104.152.52.25

Classification: Suspicious

104.152.52.25 is a suspicious IP address. Reported by 11 threat sources, last seen 2026-08-07. Network: AS14987 Rethem Hosting LLC.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
SSH Attacker Blocklist.de 2020-03-26 07:19:34 2026-08-07 14:00:06 attacker malicious-activity
Suspicious Host AbuseIPDB 2024-07-13 02:04:04 2026-05-21 09:19:48 anomalous-activity
DDoS Attacker Blocklist.net.ua 2024-12-13 08:40:36 2025-06-08 12:14:42 malicious-activity
SSH Attacker AbuseIPDB 2024-11-26 07:48:16 2025-03-18 02:28:49 malicious-activity
Bruteforce AbuseIPDB 2024-11-15 14:03:21 2025-03-17 14:02:27 malicious-activity
Port Scanner AbuseIPDB 2024-11-16 11:03:43 2025-03-17 06:45:40 anomalous-activity
Hacking AbuseIPDB 2024-11-30 12:46:01 2025-03-16 01:38:22 malicious-activity
HTTP Attacker AbuseIPDB 2024-11-30 12:46:01 2025-03-16 01:38:22 malicious-activity
DDoS attack AbuseIPDB 2024-12-11 18:51:21 2025-03-07 10:18:03 malicious-activity
Mail Spammer AbuseIPDB 2024-11-24 22:31:37 2025-02-26 10:33:18 malicious-activity
HTTP Scrapper AbuseIPDB 2025-02-02 19:41:16 2025-02-08 08:24:33 anomalous-activity
IMAP Attacker Blocklist.de 2024-12-06 10:12:44 2024-12-07 09:53:45 malicious-activity
Mail Spammer Blocklist.de 2019-10-27 00:44:16 2024-12-06 10:28:39 malicious-activity
FTP Attacker AbuseIPDB 2024-11-23 13:00:12 2024-11-23 13:00:12 malicious-activity
Malicious Host CIArmy 2019-01-01 07:16:59 2021-08-15 04:45:32 malicious-activity
Malicious Host HoneyDB 2019-07-23 00:00:00 2021-04-30 00:00:00 malicious-activity
Unauthorized scanning of hosts Blocklist.net.ua 2020-09-20 03:35:53 2021-04-26 01:38:10 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP UDP Emerging Threats 2020-02-15 01:50:52 2021-04-21 10:54:51 malicious-activity
ET CINS Active Threat Intelligence Poor Reputation IP TCP Emerging Threats 2020-02-15 01:50:51 2021-04-21 10:54:47 malicious-activity
Malicious Host Alienvault Ip Reputation Database 2019-01-02 06:46:52 2020-12-07 06:29:50 malicious-activity
Scanning IPs IBM X-Force Exchange 2018-12-17 10:12:00 2019-12-23 16:25:00
Malicious site Hybrid-Analysis 2019-03-04 15:18:56 2019-10-04 11:15:08
SNMP Attacker Nothink.org 2019-09-01 02:37:41 2019-09-01 02:37:41
HTTP Attacker BadIPs 2019-02-12 07:00:03 2019-03-09 06:58:18
Bots IBM X-Force Exchange 2015-08-24 15:49:00 2015-08-24 15:49:00

Tags

mail spam apache attacker modsec snmp bot ssh bruteforce abuse imap pop3 sasl

Whois information

AS name
AS14987 Rethem Hosting LLC
AS registry
arin
AS date
2014-07-11 00:00:00
AS CIDR
104.152.52.0/24
CIDR
104.152.52.0/22
Registrant
Rethem Hosting LLC
Address
500 N. Michigan Ave Suite 300
City
Chicago
State
IL
Postal code
60602
Country
US — United States 🇺🇸
Contact email
[email protected]
First indexed
2019-01-01 07:16:59
Last updated
2026-08-07 14:00:06

Malicious IPs in the same CIDR

104.152.52.243 104.152.52.208 104.152.52.209 104.152.52.143 104.152.52.136 104.152.52.132 104.152.52.213 104.152.52.234 104.152.52.202 104.152.52.122 104.152.52.45 104.152.52.220 104.152.52.114 104.152.52.221 104.152.52.128 104.152.52.147 104.152.52.133 104.152.52.205 104.152.52.210 104.152.52.226 104.152.52.120 104.152.52.121 104.152.52.117 104.152.52.224 104.152.52.242