Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
209.141.39.45 has been reported 7
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
IP Abuse Reports for 209.141.39.45
This IP address has been reported a total of
7
times from
2 distinct
sources.
209.141.39.45 was first reported on
, and the most recent report was
.
Received Aug 20, 2025 at 10:12:33 EDT. Unsolicited adult-themed solicitation urging me to “view prof ...
show moreReceived Aug 20, 2025 at 10:12:33 EDT. Unsolicited adult-themed solicitation urging me to “view profile,” “naked photo/video,” and click a tracking URL. Delivered from 209.141.39.45 (bergstrom.avvyglow.com) using a throwaway subdomain. Auth: SPF=pass; DKIM=pass (rsa-sha1, deprecated); no DMARC result shown. Headers contain forged/misleading fields (X-Original-Sender, X-Google-Sender-Delegation, List-ID) that impersonate the recipient and fabricate a mailing list. MIME misuse: advertising sent as multipart/report. Violations: CAN-SPAM/FTC 16 CFR Part 316 (deceptive headers/subject, no valid physical address/opt-out), RFC 5321/5322 header integrity; DKIM uses deprecated hash (RFC 8301 guidance). This spam continues despite prior complaints; the host appears indifferent. All headers preserved for the provider. [email protected] bounces back as UNDELIVERABLE!!!! 100% NON-RESPONSIVE to spam complaints!!!!
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received on Aug 19, 2025 14:07:07 -0700 (PDT). Bulk HTML lure advertising “free Omaha Steaks,” linki ...
show moreReceived on Aug 19, 2025 14:07:07 -0700 (PDT). Bulk HTML lure advertising “free Omaha Steaks,” linking to obfuscated storage-based pages and urging survey clicks. Headers show bulk/precedence and manipulative subject that reuses the recipient’s name. Content attempts to drive traffic off-site and solicit engagement with deceptive rewards.
Auth results: SPF pass for return@… via 209.141.39.45; DKIM pass for mz8k5erzfrx64.folly.ing.pare.uk.com; DMARC result not shown/unaligned. Multiple header anomalies (forged X-Original-Sender, misleading X-Google-Sender-Delegation, odd List-ID) and weak rsa-sha1 DKIM contravene best practices (RFC 5322/8301; DMARC RFC 7489 absent).
Sending IP: 209.141.39.45 (rDNS ip4.static.sl-reverse.com / bergstrom.avvyglow.com). Also seen in path: mta8132.mp2200.com [162.247.118.132]. Network owner for 209.141.39.45: FranTech Solutions (PONYNET); abuse: [email protected]. Spam complaints to this address BOUNCE as UNDELIVERABLE!!!
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
You received an unsolicited bulk message arriving via the IP 209.141.39.45. The email impersonated t ...
show moreYou received an unsolicited bulk message arriving via the IP 209.141.39.45. The email impersonated the recipient by including the recipient’s address in the From field (i.e. the sender used the recipient's name falsely). The message advertised a “private message” and embedded misleading list‑unsubscribe links. The content aimed to lure the recipient into clicking tracking links claiming to be personalized. The message was multipart HTML‑encoded and included <meta> tags and links that appear designed to track engagement or harvest data.
The IP is operated by FranTech Solutions, a data‑center / web‑hosting provider
. No publicly listed contact email or phone number for FranTech Solutions was found.
Likely violates CAN‑SPAM Act (18 U.S.C. § 1037) by sending unsolicited commercial email using deceptive header information and misleading subject lines. Violates RFC 5322 (purported From header forgery) and RFC 7208 (DMARC failure via lack of alignment of sender domains).
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received on Sat, 12 Jul 2025 at 19:29:51 PDT. This email is a classic phishing/spam attempt disguise ...
show moreReceived on Sat, 12 Jul 2025 at 19:29:51 PDT. This email is a classic phishing/spam attempt disguised as a fake promotion from "Tractor Supply," claiming the recipient has won a free "Mini Jeep" if they click a suspicious link. The message uses deceptive branding and formatting to mimic a legitimate company. The "From" field impersonates the recipient's own name, a common spoofing technique to increase trust. Despite SPF and DKIM passing, this is likely due to a misconfigured or abused subdomain (qc7nhr1e5pdt.snig.gles.heytapmobile.us.com) hosted on a compromised server. Content is HTML-heavy and designed to deceive users into clicking fraudulent links. The message was bulk-prepared and originated from IP 209.141.39.45 with obfuscated campaign tracking IDs. This activity poses phishing, email spoofing, and web spam threats. Reports to [email protected] yield no results from this host sending the spam.
show less
Received on Sat, 12 Jul 2025 at 10:30:56 PDT. This email is a deceptive phishing attempt posing as a ...
show moreReceived on Sat, 12 Jul 2025 at 10:30:56 PDT. This email is a deceptive phishing attempt posing as a promotional giveaway from "Tractor Supply." The body claims the recipient has won a free "Mini Jeep" and includes suspicious links masked with tracking codes. The message uses sophisticated HTML/CSS styling and embedded base64 elements to mislead recipients. The "From" field impersonates the recipient's name, a clear attempt at spoofing for social engineering. The return path domain (phal.lics.heytapmobile.us.com) does not match the claimed sender, further signaling fraud. While SPF and DKIM both passed, DMARC status was missing or not enforced, allowing spoofing to bypass filtering. Email originated from IP 209.141.39.45 (sl-reverse.com), hosted by bergstrom.cluiaworld.com. The email was bulk in nature and likely sent using automation. This behavior violates sending policy and targets recipients with fraudulent bait.
show less
Phishing
Web Spam
Email Spam
Spoofing
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