Verified relay โ repeat offender IP, iCloud phish
IP: 46.8.182.46 | Received: Mon, 20 Jul 202 ...
show moreVerified relay โ repeat offender IP, iCloud phish
IP: 46.8.182.46 | Received: Mon, 20 Jul 2026 06:54:12 +0000
Envelope: [email protected]
DKIM: d=jlxmvhxp.aasx.fetosm.co.uk s=smtp rsa-sha1
Msg-ID: <ujdgbvdneslcsbfzqcwwcztpzsrgzr@oso2fany6ea9h5oeae>
Evidence: SPF pass / Received-SPF client-ip= match. Confirmed genuine relay.
Payload: storage.googleapis.com/sdghfertytyuuyy/serksmhajdjddjd.html
Pattern: this exact IP previously sent a DirectMeds ad (sumiamp.me) on
2026-07-04 โ now reused 16 days later under a different domain/lure.
Third confirmed case of this operator recycling IPs (also seen with
94.125.163.211 and 205.251.145.44, each ~7 days). Same Panel Family A
fingerprint across 20+ specimens spanning 16+ days.
show less
This IP served as the genuine SMTP relay for a phishing message, confirmed via SPF pass and matching ...
show moreThis IP served as the genuine SMTP relay for a phishing message, confirmed via SPF pass and matching Authentication-Results client-IP alignment. The message carried a fabricated, structurally invalid decoy Received line naming an unrelated IP, and reverse DNS was set to a string now confirmed across eleven or more unrelated netblocks in an ongoing tracked campaign. It impersonated iCloud and linked to a Google Cloud Storage page confirmed reused across twelve sends spanning six days and four different TLDs.
show less
Sending IP for unsolicited bulk final-expense insurance advertising email. SPF passes for return@asx ...
show moreSending IP for unsolicited bulk final-expense insurance advertising email. SPF passes for [email protected]. DKIM d=rpufqkjl.asxz.acertub.me, s=smtp, rsa-sha1. Headers contain the same fabricated decoy Received line (efianalytics.com [216.244.76.116]) and duplicate Content-Length header pair (1939/5467) seen in prior specimens from this operator. Reverse DNS (adgame.fruitmail.net) is identical to that seen on a separate, unrelated IP in a different network, confirming this PTR value is deliberately configured across multiple infrastructure pools rather than a genuine per-IP reverse-DNS record. Payload links to storage.googleapis.com/sdghfertytyuuyy/, a bucket also used by two unrelated prior campaigns. Received Fri 2026-07-10.
show less
[SPAM] DirectMeds pharma ad, repeat abuse on already-listed IP
IP: 46.8.182.46 | Envelope: asxz.s ...
show more[SPAM] DirectMeds pharma ad, repeat abuse on already-listed IP
IP: 46.8.182.46 | Envelope: asxz.sumiamp.me
DKIM: d=btrpigup.asxz.sumiamp.me s=smtp rsa-sha1
Evidence: SPF pass matching Received-SPF client-ip=46.8.182.46, genuine
relay. IP already Spamhaus XBL/CBL-listed; this adds corroborating
evidence of continued active abuse from the same operator toolkit.
Payload: storage.googleapis.com/sdghfertytyuuyy/serksmhajdjddjd.html
DirectMeds GLP-1/weight-loss pharma affiliate ad on the campaign's
primary multi-purpose loader.
Pattern: same DKIM selector/fingerprint as dozens of prior submissions
on this loader object.
show less
Genuine, verified spam-sending host โ confirmed via complete Received
header matching Received-SPF ...
show moreGenuine, verified spam-sending host โ confirmed via complete Received
header matching Received-SPF client-ip=. PTR: adgame.fruitmail.net
(recurring hostname across multiple IPs in this campaign cluster). This
IP is already Spamhaus SBL-listed (127.0.0.3); this report adds
corroborating evidence: envelope domain asxz.torweep.me, DKIM s=smtp
rsa-sha1, payload via GCS bucket sdghfertytyuuyy (confirmed
multi-campaign loader โ pharma/weight-loss lure in this send).
show less
Email Spam
Phishing
Showing 1 to
5
of 5 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