Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
196.189.51.242 has been reported 10
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 196.189.51.242
This IP address has been reported a total of
10
times from
9 distinct
sources.
196.189.51.242 was first reported on
, and the most recent report was
.
Automated report from fail2ban on mail.fitzgerald.eu. Jail: postfix. First seen: 2026-06-16 11:25:48 ...
show moreAutomated report from fail2ban on mail.fitzgerald.eu. Jail: postfix. First seen: 2026-06-16 11:25:48. Events: 18. Reported by ipdb-security/fitzgerald.eu
show less
Reported from MailHold | From: [email protected] | Subject: ***SPAM*** Your Capital One Car ...
show moreReported from MailHold | From: [email protected] | Subject: ***SPAM*** Your Capital One Card Purchase is Under Review. | Date: Tue, 05 May 2026 14:44:35 GMT
Headers:
Return-Path: <[email protected]>
Delivered-To: [email protected]
Received: from amsngx344.inmotionhosting.com
by amsngx344.inmotionhosting.com with LMTP
id iPxMGlYC+mm/ODwAJKh/Hw
(envelope-from <[email protected]>)
for <[email protected]>; Tue, 05 May 2026 16:44:38 +0200
Return-path: <[email protected]>
Envelope-to: [email protected]
Delivery-date: Tue, 05 May 2026 16:44:38 +0200
Received: from [196.189.51.242] (port=60585 helo=yale.edu)
by amsngx344.inmotionhosting.com with esmtp (Exim 4.99.2)
(envelope-from <[email protected]>)
id 1wKH0m-0000000GpcG-0KDM
for [email protected];
Tue, 05 May 2026 16:44:38 +0200
From: "Capital One" <[email protected]>
To: [email protected]
Date: 05 May 2026 07:44:35 -0700
Message-ID: <20260505074434.FFFBD76AB53B4F32@yale
show less
May 5 23:17:29 box postfix/smtpd[732202]: NOQUEUE: reject: RCPT from unknown[196.189.51.242]: 554 5 ...
show moreMay 5 23:17:29 box postfix/smtpd[732202]: NOQUEUE: reject: RCPT from unknown[196.189.51.242]: 554 5.7.1 Service unavailable; Client host [196.189.51.242] blocked using zen.spamhaus.org; Listed by PBL, see https://check.spamhaus.org/query/ip/196.189.51.242 / Listed by CSS, see https://check.spamhaus.org/query/ip/196.189.51.242; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<yale.edu>
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
Blocked 31 connection attempts due to Spamhaus RBL (RJCT05) in the past 4 hours. To request delistin ...
show moreBlocked 31 connection attempts due to Spamhaus RBL (RJCT05) in the past 4 hours. To request delisting, visit https://www.spamhaus.org/lookup/ to check your IP status and submit a delist request if eligible.
show less
(smtp-25-to-rcpt-from-2007-leak) Recipient address has been leaked in 2007 196.189.51.242 (ET/Ethiop ...
show more(smtp-25-to-rcpt-from-2007-leak) Recipient address has been leaked in 2007 196.189.51.242 (ET/Ethiopia/-)
show less
NOQUEUE - IP: 196.189.51.242 - May 5 15:03:38 plesk postfix/smtpd[640416]: NOQUEUE: reject: RCPT fr ...
show moreNOQUEUE - IP: 196.189.51.242 - May 5 15:03:38 plesk postfix/smtpd[640416]: NOQUEUE: reject: RCPT from unknown[196.189.51.242]: 554 5.7.1 Service unavailable; Client host [196.189.51.242] blocked using dnsbl-2.uceprotect.net; Net 196.189.32.0/19 is UCEPROTECT-Level2 listed because 282 impacts are seen from EthioNet-AS, ET/AS24757 there. See: http://www.uceprotect.net/rblcheck.php?ipr=196.189.51.242 / Net 196.189.0.0/18 is UCEPROTECT-Level2 listed because 305 impacts are seen from EthioNet-AS, ET/AS24757 there. See: http://www.uceprotect.net/rblcheck.php?ipr=196.189.51.242; from=<[email protected]> to=<REDACTED@REDACTED> proto=ESMTP helo=<yale.edu>
show less
Blocked 12 connection attempts due to Spamhaus RBL (RJCT05) in the past 4 hours. To request delistin ...
show moreBlocked 12 connection attempts due to Spamhaus RBL (RJCT05) in the past 4 hours. To request delisting, visit https://www.spamhaus.org/lookup/ to check your IP status and submit a delist request if eligible.
show less
Attack Type: Phishing campaign with email domain spoofing
Description: This IP (196.189.51.242) a ...
show moreAttack Type: Phishing campaign with email domain spoofing
Description: This IP (196.189.51.242) actively sent phishing emails impersonating Capital One while spoofing the yale.edu domain in the From header. The email claims fraudulent card activity and directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
Timestamp: 2026-05-05 12:08:33 UTC
Protocol: SMTP (TCP connection completed - three-way handshake verified)
Originating IP: 196.189.51.242 (actual mail server, NOT affiliated with yale.edu)
Spoofed Domain: yale.edu (in From header: [email protected])
Authentication: SPF softfail, DMARC fail (policy=quarantine)
Malicious Payload: HTML phishing template with credential harvesting link
Note: This is NOT a spoofed packet attack. The TCP SMTP connection originated legitimately from this IP. The IP is the actual sender of malicious content, while yale.edu is a victim of domain spoofing.
show less
Spoofing
Exploited Host
Phishing
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