IOC Radar
IPMediumSignal 76/100

105.73.202.217

Location
MoroccoMorocco
Méchouar de Casablanca, Casablanca-Settat
ASN
AS36884
Wana Corporate
First Seen
Dec 26, 2024
Last Seen
Feb 24, 2026
Dec 26
First Seen
546d ago
Feb 24
Last Seen
121d ago
7
Reports
source reports
76%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
76%
Signal Score
76 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

34 techniques

Network Information

CountryMAMorocco
RegionMéchouar de Casablanca, Casablanca-Settat
ASNAS36884
OrganizationWana Corporate

Feed Intelligence Summary

7 reports76% confidence
7
Source reports
76%
Confidence score
Category tags
abuseaccess controlactive scanningafricaaustraliabotnetbrute forcebrute force attackbrute force attacksbrute force attemptcommand and controlcommunication protocolcowrie honeypotcredential accesscredential stuffingdata exfiltrationddosddos attacksdecoy systemdenial of servicedionaea honeypotdistributed attacksexploit attemptsfattftpftp brute forcehoneytrap honeypothttp brute forcehttp scannerindicatorinternet of thingsintrusion detectioniociot botnetiot/ics attacklateral movementlogin failuremamailoney honeypotmalicious activitymalicious softwaremalwaremalware behaviourmalware capturemalware propagationmalware scanningmirai botnetmorocconetworknetwork attacksnetwork intrusionnetwork intrusion attemptsnetwork probingnetwork scanningnetwork securitynetwork service scanningoceaniap0fpassword attackpassword attacksphishing attackphishing trapprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedresource hijackingscanscannersecurity policysensor-taggedsentrypeer botnetsmtpsmtp brute forcesql injection attemptsssh attackssh monitoringt1021t1021.001t1021.002t1040t1046t1055t1059t1059.004t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1199t1204.002t1210t1486t1496t1499.001t1499.002t1499.003t1563t1565t1588t1595t1595.001t1595.002t1595.003tannertcp protocoltcp/23telecommunicationstelnet threatthreat detectionthreat intelligencethreat preventiontpotvoipvoip attackweb traffic

Activity Timeline

1 total obs
Feb 24Feb 24

Threat Activity Heatmap

· Peak: 2026-02-24
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreHigh Risk
76
SIGNAL
Signal Score
76%
Confidence
7
Reports
First seenDec 26, 2024
Last seenFeb 24, 2026
GeolocationMA
CountryMorocco
LocationMéchouar de Casablanca, Casablanca-Settat
ASNAS36884
OrgWana Corporate
Coords32.0000, -5.0000

VirusTotal

Not checked

WHOIS

raw
inetnum: 105.64.0.0 - 105.79.255.255 netname: WANA-INWI-IPv4-2014 descr: Wana Corporate country: MA org: ORG-MC5-AFRINIC admin-c: HE9-AFRINIC tech-c: HE9-AFRINIC status: ALLOCATED PA mnt-by: AFRINIC-HM-MNT mnt-lower: MCNET-MNT mnt-domains: MCNET-MNT source: AFRINIC # Filtered parent: 105.0.0.0 - 105.255.255.255 organisation: ORG-MC5-AFRINIC org-name: Wana Corporate org-type: LIR country: MA address: Lotissement La Colline II - Lot. 1 - 2 - Sidi Maârouf address: Casablanca 20190 phone: tel:+212-5290-00000 fax-no: tel:+212-5290-00610 admin-c: HE9-AFRINIC tech-c: HE9-AFRINIC mnt-ref: AFRINIC-HM-MNT mnt-ref: MCNET-MNT mnt-by: AFRINIC-HM-MNT source: AFRINIC # Filtered person: Hassan Elmansouri address: Lotissement La Colline II - Lot 1 et 2 Sidi Maarouf phone: tel:+212-5290-00000 nic-hdl: HE9-AFRINIC mnt-by: GENERATED-ZC4BQXQQZWNYOHFUBNFHDRV4CONR4FIV-MNT source: AFRINIC # Filtered route: 105.64.0.0/12 descr: Provider 36884 Wana Corporate origin: AS36884 mnt-by: MCNET-MNT source: AFRINIC # Filtered

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 7 threat reports