Received Thu, 14 Aug 2025 00:43:20 -0700 (PDT). Bulk/phishing mail impersonating “UnitedHealthCare” ...
show moreReceived Thu, 14 Aug 2025 00:43:20 -0700 (PDT). Bulk/phishing mail impersonating “UnitedHealthCare” with a deceptive subject using the recipient’s name and a “verify now” lure; links resolve to storage.googleapis.com; HTML is obfuscated. Delivered via 89.163.214.250 (libetwitt.liberation.fr / quigley.basketalike.com). Auth results: SPF pass for 033755.com; DKIM none; DMARC none observed; ARC cv=none. Header anomalies include multipart/report used for marketing, bogus sender token, and broken Message-ID. Violations: CAN-SPAM (15 U.S.C. §7701 et seq.—deceptive headers/subject, no valid opt-out); RFC 5321/5322 (misleading identifiers); RFC 6376/7489 (unauthenticated domain use). Host: WIIT AG (formerly myLoc managed IT AG). Abuse: [email protected]; phone +49 211 61708110.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received a phishing email on August 3, 2025 at 12:47 PM PDT promoting fake weight loss products with ...
show moreReceived a phishing email on August 3, 2025 at 12:47 PM PDT promoting fake weight loss products with the subject "Revolutionary Discovery - Weight Loss without Exercise!". The body contained deceptive content claiming a Nobel Prize-winning scientist discovered a natural compound that causes rapid weight loss with no diet or exercise. The message used a shortened tracking URL and included fake unsubscribe links. The "From" field impersonated the recipient's name to trick the user. SPF and DKIM both failed authentication, and DMARC was not aligned, indicating clear spoofing of the sending domain. These signs strongly suggest a fraudulent email campaign using forged headers to bypass spam filters and socially engineer the recipient. The sending IP is hosting a mail server used for malicious campaigns targeting consumers with misleading health claims. How come SpamCop complaints to [email protected] doesn't stop these junk emails for this IP address that keeps sending spam?
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Email received on Sun, 4 Aug 2025 at 23:48:06 -0700. This message is an unsolicited and fraudulent e ...
show moreEmail received on Sun, 4 Aug 2025 at 23:48:06 -0700. This message is an unsolicited and fraudulent email designed to mislead the recipient into clicking a deceptive link using a fake shipping notice. The content falsely claims a USPS delivery could not be completed and instructs the recipient to "reschedule your delivery" via a malicious hyperlink impersonating USPS. The intent is clearly phishing. The email subject uses shipping urgency to provoke action. The From field was manipulated to display the recipient’s own name in order to appear more credible. The message failed DMARC authentication. SPF passed, but DKIM failed, which raises red flags regarding email legitimacy. This is a classic phishing attempt that abuses legitimate delivery brand trust to harvest credentials or infect systems. IP should be blacklisted due to its involvement in email-based phishing and spam abuse.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Email received on July 21, 2025, at 2:08 PM PDT. The message claims to be from "Aetna" with a fabric ...
show moreEmail received on July 21, 2025, at 2:08 PM PDT. The message claims to be from "Aetna" with a fabricated subject line “[motoroilguy], Verify Order #[84766-30]” and was sent to an unrelated Gmail address. The "From" field deceptively used the recipient's name, a tactic commonly associated with phishing and identity deception. The email included unsolicited marketing content with embedded tracking URLs and large amounts of HTML designed to bypass filters. The sending IP is 89.163.214.250, hosted by Hetzner Online GmbH, and continues to deliver spam from similar domains despite previous complaints. SPF passed, but no DKIM or DMARC signatures were present in the header, which violates proper authentication protocols (RFC 6376 and RFC 7489). This is a violation of the CAN-SPAM Act due to misleading headers, falsified sender identity, and lack of user consent. The hosting provider appears unresponsive, as spam from this source persists across multiple complaints.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received on July 21, 2025 at 08:15 AM PDT, this email falsely used the recipient’s name in the “From ...
show moreReceived on July 21, 2025 at 08:15 AM PDT, this email falsely used the recipient’s name in the “From” field to impersonate a legitimate brand, referencing a bogus Aetna order. It includes deceptive HTML content with fake order confirmations and embedded graphics designed to lure the user into clicking malicious links. SPF passed, but there are no valid DKIM or DMARC authentication results, suggesting spoofing tactics. The message originated from quigley.basketalike.com, resolving to 89.163.214.250, and was delivered via Sailthru servers, which are often abused in phishing campaigns. The email violates RFC 5322 due to malformed headers and impersonation. Despite numerous abuse reports, spam continues from this host, implying a disregard for enforcement. This is an example of a fraudulent, misleading message crafted to manipulate recipients under false pretenses.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
On July 15, 2025 at 11:30 PM PDT, this IP address was observed sending a deceptive email claiming th ...
show moreOn July 15, 2025 at 11:30 PM PDT, this IP address was observed sending a deceptive email claiming the recipient was nominated for “Who’s Who 2025.” The message impersonated the recipient by falsely using their name in the "From" field. The content was highly promotional and misleading, using emotional language to entice the recipient to click links to external, potentially harmful websites. The message contained exaggerated and fabricated claims about recognition and professional prestige. The HTML payload was bloated with tracking code and redirect links, suggesting an attempt to phish or harvest user data. SPF passed, but DKIM and DMARC results were not present, which weakens sender authentication and raises the likelihood of spoofing. This was an unsolicited and suspicious commercial email, possibly part of a mass-mailing or phishing campaign. The origin server appears to be quigley.basketalike.com at IP 89.163.214.250, which has no legitimate association with the recipient.
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Showing 1 to
7
of 7 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown 🚩