is 222.161.2.46 misbehaving (engaging in SPAM, brute-force, DOS attack, phishing, or other fraud? Report the abuser now!

Port Scanning - filed under Port Scanning
>2 years ago
Firewall Security Log Message:
Somebody is scanning your computer.
Your computer's TCP ports:
3128, 8089, 80, and 6588 have been scanned from 122.227.164.96
Hitting my IP multiple times an hour. - filed under Port Scanning
>2 years ago
Port scanning my IP.
coincidence - filed under Port Scanning
>2 years ago
must be.
http://www.globalsecurity.org/military/world/china/changchun.htm
TCP scanned port list, 9000, 808, 9415, 8090, 1080 - filed under Port Scanning
>2 years ago
1/19/2009 17:58:31.320
Alert Intrusion Prevention
Possible port scan detected
source: 122.227.164.96, 12200, X1 dest: 206.253.53.110, 8888, X1
TCP scanned port list, 9000, 808, 9415, 8090, 1080

TCP scanned port list, 8085, 6588, 808, 8090, 8888 - filed under Port Scanning
>2 years ago
11/18/2009 18:06:40.112
Alert Intrusion Prevention
Possible port scan detected
Source: 122.227.164.96, 12200, X1 Dest: 206.253.53.110, 8086, X1
TCP scanned port list, 8085, 6588, 808, 8090, 8888
Port scan blocked from 122.227.164.96 on my home mac - filed under Port Scanning
>2 years ago
Three days now I have been scanned from this IP all blocked. I reversed it and came up with a list of their open ports. Port Scanning host: 122.227.164.96

