🇺🇸
mnogoweb
2026-08-31 19:02:38
(1 day ago)
(smtpauth) Failed SMTP AUTH login from 117.50.194.130 (CN/China/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 117.50.194.130 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-08-31 12:13:49 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-31 12:19:32 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-31 12:54:17 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-31 12:57:17 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-31 12:58:42 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇺🇸
mnogoweb
2026-08-30 22:14:35
(2 days ago)
(smtpauth) Failed SMTP AUTH login from 117.50.194.130 (CN/China/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 117.50.194.130 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-08-30 15:30:11 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-30 15:30:28 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-30 15:49:53 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
2026-08-30 16:00:48 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data
2026-08-30 16:14:33 login authenticator failed for (117.50.194.130) [117.50.194.130]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇵🇱
MatStef132
2026-08-30 02:53:33
(2 days ago)
MatShield L7: blocked on test-clean.mathost.eu (ua-quarantined)
Bad Web Bot
🇳🇱
EGP Abuse Dept
2026-08-29 06:19:44
(3 days ago)
Port connection indicating compromised host
Port Scan
Hacking
Exploited Host
🇮🇩
sockominfo
2026-08-22 19:00:10
(1 week ago)
Zimbra: Login failures from malicious IP: 117.50.194.130. Threat Score: 6/10 (MEDIUM). Reported by T ...
show more
Zimbra: Login failures from malicious IP: 117.50.194.130. Threat Score: 6/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇪
anycast_ac
2026-08-19 06:29:01
(1 week ago)
[WebProtection] L4/L7 attack source · PROTO-443-SILENT-DROP · 5 hits/window
Port Scan
Anonymous
2026-08-13 16:30:31
(2 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
🇪🇸
el-brujo
2026-08-13 16:23:00
(2 weeks ago)
HTTP DDoS Attack Layer 7
DDoS Attack
🇩🇪
anycast_ac
2026-08-11 10:39:40
(3 weeks ago)
[WebProtection] L4/L7 attack source · PROTO-443-SILENT-DROP · 5 hits/window
Port Scan
🇩🇪
anycast_ac
2026-08-05 15:59:43
(3 weeks ago)
[WebProtection] L4/L7 attack source · PROTO-443-SILENT-DROP · 5 hits/window
Port Scan
Anonymous
2026-08-02 22:53:01
(4 weeks ago)
...
Brute-Force
🇨🇦
1gz
2026-07-31 20:25:51
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
COMPLEX
2026-07-28 19:39:29
(1 month ago)
Banned by Multi Agent · node …jrh1 · reason=SSH banner invalid / banner exchange invalid format · at ...
show more
Banned by Multi Agent · node …jrh1 · reason=SSH banner invalid / banner exchange invalid format · attempts=1 · SSH banner invalid / banner exchange invalid format
show less
Brute-Force
SSH
🇮🇩
sockominfo
2026-07-27 19:00:52
(1 month ago)
Zimbra: Login failures from malicious IP: 117.50.194.130. Threat Score: 6.4/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 117.50.194.130. Threat Score: 6.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 75%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-07-27 18:00:52
(1 month ago)
Zimbra: Login failures from malicious IP: 117.50.194.130. Threat Score: 6.4/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 117.50.194.130. Threat Score: 6.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 68%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack