From: GmailSupportTeam <[email protected]>
Your Subscription wi ...
show moreFrom: GmailSupportTeam <[email protected]>
Your Subscription will be Closed at Tue,02 Sep-2025 [ Final Warning ]
Malicious Link
show less
Phishing email received on Sat, 12 Jul 2025 22:32:48 PDT. The message falsely impersonates a financi ...
show morePhishing email received on Sat, 12 Jul 2025 22:32:48 PDT. The message falsely impersonates a financial transaction from a payment provider, referencing a fabricated confirmation receipt and claiming a balance of $8,500 for the recipient's account. The message contains garbled plain-text and a heavily obfuscated HTML payload designed to mislead and lure the user into clicking malicious links, possibly for credential harvesting. The DKIM authentication failed with a โpermerrorโ due to an invalid or missing public key. DMARC is not explicitly mentioned as passing, and the SPF check passed. The โFromโ header deceptively used the recipientโs name, which is a clear spoofing tactic to manipulate trust. The payload includes attempts to appear legitimate by mimicking transactional formatting and logos. Overall, the structure and intent indicate malicious behavior with phishing characteristics and spoofing of identity. Over 70 spam complaints to the host and they do absolutely nothing to stop the spam.
show less
Unsolicited email received on Sat, 05 Jul 2025 at 11:55 PM EDT contained misleading subject "Account ...
show moreUnsolicited email received on Sat, 05 Jul 2025 at 11:55 PM EDT contained misleading subject "Account-ID : 64242030" and originated from IP 27.102.128.53. The message impersonated the recipient by using their name in the "From" field, which is a deceptive tactic. The body included nonsensical strings and obscure HTML code, commonly associated with obfuscation used in spam or phishing templates. The email claims to provide a payout of "$4500.00" with links redirecting to storage.googleapis.com, potentially leading to malicious or scam websites. The domain kjkk5e.a7wc7j.cscipt.us used for DKIM signing produced a DKIM permerror (no public key found). While SPF passed, DMARC results were not observed, increasing the likelihood of spoofing. This message exhibits hallmarks of abuse, fraudulent content, deceptive marketing, and possible phishing. The use of randomized domains and confusing message structure supports classification as malicious spam.
show less