104.152.52.148
Classification: Malicious
104.152.52.148 is a malicious IP address. Reported by 7 threat sources, last seen 2026-09-02. Network: AS14987 Rethem Hosting LLC.
Current activity
- Known attacker — Seen launching attacks over the Internet.
- Known scanner — Seen scanning hosts over the Internet.
- IoT threat — Seen attacking IoT devices.
- Open proxy — Provides anonymization that can hide an attacker.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Port Scanner | AbuseIPDB | 2025-02-18 14:21:08 | 2026-09-02 09:20:28 | anomalous-activity attacker malicious-activity reconnaissance | |
| SSH Attacker | AbuseIPDB | 2025-02-18 14:21:08 | 2026-09-02 08:00:22 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2025-02-17 20:51:23 | 2026-09-02 08:00:22 | attacker malicious-activity | |
| Hacking | AbuseIPDB | 2025-02-21 02:05:46 | 2026-09-02 07:56:28 | attacker malicious-activity | |
| IoT Attacker | AbuseIPDB | 2025-08-03 09:51:04 | 2026-09-02 04:06:25 | iot malicious-activity | |
| Malicious Host | AbuseIPDB | 2025-01-19 22:05:27 | 2026-09-01 20:52:01 | attacker compromised malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2025-02-18 14:21:08 | 2026-09-01 19:02:41 | attacker malicious-activity | |
| HTTP Scrapper | AbuseIPDB | 2025-02-18 14:21:08 | 2026-08-30 15:23:48 | anomalous-activity attacker malicious-activity | |
| DDoS Attacker | AbuseIPDB | 2025-08-03 06:26:14 | 2026-08-28 22:11:35 | attacker malicious-activity | |
| Mail Spammer | AbuseIPDB | 2025-02-18 14:21:08 | 2026-08-28 02:00:15 | attacker malicious-activity | |
| SSH Attacker | Blocklist.de | 2023-04-10 05:07:30 | 2026-08-17 14:00:08 | attacker malicious-activity | |
| Proxy | AbuseIPDB | 2026-02-27 18:08:55 | 2026-07-17 02:32:07 | anonymization proxy | |
| IMAP Attacker | AbuseIPDB | 2025-08-03 15:24:03 | 2026-06-18 06:32:54 | attacker malicious-activity | |
| Phishing | AbuseIPDB | 2025-09-04 18:56:27 | 2026-06-18 06:32:54 | malicious-activity phishing | |
| FTP Attacker | AbuseIPDB | 2026-02-27 05:10:12 | 2026-02-27 05:10:12 | malicious-activity | |
| Mail Spammer | Blocklist.de | 2024-06-17 03:13:03 | 2026-01-30 09:00:53 | malicious-activity | |
| Suspicious Host | AbuseIPDB | 2024-07-14 11:54:23 | 2025-12-24 23:00:36 | anomalous-activity | |
| SQL Injection | AbuseIPDB | 2025-05-06 16:45:51 | 2025-10-20 04:06:01 | malicious-activity | |
| DNS Compromise | AbuseIPDB | 2025-09-19 23:17:59 | 2025-09-19 23:17:59 | compromised | |
| Malicious Host | CIArmy | 2022-09-13 04:15:20 | 2025-04-11 22:58:00 | malicious-activity | |
| SIP Attacker | AbuseIPDB | 2025-04-07 16:41:34 | 2025-04-07 16:41:34 | malicious-activity | |
| DDoS attack | AbuseIPDB | 2025-02-18 14:21:08 | 2025-02-18 14:21:08 | malicious-activity | |
| Unauthorized scanning of hosts | Blocklist.net.ua | 2024-12-08 16:38:47 | 2024-12-08 16:38:47 | malicious-activity | |
| HTTP Attacker | Blocklist.de | 2022-02-27 00:38:11 | 2024-08-20 08:42:41 | malicious-activity | |
| Malicious Host | HoneyDB | 2022-11-20 00:00:00 | 2023-11-10 00:00:00 | malicious-activity | |
| Malicious URL | Hybrid-Analysis | 2023-10-18 13:24:07 | 2023-10-18 13:24:07 | ||
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2022-09-14 03:06:20 | 2023-07-23 13:40:57 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2022-09-14 03:06:19 | 2023-07-23 13:40:49 | malicious-activity | |
| Bruteforce login attacker | Blocklist.de | 2022-02-27 00:45:35 | 2022-10-25 02:19:06 | malicious-activity | |
| IMAP Attacker | Blocklist.de | 2022-05-14 01:12:00 | 2022-05-15 01:22:44 | malicious-activity |
Tags
ssh bruteforce bot attacker login joomla wordpress apache ddos rfi imap pop3 sasl mail spam abuseWhois information
- AS name
- AS14987 Rethem Hosting LLC
- AS registry
- arin
- AS date
- 2014-07-11 00:00:00
- AS CIDR
- 104.152.52.0/24
- CIDR
- 104.152.52.0/22
- Registrant
- Rethem Hosting LLC
- Address
- 500 N. Michigan Ave Suite 300
- City
- Chicago
- State
- IL
- Postal code
- 60602
- Country
- US — United States 🇺🇸
- Contact email
- [email protected]
- First indexed
- 2022-02-27 00:38:11
- Last updated
- 2026-09-02 11:41:51
Malicious IPs in the same CIDR
104.152.52.45 104.152.52.220 104.152.52.114 104.152.52.208 104.152.52.221 104.152.52.128 104.152.52.147 104.152.52.133 104.152.52.213 104.152.52.205 104.152.52.210 104.152.52.226 104.152.52.120 104.152.52.121 104.152.52.117 104.152.52.224 104.152.52.242 104.152.52.146 104.152.52.134 104.152.52.148 104.152.52.225 104.152.52.118 104.152.52.206 104.152.52.82 104.152.52.132