← Back to feed
104.152.52.142
Location
🇺🇸 US
ASN
AS14987 · Rethem Hosting LLC
Cloud Provider
—
Total Events
3
Below average by volume
Agent Count
1
First / Last Seen
2026-04-29 04:35 — 2026-04-29 04:35
Attack Types
MITRE ATT&CK Techniques
External Corroboration
Not flagged by any external feeds
Campaigns
Multi-Agent Scan
SCAN
Active
medium
80 IPs
154716 events
2026-04-21 — ongoing · 80 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
82 IPs
155541 events
2026-04-21 — ongoing · 82 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
82 IPs
155538 events
2026-04-21 — ongoing · 82 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
81 IPs
141109 events
2026-04-21 — ongoing · 81 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
8 IPs
948 events
2026-03-17 — ongoing · 8 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on Linode. Scanning the same …
Multi-Agent Scan
SCAN
Active
medium
97 IPs
34316 events
2026-03-14 — ongoing · 97 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
24 IPs
9173 events
2026-03-07 — ongoing · 24 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
57 IPs
13751 events
2026-02-23 — ongoing · 57 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan
SCAN
Active
medium
23 IPs
2623 events
2026-02-23 — ongoing · 23 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Subnet 104.152.52.0/24
SUBNET
Active
high
🇺🇸 US
9 IPs
45 events
ssh:bruteforce
2026-02-19 — ongoing · 9 IPs from the same /24 subnet (104.152.52.0/24) were observed attacking our sensors within the same time window. …
Session Forensics
Sessions
3
Avg Depth Score
0.15
Commands Executed
0
Files Downloaded
0
Fingerprints
HASSH
SSH Client
Evidence Timeline
Scanner
d1daf12e9f0f
15%
Loading events...
\xca\xc6ؐ\xfa\xe5:\xc7N\xfeM\xe4…