Open TCP Port: 1 tcpmux
Open TCP Port: 75
Open TCP Port: 80 http
Open TCP Port: 135 epmap
Open TCP Port: 139 netbios-ssn
Open TCP Port: 269
Open TCP Port: 351 matip-type-b
Open TCP Port: 435 mobilip-mn
Open TCP Port: 510 fcp
Open TCP Port: 604 tunnel
Open TCP Port: 679 mrm
Open TCP Port: 767 phonebook
Open TCP Port: 858
Open TCP Port: 940
Open TCP Port: 1025 blackjack
Open TCP Port: 1026 cap
Open TCP Port: 1192 caids-sensor
Open TCP Port: 1271 dabew
Open TCP Port: 1364 ndm-server
Open TCP Port: 1446 ora-lm
Open TCP Port: 1517 vpac
Open TCP Port: 1584 tn-tl-fd2
Open TCP Port: 1662 netview-aix-2
Open TCP Port: 1735 privatechat
Open TCP Port: 1831 myrtle
Open TCP Port: 1930 driveappserver
Open TCP Port: 2007 dectalk
Open TCP Port: 2085 ada-cip
Open TCP Port: 2158
Open TCP Port: 2244 nmsserver
Open TCP Port: 2323 3d-nfsd
Open TCP Port: 2395 lan900_remote
Open TCP Port: 2460 ms-theater
Open TCP Port: 2538 vnwk-prapi
Open TCP Port: 2609 system-monitor
Open TCP Port: 2701 sms-rcinfo
Open TCP Port: 2768 uacs
Open TCP Port: 2841 l3-ranger
Open TCP Port: 2986 stonefalls
Open TCP Port: 3062 ncacn-ip-tcp
Open TCP Port: 3225 fcip-port
Open TCP Port: 3316 aicc-cmi
Open TCP Port: 3389 ms-wbt-server
Open TCP Port: 3522 nssocketport
Open TCP Port: 3596 iw-mmogame
Open TCP Port: 3685 dsx-agent
Open TCP Port: 3837 mkm-discovery
Open TCP Port: 3925 zmp
Open TCP Port: 4010 samsung-unidex
Open TCP Port: 4084
Open TCP Port: 4166
Open TCP Port: 4226
Open TCP Port: 4306
proxy scanning? - filed under Directory Harvest
>2 years ago
This guy hits my web server a couple a times a day trying to retrieve the same URL \\\"/fastenv\\\" which appears to be some kind of tool used along side proxies. So my guess is he is scanning for proxies. However not sure why he needs to scan the same boxes 5 times a day. I just blocked his IP at my router.
Chinese Script Kiddie - filed under Brute Force
>2 years ago
Scans multiple times a day on all ports. My router is set to drop all packets from that IP now, so he doesn't see anything. Send abuse reports to anti_spam@mail.nbptt.zj.cn. If they get enough complaints, maybe they'll do something.
Port scanning while using a verizon modem... - filed under Port Scanning
>2 years ago
Tries to get into my linux system whenever I am using my USB 3G modem (Rather than my lan connection].
Chinks scanning my ports! - filed under Port Scanning
>2 years ago
How do you stop this behavior?
Port scan occuring frequently from this ip - filed under Port Scanning
>2 years ago
Is attempting to gain entry to my system. Firewall (praise be to the designers) is thankfuly keeping them(it) out. Why on earth can the network community be spared this flagrant disregard to one's privacy and enjoyment.
Port scan occuring frequently from this ip - filed under Port Scanning
>2 years ago
Is attempting to gain entry to my system. Firewall (praise be to the designers) is thankfuly keeping them(it) out. Why on earth can the network community be spared this flagrant disregard to one's privacy and enjoyment.
Port scan occuring frequently from this ip - filed under Port Scanning
>2 years ago
Is attempting to gain entry to my system. Firewall (praise be to the designers) is thankfuly keeping them(it) out. Why on earth can the network community be spared this flagrant disregard to one's privacy and enjoyment.
Portscanner/attempting to hack - filed under Port Scanning
>2 years ago
Scriptkiddie doing a portscan then trying to connect to every port avail.
122.227.164.96 port scan logged - filed under Port Scanning
>2 years ago
These attacks have been going on for days, but only while my computer is turned on. They only last a few seconds but are becoming a real pain. Who can stop this A**HOLE? Leave me alone and get a real life.
122.227.164.96 port scan logged - filed under Port Scanning
>2 years ago
These attacks have been going on for days, but only while my computer is turned on. They only last a few seconds but are becoming a real pain. Who can stop this A**HOLE? Leave me alone and get a real life.
Port scan by 122.227.164.96 reported - filed under Port Scanning
>2 years ago
My security system is reporting port scans to my home computer which last around ten seconds each occurrence. I am notified while performing various tasks, my work, which causes me to stop work and investigate the attack. Thus, I lose valuable time and resources due to these frequent attacks. This is now causing me to lose money and time. It is horrible to have this happen and I wish it would stop.
Port scan by 122.227.164.96 reported - filed under Port Scanning
>2 years ago
My security system is reporting port scans to my home computer which last around ten seconds each occurrence. I am notified while performing various tasks, my work, which causes me to stop work and investigate the attack. Thus, I lose valuable time and resources due to these frequent attacks. This is now causing me to lose money and time. It is horrible to have this happen and I wish it would stop.
MSTASK.EXE 122.227.164.96 12200 Inbound TCP 1025 LocalHost - filed under Firewall Alert
>2 years ago
OUTPOST FireWall on - Win2000 - SP1
Block activity for application MSTASK.EXE

MSTASK.EXE 122.227.164.96
remote port 12200
Inbound TCP
local port 1025 (LocalHost)
this computer 122.227.164.96 is a hacker - filed under Hacking
>2 years ago
he or she attacks constantly throughout the day
122.227.164.96 attempted portscan at least 5 times daily - filed under Firewall Alert
>2 years ago
Firewall is stopping these attempted portscans from this IP.
- filed under Port Scanning
>2 years ago
Attempt to hack ftp server - filed under FTP Hacking
>3 years ago
Keeps sending numerous log-in attepmts to access FTP services using an Administrator username.
Attempt to hack ftp server - filed under FTP Hacking
>3 years ago
Tried to hack our ftp server for several hours sending numerous logon attempts on the administrator account.
ries to get in my computer at least 15 times an hour. - filed under Fraud
>3 years ago
UDP packet from 222.161.2.46:54856 to :1027
hacking, phishing - filed under Hacking
>4 years ago
tries to get in my computer at least 15 times an hour.
Port Scan - filed under Port Scanning
>4 years ago
Description Packet sent from 222.161.2.46 (UDP Port 55901) to 98.193.135.183 UDP Port 1027) was blocked
Rating Medium
Date / Time 2008/02/29 17:52:30-6:00 GMT
Type Firewall
Protocol UDP
Program
Source IP 222.161.2.46:55901
Destination IP 98.193.135.183:1027
Direction Incoming
Action Taken Blocked
Count 1
Source DNS


