20.196.197.230

Classification: Malicious

20.196.197.230 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-11. Network: AS8075 Microsoft Corporation.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Empty reason Blocklist.net.ua 2026-09-04 16:05:09 2026-09-11 16:03:31 attacker malicious-activity
DDoS Attacker Blocklist.net.ua 2026-04-17 12:05:16 2026-09-10 16:04:16 attacker malicious-activity
Malicious Host AbuseIPDB 2026-04-15 20:15:13 2026-05-05 02:05:51 compromised malicious-activity
HTTP Attacker Blocklist.de 2026-04-16 03:00:19 2026-04-22 03:01:12 malicious-activity
Bruteforce login attacker Blocklist.de 2026-04-16 05:00:17 2026-04-21 05:00:58 malicious-activity
HTTP Attacker AbuseIPDB 2026-04-15 19:43:39 2026-04-15 23:34:04 malicious-activity
Bruteforce AbuseIPDB 2026-04-15 19:45:03 2026-04-15 23:18:38 malicious-activity
Hacking AbuseIPDB 2026-04-15 19:46:00 2026-04-15 22:30:36 malicious-activity
DDoS Attacker AbuseIPDB 2026-04-15 22:22:02 2026-04-15 22:22:02 malicious-activity
SSH Attacker AbuseIPDB 2026-04-15 22:10:11 2026-04-15 22:10:11 malicious-activity
HTTP Scrapper AbuseIPDB 2026-04-15 19:46:00 2026-04-15 22:00:51 anomalous-activity
Port Scanner AbuseIPDB 2026-04-15 21:48:41 2026-04-15 21:48:41 anomalous-activity

Tags

apache ddos rfi attacker login bruteforce bot joomla wordpress abuse

Whois information

AS name
AS8075 Microsoft Corporation
Registrant
Microsoft Corporation
City
Seoul
Postal code
04523
Country
KR — Korea, Republic of 🇰🇷
First indexed
2026-04-16 00:01:34
Last updated
2026-09-11 16:03:31