AbuseIPDB » 104.214.54.223
104.214.54.223 was found in our database!
This IP was reported 290 times. Confidence of Abuse is 83%: ?
| ISP | Microsoft Corporation |
|---|---|
| Usage Type | Data Center/Web Hosting/Transit |
| ASN | AS8075 |
| Domain Name | microsoft.com |
| Country | πΊπΈ United States of America |
| City | San Antonio, Texas |
IP info including ISP, Usage Type, and Location provided by IPInfo. Updated weekly.
IP Abuse Reports for 104.214.54.223:
This IP address has been reported a total of 290 times from 13 distinct sources. 104.214.54.223 was first reported on , and the most recent report was .
Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.
| Reporter | IoA Timestamp (UTC) | Comment | Categories | |
|---|---|---|---|---|
| πΊπΈ sargetun |
Honeypot: RDP probe on port 3389 at 2026-09-23 05:23:03.474730. Automated report from VPS honeypot.
|
Port Scan | ||
| πΊπΈ Cotty |
|
Brute-Force | ||
| πΊπΈ drewf.ink |
[04:47] RDP NLA authentication attempt as luz.salazar (NTLMv2 captured, workstation='workstation')
|
Brute-Force Hacking | ||
| πΊπΈ drewf.ink |
[03:58] RDP NLA authentication attempt as luixsmi2 (NTLMv2 captured, workstation='workstation')
|
Brute-Force Hacking | ||
| πΊπΈ drewf.ink |
[02:59] RDP NLA authentication attempt as luis.marquez (NTLMv2 captured, workstation='workstation')
|
Brute-Force Hacking | ||
| π¦πΊ dyln |
Dyls honeypot brute-force: RDP (422 total hits)
|
Brute-Force | ||
| π«π· β¨ |
|
SSH Brute-Force | ||
| πΊπΈ drewf.ink |
|
Brute-Force Hacking | ||
| π³π± knock |
Knock-Knock honeypot brute-force: RDP (219 total hits)
|
Brute-Force | ||
| πΊπΈ drewf.ink |
[02:08] RDP NLA authentication attempt as lucilam (NTLMv2 captured, workstation='workstation')
|
Brute-Force Hacking | ||
| πΊπΈ drewf.ink |
[01:35] RDP NLA authentication attempt as Luchana.Chin (NTLMv2 captured, workstation='workstation')
|
Brute-Force Hacking | ||
| πΊπΈ ShadowWhisperer |
|
Brute-Force Hacking | ||
| πΊπΈ drewf.ink |
|
Brute-Force Hacking | ||
| πΊπΈ drewf.ink |
[00:15] RDP NLA authentication attempt as lsterenborg (NTLMv2 captured, workstation='workstation')
|
Brute-Force Hacking | ||
| πΊπΈ Cotty |
|
Brute-Force |
Showing 1 to 15 of 290 reports
Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown π©