20.91.199.21
Classification: Whitelisted
20.91.199.21 is a whitelisted (trusted) IP address. Reported by 4 threat sources, last seen 2026-09-11. Network: AS8075 Microsoft Corporation.
Current activity
- Known attacker β Seen launching attacks over the Internet.
- Known scanner β Seen scanning hosts over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Empty reason | Blocklist.net.ua | 2026-09-04 16:04:44 | 2026-09-11 16:02:57 | attacker malicious-activity | |
| DDoS Attacker | Blocklist.net.ua | 2026-07-30 16:00:14 | 2026-09-10 16:03:52 | attacker malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2026-08-01 09:00:28 | 2026-08-07 09:01:11 | attacker malicious-activity | |
| HTTP Attacker | Blocklist.de | 2026-08-01 07:00:26 | 2026-08-07 07:01:13 | attacker malicious-activity | |
| HTTP bot | Blocklist.de | 2026-07-31 08:00:43 | 2026-07-31 08:00:43 | attacker malicious-activity | |
| Matched whitelist source: Microsoft_asn | Maltiverse | 2026-07-30 16:00:15 | 2026-07-30 16:00:15 | benign | |
| Hacking | AbuseIPDB | 2026-07-30 09:41:33 | 2026-07-30 15:56:11 | attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-07-30 09:34:37 | 2026-07-30 15:56:11 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-07-30 09:46:00 | 2026-07-30 15:27:14 | anomalous-activity attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-07-30 09:40:02 | 2026-07-30 15:27:14 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-07-30 10:40:29 | 2026-07-30 15:21:56 | anomalous-activity attacker malicious-activity reconnaissance | |
| Malicious Host | AbuseIPDB | 2026-07-30 10:22:03 | 2026-07-30 15:10:30 | attacker compromised malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-07-30 10:54:49 | 2026-07-30 13:27:53 | attacker malicious-activity | |
| Known Attacker | AbuseIPDB | 2026-07-30 12:48:48 | 2026-07-30 12:48:48 | attacker malicious-activity | |
| FTP Attacker | AbuseIPDB | 2026-07-30 12:48:48 | 2026-07-30 12:48:48 | attacker malicious-activity | |
| Phishing | AbuseIPDB | 2026-07-30 12:48:48 | 2026-07-30 12:48:48 | malicious-activity phishing | |
| SQL Injection | AbuseIPDB | 2026-07-30 12:07:02 | 2026-07-30 12:48:48 | attacker malicious-activity | |
| Mail Spammer | AbuseIPDB | 2026-07-30 10:54:49 | 2026-07-30 12:48:48 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-07-30 09:57:54 | 2026-07-30 12:48:48 | attacker malicious-activity |
Tags
abuse attacker spam bruteforce bot apache ddos rfi login joomla wordpressWhois information
- AS name
- AS8075 Microsoft Corporation
- Registrant
- Microsoft Corporation
- City
- Gavle
- Postal code
- 801 38
- Country
- SE β Sweden πΈπͺ
- First indexed
- 2026-07-30 16:00:14
- Last updated
- 2026-09-11 16:02:57