IOC Radar
IPMediumSignal 30/100

196.64.210.33

Location
MoroccoMorocco
Kenitra, Rabat-Salé-Kénitra
ASN
AS36903
Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM
First Seen
Feb 3, 2025
Last Seen
Nov 25, 2025
Feb 3
First Seen
496d ago
Nov 25
Last Seen
201d ago
6
Reports
source reports
30%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
IPv4 Address
Network layer indicator observed in threat reports.
MISP Category
Network Activity
Confidence
30%
Signal Score
30 / 100
IDS Rule
No
Threat Context
Tags

Network Information

CountryMAMorocco
RegionKenitra, Rabat-Salé-Kénitra
ASNAS36903
OrganizationOffice National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM

Feed Intelligence Summary

6 reports30% confidence
6
Source reports
30%
Confidence score
Category tags
africaindicatormamalwaremorocconetworkresearched

Activity Timeline

1 total obs
Nov 25Nov 25

Threat Activity Heatmap

· Peak: 2025-11-25
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), an IPv4 address identified as 196.64.210.33, carries significant implications for organizational security, demanding immediate attention. Its association with the Orcus RAT trojan, a highly potent remote access tool, signifies a potential Command and Control (C2) server or a point of malware distribution. The presence of this IOC in network traffic or logs would strongly suggest a compromised system, opening avenues for unauthorized remote control, extensive d…

Threat ScoreLow Risk
30
SIGNAL
Signal Score
30%
Confidence
6
Reports
First seenFeb 3, 2025
Last seenNov 25, 2025
GeolocationMA
CountryMorocco
LocationKenitra, Rabat-Salé-Kénitra
ASNAS36903
OrgOffice National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM
Coords34.2610, -6.5802

VirusTotal

Not checked

WHOIS

raw
inetnum: 196.64.0.0 - 196.95.255.255 netname: ADSL-4G-SERVICES descr: Maroc Telecom country: MA org: ORG-ONdP1-AFRINIC admin-c: SM13-AFRINIC admin-c: KA89-AFRINIC tech-c: SM13-AFRINIC status: ALLOCATED PA mnt-by: AFRINIC-HM-MNT mnt-lower: ONPT-MNT source: AFRINIC # Filtered parent: 196.0.0.0 - 196.255.255.255 organisation: ORG-ONdP1-AFRINIC org-name: Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM org-type: LIR country: MA address: Division Exploitation et maintenance des PFS address: MAROC TELECOM address: Avenue Hay annakhil immeuble Riad 2 address: Rabat address: Morocoo phone: tel:+212-5372-84314 phone: tel:+212-37203022 admin-c: SM13-AFRINIC admin-c: KA89-AFRINIC tech-c: SM13-AFRINIC mnt-ref: AFRINIC-HM-MNT mnt-ref: ONPT-MNT mnt-by: AFRINIC-HM-MNT remarks: data has been transferred from RIPE Whois Database 20050221 source: AFRINIC # Filtered person: Kaddouhi Abdelaziz address: Avenue Annakhil Maroc Telecom Rabat address: RABAT address: Morocco phone: tel:+212-5372-85549 nic-hdl: KA89-AFRINIC source: AFRINIC # Filtered mnt-by: GENERATED-P6SZUCS7GAJHPELP6WVSRCFIOV8WGIGB-MNT person: Sektaoui Marouane nic-hdl: SM13-AFRINIC address: Maroc Telecom address: Rabat address: Morocco phone: tel:+212-5376-86318 remarks: Ingenieur Reseaux remarks: Service Exploitation des Plates-formes remarks: de Services/Division Exploitation et remarks: Maintenance des Plates-formes de remarks: Services mnt-by: GENERATED-KPHLBILBATGCQACTMADSBE8WVX35UDAG-MNT source: AFRINIC # Filtered route: 196.64.0.0/11 descr: route object origin: AS36903 mnt-by: ONPT-MNT source: AFRINIC # Filtered route: 196.64.0.0/11 descr: route object origin: AS6713 mnt-by: ONPT-MNT source: AFRINIC # Filtered

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 6 months ago
Appeared in 6 threat reports