Activity Trending Down
This IP hasn't received reports recently, which causes the score to decay.
IPv6 SLAAC Note
Public IPv6 addresses may implement the SLAAC
privacy extension. With SLAAC, the interface identifier is randomly generated. SLAAC also implements a
configurable time out, so that the original IPv6 interface addresses will be discarded in favor of a new
interface identifier.
This IP address has been reported a total of
26
times from
24 distinct
sources.
2604:a880:400:d1:0:5:581:d001 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
France
with 8
reports;
Germany
with 5
reports;
Denmark
with 2
reports.
The most common categories in these recent reports were:
Brute-Force
21
times;
Email Spam
11
times;
Hacking
4
times;
Port Scan
3
times;
Web App Attack
2
times;
Other
6
times.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
2026-09-22T18:02:27.217399+02:00 vegeta postfix/smtpd[2780240]: improper command pipelining after CO ...
show more2026-09-22T18:02:27.217399+02:00 vegeta postfix/smtpd[2780240]: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]: \n
show less
2026-09-23T00:42:32.686339+09:00 ssv02 postfix/smtpd[1693682]: improper command pipelining after CON ...
show more2026-09-23T00:42:32.686339+09:00 ssv02 postfix/smtpd[1693682]: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]: \n
...
show less
2026-09-22T17:12:34.537078+02:00 kakarott postfix/smtpd[1895720]: improper command pipelining after ...
show more2026-09-22T17:12:34.537078+02:00 kakarott postfix/smtpd[1895720]: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]: \n
show less
PortSentry honeypot: unsolicited TCP connection to closed decoy port 25 (SMTP) on a host running no ...
show morePortSentry honeypot: unsolicited TCP connection to closed decoy port 25 (SMTP) on a host running no such service. Automated port-scan detection at 2026-09-22T14:45:17Z.
show less
2026-09-22T14:02:04.217785+00:00 stardust postfix/smtpd[1267296]: improper command pipelining after ...
show more2026-09-22T14:02:04.217785+00:00 stardust postfix/smtpd[1267296]: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]: \n
...
show less
2026-09-22T15:47:54.166227+02:00 baradur.es postfix/postscreen[275885]: PREGREET 1 after 0 from [260 ...
show more2026-09-22T15:47:54.166227+02:00 baradur.es postfix/postscreen[275885]: PREGREET 1 after 0 from [2604:a880:400:d1:0:5:581:d001]:34718: \n
...
show less
Email Spam
Hacking
Brute-Force
Anonymous
This IP was detected by CrowdSec triggering crowdsecurity/postscreen-rbl
2026-09-22T12:25:30.741948+02:00 ipoac.nl postfix/smtpd-: improper command pipelining after CONNECT ...
show more2026-09-22T12:25:30.741948+02:00 ipoac.nl postfix/smtpd-: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]:42138: n
2026-09-22T14:41:45.488887+02:00 ipoac.nl postfix/smtpd-: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]:54982: n
2026-09-22T14:47:25.362225+02:00 ipoac.nl postfix/smtpd-: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]:34628: n
2026-09-22T15:07:11.731071+02:00 ipoac.nl postfix/smtpd-: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]:42034: n
show less
2026-09-22T14:05:57.855737 webhost1 postfix/smtpd[547926]: improper command pipelining after CONNECT ...
show more2026-09-22T14:05:57.855737 webhost1 postfix/smtpd[547926]: improper command pipelining after CONNECT from unknown[2604:a880:400:d1:0:5:581:d001]: \n
...
show less
Known exploit / shellcode injection attempt / network protocol violation, may be port scanning false ...
show moreKnown exploit / shellcode injection attempt / network protocol violation, may be port scanning false positive
show less
Ip 2604:a880:400:d1:0:5:581:d001 performed 'crowdsecurity/postscreen-rbl' (1 events over 0s) at 2026 ...
show moreIp 2604:a880:400:d1:0:5:581:d001 performed 'crowdsecurity/postscreen-rbl' (1 events over 0s) at 2026-09-22 12:33:01.544762589 +0000 UTC
show less