Log in to view charts and search reports for this IP.
Log In
Reports Activity
Example preview
Report Categories (Last 60 Days)
Example preview
Top Reporter Countries (Last 60 Days)
Example preview
Account required for the enhanced features
Log inSign up
IP Abuse Reports for 172.245.92.116
This IP address has been reported a total of
42
times from
19 distinct
sources.
172.245.92.116 was first reported on
, and the most recent report was
.
In the last 60 days, the only reporter location was:
United States of America
with 1
report.
The only category in these recent reports was:
Email Spam
1
time.
Old Reports
The most recent abuse report for this IP address is from
. It is possible that this IP is no
longer involved in abusive activities.
Blocked 19 connection attempts due to Spamhaus RBL (RJCT05) in the past 4 hours. To request delistin ...
show moreBlocked 19 connection attempts due to Spamhaus RBL (RJCT05) in the past 4 hours. To request delisting, visit https://www.spamhaus.org/lookup/ to check your IP status and submit a delist request if eligible.
show less
[FriJul2400:19:56.6464362026][security2:error][pid571020:tid571138][client172.245.92.116:0]ModSecuri ...
show more[FriJul2400:19:56.6464362026][security2:error][pid571020:tid571138][client172.245.92.116:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.swisservers.com\"][uri\"/\"][unique_id\"amKTjLiX7j1w-HhZu3lKRwAAAU4\"]
show less
Received 21 Aug 2025 10:14:39 -0400. Message is a deceptive “Please check your account” notice with ...
show moreReceived 21 Aug 2025 10:14:39 -0400. Message is a deceptive “Please check your account” notice with bogus balance claims and credential-harvest/monetized links (incl. Google Storage URLs). Sent from 172.245.92.116 (ESMTPS) with a forged chain (“localhost” at uic.edu; Reply-To at *.uic.edu). The “From” display name used the recipient’s name falsely. Auth: SPF=pass for return@…deparamily.com (unrelated to header From); DKIM=permerror (no key for d=otmp…net); DMARC=no result observed/likely misaligned. Indicators strongly suggest bulk phishing/spam. Likely violates CAN-SPAM (15 U.S.C. §7701 et seq.); credential theft could implicate 18 U.S.C. §1343 (wire fraud) and §1030 (CFAA). RFCs implicated: 5322 (misleading From), 7489 (DMARC misalignment), 6376 (invalid DKIM). Please investigate and terminate this abuse.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
TCP src-port=52925 dst-port=25 Listed on dnsbl-sorbs (Project Honey Pot rated Suspicious ...
show moreTCP src-port=52925 dst-port=25 Listed on dnsbl-sorbs (Project Honey Pot rated Suspicious) (164)
show less
spamassassin . (warning: [email protected] storage has zero kb available) . (alisourcepro@se ...
show morespamassassin . (warning: [email protected] storage has zero kb available) . ([email protected]) . RCVD IN UCEPROTECT2[1.9] . RCVD IN UCEPROTECT1[2.2] . RCVD IN UCEPROTECT3[1.3] . RCVD IN FABEL[4.0] . RCVD IN S5HBL[1.0] . URIBL ABUSE SURBL[1.2] . BL 2 POLSPAM PL[3.9] . BL 3 POLSPAM PL[2.9] . INTERSERVER DNSBL[1.4] . RCVD IN BRUKALAI BLACK[1.3] . MIME HTML ONLY[0.1] . RAZOR2 CF RANGE 51 100[1.9] . RAZOR2 CHECK[0.9] . SPF NOT PASS[1.1] . LOCAL IP BAD 172 245 92 116[6.0] . LOCAL HEAD HTML[1.0] (221)
show less
TCP src-port=63962 dst-port=25 Listed on dnsbl-sorbs (Project Honey Pot rated Suspicious ...
show moreTCP src-port=63962 dst-port=25 Listed on dnsbl-sorbs (Project Honey Pot rated Suspicious) (440)
show less