Im operating a mail server which handles email flows from multiple domains (20 domains). The server is under a massive IMAPS (%%port:993%%) scan for a few days. More details about the ongoing attack:

  • Some logins are valid
  • Some logins seemto be part of a dictionary
  • Some logins are old or unused (like scraped from web pages)
    Someone else has already detected the same kind of scan?


