This IP address has been reported a total of
8
times from
3 distinct
sources.
95.168.160.83 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
This asshat is sending tons of scam emails.
Top Insurance Quotes <lrnsupportyaa@vmcjmrzncyuyktmkw ...
show moreThis asshat is sending tons of scam emails.
Top Insurance Quotes <[email protected]>
Car insurance rates as low as $19/mo
To: Google
Received: from balistreri.jamesonally.com.de (balistreri.jamesonally.com.de. [95.168.160.83])
show less
Received Aug 21, 2025 12:52:15 PDT (15:52:15 EDT). Fraud email claims a โ$5,000.50 direct deposit,โ ...
show moreReceived Aug 21, 2025 12:52:15 PDT (15:52:15 EDT). Fraud email claims a โ$5,000.50 direct deposit,โ hides behind a fake delivery-status (multipart/report) and heavy base64/HTML noise, and pushes obfuscated links (incl. storage.googleapis.*)โclassic credential-harvest phish. The From display name reused the recipientโs own name to mislead. Auth: SPF PASS for a return path at auth.email-secure.us.dramational.com via 95.168.160.83; DKIM permerror (no key) for rdyzmduomwykhkmdqxkqxlfb.com; DMARC alignment fails (SPF domain not aligned with From). Received chain shows balistreri.jamesonally.com.de [95.168.160.83] as sending host. Please investigate, disable the source, and remove related landing pages/assets.
Categories to tick: Email Spam, Phishing, Spoofing.
Likely host/abuse desk (for 95.168.160.0/20, AS60781): LeaseWeb โ abuse: [email protected]
, phone: +31 20 316 2880 (global contact page also lists [email protected]
and support numbers).
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host
Received Aug 21, 2025 at 2:20 PM EDT. Unsolicited bulk email advertising โMiracle_Sheets,โ stuffed w ...
show moreReceived Aug 21, 2025 at 2:20 PM EDT. Unsolicited bulk email advertising โMiracle_Sheets,โ stuffed with obfuscated payloads, tracking/redirect links, fake unsubscribe, and credential-harvesting lures (โaccount information,โ โactivate your account,โ etc.). Authentication: SPF PASS for leverbavoir.auth.email-secure.us.incipatier.com (but not aligned with visible From); DKIM PERMERROR (no key) for fwyspmfvwdqlewrjusgepdjm.com; DMARC not shownโlikely FAIL due to misalignment. Origination IP seen in Received: 95.168.160.83. Compliance: violates CAN-SPAM (15 U.S.C. ยง7701 et seq.) via deceptive headers/subject & no valid opt-out; attempted phishing implicates 18 U.S.C. ยง1343/ยง1028. RFC issues: malformed Date ending with a period (RFC 5322 ยง3.3) and misuse of multipart/report for marketing (RFC 3462/6522).
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Exploited Host