217.154.152.20
Classification: Malicious
217.154.152.20 is a malicious IP address. Reported by 5 threat sources, last seen 2026-09-10. Network: AS8560 IONOS SE.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Malicious Host | HoneyDB | 2026-08-09 00:00:00 | 2026-09-10 00:00:00 | attacker malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2026-08-18 09:18:21 | 2026-09-08 09:17:10 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2026-08-01 00:30:45 | 2026-09-07 19:00:30 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2026-07-11 13:56:12 | 2026-09-07 19:00:30 | attacker malicious-activity | |
| Port Scanner | AbuseIPDB | 2026-07-31 21:30:23 | 2026-09-07 13:27:43 | anomalous-activity attacker malicious-activity reconnaissance | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2026-08-18 09:18:19 | 2026-09-07 09:17:23 | attacker malicious-activity | |
| SIP Attacker | AbuseIPDB | 2026-07-26 03:00:08 | 2026-09-07 03:06:26 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2026-07-26 03:00:08 | 2026-09-07 02:34:06 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2026-08-01 00:46:19 | 2026-09-06 19:29:11 | attacker compromised malicious-activity | |
| FTP Attacker | AbuseIPDB | 2026-08-09 10:01:10 | 2026-09-06 17:17:39 | attacker malicious-activity | |
| SIP Attacker | Blocklist.de | 2026-08-01 13:00:04 | 2026-09-06 13:00:04 | attacker malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2026-08-18 15:30:35 | 2026-09-06 02:17:12 | attacker malicious-activity | |
| Malicious Host | CIArmy | 2026-08-17 20:03:14 | 2026-09-05 20:03:57 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2026-08-17 13:55:47 | 2026-09-05 15:25:45 | anomalous-activity attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2026-08-09 10:21:18 | 2026-09-05 15:25:45 | attacker malicious-activity |
Tags
sip bruteforce bot attackerWhois information
- AS name
- AS8560 IONOS SE
- Registrant
- IONOS SE
- City
- Berlin
- Postal code
- 10178
- Country
- DE — Germany 🇩🇪
- First indexed
- 2026-08-01 13:00:04
- Last updated
- 2026-09-10 22:01:06