Log in to view charts and search reports for this IP.
Log In
Top Reporter Countries (Last 60 Days)
Example preview
Report Categories (Last 60 Days)
Example preview
Reports Activity
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 158.158.120.48:
This IP address has been reported a total of
9
times from
5 distinct
sources.
158.158.120.48 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Spain
with 3
reports;
Guam
with 3
reports;
France
with 1
report.
The most common categories in these recent reports were:
Email Spam
9
times;
Phishing
5
times;
Fraud Orders
4
times;
DDoS Attack
3
times;
Web Spam
3
times;
Other
12
times.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Spam email received in Outlook.com Junk Email folder.
Likely originating IP: 158.158.120.48
Origin s ...
show moreSpam email received in Outlook.com Junk Email folder.
Likely originating IP: 158.158.120.48
Origin source header: Authentication-Results
Origin evidence: sender IP is 158.158.120.48
ReceivedDateTime: 09/06/2026 10:37:17
InternetMessageId: <PLS26J7N55ZKX85C4PNWYWNR6@geopod-ismtpd-4-4>
Selection reason: Selected explicit public sender IP from Authentication-Results
Known-good relay/IP/CIDR filtering was enabled.
Reporting mode: one report per qualifying Junk Email message
show less
Spam email received in Outlook.com Junk Email folder.
Likely originating IP: 158.158.120.48
Origin s ...
show moreSpam email received in Outlook.com Junk Email folder.
Likely originating IP: 158.158.120.48
Origin source header: Authentication-Results
Origin evidence: sender IP is 158.158.120.48
ReceivedDateTime: 09/06/2026 13:33:27
InternetMessageId: <04LTBFYJ6KQYEO9BTHF94P0MX@geopod-ismtpd-4-4>
Selection reason: Selected explicit public sender IP from Authentication-Results
Known-good relay/IP/CIDR filtering was enabled.
Reporting mode: one report per qualifying Junk Email message
show less
Spam email received in Outlook.com Junk Email folder.
Likely originating IP: 158.158.120.48
Origin s ...
show moreSpam email received in Outlook.com Junk Email folder.
Likely originating IP: 158.158.120.48
Origin source header: Authentication-Results
Origin evidence: sender IP is 158.158.120.48
ReceivedDateTime: 09/06/2026 13:33:27
InternetMessageId: <04LTBFYJ6KQYEO9BTHF94P0MX@geopod-ismtpd-4-4>
Selection reason: Selected explicit public sender IP from Authentication-Results
Known-good relay/IP/CIDR filtering was enabled.
Reporting mode: duplicate IP suppression enabled
show less
Sites involved in spam and fraud:
6641.regione.toscana.it
in2.getdrip.com
IN NAMECHEAP
"http://p ...
show moreSites involved in spam and fraud:
6641.regione.toscana.it
in2.getdrip.com
IN NAMECHEAP
"http://peopletoholdonyo.net/op/344_rd/1009/0/2037/678/6a7b928545466e33fadd1f70"
show less
Fraud Orders
DDoS Attack
Web Spam
Email Spam
Phishing
Sites involved in spam and fraud:
in2.getdrip.com
6641.regione.toscana.it
http://peopletoholdonyo ...
show moreSites involved in spam and fraud:
in2.getdrip.com
6641.regione.toscana.it
http://peopletoholdonyo.net/op/344_rd/1009/0/2037/678/6a7b928545466e33fadd1f70 (NAMECHEAP)
show less
Fraud Orders
DDoS Attack
Web Spam
Email Spam
Phishing
Anonymous
Received: from 6641.regione.toscana.it (158.158.120.48);
http://peopletoholdonyo.net;
Microsoft Si ...
show moreReceived: from 6641.regione.toscana.it (158.158.120.48);
http://peopletoholdonyo.net;
Microsoft Singapore Pte. Ltd.;
AS8075;
microsoft.com
show less
DNS Compromise
DNS Poisoning
Fraud Orders
Spoofing
Brute-Force
Exploited Host
Web App Attack
Web Spam
Email Spam
Port Scan
Phishing
Hacking
Blog Spam
Spam, fraud and phishing. Sites involved in spam and fraud:
6641.regione.toscana.it
in2.getdrip.c ...
show moreSpam, fraud and phishing. Sites involved in spam and fraud:
6641.regione.toscana.it
in2.getdrip.com
http://peopletoholdonyo.net/cl/448_rd/1009/0/2037/678/6a7b928545466e33fadd1f70
show less
Fraud Orders
DDoS Attack
Email Spam
Phishing
Anonymous
Authentication-Results: spf=none (sender IP is 158.158.120.48) smtp.mailfrom=aboutabsence.it; dkim=n ...
show moreAuthentication-Results: spf=none (sender IP is 158.158.120.48) smtp.mailfrom=aboutabsence.it; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=aixvixezxtxlpt; | Received-SPF: None (protection.outlook.com: aboutabsence.it does not designate permitted sender hosts) | Received: from dr5a.aboutabsence.it (158.158.120.48) by DM3NAM02FT042.mail.protection.outlook.com (10.13.4.213) with Microsoft SMTP Server id 15.21.382.10 via Frontend Transport; Mon, 31 Aug 2026 11:29:26 +0000 | Subject: Diese Woche wieder ohne Geländer gehen | From: Kinzeno Gesundheitspartner<no-reply@aixvixezxtxlpt>
show less
Unsafe SMTP message sender, Original hostname '158.158.120.48'. Participation in threat networks: re ...
show moreUnsafe SMTP message sender, Original hostname '158.158.120.48'. Participation in threat networks: regular.
show less
Email Spam
Open Proxy
VPN IP
Showing 1 to
9
of 9 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