20.88.55.220 Threat Intelligence and Host Information
Apr 09, 2025
ipinfopage
General
IP Address
20.88.55.220
IPv4 Address
Location
🇺🇸 Chicago, United States
US
Network
AS8075
MICROSOFT-CORP-MSN-AS-BLOCK
Threat Score
65/100
High Risk
atiffeedbanlistfeedbinarydefenseBrute-Forcbrute
Attack Intelligence
MITRE ATT&CK Techniques
T1078 - Valid Accounts, T1083 - File and Directory Discovery, T1098.004 - SSH Authorized Keys, T1105 - Ingress Tool Transfer, T1110.004 - Credential Stuffing, T1110 - Brute Force, T1595 - Active Scanning
Geographic Location
Coordinates
41.8874, -87.6318
Network Information
Organization
MICROSOFT-CORP-MSN-AS-BLOCK
Network
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK
WHOIS Information
NetRange
20.33.0.0 - 20.128.255.255
CIDR
20.34.0.0/15, 20.36.0.0/14, 20.33.0.0/16, 20.48.0.0/12, 20.64.0.0/10, 20.128.0.0/16, 20.40.0.0/13
Parent
NET20 (NET-20-0-0-0-0)
Organization
Microsoft Corporation (MSFT)
Ref
https://rdap.arin.net/registry/entity/MSFT
OrgName
Microsoft Corporation
Comment
* IOC@microsoft.com
OrgTechPhone
+1-425-882-8080
OrgTechEmail
averykim@microsoft.com
OrgTechRef
https://rdap.arin.net/registry/entity/KIMAV-ARIN
Attack Logs
| Date |
Target Location |
Protocol |
Link |
| 2025-04-09 |
Singapore |
SSH |
View Log |
- Country: United States
- Network:
- Noticed: 50 times
- Protocols Attacked: ssh
- Countries Attacked: Australia, Canada, Czechia, Denmark, Estonia, France, Germany, Latvia, Lithuania, Norway, Poland, Romania, Turkey, Ukraine, United Kingdom of Great Britain and Northern Ireland, United States of America
- Passive DNS Results: sbziudo0s1eom5m.northcentralus.atlas-test.cloudapp.azure.com
mlcssltestqx5zk2.northcentralus.cloudapp.azure.com
burstableflexrunnerserver637658461550163999.postgres.database.azure.com
CVEs Detected
CVE-2006-20001
CVE-2007-2768
CVE-2007-4723
CVE-2008-3844
CVE-2009-0796
CVE-2009-1390
CVE-2009-2299
CVE-2009-3765
CVE-2009-3766
CVE-2009-3767
CVE-2011-1176
CVE-2011-2688
CVE-2012-3526
CVE-2012-4001
CVE-2012-4360
CVE-2013-0941
CVE-2013-0942
CVE-2013-2765
CVE-2013-4365
CVE-2016-20012
CVE-2019-0190
CVE-2020-14145
CVE-2021-36368
CVE-2021-41617
CVE-2021-44224
CVE-2021-44790
CVE-2022-1292
CVE-2022-2068
CVE-2022-2097
CVE-2022-22719
CVE-2022-22720
CVE-2022-22721
CVE-2022-23943
CVE-2022-26377
CVE-2022-28330
CVE-2022-28614
CVE-2022-28615
CVE-2022-29404
CVE-2022-30556
CVE-2022-31813
CVE-2022-36760
CVE-2022-37436
CVE-2022-4304
CVE-2022-4450
CVE-2023-0215
CVE-2023-0286
CVE-2023-0464
CVE-2023-0465
CVE-2023-0466
CVE-2023-25690
CVE-2023-2650
CVE-2023-27522
CVE-2023-31122
CVE-2023-3817
CVE-2023-38408
CVE-2023-45802
CVE-2023-4807
CVE-2023-48795
CVE-2023-51385
CVE-2023-51767
CVE-2023-5678
CVE-2024-0727
CVE-2024-27316
CVE-2024-38474
CVE-2024-38476
CVE-2024-38477
CVE-2024-40898
CVE-2024-6387
CVE-2025-26465
Disclaimer
This page contains threat intelligence information for the IPv4 address 20.88.55.220 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only - and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.