Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
5.39.31.122 has been reported 11
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
Received: Aug 18, 2025 09:21 -0400. Message impersonates “Gmail Support Team” and threatens account/ ...
show moreReceived: Aug 18, 2025 09:21 -0400. Message impersonates “Gmail Support Team” and threatens account/subscription closure with a “Final Warning,” pushing the user to click “Secure Your Device/Unsubscribe.” Headers show SMTP from 5.39.31.122 (workouttips.net); Return-Path is [email protected] while From is a random .us domain—mismatch. SPF: PASS for stone-wall… (5.39.31.122) but not aligned with From; DKIM: none; DMARC: alignment fails/none observed. Content includes obfuscated filler to evade filters. This appears to violate CAN-SPAM (deceptive headers/subject, noncompliant opt-out) and contravenes RFC 5322 (misleading From), RFC 7489 (DMARC alignment), RFC 6376 (no DKIM).
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received Aug 13, 2025 12:32:22 -0400. Malicious bulk mail sent from 5.39.31.122 via workouttips.net, ...
show moreReceived Aug 13, 2025 12:32:22 -0400. Malicious bulk mail sent from 5.39.31.122 via workouttips.net, posing as an urgent “payment declined / account at risk—photos & videos will be deleted” notice. Uses a nonsense From display name and random subdomain sender; body hides a cloud-storage link and filler to evade filters. SPF: pass for quantumtidex.info but not aligned to visible From; DKIM: none; DMARC: none/unaligned; ARC: cv=none. Header shows “Message-ID … [email protected]”, indicating the original lacked a Message-ID (RFC 5322), and it misuses multipart/report DSN structure (RFC 3462/6522). Violates CAN-SPAM (15 U.S.C. §7704: deceptive subject/headers, no proper opt-out) and may constitute wire fraud.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received on Aug 11, 2025 at 11:29 AM EDT. Source IP 5.39.31.122 (HELO workouttips.net) connected to ...
show moreReceived on Aug 11, 2025 at 11:29 AM EDT. Source IP 5.39.31.122 (HELO workouttips.net) connected to Gmail via TLS and delivered casino-lure spam: Subject “Jackpot Secured: $8,613.94 Ready for You – Claim Before Midnight!” with links via storage.googleapis.com urging immediate claim. Return-Path domain impersonates a gov-like name (higher-education.grants.ed.gov.countriforce.org.uk) and does not align with the visible From, indicating spoofing. Auth results: SPF=pass for that domain; DKIM=none; DMARC=none observed. Header quality: Message-ID was missing/invalid and added by Gmail (SMTPIN_ADDED_MISSING), violating RFC 5322 §3.6.4. Multipart/report used deceptively to bypass filters. This violates the CAN-SPAM Act (deceptive subject/headers; promotional content; no trustworthy opt-out). Host appears unresponsive to abuse reports; spam continues despite complaints. Headers and evidence forwarded to the host. Hosting: OVH SAS (OVHcloud), Abuse phone +33 9 72 10 10 07.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
From: Vivint_Home_Security <[email protected]> | Subject: Free I ...
show moreFrom: Vivint_Home_Security <[email protected]> | Subject: Free Installation* and a $50 VISA Gift Card with Purchase. Vivint Home Security.
show less
Received on Mon, 14 Jul 2025 at 11:31:11 AM EDT, this email used deceptive marketing tactics, impers ...
show moreReceived on Mon, 14 Jul 2025 at 11:31:11 AM EDT, this email used deceptive marketing tactics, impersonating a legitimate health product brand with the subject line “88% bigger with THIS?” and unsolicited HTML-rich content promoting supposed enhancement supplements. The message was sent via IP 5.39.31.122, traced to workouttips.net, using a spoofed From field that falsely displayed the recipient's name, misleadingly implying a trusted source. The return-path domain (statements.usda.gov.ryptogra.org) mimicked a U.S. government subdomain to evade filters. While SPF passed, there was no valid DKIM or DMARC authentication, making it trivial to spoof. The payload contains suspicious obfuscated links and base64-encoded HTML, indicative of spam or phishing attempts. This is part of a broader pattern of spam or possible fraudulent health product campaigns exploiting compromised infrastructure or open relays.
show less
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Unsolicited spam email received on Mon, 14 Jul 2025 at 07:39:28 AM PDT, advertising a Vivint home se ...
show moreUnsolicited spam email received on Mon, 14 Jul 2025 at 07:39:28 AM PDT, advertising a Vivint home security system with claims of free installation and a $50 VISA gift card. The message was misleading, promoting a service with exaggerated claims and unverifiable affiliate disclaimers. The message content was heavily encoded, with large HTML/CSS blocks and embedded tracking URLs. The "From" field deceptively used the recipient's name to impersonate a legitimate sender. This is a clear spoofing tactic. The email passed SPF, but there is no DKIM or DMARC authentication in the header, indicating poor or manipulated authentication practices. This email originated from IP address 5.39.31.122 via workouttips.net. Based on its deceptive content, impersonation tactic, and unsolicited nature, this is a coordinated spam and phishing attempt.
show less
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host