IOC Radar
IPMediumSignal 11/100

102.50.245.189

Location
MoroccoMorocco
Casablanca, 06
ASN
AS6713
Maroc telecom static ip adress
First Seen
Mar 4, 2025
Last Seen
Sep 2, 2025
Mar 4
First Seen
479d ago
Sep 2
Last Seen
297d ago
3
Reports
source reports
11%
Confidence
medium
Found in 3 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
11%
Signal Score
11 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

23 techniques

Network Information

CountryMAMorocco
RegionCasablanca, 06
ASNAS6713
OrganizationMaroc telecom static ip adress

Feed Intelligence Summary

3 reports11% confidence
3
Source reports
11%
Confidence score
Category tags
active scanningafricaattackbotnetbrute forcecommand and controlcowrie honeypotcowrie honeypot datacredential accesscredential harvestingcredential stuffingdata exfiltrationdecoy systemdistributed attackshoneytrap honeypotindicatorlampmailoney honeypotmalicious activitymalicious softwaremalwaremorocconetworknetwork probingnetwork scanningnetwork service scanningphishingphishing attackphishing trapprocess injectionreconnaissanceresearchedself-signedsftp attacksftp exploit attemptsocial engineeringssh attackssh monitoringt1021t1021.004t1041t1055t1071.001t1110t1110.001t1110.002t1110.003t1190t1486t1496t1499.002t1499.003t1565t1566.001t1566.002t1566.003t1566.004t1595t1595.001t1595.002t1595.003threat actorthreat detectionunauthorized access attempt

Activity Timeline

1 total obs
Sep 2Sep 2

Threat Activity Heatmap

· Peak: 2025-09-02
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreLow Risk
11
SIGNAL
Signal Score
11%
Confidence
3
Reports
First seenMar 4, 2025
Last seenSep 2, 2025
GeolocationMA
CountryMorocco
LocationCasablanca, 06
ASNAS6713
OrgMaroc telecom static ip adress
Coords33.5922, -7.6184

VirusTotal

Not checked

WHOIS

description
2025-02-19T13:19:50.398Z Honeypot : Cowrie : Source: 102.50.245.189 Data: New connection: 102.50.245.189:58630 (172.25.0.2:22) [session: 8f466abcfdd3]
raw
inetnum: 102.48.0.0 - 102.51.255.255 netname: Maroc_telecom_static_ip_adress descr: Maroc telecom static ip adress country: MA admin-c: SMT1-AFRINIC tech-c: DMT1-AFRINIC status: ASSIGNED PA mnt-by: ONPT-MNT source: AFRINIC # Filtered parent: 102.48.0.0 - 102.55.255.255 person: DEMPFS Maroc Telecom nic-hdl: DMT1-AFRINIC address: Si�ge de Maroc telecom Avenue Annakhil Hay Riad Rabat address: Rabat 10100 address: Morocco phone: tel:+212-37284319 phone: tel:+212-37284312 mnt-by: GENERATED-59UQAQ1UAZKQWKK5GWNQRJ9VGMHDFDGD-MNT source: AFRINIC # Filtered person: SEPFS Maroc Telecom nic-hdl: SMT1-AFRINIC address: Service Exploitation des PFS address: MAROC TELECOM address: Avenue Hay Annakhil Riad address: rabat address: Morocco phone: tel:+212-37284319 phone: tel:+212-37284314 mnt-by: GENERATED-QKJHRQGRJU8KJEZGF62S2JCUXLD0D81A-MNT source: AFRINIC # Filtered route: 102.48.0.0/13 descr: route object origin: AS36903 mnt-by: ONPT-MNT source: AFRINIC # Filtered route: 102.48.0.0/13 descr: route object origin: AS6713 mnt-by: ONPT-MNT source: AFRINIC # Filtered
references
https://raw.githubusercontent.com/ahamed-rizvan/IOCs/refs/heads/main/Malicous%20IP%20Address.txt, https://github.com/telekom-security/tpotce

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 9 months ago
Appeared in 3 threat reports