AbuseIPDB » 196.217.25.119
196.217.25.119 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 51% : ?
ISP
Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM
Usage Type
Fixed Line ISP
ASN
AS36903
Hostname(s)
adsl196-119-25-217-196.adsl196-9.iam.net.ma
Domain Name
iam.ma
Country
🇲🇦
Morocco
City
Rabat, Rabat-Sale-Kenitra
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 196.217.25.119 :
This IP address has been reported a total of
9
times from
8 distinct
sources.
196.217.25.119 was first reported on
June 17th 2026 , and the most recent report was
22 hours ago .
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
🇳🇱
BlueWire Hosting
2026-06-18 10:18:48
(22 hours ago)
Probing websites for vulnerabilities
Web App Attack
🇫🇮
inlink.ltd
2026-06-18 08:21:04
(1 day ago)
Known malicious PHP file or CMS probe
Web App Attack
🇩🇪
big-cloud.nl
2026-06-18 07:14:42
(1 day ago)
Try to access /xmlrpc.php
Web App Attack
🇬🇷
setupgr
2026-06-17 23:11:32
(1 day ago)
(XMLRPC) WP XMLPRC Attack 196.217.25.119 (MA/Morocco/Rabat-Salé-Kénitra/Rabat/-/[AS36903 MT-MPLS]) ...
show more
(XMLRPC) WP XMLPRC Attack 196.217.25.119 (MA/Morocco/Rabat-Salé-Kénitra/Rabat/-/[AS36903 MT-MPLS]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 196.217.25.119 - - [18/Jun/2026:02:07:22 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18934 "-" "Mozilla/5.0 (Linux; Android 10; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/12.0.0.0 Safari/537.36"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-06-17 22:36:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 196.217.25.119 (adsl196-119-25-217-196.adsl196- ...
show more
(mod_security) mod_security (id:225170) triggered by 196.217.25.119 (adsl196-119-25-217-196.adsl196-9.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 18:36:51.723893 2026] [security2:error] [pid 9739:tid 9739] [client 196.217.25.119:49658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||uphillfarmvt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "uphillfarmvt.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ajMhg_L76WtAllwovl7d_wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-17 22:07:04
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 196.217.25.119 (adsl196-119-25-217-196.adsl196- ...
show more
(mod_security) mod_security (id:225170) triggered by 196.217.25.119 (adsl196-119-25-217-196.adsl196-9.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 18:06:57.686994 2026] [security2:error] [pid 21343:tid 21351] [client 196.217.25.119:54436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||travelusa.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "travelusa.us"] [uri "/wp-json/wp/v2/users"] [unique_id "ajMagWVCvpR3SYbpIjn64wAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-06-17 21:35:10
(1 day ago)
(wordpress) Failed wordpress login from 196.217.25.119 (MA/Morocco/Rabat-Salé-Kénitra/Rabat/adsl196- ...
show more
(wordpress) Failed wordpress login from 196.217.25.119 (MA/Morocco/Rabat-Salé-Kénitra/Rabat/adsl196-119-25-217-196.adsl196-9.iam.net.ma/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇩🇪
LRob.fr
2026-06-17 19:00:20
(1 day ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇸🇬
securejdprop
2026-06-17 16:53:48
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing. crowdsecurity/http-probing
Hacking
Web App Attack
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩
Recently Reported IPs: