🇮🇩
sockominfo
2026-08-25 16:00:53
(4 days ago)
Email: Login failures from Bad Reputation IP: 31.220.40.59. Threat Score: 6.1/10 (MEDIUM). Confidenc ...
show more
Email: Login failures from Bad Reputation IP: 31.220.40.59. Threat Score: 6.1/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.3/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1566 (Phishing). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-08-25 15:00:10
(4 days ago)
Email: Login failures from Bad Reputation IP: 31.220.40.59. Threat Score: 5/10 (MEDIUM). Reported by ...
show more
Email: Login failures from Bad Reputation IP: 31.220.40.59. Threat Score: 5/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇷🇸
Smel
2026-08-25 03:19:17
(4 days ago)
Mail/25/465/587-993/995 Probe, Reject, BadAuth, Hack, SPAM -
Email Spam
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-08-24 16:16:44
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 31.220.40.59 (propione.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 31.220.40.59 (propione.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:16:38.185776 2026] [security2:error] [pid 4462:tid 4462] [client 31.220.40.59:61905] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||qualityelevatorcabs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "qualityelevatorcabs.com"] [uri "/[email protected] "] [unique_id "aoxuZhYtlx48o2HBQqEAhAAAAAU"], referer: http://qualityelevatorcabs.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-08-22 20:56:08
(6 days ago)
2026-08-22T22:56:06.581758mail1.inartis.it postfix/smtpd[1874051]: warning: unknown[31.220.40.59]: S ...
show more
2026-08-22T22:56:06.581758mail1.inartis.it postfix/smtpd[1874051]: warning: unknown[31.220.40.59]: SASL PLAIN authentication failed: authentication failure, [email protected]
...
show less
Port Scan
Brute-Force
Anonymous
2026-08-22 15:35:21
(1 week ago)
Automated abuse report: malicious SMTP/IMAP activity detected by mail server.
Brute-Force
Email Spam
🇮🇩
xveil
2026-08-21 14:14:28
(1 week ago)
2026-08-21T21:14:25.432237 mail-honeypot postfix/submission/smtpd[2801]: warning: unknown[31.220.40. ...
show more
2026-08-21T21:14:25.432237 mail-honeypot postfix/submission/smtpd[2801]: warning: unknown[31.220.40.59]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
🇷🇺
saiva
2026-08-20 22:10:05
(1 week ago)
RdpGuard detected brute-force attempt on SMTP
Brute-Force
🇮🇩
xveil
2026-08-20 00:03:32
(1 week ago)
2026-08-20T07:03:29.729271 mail-honeypot postfix/submission/smtpd[9962]: warning: unknown[31.220.40. ...
show more
2026-08-20T07:03:29.729271 mail-honeypot postfix/submission/smtpd[9962]: warning: unknown[31.220.40.59]: SASL PLAIN authentication failed: authentication failure
...
show less
Brute-Force
🇷🇸
Smel
2026-08-16 08:49:14
(1 week ago)
Mail/25/465/587-993/995 Probe, Reject, BadAuth, Hack, SPAM -
Email Spam
Hacking
Brute-Force
Anonymous
2026-08-15 04:32:56
(2 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
🇮🇩
sockominfo
2026-08-14 07:00:53
(2 weeks ago)
Zimbra: Login failures from malicious IP: 31.220.40.59. Threat Score: 6.1/10 (MEDIUM). Confidence: 4 ...
show more
Zimbra: Login failures from malicious IP: 31.220.40.59. Threat Score: 6.1/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-08-14 06:00:56
(2 weeks ago)
Zimbra: Login failures from malicious IP: 31.220.40.59. Threat Score: 6.3/10 (MEDIUM). Confidence: 4 ...
show more
Zimbra: Login failures from malicious IP: 31.220.40.59. Threat Score: 6.3/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-08-14 05:00:09
(2 weeks ago)
Zimbra: Login failures from malicious IP: 31.220.40.59. Threat Score: 5.2/10 (MEDIUM). Reported by T ...
show more
Zimbra: Login failures from malicious IP: 31.220.40.59. Threat Score: 5.2/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇰
powerhostingdk
2026-08-13 23:30:43
(2 weeks ago)
[mailserver] CrowdSec detected crowdsecurity/postscreen-rbl (1 events). Automated abuse report.
Email Spam
Brute-Force