[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] [RaQ3] ns imapd - has anyone seen this before



Hi yah,

Just been checking the logs and about 4 hours ago this started appearing and
now seems to be one a regular cycle ...

Sep 26 02:30:01 ns imapd[23369]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 02:45:02 ns imapd[24010]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 03:00:03 ns imapd[24609]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 03:15:03 ns imapd[25222]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 03:30:02 ns imapd[25833]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 03:45:03 ns imapd[26432]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 04:00:03 ns imapd[27033]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 04:15:06 ns imapd[28217]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 04:45:14 ns imapd[32367]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 05:00:06 ns imapd[540]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]
Sep 26 05:15:01 ns imapd[1135]: Login failure user=Active_Monitor_69
host=localhost [127.0.0.1]

Anyone know what Active Monitor is?

I have a sneaky feeling that this might be a monitoring system that the
network centre is using but not 100% sure, thought I'd ask here first before
I ask what they are up to.

Many thanks in advance and regards from Auckland

Chae