A phishing email was sent to an address under the rock.ma domain, attempting to impersonate an offic ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate an official entity. The email originated from the IP 109.248.151.149 using the fraudulent sender address [email protected].
The email was relayed through cloud-fcbb8d.managed-vps.net before reaching our mail server. The SPF check failed (softfail), indicating that the sending IP was not authorized to send emails on behalf of downloadbybit.com. Additionally, the reply-to address was set to [email protected], further evidencing fraudulent intent.
Technical Details:
Return Path: [email protected]
Sender Domain: downloadbybit.com
Reply-To Address: [email protected]
SPF Check: Softfail (unauthorized sending IP)
Mail Relay: cloud-fcbb8d.managed-vps.net
Message Subject: "End seller mandate"
IP Address Responsible for Sending: 109.248.151.149
show less
A fraudulent email was sent to an address under the rock.ma domain, falsely offering web design and ...
show moreA fraudulent email was sent to an address under the rock.ma domain, falsely offering web design and development services. The email appears to be spam or an unsolicited phishing attempt. The sender uses mobrilztechnologies.com, which does not have any business relation with us.
Technical Details:
Return Path: [email protected]
Sender Domain: mobrilztechnologies.com
DKIM Signature: Passed for mobrilztechnologies-com.20230601.gappssmtp.com
SPF: Passed for IP 2401:4900:1c64:62da:c4fd:65d7:12f4:15ff
Message Subject: WEB (Designing & Development)...!
Message Sent From: Desktop email client using Microsoft Office Outlook 12.0
Message-ID: <1846501db8dc9$077d80d0$16788270$@com>
show less
A phishing email was sent to [email protected], impersonating cPanel On Rock, falsely requesting subsc ...
show moreA phishing email was sent to [email protected], impersonating cPanel On Rock, falsely requesting subscription confirmation. The email was sent from the domain berkeleytattoo.com, which has no association with rock.ma. The sending IP (2a01:8640:2:11::3191:e4b6) failed SPF verification and had a reverse DNS lookup failure, further indicating spoofing or a compromised mail server.
Technical Details:
Return Path: [email protected]
Sender Domain: berkeleytattoo.com
DKIM Signature: Passed for berkeleytattoo.com, indicating legitimate signing but possible misuse.
SPF: Softfail for IP 2a01:8640:2:11::3191:e4b6.
ARC-Seal Header: Suggests relay via multiple mail servers.
Reverse DNS Lookup: Failed for 2a01:8640:2:11::3191:e4b6.
Message Subject: "Please confirm your subscription" – Phishing attempt to deceive the recipient.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization by claiming to be an ICANN domain validation request. The email urges the recipient to take action regarding their webmail account. The email passed SPF and DKIM verification for a domain unrelated to us (gamrna.com) and was sent from the IP 216.126.231.248.
Technical Details:
Return Path: [email protected]
Sender Domain: gamrna.com
DKIM Signature: Passed for gamrna.com.
SPF: Passed for IP 216.126.231.248.
ARC-Seal Header: Impersonation detected through mail relays.
Message Subject: Webmail account validation for rock.ma user(s).
show less
A phishing email was sent to [email protected], attempting to impersonate a legitimate sender and dece ...
show moreA phishing email was sent to [email protected], attempting to impersonate a legitimate sender and deceive the recipient into opening fraudulent purchase order details. The email claims to originate from [email protected], but the headers indicate it was sent from an unauthorized third-party mail server (vm-25456.veeblehosting.com, IP: 66.85.173.40).
Technical Details:
Return Path: [email protected]
Sender Domain: ipc.fukushima-u.ac.jp (compromised or spoofed)
Actual Sending Server: vm-25456.veeblehosting.com (66.85.173.40)
SPF Result: SoftFail – The IP 66.85.173.40 is not an authorized sender for ipc.fukushima-u.ac.jp
Reverse DNS Lookup: Failed for 66.85.173.40
Message Subject: Fake Purchase Order Attempt (New Purchase Order From Yunkong 4501163048)
show less
An unsolicited email was received at an address under our domain rock.ma, promoting financial servic ...
show moreAn unsolicited email was received at an address under our domain rock.ma, promoting financial services from a suspicious source. The sender, [email protected], appears to be using a deceptive email domain to contact our clients.
