23.158.40.89

Classification: Malicious

23.158.40.89 is a malicious IP address. Reported by 2 threat sources, last seen 2026-09-02. Network: AS63023 GTHost.

Current activity

  • Malware distribution β€” This indicator is distributing malware.
  • Open proxy β€” Provides anonymization that can hide an attacker.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Maltiverse Threat Observatory 2026-06-27 20:10:06 2026-09-02 18:15:12 anomalous-activity country_code:ar country_code:br country_code:ca country_code:co country_code:do country_code:us industry:education-and-nonprofits industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications malicious-activity malware
Proxy FireHOL 2026-05-03 09:07:57 2026-09-02 17:59:04 anomalous-activity anonymization proxy
Anonymizer FireHOL 2026-05-03 08:10:52 2026-09-02 17:02:43 anomalous-activity anonymization
VPN vpnsuper Maltiverse Threat Observatory 2026-06-24 21:16:30 2026-09-02 09:46:07 anomalous-activity anonymization country_code:ar country_code:br country_code:ca country_code:co country_code:do country_code:ec country_code:us industry:education-and-nonprofits industry:healthcare-and-pharmaceutical industry:manufacturing industry:retail-and-hospitality industry:technology-and-telecommunications malicious-activity

Tags

anonymization port:7000 port:9014 port:110 port:8281 port:5959 port:800 port:443 port:8080

Whois information

AS name
AS63023 GTHost
Registrant
GTHost
City
Phoenix
State
AZ
Postal code
85004-1905
Country
US β€” United States πŸ‡ΊπŸ‡Έ
First indexed
2026-05-03 08:10:52
Last updated
2026-09-02 20:52:54