This IP address has been reported a total of
3
times from
2 distinct
sources.
23.218.80.154 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
On 10 Sep 2021 at 19:41:43 -0700 (PDT) an insidious spammer abusing the email source IP address 185. ...
show moreOn 10 Sep 2021 at 19:41:43 -0700 (PDT) an insidious spammer abusing the email source IP address 185.198.58.31 sent a malicious unsolicited phishing email fraudulently spoofing Dick's Sporting Goods stores in an attempt capture sensitive information. The phishing email's content was hidden on an exploited web host at 162.216.243.20 in order to avoid discovery by email servers' spam, phishing, and malware detectors. The site then deviously reroutes the victims to content hidden on a malicious exploited host at 185.225.138.166 (daaafk.com) and then to 23.218.80.154 (r3.o.lencr.org) which is rated by the security vendors Blueliv and Quttera as Malicious and Comodo Valkyrie Verdict security as Malware. This malicious phishing email also contains over 32KB of text strings concerning random topics unrelated to the email's subject to further evade discovery of this content by security software. No legitimate business correspondence would have reason to go to such lengths to mask their email's content.
show less
Phishing
Web Spam
Spoofing
Exploited Host
Anonymous
On 9 Sep 2021 at 16:38:18 -0700 (PDT) an insidious spammer abusing the email source IP address 89.1 ...
show moreOn 9 Sep 2021 at 16:38:18 -0700 (PDT) an insidious spammer abusing the email source IP address 89.163.237.87 sent a malicious unsolicited phishing email fraudulently spoofing Dick's Sporting Goods stores in an attempt capture sensitive information. The phishing email's content was hidden on an exploited web host at 77.74.196.188 in order to avoid discovery by email servers' spam, phishing, and malware detectors. The site then deviously reroutes the victims to content hidden on a malicious exploited host at 185.225.138.166 (daaafk.com) and then to 23.218.80.154 (r3.o.lencr.org) which is rated by the security vendors Blueliv and Quttera as Malicious and Comodo Valkyrie Verdict security as Malware. This malicious phishing email also contains over 26KB of text strings concerning random topics unrelated to the email's subject to further evade discovery of this content by security software. No legitimate business correspondence would have reason to go to such lengths to mask their email's content.
show less