(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 66.56.80.141 (CA/Canada/-): 2 in the ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 66.56.80.141 (CA/Canada/-): 2 in the last 3600 secs (0-193)
show less
Suspicious activity detected from IP 66.56.80.141 based on mailserver logs.
Sample logs:
2026-02-24 ...
show moreSuspicious activity detected from IP 66.56.80.141 based on mailserver logs.
Sample logs:
2026-02-24 11:26:29,032 INFO [qtp2102534528-69579] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.141;oport=36824;oproto=smtp;port=38592;soapId=2e78eebb;] soap - AuthRequest elapsed=1
2026-02-24 11:26:41,200 INFO [qtp2102534528-69579] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.141;oport=3487;oproto=smtp;port=35024;soapId=2e78eebc;] SoapEngine - handler exception: authentication failed for [**], LDAP error: - unable to ldap authenticate: invalid credentials
2026-02-24 11:26:41,200 INFO [qtp2102534528-69579] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.141;oport=3487;oproto=smtp;port=35024;soapId=2e78eebc;] soap - AuthRequest elapsed=2
2026-02-24 11:26:41,659 INFO [qtp2102534528-69566] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.141;oport=3487;oproto=smtp;port=35040;soapId=2e78eebd;] SoapEngine - handler exception: authentication failed for [**], LDAP error: - unable to ldap authenticate: invalid cred
show less
Blocked by UFW (TCP on 38474)
Source port: 51174
TTL: 51
Packet length: 60
TOS: 0x08
This report (f ...
show moreBlocked by UFW (TCP on 38474)
Source port: 51174
TTL: 51
Packet length: 60
TOS: 0x08
This report (for 66.56.80.141) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less