🖥 152.53.225.147 — netcup GmbH
netcup GmbH · AS197540 · DE · 152.53.225.0/24 · IP Blocklists · threat 0.50 · 34x · 21 sources · PTR v2202504267383332676.goodsrv.de
reputation 37.2 (GUARDED)
· first seen 16h ago · last seen 9h ago
No special flags ip medium-severity auto-tagged
Reputation
37.2
GUARDED
Threat Score
0.50
34 sightings
ASN
AS197540
from indicator
Peers on ASN
1
malicious co-tenants
Bad neighborhood
0
152.53.225.0/24
Country
DE
from indicator
🕵 Team Cymru Scout
Team Cymru Scout not configured — add config.scout.php or set cymruscout in API Config.
🌐 Network & Geo (local-first)
| IP | 152.53.225.147 |
| Organization | netcup GmbH |
| ASN | AS197540 |
| Netname | — |
| Netblock | — |
| Reverse DNS (PTR) | v2202504267383332676.goodsrv.de |
| Country | DE country intel |
Identity resolves from the indicator's own columns first, then on demand from the local ip_ranges dataset by integer range — complete even before the bulk resolver runs.
🔥 Threat severity (AS197540 neighborhood)
2
Avg threat 0.5 · peak 0.5 across 2 local IPs on AS197540
📁 Categories (ASN neighborhood)
1
1
🦠 Malware families (ASN neighborhood)
No local data.
🏷 Tags (ASN neighborhood)
1
1
1
🔌 Sources (ASN neighborhood)
1
1
1
1
1
1
1
1
1
1
1
1
1
1
🌎 Geographic spread
2
📅 First-seen timeline
2
Reporting Sources for this IP (21)
FireHOL: firehol_level2.netset | IP Blocklists |
FireHOL: firehol_level3.netset | IP Blocklists |
Blocklist.de: all | IP Blocklists |
Blocklist.de: ssh | IP Blocklists |
ET Compromised | IP Blocklists |
ThreatView IP | IP Blocklists |
IPsum Level 1 | IP Blocklists |
IPsum Level 2 | IP Blocklists |
IPsum Level 3 | IP Blocklists |
IPsum Level 4 | IP Blocklists |
Binary Defense | IP Blocklists |
Blocklist.de All | IP Reputation |
ET Compromised IPs | IP Reputation |
BruteForceBlocker | IP Reputation |
IPsum level 1 (all) | IP Reputation |
IPsum level 5 | IP Reputation |
FireHOL level2 | IP Reputation |
FireHOL level3 | IP Reputation |
Blocklist.de SSH | IP Reputation |
stamparm ipsum | Reputation |
Emerging Threats compromised | C2 |
Passive DNS — domains resolving here (1)
152.53.225.147 2026-08-07 00:43:15
🏠 Same /24 — 152.53.225.0/24 (0 other malicious IPs)
No other flagged IPs in this /24 (or subnet data not populated).
📡 Related indicators on AS197540 (1 total, 1 shown)
| IP | Category | Country | Threat | |
|---|---|---|---|---|
159.195.212.30 |
Dark Web | DE | dossier |
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
Identity resolves local-first: the indicator's own asn/country columns, else on-demand integer-range lookup against the local
ip_ranges dataset — so ASN, org and country populate even before the bulk resolver finishes and even for IPs not yet ingested. Analytics, neighborhood and graph render entirely from the local database; live reputation providers augment only when keys and outbound access are available.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Enrich now to pull reputation/ports
- Check the /24 for a bad neighborhood
- Draft a takedown if abusive
⚙ Automation
Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php