20.240.217.248
20.240.217.248 is a threat-intelligence indicator (IPv4 address) classified as Suspicious, corroborated across 3 independent feeds. It is aggregated and de-duplicated from many open and commercial threat feeds, with confidence scoring and decay over time.
Indicator facts
- Type
- IPv4 address
- Indicator
20.240.217.248- Classification
- Suspicious
- Confidence
- 80 / 100
- Corroboration
- 3 independent sources
- First seen
- Last seen
- Network (ASN)
- AS8075 — MICROSOFT-CORP-MSN-AS-BLOCK
- Country
- US
Tags
- brute-force
- ssh
- attacker
- sshpwauth
- scanner
Related CVEs (21)
- CVE-2026-42127
- CVE-2026-33381
- CVE-2026-33380
- CVE-2026-33378
- CVE-2026-33377
- CVE-2026-33376
- CVE-2026-33375
- CVE-2026-28383
- CVE-2026-28380
- CVE-2026-28379
- CVE-2026-28376
- CVE-2026-28374
- CVE-2026-27880
- CVE-2026-21727
- CVE-2026-21725
- CVE-2026-21722
- CVE-2026-21721
- CVE-2026-21720
- CVE-2026-10601
- CVE-2025-4123
- CVE-2025-12141
← Threat intelligence command center · Explore the indicator corpus