This IP address has been reported a total of
171
times from
98 distinct
sources.
193.222.96.123 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
An unsolicited phishing email was sent to an address under the rock.ma domain. The email falsely cla ...
show moreAn unsolicited phishing email was sent to an address under the rock.ma domain. The email falsely claims to be from "Saleh Bin Gadeem" ([email protected]) and contains a fraudulent reference to "PR: 107123", likely to deceive recipients into interacting with an attached or linked malicious file.
The message was sent from IP 193.222.96.123, which passed SPF and DKIM for lovong.com, but is suspected to be part of a scam operation.
Technical Details:
Return Path: [email protected]
Sender Domain: lovong.com
DKIM Signature: Passed for lovong.com (potential misuse or compromised account).
SPF: Passed for IP 193.222.96.123.
Subject: "PR: 107123"
Message Type: Likely an invoice fraud or malware attachment phishing attempt.
Evidence:
The email attempts to trick the recipient into opening a malicious attachment.
The IP 193.222.96.123 was used for sending the scam email.
The domain lovong.com may be compromised or used for fraudulent purposes.
show less
Apr 27 23:50:52 server postfix/smtpd[3227]: NOQUEUE: reject: RCPT from unknown[193.222.96.123]: 454 ...
show moreApr 27 23:50:52 server postfix/smtpd[3227]: NOQUEUE: reject: RCPT from unknown[193.222.96.123]: 454 4.7.1 : Relay access denied; from= to= proto=ESMTP helo=
show less
Apr 26 00:53:35 mail postfix/postscreen[2144214]: NOQUEUE: reject: RCPT from [193.222.96.123]:52023: ...
show moreApr 26 00:53:35 mail postfix/postscreen[2144214]: NOQUEUE: reject: RCPT from [193.222.96.123]:52023: 550 5.7.1 Service unavailable; client [193.222.96.123] blocked using zen.spamhaus.org; from=<[email protected]>, to=<[email protected]>, proto=ESMTP, helo=<WIN-4TTI4DH7SGH>
...
show less
Domain : tiscali.it
Rule : SMTP
04/24/24 17:50:32 872 193.222.96.123 EHLO ehlo WIN-4TTI4DH7SGH ***h ...
show moreDomain : tiscali.it
Rule : SMTP
04/24/24 17:50:32 872 193.222.96.123 EHLO ehlo WIN-4TTI4DH7SGH ***hidden-privacy*** [193.222.96.123], this server offers 7 extensions 271 22
04/24/24 17:50:32 872 193.222.96.123 RSET Rset 250 Requested mail action okay, completed 43 6
04/24/24 17:50:33 872 193.222.96.123 MAIL Mail from:<[email protected]> 250 Requested mail action okay, completed 43 32
04/24/24 17:50:33 872 193.222.96.123 RCPT RCPT to:<[email protected]> 503 This mail server requires authentication when attempting to send to a non-local e-mail address. Please check your mail client settings or contact your administrator to verify that the domain or address is defined for this server. 235 30
show less
Domain : tiscali.it
Rule : SMTP
04/23/24 22:56:05 1184 193.222.96.123 ***hidden-privacy*** ESMTP ...
show moreDomain : tiscali.it
Rule : SMTP
04/23/24 22:56:05 1184 193.222.96.123 ***hidden-privacy*** ESMTP MAIL Service ready at 04/23/24 22:56:05 75 0
04/23/24 22:56:07 1184 193.222.96.123 EHLO ehlo WIN-4TTI4DH7SGH ***hidden-privacy*** [193.222.96.123], this server offers 7 extensions 271 22
04/23/24 22:56:07 1184 193.222.96.123 RSET Rset 250 Requested mail action okay, completed 43 6
04/23/24 22:56:07 1184 193.222.96.123 MAIL Mail from:<[email protected]> 250 Requested mail action okay, completed 43 32
04/23/24 22:56:07 1184 193.222.96.123 RCPT RCPT to:<[email protected]> 503 This mail server requires authentication when attempting to send to a non-local e-mail address. Please check your mail client settings or contact your administrator to verify that the domain or address is defined for this server. 235 30
show less
Apr 23 08:57:02 server postfix/smtpd[597481]: NOQUEUE: reject: RCPT from unknown[193.222.96.123]: 45 ...
show moreApr 23 08:57:02 server postfix/smtpd[597481]: NOQUEUE: reject: RCPT from unknown[193.222.96.123]: 454 4.7.1 : Relay access denied; from= to= proto=ESMTP helo=
show less