104.152.52.243

Classification: Malicious

104.152.52.243 is a malicious IP address. Reported by 7 threat sources, last seen 2026-09-11. Network: AS14987 Rethem Hosting LLC.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Known scanner β€” Seen scanning hosts over the Internet.
  • IoT threat β€” Seen attacking IoT devices.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Port Scanner AbuseIPDB 2024-11-11 07:53:58 2026-09-11 16:24:18 anomalous-activity attacker malicious-activity reconnaissance
HTTP Scrapper AbuseIPDB 2024-11-20 00:06:20 2026-09-11 04:23:20 anomalous-activity attacker malicious-activity
Hacking AbuseIPDB 2024-11-28 06:06:14 2026-09-11 02:33:31 attacker malicious-activity
HTTP Attacker AbuseIPDB 2024-11-14 09:44:09 2026-09-10 20:55:49 attacker malicious-activity
Bruteforce AbuseIPDB 2024-11-14 17:27:04 2026-09-10 07:00:30 attacker malicious-activity
IoT Attacker AbuseIPDB 2025-08-17 08:51:03 2026-09-10 03:40:27 iot malicious-activity
Mail Spammer AbuseIPDB 2025-01-08 08:00:12 2026-09-08 08:40:17 attacker malicious-activity
SSH Attacker AbuseIPDB 2024-11-19 12:42:46 2026-09-08 02:28:13 attacker malicious-activity
Malicious Host AbuseIPDB 2024-07-02 04:27:28 2026-09-04 07:00:06 attacker compromised malicious-activity
IMAP Attacker AbuseIPDB 2024-12-20 01:24:44 2026-08-31 06:18:09 attacker malicious-activity
Phishing AbuseIPDB 2025-08-28 23:12:09 2026-08-31 06:18:09 malicious-activity phishing
DDoS Attacker AbuseIPDB 2025-07-17 07:08:44 2026-07-29 15:33:21 attacker malicious-activity
DNS Compromise AbuseIPDB 2025-01-08 21:36:10 2026-06-25 06:14:06 compromised malicious-activity
SSH Attacker Blocklist.de 2022-12-02 00:57:58 2026-06-04 14:00:16 malicious-activity
Proxy AbuseIPDB 2025-08-18 02:02:05 2026-03-12 03:02:03 anonymization
Suspicious Host AbuseIPDB 2024-09-13 08:46:58 2025-12-18 11:05:54 anomalous-activity
FTP Attacker AbuseIPDB 2025-03-08 13:25:06 2025-10-05 11:06:01 malicious-activity
SQL Injection AbuseIPDB 2025-01-08 21:36:10 2025-10-05 10:51:02 malicious-activity
Mail Spammer Blocklist.de 2024-06-01 03:16:31 2025-09-21 07:56:34 malicious-activity
DDoS attack AbuseIPDB 2025-01-08 21:36:10 2025-08-12 21:29:42 malicious-activity
Malicious Host CIArmy 2022-09-13 04:15:22 2025-04-07 00:25:32 malicious-activity
DNS Poisoning AbuseIPDB 2024-12-25 11:20:04 2025-03-01 00:59:22 compromised
Unauthorized scanning of hosts Blocklist.net.ua 2024-12-08 16:39:09 2024-12-08 16:39:09 malicious-activity
Malicious Host HoneyDB 2023-02-25 00:00:00 2024-01-01 00:00:00 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2022-09-14 03:06:24 2023-06-19 12:59:44 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2022-09-14 03:06:22 2023-06-19 12:59:35 malicious-activity
SSH Attacker Maltiverse 2022-10-27 15:30:18 2023-01-20 22:54:42 malicious-activity
Bruteforce Maltiverse 2022-10-25 07:43:57 2023-01-20 22:54:42 malicious-activity
Port Scanner Maltiverse 2022-10-24 10:16:49 2023-01-20 22:54:42 anomalous-activity
Hacking Maltiverse 2022-10-25 04:54:29 2023-01-19 11:00:41 malicious-activity
Malicious Host Maltiverse 2022-10-25 04:54:29 2023-01-19 11:00:41 compromised malicious-activity
DDoS attack Maltiverse 2022-12-22 13:10:00 2023-01-18 19:39:11 malicious-activity
HTTP Attacker Maltiverse 2022-10-27 06:26:23 2023-01-18 03:57:03 malicious-activity
Mail Spammer Maltiverse 2022-10-30 19:02:15 2023-01-12 05:30:40 malicious-activity
HTTP Scrapper Maltiverse 2022-12-04 01:10:32 2022-12-23 08:18:09 anomalous-activity
IoT Attacker Maltiverse 2022-12-09 09:53:21 2022-12-09 09:53:21 malicious-activity
DNS Poisoning Maltiverse 2022-12-04 01:10:32 2022-12-04 01:10:32 compromised
FTP Attacker Maltiverse 2022-12-04 01:10:32 2022-12-04 01:10:32 malicious-activity
Proxy Maltiverse 2022-12-04 01:10:32 2022-12-04 01:10:32 anonymization
SIP Attacker Maltiverse 2022-10-29 08:48:50 2022-10-29 08:48:50 malicious-activity

Tags

ssh bruteforce bot mail spam abuse

Whois information

AS name
AS14987 Rethem Hosting LLC
AS registry
arin
AS date
2014-07-11 00:00:00
AS CIDR
104.152.52.0/24
CIDR
104.152.52.0/22
Registrant
Rethem Hosting LLC
Address
500 N. Michigan Ave Suite 300
City
Chicago
State
IL
Postal code
60666
Country
US β€” United States πŸ‡ΊπŸ‡Έ
Contact email
[email protected]
First indexed
2022-09-13 04:15:22
Last updated
2026-09-11 19:30:54

Malicious IPs in the same CIDR

104.152.52.243 104.152.52.208 104.152.52.209 104.152.52.143 104.152.52.136 104.152.52.132 104.152.52.213 104.152.52.234 104.152.52.202 104.152.52.122 104.152.52.45 104.152.52.220 104.152.52.114 104.152.52.221 104.152.52.128 104.152.52.147 104.152.52.133 104.152.52.205 104.152.52.210 104.152.52.226 104.152.52.120 104.152.52.121 104.152.52.117 104.152.52.224 104.152.52.242