104.152.52.243
Classification: Malicious
104.152.52.243 is a malicious IP address. Reported by 7 threat sources, last seen 2026-09-11. Network: AS14987 Rethem Hosting LLC.
Current activity
- Known attacker β Seen launching attacks over the Internet.
- Known scanner β Seen scanning hosts over the Internet.
- IoT threat β Seen attacking IoT devices.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Port Scanner | AbuseIPDB | 2024-11-11 07:53:58 | 2026-09-11 16:24:18 | anomalous-activity attacker malicious-activity reconnaissance | |
| HTTP Scrapper | AbuseIPDB | 2024-11-20 00:06:20 | 2026-09-11 04:23:20 | anomalous-activity attacker malicious-activity | |
| Hacking | AbuseIPDB | 2024-11-28 06:06:14 | 2026-09-11 02:33:31 | attacker malicious-activity | |
| HTTP Attacker | AbuseIPDB | 2024-11-14 09:44:09 | 2026-09-10 20:55:49 | attacker malicious-activity | |
| Bruteforce | AbuseIPDB | 2024-11-14 17:27:04 | 2026-09-10 07:00:30 | attacker malicious-activity | |
| IoT Attacker | AbuseIPDB | 2025-08-17 08:51:03 | 2026-09-10 03:40:27 | iot malicious-activity | |
| Mail Spammer | AbuseIPDB | 2025-01-08 08:00:12 | 2026-09-08 08:40:17 | attacker malicious-activity | |
| SSH Attacker | AbuseIPDB | 2024-11-19 12:42:46 | 2026-09-08 02:28:13 | attacker malicious-activity | |
| Malicious Host | AbuseIPDB | 2024-07-02 04:27:28 | 2026-09-04 07:00:06 | attacker compromised malicious-activity | |
| IMAP Attacker | AbuseIPDB | 2024-12-20 01:24:44 | 2026-08-31 06:18:09 | attacker malicious-activity | |
| Phishing | AbuseIPDB | 2025-08-28 23:12:09 | 2026-08-31 06:18:09 | malicious-activity phishing | |
| DDoS Attacker | AbuseIPDB | 2025-07-17 07:08:44 | 2026-07-29 15:33:21 | attacker malicious-activity | |
| DNS Compromise | AbuseIPDB | 2025-01-08 21:36:10 | 2026-06-25 06:14:06 | compromised malicious-activity | |
| SSH Attacker | Blocklist.de | 2022-12-02 00:57:58 | 2026-06-04 14:00:16 | malicious-activity | |
| Proxy | AbuseIPDB | 2025-08-18 02:02:05 | 2026-03-12 03:02:03 | anonymization | |
| Suspicious Host | AbuseIPDB | 2024-09-13 08:46:58 | 2025-12-18 11:05:54 | anomalous-activity | |
| FTP Attacker | AbuseIPDB | 2025-03-08 13:25:06 | 2025-10-05 11:06:01 | malicious-activity | |
| SQL Injection | AbuseIPDB | 2025-01-08 21:36:10 | 2025-10-05 10:51:02 | malicious-activity | |
| Mail Spammer | Blocklist.de | 2024-06-01 03:16:31 | 2025-09-21 07:56:34 | malicious-activity | |
| DDoS attack | AbuseIPDB | 2025-01-08 21:36:10 | 2025-08-12 21:29:42 | malicious-activity | |
| Malicious Host | CIArmy | 2022-09-13 04:15:22 | 2025-04-07 00:25:32 | malicious-activity | |
| DNS Poisoning | AbuseIPDB | 2024-12-25 11:20:04 | 2025-03-01 00:59:22 | compromised | |
| Unauthorized scanning of hosts | Blocklist.net.ua | 2024-12-08 16:39:09 | 2024-12-08 16:39:09 | malicious-activity | |
| Malicious Host | HoneyDB | 2023-02-25 00:00:00 | 2024-01-01 00:00:00 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP UDP | Emerging Threats | 2022-09-14 03:06:24 | 2023-06-19 12:59:44 | malicious-activity | |
| ET CINS Active Threat Intelligence Poor Reputation IP TCP | Emerging Threats | 2022-09-14 03:06:22 | 2023-06-19 12:59:35 | malicious-activity | |
| SSH Attacker | Maltiverse | 2022-10-27 15:30:18 | 2023-01-20 22:54:42 | malicious-activity | |
| Bruteforce | Maltiverse | 2022-10-25 07:43:57 | 2023-01-20 22:54:42 | malicious-activity | |
| Port Scanner | Maltiverse | 2022-10-24 10:16:49 | 2023-01-20 22:54:42 | anomalous-activity | |
| Hacking | Maltiverse | 2022-10-25 04:54:29 | 2023-01-19 11:00:41 | malicious-activity | |
| Malicious Host | Maltiverse | 2022-10-25 04:54:29 | 2023-01-19 11:00:41 | compromised malicious-activity | |
| DDoS attack | Maltiverse | 2022-12-22 13:10:00 | 2023-01-18 19:39:11 | malicious-activity | |
| HTTP Attacker | Maltiverse | 2022-10-27 06:26:23 | 2023-01-18 03:57:03 | malicious-activity | |
| Mail Spammer | Maltiverse | 2022-10-30 19:02:15 | 2023-01-12 05:30:40 | malicious-activity | |
| HTTP Scrapper | Maltiverse | 2022-12-04 01:10:32 | 2022-12-23 08:18:09 | anomalous-activity | |
| IoT Attacker | Maltiverse | 2022-12-09 09:53:21 | 2022-12-09 09:53:21 | malicious-activity | |
| DNS Poisoning | Maltiverse | 2022-12-04 01:10:32 | 2022-12-04 01:10:32 | compromised | |
| FTP Attacker | Maltiverse | 2022-12-04 01:10:32 | 2022-12-04 01:10:32 | malicious-activity | |
| Proxy | Maltiverse | 2022-12-04 01:10:32 | 2022-12-04 01:10:32 | anonymization | |
| SIP Attacker | Maltiverse | 2022-10-29 08:48:50 | 2022-10-29 08:48:50 | malicious-activity |
Tags
ssh bruteforce bot mail spam abuseWhois information
- AS name
- AS14987 Rethem Hosting LLC
- AS registry
- arin
- AS date
- 2014-07-11 00:00:00
- AS CIDR
- 104.152.52.0/24
- CIDR
- 104.152.52.0/22
- Registrant
- Rethem Hosting LLC
- Address
- 500 N. Michigan Ave Suite 300
- City
- Chicago
- State
- IL
- Postal code
- 60666
- Country
- US β United States πΊπΈ
- Contact email
- [email protected]
- First indexed
- 2022-09-13 04:15:22
- Last updated
- 2026-09-11 19:30:54
Malicious IPs in the same CIDR
104.152.52.243 104.152.52.208 104.152.52.209 104.152.52.143 104.152.52.136 104.152.52.132 104.152.52.213 104.152.52.234 104.152.52.202 104.152.52.122 104.152.52.45 104.152.52.220 104.152.52.114 104.152.52.221 104.152.52.128 104.152.52.147 104.152.52.133 104.152.52.205 104.152.52.210 104.152.52.226 104.152.52.120 104.152.52.121 104.152.52.117 104.152.52.224 104.152.52.242