View WHOIS information for 222.161.2.46
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net node-2]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

inetnum: 222.160.0.0 - 222.163.31.255
netname: UNICOM-JL
descr: China Unicom Jilin province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: WT92-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-JL
mnt-routes: MAINT-CNCGROUP-RR
changed: hm-changed@apnic.net 20031212
status: ALLOCATED PORTABLE
changed: hm-changed@apnic.net 20040301
changed: hm-changed@apnic.net 20060124
changed: hm-changed@apnic.net 20090508
source: APNIC

route: 222.160.0.0/14
descr: CNC Group CHINA169 Jilin Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060118
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@chinaunicom.cn
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: abuse@chinaunicom.cn 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: Wang Tiegang
nic-hdl: WT92-AP
e-mail: jhli_jl@mail.jl.cn
address: NO.3535,Renmin Street, ChangChun ,
address: Jilin province , 130021 , P.R. China
phone: +86-431-5560792
fax-no: +86-431-5560816
country: CN
changed: jhli_jl@mail.jl.cn 20060626
mnt-by: MAINT-CNCGROUP-JL
source: APNIC


15 Latest Attacks
89.108.127.160 - Site is a scam - filed under Fraud
one of the sites through this host, everingame.com has defrauded hundreds of users. http://www.scamb...
2 hr 1 min  ago
114.36.160.94 - mindless stuff - filed under Spam
Hacking attemps, spaming. He has inserted himeslf into our medical servicesrecipients. It has been r...
2 hr 23 min  ago
205.186.130.61 - email hijacking - filed under Hacking
This person has been logging into my gmail account and sent out spam emails to my entire contact lis...
2 hr 23 min  ago
202.104.197.118 - Attempted login to FTP - filed under Brute Force
Brute force attempts to log into my server FTP with the username "administrator." A sim...
2 hr 52 min  ago
74.128.173.47 - Bet2day casino - filed under Spam
Same as the rest, spam mail every hour now on 3 of my emails. No way to unsubscribe and impossible t...
3 hr 50 min  ago
173.9.198.249 - website was hacked 2 days ago - filed under FTP Hacking
2 days ago from this ip several of our websites we're hacked by logging on to our ftp webhosting ac...
4 hr 2 min  ago
66.147.240.186 - This IP is trying to logon my website - filed under Brute Force
Website: http://www.iphonesp.com.br/ Page: /administrator/index.php Description: There was an unsu...
4 hr 32 min  ago
94.183.53.255 - Attacking Google account - filed under Hacking
Someone recently tried to sign in to your Google Account, XXXXX. We prevented the sign-in attempt in...
5 hr 5 min  ago
67.205.111.248 - 184.107.157.130 - filed under Hacking
this site keeps port scanning my IP addresses. i have him blocked but clearly theres a problem with...
5 hr 36 min  ago
72.21.194.32 - Risky connection blocked - filed under Malware
Looks to me like 72.21.194.32 is a server leased from Amazon's cloud services server farm by someon...
6 hr 8 min  ago
74.128.173.47 - unsubscribe bet2day from Ryan Hardy - filed under Spam
no way to unsubscribe to their unwanted mail about bet2day; looks to me a kind of spam or other non...
6 hr 44 min  ago
[00001] 2012-05-14 18:09:02 [Root]system-critical-00441: ICMP ping id=0! From 178.33.224.175 to 66.2...
7 hr 16 min  ago
Unsolicited spam from webmaster@arclip.ru -user17662 Received: from s6.cishost.ru ([92.38.199.150])...
7 hr 23 min  ago
77.78.228.62 - malware - filed under Malware
2012/05/16 20:18:16 +0300 DEOCAMDATARDS computer IP-BLOCK 77.78.228.62 (Type: incoming) 2012/05/16 2...
8 hr 24 min  ago
200.107.124.36 - spam - filed under Spam
Spam 200.107.124.36 "From rrenat31391@mail.ru Wed May 16 19:06:25 2012 DKIM-Signature: v=1; ...
