20.196.197.230
Classification: Malicious
20.196.197.230 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-11. Network: AS8075 Microsoft Corporation.
Current activity
- Known attacker — Seen launching attacks over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Empty reason | Blocklist.net.ua | 2026-09-04 16:05:09 | 2026-09-11 16:03:31 | attacker malicious-activity | |
| DDoS Attacker | Blocklist.net.ua | 2026-04-17 12:05:16 | 2026-09-10 16:04:16 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-04-15 20:15:13 | 2026-05-05 02:05:51 | compromised malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-04-16 03:00:19 | 2026-04-22 03:01:12 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-04-16 05:00:17 | 2026-04-21 05:00:58 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-04-15 19:43:39 | 2026-04-15 23:34:04 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-04-15 19:45:03 | 2026-04-15 23:18:38 | malicious-activity | |
| Hacking | AbuseIPDB | 2026-04-15 19:46:00 | 2026-04-15 22:30:36 | malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-04-15 22:22:02 | 2026-04-15 22:22:02 | malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-04-15 22:10:11 | 2026-04-15 22:10:11 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-04-15 19:46:00 | 2026-04-15 22:00:51 | anomalous-activity | |
| Port Scanner | AbuseIPDB | 2026-04-15 21:48:41 | 2026-04-15 21:48:41 | anomalous-activity |
Tags
apache ddos rfi attacker login bruteforce bot joomla wordpress abuseWhois information
- AS name
- AS8075 Microsoft Corporation
- Registrant
- Microsoft Corporation
- City
- Seoul
- Postal code
- 04523
- Country
- KR — Korea, Republic of 🇰🇷
- First indexed
- 2026-04-16 00:01:34
- Last updated
- 2026-09-11 16:03:31