Technical Details:
Return Path: [email protected]
Sender Domain: alkadicapitalinvest.com
Sending IP: 193.222.96.55
SPF Check: SoftFail (domain does not designate 193.222.96.55 as a permitted sender)
Received Header: Shows relay via heart.bydob.com
Message Subject: "Drive Project Success with Our Competitive Financing Solutions"
Disposition-Notification-To: Sender requested a read receipt, indicating an attempt to validate active email addresses.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate Maersk b ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate Maersk by using esnaholiday.com as a fraudulent sender. The email contains a malicious "Download link" leading to a potentially harmful file.
The attack is using SRS (Sender Rewriting Scheme) abuse, forwarding an email from esnaholiday.com through rock.ma to make it appear legitimate. This tactic exploits email forwarding systems to bypass basic spam filters.
Technical Details:
Return Path: [email protected]
Sender Domain: esnaholiday.com
DKIM Signature: Fail for esnaholiday.com, indicating tampering.
SPF: Pass for IP 196.251.93.146.
ARC-Seal & ARC-Authentication: Attempting to manipulate email relay authentication.
Subject: Fraudulent shipping notice: "Arrival Notice ready for Bill of Lading"
show less
A fraudulent email was sent to an address under the rock.ma domain, impersonating a distributor and ...
show moreA fraudulent email was sent to an address under the rock.ma domain, impersonating a distributor and claiming an invoice is due. This is a phishing attempt designed to deceive the recipient into opening a malicious invoice or engaging in financial fraud.
The email originated from 64.74.161.203, falsely presenting itself as studylink.org. The SPF authentication resulted in a softfail, indicating that the sender is not authorized to send emails on behalf of studylink.org. Additionally, the reverse DNS lookup failed for the IP, which is a red flag for fraudulent activity.
Technical Details:
Return Path: [email protected]
Sender Domain: studylink.org
IP Address: 64.74.161.203 (Failed Reverse DNS Lookup)
SPF Authentication: Softfail – Unverified sender
Message Subject: Invoice Number: INV-2025-00123
X-Complaints-To: [email protected]show less
A phishing email was sent to [email protected] impersonating DocuSign in an attempt to deceive the rec ...
show moreA phishing email was sent to [email protected] impersonating DocuSign in an attempt to deceive the recipient. The email originates from an unauthorized sender domain (bigncreative.com) using the IP address 5.250.180.191. The sender domain failed SPF authentication (softfail) and lacks DKIM verification.
Technical Details:
Return Path: [email protected]
Sender Domain: bigncreative.com
SPF Result: Softfail – unauthorized IP sending email for bigncreative.com
Subject: Fake DocuSign message titled "Hey Reaching Out with"
Mail Server Used: ip5-250-180-191.pbiaas.com
show less
A fraudulent email was received by addresses under the domain rock.ma, impersonating legitimate fina ...
show moreA fraudulent email was received by addresses under the domain rock.ma, impersonating legitimate financial communications (overdue payment notice). The email uses misleading sender details with domain pqsoil.com, passed SPF and DKIM verifications, but was detected as spam through multiple spam filters, including Spamhaus (SBL, CSS), Spamcop, and ABUSE SURBL blocklists. The email originates from IP address 196.251.92.86, which is listed on multiple spam blocklists.
Sender Domain: pqsoil.com (unauthorized and impersonating)
Envelope-From: [email protected]
Spam Score: 13.2 (SpamAssassin)
Confirmed blacklisted on Spamhaus SBL, CSS, and Spamcop blocklists.
Contains malicious URLs: IPFS hosted URL bafybeidrugrwrutnmgil4w75ksrfrbdrug6hv7lm7hfqatcwgqtnq3clue.ipfs.dweb.link
Failed Authentication (DKIM): dkim failed validation checks, despite SPF pass, indicating spoofed headers or compromised sender infrastructure.
Purpose of Email: Attempting to trick users into clicking m
show less
A fraudulent email was sent to an address under the rock.ma domain, attempting to mislead recipients ...
show moreA fraudulent email was sent to an address under the rock.ma domain, attempting to mislead recipients with a fake domain service expiration warning. The sender domain (mail-dns.asia) is not associated with our infrastructure, and this is a clear phishing attempt designed to trick users into taking unauthorized actions. The email originated from the IP 176.96.131.18, which failed reverse DNS lookup verification, indicating suspicious behavior.
Technical Details:
Return Path: [email protected]
Sender Domain: mail-dns.asia
DKIM Signature: Passed for mail-dns.asia, but domain is not related to rock.ma.
SPF: Passed for IP 176.96.131.18.
Reverse DNS Lookup: Failed.
Message Subject: Urgent Warning: Password Expiration Notification
show less
A phishing email was sent to an address under the rock.ma domain, fraudulently impersonating our IT ...
show moreA phishing email was sent to an address under the rock.ma domain, fraudulently impersonating our IT helpdesk. The email falsely claims an account termination warning and attempts to mislead the recipient into taking action.