8 hr 44 min  ago
More Attacks
123.4.42.80 - port scan - filed under Port Scanning
13 attempts in 30 minutes 22.4.2010 22.33...
>2 years ago
187.10.119.17 - Spam & possible phishing - filed under Spam
Email content: 99.99% Genuine look of Original Super Expensive Watches We_offer the fin...
>3 years ago
205.234.235.188 - This IP leaves comment Spam on websites - filed under Spam
205.234.235.188 This IP address is used by a party that employs and automated method of comment Spam...
>2 years ago
64.187.107.83 - Possible Phishing - filed under Spam
This IP is spamming and possibly phishing by using the domain name: autoeciously.net...
>3 years ago
180.74.253.151 - US$10.5M - filed under Fraud
Here is the e-mail 's header : ============== x-store-info:4r51+eLowCe79NzwdU2kR3P+ctWZsO+J Authent...
26 days  ago
193.105.240.173 - tried to get into Wordpress account - filed under FTP Hacking
This IP address tried to get into Wordpress account on Thursday, February 16, 2012. I'm hoping that...
>3 months ago
58.218.199.87 - hackers - filed under Port Scanning
many security alerts from this ip addy, mostly port scans and trying to access TCP Port: 6515, TCP s...
27 days  ago
A brute force attack has been detected in one of your service logs. IP 212.160.170.220 has 17 faile...
16 days  ago
10:59:36 PM Block IN TCP 175.45.25.87 12200 86.127.74.46 1337 SYN Blocked by the Attack Detecton com...
>3 months ago
Probably an unwitting participant in a Botnet, attempting an SSH dictionary attack...
>2 years ago
206.161.121.5 - what is this? - filed under Malware
my malaware is constantly blocking this IP. is there something wrong with it? Can't get it complet...
29 days  ago
208.113.145.242 - 2-5 emails a day from - filed under Spam
2-5 emails a day from Jason Jones [jason@canadianhomebuying.com]...
>2 years ago
fraud@antihotmail.com ------------------------------ http://santander-usuarios.ibgconfacil.com/Vali...
>2 months ago
119.145.248.42 - Port Scanning Asain MONKEY. - filed under Port Scanning
Firewall log: Thu Feb 4 20:44:44 2010 =>Found attack from 119.145.248.42. Source port is 6000 and ...
>2 years ago
173.212.195.34 - HOSTNOC - BURSTNET - Joomla Hackers - filed under SQL Injection
Attacks from HostNOC servers - SQL injections there has been a massive hacking spree originating fr...
>4 months ago
fraud@antihotmail.com ------------------------------ http://wilfigs.com/session=de23DIsdf34599df/MB...
6 days  ago
91.121.135.128 - SPAM IP France - Roubaix - filed under Spam
I have hundtreds spam comments every day from this IP - 91.121.135.128...
>3 years ago
61.139.105.163 - port scan attack from 67.202.28.159 - filed under Hacking
my fire wall shows ofnely port scan attacked & somebody scanning your computer's tcp ports 808,8080,...
>2 years ago
123.134.95.199 - Somebody is scanning your computer. - filed under Hacking
Somebody is scanning your computer. Your computer's TCP ports: 8085, 8080, 8000, and 3128 have...
>2 years ago
Email was asking for you to change your password with an html link to this ip. 202.143.162.157...
>2 years ago
This ip adress treid to hack FTP servers...
>1 year ago
89.17.220.220 - Revisar - filed under Malware
Malwarebytes me bloquea esta ip 89.17.220.220 y tambien 46.249.55.136, no puedo saber de que es y me...
>3 months ago
188.116.55.243 - HackAttack: [TCP SYN Flooding] - filed under Firewall Alert
Feb 10 02:47:45 HackAttack: [TCP SYN Flooding] TCP packet from [nas0] 188.116.55.243:6665 to 80.220....
>3 months ago
fraud@antihotmail.com --------------------------------- http://rivieraspecialties.com/.login-secure...
>7 months ago
blocked by firewall in my router. ASS HOLE...
>3 years ago