This IP address has been reported a total of
14
times from
13 distinct
sources.
162.252.52.183 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show moreMalicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0 | 2026-09-13 09:51 UTC
show less
[RoutePulse | 2026-09-10T22:23:33Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 162.252.52. ...
show more[RoutePulse | 2026-09-10T22:23:33Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 162.252.52.183 ยท AS26548 PureVoltage Hosting Inc. ยท United States
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv โ portal under siege (61 real failed logins / 15 min): 4 attacker IPs in 162.252.52.0/24 from campaign AS26548 PUREVOLTAGE-INC - PureVoltage Hosting Inc. (183 IPs over the campaign); the attacker reuse ยท /24 aggregate member of 162.252.52.0/24
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 162.252.52.183 (US/United States/-): ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 162.252.52.183 (US/United States/-): 1 in the last 3600 secs (0-195)
show less