40.89.161.203

Classification: Whitelisted

40.89.161.203 is a whitelisted (trusted) IP address. Reported by 4 threat sources, last seen 2026-09-05. Network: AS8075 Microsoft Corporation.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2022-12-28 02:58:44 2026-09-05 16:11:48 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 16:13:34 2026-09-04 16:13:34 attacker malicious-activity
Matched whitelist source: Microsoft_asn Maltiverse 2026-06-22 08:19:08 2026-06-22 08:19:08 benign
Malicious Host AbuseIPDB 2026-05-24 22:00:23 2026-05-30 22:00:31 malicious-activity
Suspicious Host AbuseIPDB 2026-04-20 13:13:16 2026-05-17 05:23:07 anomalous-activity
HTTP Attacker Blocklist.de 2022-11-11 01:55:58 2022-11-12 01:57:36 malicious-activity
Mail Spammer Maltiverse 2022-09-30 22:37:18 2022-11-10 22:43:26 malicious-activity
HTTP Scrapper Maltiverse 2022-09-30 06:32:07 2022-11-10 22:43:26 anomalous-activity
HTTP Attacker Maltiverse 2022-09-30 06:03:02 2022-11-10 22:43:26 malicious-activity
Hacking Maltiverse 2022-10-01 07:17:39 2022-11-10 14:02:34 malicious-activity
Bruteforce Maltiverse 2022-09-30 06:03:02 2022-11-10 14:02:34 malicious-activity
Known Attacker Maltiverse 2022-11-09 03:26:34 2022-11-09 03:26:34 malicious-activity
Port Scanner Maltiverse 2022-10-01 10:28:02 2022-11-08 15:44:41 anomalous-activity
Malicious Host Maltiverse 2022-10-05 05:56:35 2022-10-05 05:56:35 compromised malicious-activity

Tags

abuse apache ddos rfi attacker

Whois information

AS name
AS8075 Microsoft Corporation
AS registry
arin
AS date
2015-02-23 00:00:00
AS CIDR
40.80.0.0/12
CIDR
40.125.0.0/17, 40.120.0.0/14, 40.96.0.0/12, 40.124.0.0/16, 40.76.0.0/14, 40.74.0.0/15, 40.80.0.0/12, 40.112.0.0/13
Registrant
Microsoft Corporation
Address
One Microsoft Way
City
Paris
State
WA
Postal code
75007
Country
FR — France 🇫🇷
Contact email
[email protected], [email protected], [email protected], [email protected]
First indexed
2022-11-11 01:55:58
Last updated
2026-09-05 16:11:48

Malicious IPs in the same CIDR

40.84.128.138