IP Address

221.139.88.149

IPv4 Public
KR KR
AS9318
SK Broadband Co Ltd
168 Reports
This IP is on the Blacklist High confidence threat - blocking recommended
10/10 Threat
100% Confidence
168 Reports

Threat Intelligence Analysis

AI-generated security assessment based on aggregated threat data

Top 5% Most Dangerous
KR
KR Location
SK Broadband Co Ltd ASN 9318
168 Reports
Honeypot Data Source

Severe Risk

IP 221.139.88.149 is a critical-risk address originating from South Korea that has been flagged in 168 abuse reports for sustained SSH brute-force attacks and broader intrusion activity, with honeypot sensors confirming repeated exploitation attempts against SSH services. The volume of reporting, maximum threat score and detection across multiple automated sensors collectively paint a picture of persistent credential-attack infrastructure rather than opportunistic scanning.

Network intelligence places this IP within AS9318, operated by SK Broadband Co Ltd in South Korea, with activity documented between February 2026 and May 2026. The 168 total reports break down across three primary categories: SSH brute-force attempts (20 reports), general hacking/intrusion activity (19 reports), and exploited-host behaviour (9 reports). Activity frequency of 8/10 indicates ongoing, sustained offensive operations rather than isolated burst activity, and the 20 distinct honeypot sources confirm distributed detection across sensor networks. The coexistence of exploited-host tags alongside active attack signatures suggests this address may be running attack tooling while simultaneously showing indicators of compromise itself.

SSH brute-force attacks remain one of the most common initial-access vectors for server compromise. Automated tools cycle through username/password combinations against exposed SSH daemons, exploiting weak or default credentials to gain shell access. Once inside, attackers deploy cryptocurrency miners, ransomware, or pivot deeper into networks. The "exploited" designation on several Suricata alerts associated with this IP suggests that whatever SSH service it contacted was itself already compromised, indicating either a chained botnet node or a compromised residential connection being weaponised without the owner's knowledge.

Site operators exposing SSH to the internet should immediately block this IP at the firewall level and implement key-based authentication to eliminate password-based login entirely. Adjusting the default SSH port reduces automated scanning exposure, while tools such as fail2ban can dynamically ban repeat offenders after a configurable violation threshold. Enabling intrusion-detection monitoring and reviewing authentication logs for any matching attempts during the February–May 2026 window will help determine whether any probing succeeded.

More threatening than 100% of monitored IPs

Threat Categories

SSH 30
Hacking 27
Exploited Host 13

Technical Details

SSH attacks attempt to gain server access through password guessing or exploitation of SSH vulnerabilities.

Recommended Mitigations

Use key-based authentication, change default ports, implement fail2ban, and disable root login.

Behavioral Analysis

Activity Pattern: Consistent Activity

Steady malicious activity over 1 week indicates persistent threat actor operations.

First Observed 10. May 2026
Last Activity 19. May 2026
Recent (7 days) 0 incidents

Moderate Network Risk

The network hosting this IP (ASN 9318, operated by SK Broadband Co Ltd) shows moderate threat indicators. Some concerning activity has been detected from neighboring addresses.

Consider the network context when assessing this individual IP.

Security Recommendations

Long-term blocking recommended.

This analysis is automatically generated from aggregated, anonymized threat intelligence data. No personal information is displayed or stored. Assessment accuracy depends on available data volume and diversity.

Reputation Summary

Threat Level 10/10 Critical
Critical
Activity Frequency 8/10 High
Confidence Score 95% Verified

Confidence History

7. May 2026 - 19. May 2026
100% Current
Stable Trend

The confidence score shows the reliability of the threat assessment based on the number and quality of reports.

