This IP address has been reported a total of
39
times from
32 distinct
sources.
165.154.50.219 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Blocked by UFW (TCP on 90)
Source port: 40381
TTL: 50
Packet length: 44
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 90)
Source port: 40381
TTL: 50
Packet length: 44
TOS: 0x00
This report (for 165.154.50.219) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Blocked by UFW (TCP on 83)
Source port: 59676
TTL: 51
Packet length: 44
TOS: 0x00
This report (for ...
show moreBlocked by UFW (TCP on 83)
Source port: 59676
TTL: 51
Packet length: 44
TOS: 0x00
This report (for 165.154.50.219) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
SMTP Bruteforce. 2026-09-16T14:50:57.726192+02:00 *.* postfix/submission/smtpd[4080095]: improper co ...
show moreSMTP Bruteforce. 2026-09-16T14:50:57.726192+02:00 *.* postfix/submission/smtpd[4080095]: improper command pipelining after CONNECT from unknown[165.154.50.219]: 026003001000374001000000370003003h313216270<333376017312P220c233314322002=251233365253000225225217350327031245034362k 331023367g377302361267d363004st256+Ou306221322360001Yu027221334B211000315G0004314250314251300/3000300+300,300t0002363142503142520003
2026-09-16T14:51:41.621487+02:00 *.* postfix/submission/smtpd[4080568]: improper command pipelining after CONNECT from unknown[165.154.50.219]: 026003001000306001000000302003003211321M<366)300037rv307Ba350035206333304207<a*024243203274340262257365{222 1T325v.;P355355272245K331"?177275>247<35134303343702235-230365t335000.314250314251300/3000300+300,300t0002363142503142520003
show less
2026-09-16T15:47:56.266237+03:00 ns1 postfix/submission/smtpd[1552990]: improper command pipelining ...
show more2026-09-16T15:47:56.266237+03:00 ns1 postfix/submission/smtpd[1552990]: improper command pipelining after CONNECT from unknown[165.154.50.219]: \026\003\001\000\374\001\000\000\370\003\003\201\026zg\234EP \263DW3EW\365m\233'p\r\325\272\272\005\274K\363\373\374\365\023\020 \372\373f\337\207\234\3404`6\306=\230\253#O\350\2242~D\213\336\260\320\214#FO\342\a&\0004\314\250\314\251\300/\3000\300+\300,\300\t\000\236\314\250\314\252\0003
2026-09-16T15:48:15.291552+03:00 ns1 postfix/submission/smtpd[1553017]: improper command pipelining after CONNECT from unknown[165.154.50.219]: HELP\r\n
...
show less
2026-09-16T22:42:01.356126+10:00 smtp.geddy.au exim[2030978]: SMTP call from [165.154.50.219] droppe ...
show more2026-09-16T22:42:01.356126+10:00 smtp.geddy.au exim[2030978]: SMTP call from [165.154.50.219] dropped: too many syntax or protocol errors (last command was "?", NULL)
2026-09-16T22:42:32.342069+10:00 smtp.geddy.au exim[2030980]: SMTP protocol error in "STARTTLS" H=[165.154.50.219] STARTTLS command used when not advertised
2026-09-16T22:42:38.023796+10:00 smtp.geddy.au exim[2030981]: SMTP protocol error in "AUTH NTLM" H=(112.213.38.174) [165.154.50.219] AUTH command used when not advertised
...
show less
Source IP from blacklist is still actively scanning our network. (5 hits in last hour, last seen 202 ...
show moreSource IP from blacklist is still actively scanning our network. (5 hits in last hour, last seen 2026-09-16 10:58:02)
show less