← Back to feed

104.152.52.142

Threat Confidence
18%
Location
🇺🇸 US
ASN
AS14987 · Rethem Hosting LLC
Cloud Provider
Total Events
3
Below average by volume
Agent Count
1
First / Last Seen
2026-04-29 04:35 — 2026-04-29 04:35
Attack Types
ssh:bruteforce
MITRE ATT&CK Techniques
Reconnaissance
Credential Access
Discovery
External Corroboration
Not flagged by any external feeds
Campaigns
Multi-Agent Scan SCAN Active medium
80 IPs 154716 events
2026-04-21 — ongoing · 80 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
82 IPs 155541 events
2026-04-21 — ongoing · 82 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
82 IPs 155538 events
2026-04-21 — ongoing · 82 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
81 IPs 141109 events
2026-04-21 — ongoing · 81 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
8 IPs 948 events
2026-03-17 — ongoing · 8 IPs independently targeted the same honeypot sensors within a 24-hour window. Hosted on Linode. Scanning the same …
Multi-Agent Scan SCAN Active medium
97 IPs 34316 events
2026-03-14 — ongoing · 97 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
24 IPs 9173 events
2026-03-07 — ongoing · 24 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
57 IPs 13751 events
2026-02-23 — ongoing · 57 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Multi-Agent Scan SCAN Active medium
23 IPs 2623 events
2026-02-23 — ongoing · 23 IPs independently targeted the same honeypot sensors within a 24-hour window. Scanning the same targets in close …
Subnet 104.152.52.0/24 SUBNET Active high 🇺🇸 US
9 IPs 45 events
ssh:bruteforce
2026-02-19 — ongoing · 9 IPs from the same /24 subnet (104.152.52.0/24) were observed attacking our sensors within the same time window. …
Session Forensics
scanner ×3
Sessions
3
Avg Depth Score
0.15
Commands Executed
0
Files Downloaded
0
Fingerprints
\xca\xc6ؐ\xfa\xe5:\xc7N\xfeM\xe4U\xa7p\xfe\xa6Y\x82\x8c\xb9\x8b\x85WlJU\xaeɃ \xd1I%yto\xe7{\xdbL\xe7\xa4BXC\xea\xfap^\x80)\xe2\xeb\x8b!\x8f,\xc0+\xc0/\xc0,\xc00̨̩\xc0 \xc0\xc0SSH-2.0-Go
Evidence Timeline
Scanner 295a5bf85dd1 newark_01 · 2026-05-02 22:03
15%
Loading events...
Scanner a7513a987895 w4m_seattle_01 · 2026-05-01 03:47
15%
Loading events...
Scanner d1daf12e9f0f w4m_seattle_01 · 2026-04-29 04:35
15%
Loading events...