Jun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN ... show moreJun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54]
Jun 5 16:59:46 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:46 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54]
Jun 5 16:59:57 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:57 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54] show less
Jun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN ... show moreJun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54]
Jun 5 16:59:46 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:46 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54]
Jun 5 16:59:57 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:57 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54] show less
Jun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN ... show moreJun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:39 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54]
Jun 5 16:59:46 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:46 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54]
Jun 5 16:59:57 web01.schwick.de postfix/smtpd[2222100]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Jun 5 16:59:57 web01.schwick.de postfix/smtpd[2222100]: lost connection after AUTH from unknown[45.128.234.54] show less
Added into the Abuse.ch ThreatFox IOC database by @abuse_ch for being involved with the malware fami ... show moreAdded into the Abuse.ch ThreatFox IOC database by @abuse_ch for being involved with the malware family Remcos with tags: remcos.
Source: https://threatfox.abuse.ch/ioc/1113524/ show less
May 1 02:22:48 web01.agentur-b-2.de postfix/smtpd[1628869]: warning: unknown[45.128.234.54]: SASL L ... show moreMay 1 02:22:48 web01.agentur-b-2.de postfix/smtpd[1628869]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
May 1 02:22:48 web01.agentur-b-2.de postfix/smtpd[1628869]: lost connection after AUTH from unknown[45.128.234.54]
May 1 02:22:48 web01.agentur-b-2.de postfix/smtpd[1628869]: disconnect from unknown[45.128.234.54] ehlo=2 starttls=1 auth=0/1 commands=3/4
May 1 02:22:54 web01.agentur-b-2.de postfix/smtpd[1661896]: warning: unknown[45.128.234.54]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
May 1 02:22:54 web01.agentur-b-2.de postfix/smtpd[1661896]: lost connection after AUTH from unknown[45.128.234.54] show less
Apr 4 13:44:11 mx postfix/smtpd[2790]: connect from unknown[45.128.234.54]
Apr 4 13:48:23 m ... show moreApr 4 13:44:11 mx postfix/smtpd[2790]: connect from unknown[45.128.234.54]
Apr 4 13:48:23 mx postfix/anvil[23967]: statistics: max connection rate 25/60s for (smtpd:45.128.234.54) at Apr 4 13:44:11
Apr 4 13:48:23 mx postfix/anvil[23967]: statistics: max connection count 2 for (smtpd:45.128.234.54) at Apr 4 13:44:09 show less
(PERMBLOCK) 45.128.234.54 (NL/Netherlands/-) has had more than 4 temp blocks in the last 86400 secs; ... show more(PERMBLOCK) 45.128.234.54 (NL/Netherlands/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: 1; Trigger: LF_PERMBLOCK_COUNT; Logs: show less
(smtpauth) Failed SMTP AUTH login from 45.128.234.54 (NL/Netherlands/-): 5 in the last 3600 secs; Po ... show more(smtpauth) Failed SMTP AUTH login from 45.128.234.54 (NL/Netherlands/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2023-04-05 07:58:44 dovecot_login authenticator failed for (sK2DsVxdW) [45.128.234.54]:62172: 535 Incorrect authentication data
2023-04-05 08:56:26 dovecot_login authenticator failed for (zbJeHW6) [45.128.234.54]:51447: 535 Incorrect authentication data (set_id=lindsey)
2023-04-05 08:56:33 dovecot_login authenticator failed for (0jIBXLn) [45.128.234.54]:51966: 535 Incorrect authentication data (set_id=lindsey)
2023-04-05 08:56:40 dovecot_login authenticator failed for (e3LaAf) [45.128.234.54]:52933: 535 Incorrect authentication data (set_id=lindsey)
2023-04-05 08:56:51 dovecot_login authenticator failed for (6nYaKy) [45.128.234.54]:53994: 535 Incorrect authentication data (set_id=lindsey) show less
(smtpauth) Failed SMTP AUTH login from 45.128.234.54 (NL/Netherlands/-): 5 in the last 3600 secs; Po ... show more(smtpauth) Failed SMTP AUTH login from 45.128.234.54 (NL/Netherlands/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2023-04-05 07:51:49 dovecot_login authenticator failed for (fXcn6Ds67) [45.128.234.54]:60009: 535 Incorrect authentication data (set_id=info)
2023-04-05 07:51:56 dovecot_login authenticator failed for (QCkfyE36) [45.128.234.54]:60969: 535 Incorrect authentication data (set_id=info)
2023-04-05 07:52:07 dovecot_login authenticator failed for (ulBgS6) [45.128.234.54]:63068: 535 Incorrect authentication data (set_id=info)
2023-04-05 07:52:25 dovecot_login authenticator failed for (FOi9TLIOv4) [45.128.234.54]:50369: 535 Incorrect authentication data (set_id=info)
2023-04-05 07:52:43 dovecot_login authenticator failed for (KbsNZ3t) [45.128.234.54]:58175: 535 Incorrect authentication data (set_id=info) show less