This IP address has been reported a total of
42
times from
38 distinct
sources.
142.93.111.157 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
(TLS,handshake,Dovecot,failure) Login failure/trigger from 142.93.111.157 (DE/Germany/-): 3 in the l ...
show more(TLS,handshake,Dovecot,failure) Login failure/trigger from 142.93.111.157 (DE/Germany/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: Aug 20 21:44:49 dovecot: imap-login: Disconnected (no auth attempts in 6 secs): user=[USERNAME] rip=142.93.111.157, lip=0.0.0.x, TLS handshaking: SSL_accept() failed: error:1420918C:SSL routines:tls_early_post_process_client_hello:version too low, session=<mhIv6n5ZxTSOXW+d>
Aug 20 21:44:50 dovecot: imap-login: Disconnected (no auth attempts in 0 secs): user=[USERNAME] rip=142.93.111.157, lip=0.0.0.x, TLS handshaking: SSL_accept() failed: error:1417A0C1:SSL routines:tls_post_process_client_hello:
show less
[RoutePulse | 2026-08-19T19:27:41Z | RTBH-INJECTED]
ATTACK CLASS: exchange_bruteforce
SOURCE: 142.93 ...
show more[RoutePulse | 2026-08-19T19:27:41Z | RTBH-INJECTED]
ATTACK CLASS: exchange_bruteforce
SOURCE: 142.93.111.157 ยท AS14061 DigitalOcean, LLC ยท Germany
EVIDENCE: Mail-transport credential probing on exchange.goline.ch โ 15 accepted connections with zero real sessions in 60min via POP3S (FortiAnalyzer perimeter log: the balancer SNATs these protocols, so this is the only source of the real client IP)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
[2026-08-19 18:21:09] 142.93.111.157 triggered a honeypot. Requested on port 80. URI: /HNAP1, UA: Mo ...
show more[2026-08-19 18:21:09] 142.93.111.157 triggered a honeypot. Requested on port 80. URI: /HNAP1, UA: Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)
...
show less
Bad Web Bot
Brute-Force
Web App Attack
Hacking
SQL Injection
2026-08-20T00:49:00.519087+07:00 rapi postfix/smtpd[2385739]: lost connection after EHLO from unknow ...
show more2026-08-20T00:49:00.519087+07:00 rapi postfix/smtpd[2385739]: lost connection after EHLO from unknown[142.93.111.157]
2026-08-20T00:49:00.692520+07:00 rapi postfix/smtpd[2385739]: improper command pipelining after CONNECT from unknown[142.93.111.157]: HELP\r\n
show less
Unsolicited TCP connection from 142.93.111.157 to port 0 at 2026-08-19T12:34:57Z. Source IP complete ...
show moreUnsolicited TCP connection from 142.93.111.157 to port 0 at 2026-08-19T12:34:57Z. Source IP completed three-way handshake to non-public service on this host. Detected by automated intrusion monitoring.
show less