🇺🇸
mnogoweb
2026-09-06 16:12:14
(3 days ago)
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-06 09:33:03 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 09:59:57 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 10:10:33 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 10:11:47 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 10:12:11 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇺🇸
mnogoweb
2026-09-06 15:02:28
(3 days ago)
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-06 08:39:24 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 08:40:24 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 08:45:41 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 08:55:23 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 09:02:26 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇺🇸
mnogoweb
2026-09-06 14:21:37
(3 days ago)
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-06 07:32:24 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 07:49:07 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 08:08:47 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 08:09:37 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-06 08:21:36 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇺🇸
xmission.com
2026-09-06 13:22:07
(3 days ago)
Sourced 1 spam messages over 3x XMissions threshold. Highest score: 59.4.
Email Spam
🇺🇸
mnogoweb
2026-09-02 14:09:26
(1 week ago)
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 195.19.50.120 (RU/Russia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-02 07:19:56 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-02 07:29:22 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-02 07:31:47 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-02 07:53:43 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
2026-09-02 08:09:22 login authenticator failed for (195.19.50.120) [195.19.50.120]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇩🇪
EGP Abuse Dept
2026-09-01 00:50:16
(1 week ago)
Scanning for port/service exploits on tpc-023.mach3builders.nl
Port Scan
Hacking
🇷🇸
Smel
2026-08-23 06:19:12
(2 weeks ago)
Mail/25/465/587-993/995 Probe, Reject, BadAuth, Hack, SPAM -
Email Spam
Hacking
Brute-Force
🇩🇪
NewGastroline
2026-08-19 15:19:54
(3 weeks ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇩🇪
anycast_ac
2026-08-17 05:36:16
(3 weeks ago)
[DDoS Attacker] This IP was attacking website bgbot.bravohvh.fun and sent 1344 requests on port 443
DDoS Attack
Web App Attack
🇩🇪
NewGastroline
2026-08-14 05:37:25
(3 weeks ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-08-10 11:32:52
(4 weeks ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇮🇩
sockominfo
2026-08-05 15:00:53
(1 month ago)
Zimbra: Login failures from malicious IP: 195.19.50.120. Threat Score: 6.4/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 195.19.50.120. Threat Score: 6.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-08-05 14:00:09
(1 month ago)
Zimbra: Login failures from malicious IP: 195.19.50.120. Threat Score: 5.9/10 (MEDIUM). Reported by ...
show more
Zimbra: Login failures from malicious IP: 195.19.50.120. Threat Score: 5.9/10 (MEDIUM). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇰
powerhostingdk
2026-08-04 18:50:47
(1 month ago)
[mailserver] CrowdSec detected crowdsecurity/postscreen-rbl (1 events). Automated abuse report.
Email Spam
Brute-Force
🇩🇪
NewGastroline
2026-08-03 06:57:45
(1 month ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack