20.220.211.108

Classification: Malicious

20.220.211.108 is a malicious IP address. Reported by 3 threat sources, last seen 2026-09-11. Network: AS8075 Microsoft Corporation.

Current activity

  • Known attacker — Seen launching attacks over the Internet.
  • Open proxy — Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Empty reason Blocklist.net.ua 2026-09-04 16:05:33 2026-09-11 16:03:53 attacker malicious-activity
DDoS Attacker Blocklist.net.ua 2026-03-02 12:05:50 2026-09-10 16:04:39 attacker malicious-activity
Malicious Host AbuseIPDB 2026-03-02 09:31:31 2026-03-09 11:02:32 compromised malicious-activity
HTTP Attacker Blocklist.de 2026-03-03 03:02:04 2026-03-03 03:02:04 malicious-activity
HTTP Scrapper AbuseIPDB 2026-03-02 09:34:08 2026-03-02 12:04:29 anomalous-activity
Hacking AbuseIPDB 2026-03-02 09:29:45 2026-03-02 12:04:29 malicious-activity
HTTP Attacker AbuseIPDB 2026-03-02 09:29:26 2026-03-02 12:04:29 malicious-activity
Bruteforce AbuseIPDB 2026-03-02 09:29:01 2026-03-02 12:03:28 malicious-activity
Port Scanner AbuseIPDB 2026-03-02 10:05:45 2026-03-02 11:54:11 anomalous-activity
DDoS Attacker AbuseIPDB 2026-03-02 10:04:47 2026-03-02 11:45:20 malicious-activity
SQL Injection AbuseIPDB 2026-03-02 09:36:18 2026-03-02 11:35:04 malicious-activity
SSH Attacker AbuseIPDB 2026-03-02 09:41:24 2026-03-02 10:57:03 malicious-activity
FTP Attacker AbuseIPDB 2026-03-02 09:30:20 2026-03-02 09:30:20 malicious-activity
Proxy AbuseIPDB 2026-03-02 09:30:20 2026-03-02 09:30:20 anonymization

Tags

abuse apache ddos rfi attacker

Whois information

AS name
AS8075 Microsoft Corporation
Registrant
Microsoft Corporation
City
Toronto
Postal code
M5H 2N2
Country
CA — Canada 🇨🇦
First indexed
2026-03-02 12:05:50
Last updated
2026-09-11 16:03:53