20.127.130.112

Classification: Malicious

20.127.130.112 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-12. Network: AS8075 Microsoft Corporation.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Open proxy β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-03-04 12:04:35 2026-09-12 16:03:15 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:04:56 2026-09-11 16:03:13 attacker malicious-activity
Suspicious Host AbuseIPDB 2026-04-22 14:37:06 2026-04-22 14:37:06 anomalous-activity
Malicious Host AbuseIPDB 2026-03-03 09:56:39 2026-03-08 02:36:28 compromised malicious-activity
Bruteforce login attacker Blocklist.de 2026-03-04 05:02:42 2026-03-05 05:01:13 malicious-activity
HTTP Attacker Blocklist.de 2026-03-05 03:02:23 2026-03-05 03:02:23 malicious-activity
Bruteforce AbuseIPDB 2026-03-03 09:55:17 2026-03-03 23:45:06 malicious-activity
HTTP Attacker AbuseIPDB 2026-03-03 09:45:56 2026-03-03 23:45:06 malicious-activity
SSH Attacker AbuseIPDB 2026-03-03 13:40:03 2026-03-03 22:59:47 malicious-activity
Hacking AbuseIPDB 2026-03-03 09:53:04 2026-03-03 22:59:47 malicious-activity
HTTP Scrapper AbuseIPDB 2026-03-03 09:58:36 2026-03-03 22:18:45 anomalous-activity
SQL Injection AbuseIPDB 2026-03-03 10:21:02 2026-03-03 18:31:50 malicious-activity
Proxy AbuseIPDB 2026-03-03 13:31:37 2026-03-03 18:23:56 anonymization
Port Scanner AbuseIPDB 2026-03-03 10:13:05 2026-03-03 18:17:49 anomalous-activity
DDoS Attacker AbuseIPDB 2026-03-03 10:37:22 2026-03-03 14:24:06 malicious-activity

Tags

attacker login bruteforce bot joomla wordpress abuse apache ddos rfi

Whois information

AS name
AS8075 Microsoft Corporation
Registrant
Microsoft Corporation
City
Washington
State
DC
Postal code
20500
Country
US β€” United States πŸ‡ΊπŸ‡Έ
First indexed
2026-03-04 00:08:53
Last updated
2026-09-12 16:03:15