Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
162.211.120.40 has been reported 9
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 162.211.120.40:
This IP address has been reported a total of
9
times from
4 distinct
sources.
162.211.120.40 was first reported on
, and the most recent report was
.
Spammer. I get 3 or 4 of these a day from this asshat.
Games online <[email protected]>
400% ...
show moreSpammer. I get 3 or 4 of these a day from this asshat.
Games online <[email protected]>
400% Bonus up to €2000 + 145 Free Spins
Return-Path: <[email protected]>
show less
Received Wed, Aug 20, 2025 14:12:45 -0400. Unsolicited gambling promo email (“400% Bonus up to €2000 ...
show moreReceived Wed, Aug 20, 2025 14:12:45 -0400. Unsolicited gambling promo email (“400% Bonus up to €2000 + 145 Free Spins”) with obfuscated content and random strings. Auth results: SPF pass (non-matching bounce domain), DKIM fail (invalid sig), DMARC: no result shown and alignment fails (From domain does not align). Header/form issues: forged/misaligned From (RFC 5322), failed DKIM (RFC 6376), DMARC misalignment (RFC 7489), misuse of multipart/report delivery-status for marketing (RFC 3464). Sending path references Sailthru MTA; host in header: roberts.willica.net [162.211.120.40]. IP owner per ARIN: velia.net (AS30083). Abuse contact: [email protected]
, +49 221 429 143. Headers already reported; spam persists—host appears unresponsive. Likely violates CAN-SPAM (15 U.S.C. §7701 et seq.).
I keep emailing the host the mail headers and they do absolutely nothing to stop the spam.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Email received August 7, 2025 at 12:04 PM PDT. This is a malicious spam email using deceptive HTML c ...
show moreEmail received August 7, 2025 at 12:04 PM PDT. This is a malicious spam email using deceptive HTML content disguised as news, attempting to lure the recipient into clicking suspicious external links disguised as financial services. The "From" field falsely used the recipient’s name to increase trust, violating CAN-SPAM Act §7704(a)(1). The DKIM check failed, SPF passed, and DMARC alignment was not achieved. The mail originated from 162.211.120.40 hosted by Secure Internet LLC, a provider that continues to ignore abuse complaints and allows ongoing spam activity. Mail was relayed through multiple suspicious domains including .facebook.uybzwzwe.reachesbeast.com.de. Message also includes embedded base64 payloads and random encoded blobs indicative of obfuscation and phishing. Repeated abuse from this host has gone unresolved, suggesting negligence. RCF violation: RFC 5322 §3.6.2 (misleading header).
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
This spam email was received on Tue, 05 Aug 2025 at 16:58:50 -0400. It falsely claims a cash prize a ...
show moreThis spam email was received on Tue, 05 Aug 2025 at 16:58:50 -0400. It falsely claims a cash prize and uses manipulative urgency ("Confirm It Before 11:59 PM") to lure the recipient into clicking suspicious links. The email body is a mix of misleading HTML marketing content and encoded characters designed to evade filters. The “From” field impersonates the recipient’s name, violating ethical norms and likely intending to deceive the recipient.
SPF passed, but DKIM returned a permanent error (no key for signature), and DMARC alignment failed. The email was routed via Sailthru infrastructure (IP 173.228.155.53), suggesting use of a third-party mass-mailer or open relay. Message-ID and return-path domains do not align with legitimate sources.
This spam violates multiple standards, including CAN-SPAM Act requirements (false header info, deceptive content) and RFC 5321 (improper MAIL FROM behavior).
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received on Sat, 02 Aug 2025 10:56:31 -0700. This unsolicited spam email was sent from IP address 16 ...
show moreReceived on Sat, 02 Aug 2025 10:56:31 -0700. This unsolicited spam email was sent from IP address 162.211.120.40 (roberts.willica.net) using a forged header to appear legitimate. The “From” field falsely used the recipient’s name, a deceptive technique intended to manipulate trust and increase engagement. The email subject urged the user to “Please Check Your Account,” suggesting phishing intent.
SPF passed, but DKIM failed for domain facebook.uybzwzwe.reachesbeast.com.de, and DMARC was not aligned, indicating forged identity. The payload contained obfuscated HTML and hidden text designed to bypass spam filters, with suspicious URLs and content aimed at luring users into financial scams or account compromise.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
This IP sent an unsolicited spam email on July 12, 2025 at 04:01 AM (PDT) to a personal Gmail accoun ...
show moreThis IP sent an unsolicited spam email on July 12, 2025 at 04:01 AM (PDT) to a personal Gmail account. The message falsely used the recipient’s name in the "From" field to create the impression that it was a legitimate notification. The content promotes a gambling site (“SpinsCastle”) and attempts to lure the recipient with fake promises of €2,000 and 200 free spins. The body includes multiple deceptive links using storage.googleapis.com that redirect to suspicious domains, likely for phishing or malware delivery. SPF passed, but DKIM failed with a "permerror" (no key for signature), and DMARC failed. The email header shows return path spoofing using a nested and misleading subdomain (connected-registry.clearnet.gov.contrasolar.com) in an attempt to masquerade as a trusted entity. The HTML message design mimics legitimate branding and includes unsubscribe links to further deceive. This behavior is both malicious and fraudulent.
show less
Message impersonates a legitimate domain (plegislation.gov.russes.biz) using misleading subdomains l ...
show moreMessage impersonates a legitimate domain (plegislation.gov.russes.biz) using misleading subdomains like fcc-tetrackm, attempting to evade filters. The email promotes a fraudulent online gambling scheme (“iWin Fortune”) offering “400% Bonus up to €2000 + 145 Free Spins.” HTML contains multiple links to suspicious storage.googleapis.com URLs with complex query strings likely used for tracking or redirection to malicious content. DKIM validation failed (permerror, no key for domain gqazqwkvcerhrmyngyonnwmy.com), while SPF passed. DMARC status was not explicitly listed. The sending server (162.211.120.40) should be investigated for bulk spam behavior and deceptive email campaigns. Content was elaborate HTML with marketing imagery and fake CTA buttons. Reported due to deceptive headers, DKIM failure, and clear phishing/spam intent. Date/time received: Fri, 27 Jun 2025 02:19:52 PDT.
show less