Mail server brute force attack. Failed SASL authentication attempts targeting mail.rousie.co.uk (217 ...
show moreMail server brute force attack. Failed SASL authentication attempts targeting mail.rousie.co.uk (217.154.63.158). Systematic username enumeration detected.
show less
Suspicious activity detected from IP 66.56.80.204 based on mailserver logs.
Sample logs:
2026-04-17 ...
show moreSuspicious activity detected from IP 66.56.80.204 based on mailserver logs.
Sample logs:
2026-04-17 18:10:33,170 INFO [qtp1106043431-109530] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.204;oport=41205;oproto=smtp;port=60308;soapId=10c16357;] soap - AuthRequest elapsed=1
2026-04-17 18:10:33,174 INFO [qtp1106043431-109532] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.204;oport=15210;oproto=smtp;port=60324;soapId=10c16358;] SoapEngine - handler exception: authentication failed for [**], LDAP error: - unable to ldap authenticate: invalid credentials
2026-04-17 18:10:33,174 INFO [qtp1106043431-109532] [name=**@*.id;ip=172.16.0.182;oip=66.56.80.204;oport=15210;oproto=smtp;port=60324;soapId=10c16358;] soap - AuthRequest elapsed=1
2026-04-17 18:10:33,605 INFO [qtp1106043431-109478] [] misc - Access from IP 66.56.80.204 suspended, for repeated failed login.
2026-04-17 18:10:33,611 INFO [qtp1106043431-109493] [] misc - Access from IP 66.56.80.204 suspended, for repeated failed login.
Reported
show less