The attacker and host will generally need to be on the same network so that the attacker's packets are not dropped because they are addressed to a non-routable private IP address.
You could access the containers at 106.12.52.111 if you were in the same network (e.g. 106.12.52.0/24) and the packets did not have to traverse a router.
> Also is this still exploitable if you reject everything at the iptables level before you start using Docker?
Yes. Docker appends the FORWARD chain with custom rules that explicitly forward traffic to published ports.