This IP address has been reported a total of
14
times from
9 distinct
sources.
193.239.154.100 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Source of spoofed email forging From: @atsoho.com domain. Observed via aggregated DMARC RUA reports. ...
show moreSource of spoofed email forging From: @atsoho.com domain. Observed via aggregated DMARC RUA reports.
Between 2026-05-13 and 2026-05-17, this IP and 250+ neighbors in 193.239.154.0/24 (AS136038 HDTIDC LIMITED / AS136526 ALLCLOUD LIMITED) sent over 11,000 spoofed emails forging the From header as our domain "atsoho.com".
All messages fail SPF and DKIM authentication against atsoho.com (DMARC enforced: p=quarantine). Legitimate atsoho.com mail is sent exclusively from Google Workspace, SocketLabs, and XServer.
Reporting receivers (sample): Mail.Ru, Microsoft (Enterprise Outlook), seznam.cz, JCOM, au.com, Yahoo, GMO Pepabo, GMO Internet.
WHOIS abuse-mailbox ([email protected]) is non-functional (550 5.1.1 rejection). APNIC and RIPE NCC have been notified of the invalid abuse contact.
show less
Nov 22 07:15:52 server postfix/smtpd[3364619]: connect from unknown[193.239.154.100]
Nov 22 07:15:53 ...
show moreNov 22 07:15:52 server postfix/smtpd[3364619]: connect from unknown[193.239.154.100]
Nov 22 07:15:53 server postfix/smtpd[3364619]: NOQUEUE: reject: RCPT from unknown[193.239.154.100]: 554 5.7.1 Service unavailable; Client host [193.239.154.100] blocked using zen.spamhaus.org; Listed by XBL, see https://check.spamhaus.org/query/ip/193.239.154.100 / Listed by SBL, see https://check.spamhaus.org/sbl/query/SBL520298 / Listed by DROP, see https://check.spamhaus.org/sbl/query/SBL520298 / Listed by CSS, see https://check.spamhaus.org/query/ip/193.239.154.100; from=<> to=<[email protected]> proto=ESMTP helo=<C202511200046297.local>
...
show less