20.203.205.107
Classification: Whitelisted
20.203.205.107 is a whitelisted (trusted) IP address. Reported by 4 threat sources, last seen 2026-09-11. Network: AS8075 Microsoft Corporation.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- VPN node — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Empty reason | Blocklist.net.ua | 2026-09-04 16:05:16 | 2026-09-11 16:03:38 | attacker malicious-activity | |
| DDoS Attacker | Blocklist.net.ua | 2026-06-28 16:02:57 | 2026-09-10 16:04:23 | attacker malicious-activity | |
| HTTP bot | Blocklist.de | 2026-07-03 08:01:37 | 2026-07-17 08:01:28 | attacker malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-06-28 07:00:29 | 2026-06-30 07:05:08 | attacker malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-06-29 09:00:18 | 2026-06-29 09:00:18 | attacker malicious-activity | |
| Matched whitelist source: Microsoft_asn | Maltiverse | 2026-06-28 07:00:31 | 2026-06-28 07:00:31 | benign | |
| Port Scanner | AbuseIPDB | 2026-06-26 23:00:00 | 2026-06-28 06:58:22 | anomalous-activity | |
| Hacking | AbuseIPDB | 2026-06-27 06:20:01 | 2026-06-28 06:54:18 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-06-26 23:00:00 | 2026-06-28 06:54:18 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-06-27 06:20:01 | 2026-06-28 06:29:01 | malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-06-27 11:37:21 | 2026-06-28 06:27:45 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-06-27 11:00:54 | 2026-06-28 06:27:45 | anomalous-activity | |
| Malicious Host | AbuseIPDB | 2026-06-27 10:38:05 | 2026-06-28 05:41:00 | compromised malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-06-27 11:28:34 | 2026-06-28 04:54:24 | malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2026-06-28 02:08:34 | 2026-06-28 02:08:34 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2026-06-27 15:17:39 | 2026-06-27 23:45:50 | malicious-activity | |
| DNS Compromise | AbuseIPDB | 2026-06-27 17:59:31 | 2026-06-27 17:59:31 | compromised | |
| DNS Poisoning | AbuseIPDB | 2026-06-27 17:59:31 | 2026-06-27 17:59:31 | compromised | |
| Known Attacker | AbuseIPDB | 2026-06-27 17:59:31 | 2026-06-27 17:59:31 | malicious-activity | |
| Mail Spammer | AbuseIPDB | 2026-06-27 13:16:47 | 2026-06-27 17:59:31 | malicious-activity | |
| VPN | AbuseIPDB | 2026-06-27 13:35:54 | 2026-06-27 13:35:54 | anonymization |
Tags
apache ddos rfi attacker abuse login bruteforce bot joomla wordpress spamWhois information
- AS name
- AS8075 Microsoft Corporation
- Registrant
- Microsoft Corporation
- City
- Zürich
- Postal code
- 8001
- Country
- CH — Switzerland 🇨🇭
- First indexed
- 2026-06-28 07:00:29
- Last updated
- 2026-09-11 16:03:38