This IP address has been reported a total of
120
times from
64 distinct
sources.
1.234.20.61 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Repeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed ...
show moreRepeated SSH brute force and user enumeration attempts against a secured web server. Multiple failed authentication attempts from this IP across an extended period.
show less
Brute-Force
SSH
Anonymous
Jun 12 22:23:30 mx4 dovecot: imap-login: Disconnected (auth failed, 1 attempts in 7 secs): user=<mar ...
show moreJun 12 22:23:30 mx4 dovecot: imap-login: Disconnected (auth failed, 1 attempts in 7 secs): user=<[email protected]>, method=PLAIN, rip=1.234.20.61, lip=185.43.207.163, TLS, session=<NHaXPxRUorIB6hQ9>
Jun 12 23:40:40 mx4 dovecot: imap-login: Disconnected (auth failed, 1 attempts in 8 secs): user=<[email protected]>, method=PLAIN, rip=1.234.20.61, lip=185.43.207.163, TLS, session=<YsKLUxVUKKQB6hQ9>
...
show less
Brute-Force
Anonymous
POP or IMAP failed login attempts detected by Fail2Ban
(imapd) Failed IMAP login from 1.234.20.61 (KR/South Korea/Seoul/Gangnam-gu/-/[AS9318 SK Broadband C ...
show more(imapd) Failed IMAP login from 1.234.20.61 (KR/South Korea/Seoul/Gangnam-gu/-/[AS9318 SK Broadband Co Ltd]): 1 in the last 3600 secs
show less
2026-06-10T03:44:00.461430+00:00 mail postfix/submission/smtpd[2015522]: lost connection after CONNE ...
show more2026-06-10T03:44:00.461430+00:00 mail postfix/submission/smtpd[2015522]: lost connection after CONNECT from unknown[1.234.20.61]
2026-06-10T03:44:23.877034+00:00 mail postfix/submission/smtpd[2015612]: lost connection after STARTTLS from unknown[1.234.20.61]
2026-06-10T05:03:12.416264+00:00 mail postfix/submission/smtpd[2016188]: lost connection after CONNECT from unknown[1.234.20.61]
...
show less
2026-06-10T06:22:21.218359+02:00 v2202104133598150667 9275893e7080[958375]: Jun 10 06:22:21 9275893e ...
show more2026-06-10T06:22:21.218359+02:00 v2202104133598150667 9275893e7080[958375]: Jun 10 06:22:21 9275893e7080 postfix/submission/smtpd[52315]: lost connection after CONNECT from unknown[1.234.20.61]
2026-06-10T06:23:22.607448+02:00 v2202104133598150667 9275893e7080[958375]: Jun 10 06:23:22 9275893e7080 postfix/submission/smtpd[52316]: lost connection after STARTTLS from unknown[1.234.20.61]
2026-06-10T06:23:42.383340+02:00 v2202104133598150667 9275893e7080[958375]: Jun 10 06:23:42 9275893e7080 postfix/smtps/smtpd[52314]: warning: unknown[1.234.20.61]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
...
show less
1.234.20.61 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale in ...
show more1.234.20.61 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale industrial operation attempting unrelenting brute-force login attempts for months on end - between all CIDR ranges in the botnet, our servers receive over 800 authentication attempts per minute on smtp, imap and relative mail ports, as well as ssh, and other protocols.
IP INFO:
- IP 1.234.20.61
- Anycast false
- City N/A
- Region N/A
- Region Code N/A
- Country N/A (N/A)
- Continent N/A (N/A)
- Range N/A
- Provider N/A
- Organisation N/A
- Proxy N/A
- Type N/A
show less
1.234.20.61 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale in ...
show more1.234.20.61 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale industrial operation attempting unrelenting brute-force login attempts for months on end - between all CIDR ranges in the botnet, our servers receive over 800 authentication attempts per minute on smtp, imap and relative mail ports, as well as ssh, and other protocols.
IP INFO:
- IP 1.234.20.61
- Anycast false
- City Seoul (Toegye-ro)
- Region Seoul
- Region Code 11
- Country South Korea (KR)
- Continent Asia (AS)
- Range 1.234.20.0/23
- Provider SK Broadband Co Ltd
- Organisation SK Broadband Co Ltd
- Proxy no
- Type Residential
show less