52.159.140.52

Classification: Whitelisted

52.159.140.52 is a whitelisted (trusted) IP address. Reported by 3 threat sources, last seen 2026-08-05. Network: AS8075 Microsoft Corporation.

Current activity

  • Known attacker β€” Seen launching attacks over the Internet.
  • Known scanner β€” Seen scanning hosts over the Internet.

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Matched whitelist source: Microsoft_asn Maltiverse 2026-08-05 14:00:34 2026-08-05 14:00:34 benign
SSH Attacker Blocklist.de 2026-08-05 14:00:32 2026-08-05 14:00:32 attacker malicious-activity
Port Scanner AbuseIPDB 2026-06-24 20:12:33 2026-08-04 22:45:00 anomalous-activity attacker malicious-activity reconnaissance
SSH Attacker AbuseIPDB 2026-08-04 12:10:22 2026-08-04 17:44:14 attacker malicious-activity
Bruteforce AbuseIPDB 2026-06-24 21:58:47 2026-08-04 17:44:14 attacker malicious-activity
HTTP Attacker AbuseIPDB 2026-06-24 21:58:47 2026-08-04 12:33:15 attacker malicious-activity
Hacking AbuseIPDB 2026-06-24 20:22:43 2026-06-25 00:45:06 attacker malicious-activity
HTTP Scrapper AbuseIPDB 2026-06-24 21:58:47 2026-06-24 21:58:47 anomalous-activity
Malicious Host AbuseIPDB 2026-06-24 20:22:43 2026-06-24 20:22:43 compromised malicious-activity

Tags

ssh bruteforce bot

Whois information

AS name
AS8075 Microsoft Corporation
Registrant
Microsoft Corporation
City
San Jose
State
CA
Postal code
95110
Country
US β€” United States πŸ‡ΊπŸ‡Έ
First indexed
2026-08-05 14:00:32
Last updated
2026-08-05 14:00:32