AbuseIPDB » 41.143.21.247
41.143.21.247 was found in our database!
This IP was reported 9 times. Confidence of
Abuse
is 35% : ?
ISP
ADSL_Maroc_telecom
Usage Type
Fixed Line ISP
ASN
AS36903
Domain Name
menara.ma
Country
๐ฒ๐ฆ
Morocco
City
Casablanca, Casablanca-Settat
IP info including ISP, Usage Type, and Location provided
by IPInfo . Updated weekly.
IP Abuse Reports for 41.143.21.247 :
This IP address has been reported a total of
9
times from
8 distinct
sources.
41.143.21.247 was first reported on
June 12th 2025 , and the most recent report was
2 weeks ago .
Old Reports:
The most recent abuse report for this IP address is from
2 weeks ago
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-06-15 08:59:37
(2 weeks ago)
Jun 14 18:20:33 localhost kernel: [109820925.056092] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Jun 14 18:20:33 localhost kernel: [109820925.056092] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=41.143.21.247 DST=[mungedIP2] LEN=44 TOS=0x00 PREC=0x00 TTL=241 ID=32983 PROTO=TCP SPT=46939 DPT=1433 WINDOW=1024 RES=0x00 SYN URGP=0
Jun 14 18:20:33 localhost kernel: [109820925.056110] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=41.143.21.247 DST=[mungedIP2] LEN=44 TOS=0x00 PREC=0x00 TTL=241 ID=32983 PROTO=TCP SPT=46939 DPT=1433 SEQ=1511318832 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 OPT (02040218)
Jun 15 04:59:37 localhost kernel: [109859268.302814] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=41.143.21.247 DST=[mungedIP2] LEN=44 TOS=0x00 PREC=0x00 TTL=241 ID=58941 PROTO=TCP SPT=50670 DPT=1433 WINDOW=1024 RES=0x00 SYN URGP=0
Jun 15 04:59:37 localhost kernel: [109859268.302836] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=41.143.21.247 DST=[mungedIP
show less
Port Scan
๐ฉ๐ช
Admins@FBN
2026-06-15 06:30:49
(2 weeks ago)
FW-PortScan: Traffic Blocked srcport=46939 dstport=1433
Port Scan
Hacking
SQL Injection
๐บ๐ธ
MPL
2026-06-15 05:07:52
(2 weeks ago)
tcp/1433 (3 or more attempts)
Port Scan
๐บ๐ธ
MPL
2026-06-15 03:54:31
(2 weeks ago)
tcp/1433
Port Scan
๐ฆ๐บ
LiftUp Hosting
2026-06-15 01:16:16
(2 weeks ago)
Honeypot hit: MSSQL traffic (on 1433) with username sa and empty password
Brute-Force
๐บ๐ธ
cybsecaoccol
2026-06-14 21:56:43
(2 weeks ago)
unauthorized connection or malicious port scan attempted on tcp port - corp
Port Scan
Hacking
Anonymous
2026-06-14 12:28:39
(2 weeks ago)
Honeypot hit: MSSQL traffic (on 1433) with username sa and empty password
Reported by: https://githu ...
show more
Honeypot hit: MSSQL traffic (on 1433) with username sa and empty password
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Brute-Force
๐ฆ๐บ
prologic
2026-06-12 22:14:52
(2 weeks ago)
Coordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 ...
show more
Coordinated application-layer DDoS against git.mills.io (self-hosted Gitea), 2026-06-12 ~20:30-21:10 UTC. Deliberately expensive multi-label Gitea issue-search queries (/issues?type=all&state=closed&sort=...&labels=<multiple IDs>, ~60-113s CPU each) flooded the backend via proxy/hosting networks. ~36,700 source IPs, ~1 request per IP, identical TLS fingerprint (TLS1.3 0x1301) and one spoofed Chrome UA = single automated tool.
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TheMadBeaker
2025-06-12 15:42:46
(1 year ago)
Fail2Ban Ban Triggered
HTTP Exploit Attempt
Brute-Force
Web App Attack
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ
Recently Reported IPs: