20.115.224.107

Recent Activity This IP has received recent abuse reports, which causes the score to increase.
Abuse confidence score ?
56% Elevated
101 reports
8 reporters Β· latest 4 hours ago
ISP Microsoft Corporation
Usage Type Data Center/Web Hosting/Transit
ASN AS8075
Domain Name microsoft.com
Country πŸ‡ΊπŸ‡Έ United States of America
City Moses Lake, Washington

ISP, Usage Type, and Location provided by IPInfo. Updated weekly.

Log in to view charts and search reports for this IP. Log In

Reports Activity

Example preview

Report Categories (Last 60 Days)

Example preview

Top Reporter Countries (Last 60 Days)

Example preview
Account required for the enhanced features Log in Sign up

IP Abuse Reports for 20.115.224.107

This IP address has been reported a total of 101 times from 8 distinct sources. 20.115.224.107 was first reported on , and the most recent report was . In the last 60 days, the top reporter locations were: United States of America with 95 reports; Australia with 2 reports; Switzerland with 2 reports. The most common categories in these recent reports were: Brute-Force 99 times; Hacking 79 times; Port Scan 4 times.

Reporter IoA Timestamp (UTC) Comment Categories
πŸ‡ΊπŸ‡Έ Cotty
Brute-Force
πŸ‡ΊπŸ‡Έ Cotty
Brute-Force
πŸ‡ΊπŸ‡Έ drewf.ink
[04:30] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[04:14] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[03:58] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[03:42] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[03:26] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[03:10] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡³πŸ‡± knock
Knock-Knock honeypot brute-force: RDP (983 total hits)
Brute-Force
πŸ‡ΊπŸ‡Έ drewf.ink
[02:54] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[02:38] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ sargetun
Honeypot: RDP probe on port 3389 at 2026-10-11 02:29:17.992164. Automated report from VPS honeypot.
Port Scan
πŸ‡ΊπŸ‡Έ drewf.ink
[02:22] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[02:07] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking
πŸ‡ΊπŸ‡Έ drewf.ink
[01:52] RDP NLA authentication attempt as .\Administrator (NTLMv2 captured, workstation='?')
Brute-Force Hacking

Showing 1 to 15 of 101 reports

Think this IP has been falsely reported? You may request to have the associated reports reviewed and removed. Request Takedown 🚩

Recently Reported IPs:

πŸ‡«πŸ‡· 91.231.89.43
πŸ‡±πŸ‡° 220.247.224.226
πŸ‡ΊπŸ‡Έ 147.185.132.213
πŸ‡³πŸ‡± 45.153.34.32
πŸ‡ΈπŸ‡¬ 43.156.33.17
πŸ‡·πŸ‡΄ 2.57.121.25
πŸ‡°πŸ‡· 211.62.96.42
πŸ‡·πŸ‡Έ 178.220.136.44
πŸ‡³πŸ‡΅ 118.91.173.210
πŸ‡ΊπŸ‡Έ 103.196.9.235
πŸ‡³πŸ‡± 94.154.43.146
πŸ‡ΊπŸ‡Έ 66.132.186.218
πŸ‡¬πŸ‡§ 35.203.211.192
πŸ‡ΊπŸ‡Έ 34.106.71.71
πŸ‡¨πŸ‡³ 14.103.86.183
πŸ‡«πŸ‡· 195.177.94.118
πŸ‡ΊπŸ‡Έ 162.243.172.114
πŸ‡¬πŸ‡§ 138.68.151.204
πŸ‡―πŸ‡΅ 101.110.55.25