104.251.225.209 Threat Intelligence - United States | IP Address Lookup

General

IP Address
104.251.225.209
IPv4 Address
Location
🇺🇸 Los Angeles, United States
US
Network
AS18254
KLAYER LLC
Threat Score
48/100
Medium Risk
brute-forcebruteforcecredential-attacksshtpotvultr
Attack Intelligence
MITRE ATT&CK Techniques
T1046 - Network Service Scanning, T1110 - Brute Force, T1190 - Exploit Public-Facing Application
Noticed
4 times
Protocols Attacked
ssh
Open Ports Detected
8880
Geographic Location
Country
United States
City
Los Angeles
Region
California
Coordinates
34.0544, -118.2441
Network Information
ASN
AS18254
Organization
KLAYER LLC
Network
AS18254 KLAYER LLC
WHOIS Information
NetRange
104.251.224.0 - 104.251.239.255
CIDR
104.251.224.0/20
NetName
PSC-594
NetHandle
NET-104-251-224-0-1
Parent
NET104 (NET-104-0-0-0-0)
NetType
Direct Allocation
Organization
Prime Security Corp. (PSC-594)
RegDate
2023-09-05
Updated
2023-09-05
Ref
https://rdap.arin.net/registry/ip/104.251.224.0
OrgName
Prime Security Corp.
OrgId
PSC-594
Address
600 N Broad St Ste 5
City
Middletown
StateProv
DE
PostalCode
19709
Country
US
Comment
Prime Security Corp.
OrgTechHandle
NOC33708-ARIN
OrgTechName
NOC
OrgTechPhone
+1-326-266-6888
OrgTechEmail
noc@primesecuritycorp.com
OrgTechRef
https://rdap.arin.net/registry/entity/NOC33708-ARIN
OrgAbuseHandle
ABUSE8852-ARIN
Attack Logs
DateTarget LocationProtocolLink
2026-07-13 Vultrtokyo SSH View Log
Disclaimer
This page contains threat intelligence information for the IPv4 address 104.251.225.209 and was generated either as a result of observed malicious activity or as an information gathering exercise to assist with enrichment of security events and context. All information is gathered passively through aggregation of public sources, or observations through activity upon honeynets. The host score is calculated through a series of statistically weighted values and machine learning which takes into account metadata such as host information, frequency, volume and global distribution of malicious activity, association with other known malicious hosts or networks, proxying or anonymising behaviour such as with tor exit nodes, residential proxies or VPN services, and many other attributes. These values are historical and indicative only, and should not be taken to be an accurate representation of the users, businesses or networks in which they reside.