Suspicious activity detected from IP 209.97.189.102 based on mailserver logs.
Sample logs:
2025-12-1 ...
show moreSuspicious activity detected from IP 209.97.189.102 based on mailserver logs.
Sample logs:
2025-12-16 02:20:37,989 INFO [ImapServer-69] [ip=172.16.0.182;cid=290;oip=209.97.189.102;via=172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;] imap - ID elapsed=0 (NIO)
2025-12-16 02:20:37,989 INFO [ImapServer-69] [ip=172.16.0.182;oip=209.97.189.102;via=172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;cid=290;] imap - AUTHENTICATE elapsed=0 (NIO)
2025-12-16 02:20:38,070 INFO [ImapServer-70] [ip=172.16.0.182;oip=209.97.189.102;via=172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;cid=290;] imap - authentication failed for [**] (LDAP error: - unable to ldap authenticate: invalid credentials)
2025-12-16 02:20:38,070 INFO [ImapServer-70] [ip=172.16.0.182;oip=209.97.189.102;via=172.16.0.182(nginx/1.24.0);ua=Zimbra/24.9.7_ZEXTRAS_202410;cid=290;] account - Error occurred during authentication: authentication failed for [**]. Reason: LDAP error: - unable to ldap authe
show less