167.172.52.252

Classification: Malicious

167.172.52.252 is a malicious IP address. Reported by 4 threat sources, last seen 2026-09-05. IoC context and downloadable threat intel on Maltiverse.

Current activity

  • Known attacker — Seen launching attacks over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
DDoS Attacker Blocklist.net.ua 2026-04-21 12:59:00 2026-09-05 17:03:17 attacker malicious-activity
Empty reason Blocklist.net.ua 2026-09-04 17:06:56 2026-09-04 17:06:56 attacker malicious-activity
Bruteforce login attacker Blocklist.de 2026-04-21 05:00:40 2026-04-22 05:00:57 malicious-activity
HTTP Attacker Blocklist.de 2026-04-21 03:00:45 2026-04-22 03:00:49 malicious-activity
Suspicious Host AbuseIPDB 2026-04-20 22:30:34 2026-04-21 22:28:20 anomalous-activity
Malicious Host HoneyDB 2020-09-01 00:00:00 2020-09-01 00:00:00

Tags

apache ddos rfi attacker login bruteforce bot joomla wordpress abuse

Whois information

AS registry
ripencc
AS date
1993-08-30 00:00:00
AS CIDR
167.172.48.0/20
CIDR
167.172.0.0/16
Registrant
DigitalOcean, LLC
Address
101 Avenue of the Americas, 10th Floor New York 10013 UNITED STATES
Country
US — United States 🇺🇸
First indexed
2020-09-02 07:01:44
Last updated
2026-09-05 17:03:17

Malicious IPs in the same CIDR

167.172.63.151 167.172.54.184 167.172.52.88 167.172.51.40 167.172.49.228 167.172.59.207 167.172.52.252 167.172.51.43 167.172.48.211 167.172.59.85