Security Reports (30)

Date Categories Source Confidence
Hacking Exploited Host SSH Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Exploited Host Honeypot x3 75%
SSH Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Exploited Host Honeypot x3 75%
Hacking SSH Exploited Host Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Exploited Host Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Hacking Exploited Host SSH Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Exploited Host Honeypot x3 75%
Hacking SSH Honeypot x2 75%
SSH Hacking Exploited Host Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Hacking Exploited Host SSH Honeypot x3 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Exploited Host Honeypot x3 75%
Hacking SSH Honeypot x2 75%
SSH Honeypot 75%
Hacking SSH Exploited Host Honeypot x3 75%
Hacking Exploited Host SSH Honeypot x3 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Honeypot x2 75%
Hacking SSH Exploited Host Honeypot x3 75%

Technical Details

Basic Information

IP Address
221.139.88.149
IP Version
IPv4
Network Type
Public
Tor Network
No
Network Class
Class C

Geolocation

Country
KR KR
ASN
AS9318
ISP
SK Broadband Co Ltd

DNS Information

Reverse DNS
None
PTR Record
No
Connection Type
Static

Statistics

Total Reports
168
First Reported
21 Feb 2026
Last Reported
19 May 2026, 21:55

Network Reputation

Analysis of the entire network (ASN) that this IP address belongs to, providing context about the hosting provider and network-wide threat patterns.

Network Identity

AS9318
SK Broadband Co Ltd
KR KR

Network Threat Assessment

5/10
This network has low threat indicators with minimal suspicious activity.

Network Statistics

206
Total IPs Monitored
3,329
Total Reports
16.2
Reports per IP

Network Context

This IP address belongs to SK Broadband Co Ltd (AS9318), which manages 206 IP addresses in our monitoring system. Out of these, 3,329 have been reported for suspicious activities, resulting in a network-wide threat level of 5/10.

Network notice: This network shows some suspicious activity patterns. Monitor interactions with IPs from this ASN.

Comparative Analysis

How this IP compares to others in our threat intelligence database

100 %

Global Threat Ranking

This IP is more threatening than 100% of all IPs in our database.

Top 10% Most Dangerous

Global Comparison

Compared against 198,690 reported IPs worldwide

Threat Level 10/10 avg: 5.3 ++
Total Reports 168 avg: 23 ++

Network Comparison

Compared against 224 IPs in ASN 9318

Threat Level 10/10 network avg: 5.5 ++
Total Reports 168 network avg: 17 ++
Network SK Broadband Co Ltd has overall threat level 5/10

Geographic Comparison

Compared against 2,284 IPs in KR

Threat Level 10/10 country avg: 5.3 ++
Total Reports 168 country avg: 19 ++
Indicators:
++ Much Higher + Higher = Similar - Lower -- Much Lower

Geographic Threat Distribution

186,446 threat incidents tracked globally • Last 24h: 18,633 Logs

FEED

Top Threat Sources

  1. 01
    US
    United States US
    38,320 20.6%
  2. 02
    IN
    India IN
    28,851 15.5%
  3. 03
    CN
    China CN
    25,960 13.9%
  4. 04
    BR
    Brazil BR
    10,202 5.5%
  5. 05
    DE
    Germany DE
    7,128 3.8%
  6. 06
    SG
    Singapore SG
    6,451 3.5%
  7. 07
    ID
    Indonesia ID
    5,496 2.9%
  8. 08
    RU
    Russia RU
    4,690 2.5%
  9. 09
    PK
    Pakistan PK
    4,632 2.5%
  10. 10
    NL
    Netherlands NL
    4,350 2.3%

+40 more countries

THREAT LEVEL
LOW MED HIGH

Geographic data is aggregated and anonymized. No personal information displayed.

Map: simplemaps.com (MIT License)

Related IPs

Other IPs associated with this address through network or behavioral similarity

IPs from the same Autonomous System (AS) network provider.

20 Related IPs
9.7/10 Avg Threat
97% Avg Confidence
20 High Threat
High-risk network: Majority of related IPs are flagged

Export & Firewall Rules

Download threat data or generate firewall rules to block this IP

JSON Report

Structured data format for integration with security tools and SIEM systems.

{
    "ip_address": "221.139.88.149",
    "threat_level": 10,
    "confidence_score": 100,
    "total_reports": 168,
    "country_code": "KR",
    "isp_name": "SK Broadband Co Ltd",
    "asn": "9318",
    "first_reported": "2026-02-21 03:37:28",
    "last_reported": "2026-05-19 21:55:48",
    "exported_at": "2026-06-08T22:54:01+02:00",
    "source": "https://reportedip.de/ip/221.139.88.149/"
}

GDPR Compliant: Exports contain only IP-related threat data. No personal information or reporter details are included.