20.207.200.31
Classification: Malicious
20.207.200.31 is a malicious IP address. Reported by 3 threat sources, last seen 2026-08-28. Network: AS8075 Microsoft Corporation.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Open proxy — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| DDoS Attacker | Blocklist.net.ua | 2026-03-07 12:05:23 | 2026-08-28 16:03:41 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-03-05 19:30:31 | 2026-03-10 05:16:31 | compromised malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2022-01-31 02:09:16 | 2026-03-08 05:01:01 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2022-01-31 02:03:07 | 2026-03-08 03:01:17 | malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-03-05 14:28:14 | 2026-03-06 23:11:33 | malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-03-05 19:30:31 | 2026-03-06 23:04:13 | anomalous-activity | |
| Hacking | AbuseIPDB | 2026-03-05 19:40:03 | 2026-03-06 22:50:42 | malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-03-05 19:50:54 | 2026-03-06 22:01:14 | malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-03-05 19:20:47 | 2026-03-06 22:01:14 | malicious-activity | |
| Phishing | AbuseIPDB | 2026-03-06 15:33:13 | 2026-03-06 15:33:13 | malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-03-05 20:54:00 | 2026-03-06 14:05:06 | malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-03-05 21:05:30 | 2026-03-06 12:20:39 | anomalous-activity | |
| IMAP Attacker | AbuseIPDB | 2026-03-06 06:10:59 | 2026-03-06 06:10:59 | malicious-activity | |
| Proxy | AbuseIPDB | 2026-03-05 19:35:06 | 2026-03-06 05:05:43 | anonymization | |
| SQL Injection | AbuseIPDB | 2026-03-05 19:40:03 | 2026-03-06 03:28:26 | malicious-activity | |
| FTP Attacker | AbuseIPDB | 2026-03-05 19:35:06 | 2026-03-05 19:35:06 | malicious-activity |
Tags
attacker login bruteforce bot joomla wordpress apache ddos rfi abuseWhois information
- AS name
- AS8075 Microsoft Corporation
- AS registry
- arin
- AS date
- 2017-10-18 00:00:00
- AS CIDR
- 20.192.0.0/10
- CIDR
- 20.192.0.0/10
- Registrant
- Microsoft Corporation
- Address
- One Microsoft Way
- City
- Pune
- State
- WA
- Postal code
- 411002
- Country
- IN — India 🇮🇳
- Contact email
- [email protected], [email protected], [email protected], [email protected], [email protected]
- First indexed
- 2022-01-31 02:03:07
- Last updated
- 2026-08-28 16:03:41
Malicious IPs in the same CIDR
20.245.121.239 20.239.71.136 20.204.43.57 20.200.215.186 20.223.168.112 20.216.170.81 20.216.189.83 20.215.184.30 20.207.200.31 20.234.130.50 20.192.21.51 20.218.128.24