2026-05-04T13:27:09.922459+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unk ...
show more2026-05-04T13:27:09.922459+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unknown user (SHA1 of given password: 8ac539) - trying the next passdb
2026-05-04T13:27:15.830146+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unknown user (SHA1 of given password: 2cac48) - trying the next passdb
2026-05-04T13:27:25.931762+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unknown user (SHA1 of given password: b42d0e) - trying the next passdb
2026-05-04T13:27:48.673953+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unknown user (SHA1 of given password: e63d56) - trying the next passdb
2026-05-04T13:27:54.576111+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unknown user (SHA1 of given password: 7f955e) - trying the next passdb
2026-05-04T13:28:04.474665+08:00 mail dovecot: auth: passwd-file([email protected],178.16.55.123): unknown user (SHA1 of given password: 8a397c) - trying the next
...
show less
Suspicious activity detected from IP 178.16.55.123 based on mailserver logs.
Sample logs:
2026-05-03 ...
show moreSuspicious activity detected from IP 178.16.55.123 based on mailserver logs.
Sample logs:
2026-05-03 04:26:07,024 INFO [qtp2102534528-1770] [name=**@*.id;ip=172.16.0.182;oip=178.16.55.123;oport=64616;oproto=smtp;port=48242;soapId=6cf32735;] soap - AuthRequest elapsed=6
2026-05-03 04:26:09,756 INFO [qtp2102534528-1763] [name=**@*.id;ip=172.16.0.182;oip=178.16.55.123;oport=64576;oproto=smtp;port=48258;soapId=6cf32736;] SoapEngine - handler exception: authentication failed for [**], LDAP error: - unable to ldap authenticate: invalid credentials
2026-05-03 04:26:09,756 INFO [qtp2102534528-1763] [name=**@*.id;ip=172.16.0.182;oip=178.16.55.123;oport=64576;oproto=smtp;port=48258;soapId=6cf32736;] soap - AuthRequest elapsed=2
2026-05-03 04:26:12,482 INFO [qtp2102534528-1789] [name=**@*.id;ip=172.16.0.182;oip=178.16.55.123;oport=63945;oproto=smtp;port=56708;soapId=6cf32737;] SoapEngine - handler exception: authentication failed for [**], LDAP error: - unable to ldap authenticate: invalid
show less
Blocked by UFW (TCP on 587)
Source port: 64432
TTL: 103
Packet length: 52
TOS: 0x0A
This report (fo ...
show moreBlocked by UFW (TCP on 587)
Source port: 64432
TTL: 103
Packet length: 52
TOS: 0x0A
This report (for 178.16.55.123) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less