The sender’s domain (manipulecerto.com) is not associated with rock.ma, and the email appears to be a phishing attempt to obtain sensitive information. The sending IP (103.187.27.207) successfully passed SPF, DKIM, and DMARC checks for manipulecerto.com, indicating that the phishing attack is originating from that domain or a compromised mail server.
Technical Details:
Return Path: [email protected]
Sender Domain: manipulecerto.com
DKIM Signature: Passed for manipulecerto.com
SPF: Passed for IP 103.187.27.207
ARC-Seal Header: Shows fraudulent relay
Message Subject: [email protected] Account Termination
show less
A phishing email was sent to an address under the rock.ma domain, impersonating a shipment update no ...
show moreA phishing email was sent to an address under the rock.ma domain, impersonating a shipment update notification. The sender's email ([email protected]) and reply-to address ([email protected]) attempt to mislead recipients. The email was sent from IP 2a00:1450:4864:20::235, which appears to be associated with Google infrastructure but was used in this phishing attempt.
Technical Details:
Return Path: [email protected]
Sender Domain: gmail.com
Reply-To: [email protected]
DKIM Signature: Passed for gmail.com.
SPF: Passed for IP 2a00:1450:4864:20::235.
Message Subject: Shipment Update.
Evidence:
Full email headers provided.
The IP 2a00:1450:4864:20::235 is linked to this phishing attempt.
The email aims to deceive recipients by appearing as an official shipment notification.
show less
A phishing email was sent to an address under the rock.ma domain, falsely claiming a payment reminde ...
show moreA phishing email was sent to an address under the rock.ma domain, falsely claiming a payment reminder and attempting to solicit fraudulent action. The email impersonates a legitimate company and is designed to deceive the recipient into taking urgent action.
This email originated from the IP 193.222.96.115, associated with alive.lagodille.com. The sending domain lagodille.com does not belong to our organization, and this email is a clear case of malicious impersonation.
Technical Details:
Return Path: [email protected]
Sender Domain: lagodille.com
DKIM Signature: Passed for lagodille.com
SPF: Passed for IP 193.222.96.115
ARC-Seal Header: Shows relay information confirming email origin
Message Subject: Payment Reminder: Urgent Action Required
Evidence:
Full email headers provided
The IP 193.222.96.115 is actively used for phishing/spam
The email impersonates a financial request to defraud recipients
show less
A fraudulent email was sent to our domain (rock.ma), impersonating a legitimate company (Argos Limit ...
show moreA fraudulent email was sent to our domain (rock.ma), impersonating a legitimate company (Argos Limited), with a misleading reply-to address. The email appears to originate from an academic institution (etud.u-picardie.fr) but includes a reply-to domain argos-purchasing.com, which is not affiliated with Argos.
The phishing attempt is designed to deceive recipients into responding to a fraudulent address. The email was sent from IP 195.83.152.9, which belongs to Université de Picardie and was used as a relay for the attacker.
Technical Details:
Return Path: [email protected]
Sender Domain: etud.u-picardie.fr (likely compromised)
Reply-To Address: [email protected] (fraudulent)
DKIM Signature: Passed for u-picardie.fr.
SPF: Passed for IP 195.83.152.9.
X-Spam: Marked as spam due to Bayesian analysis.
show less
A fraudulent email was sent to an address under the rock.ma domain, attempting to impersonate a bill ...
show moreA fraudulent email was sent to an address under the rock.ma domain, attempting to impersonate a billing department. The email appears to originate from resumeprime.com via the mail server newserver3.ekonekta.com and was sent from IP 69.175.66.244.
The email is suspicious due to:
Misleading Sender: Claimed sender is [email protected], but it attempts to deceive the recipient.
Reply-To Mismatch: Redirects replies to [email protected], unrelated to resumeprime.com.
Forgery Indicators:
SPF & DKIM passed for resumeprime.com, but this does not confirm legitimacy.
Message is routed via a questionable mail relay (103.207.37.74) before reaching 69.175.66.244.
show less
A phishing email was sent to an address under the rock.ma domain, impersonating a charitable organiz ...
show moreA phishing email was sent to an address under the rock.ma domain, impersonating a charitable organization to mislead the recipient into believing they had made a donation. The email originates from [email protected] and references St. Anthony Cathedral Charity, which is not associated with rock.ma.
The email uses SPF, DKIM, and DMARC to appear legitimate while attempting to deceive recipients. The originating server (server.daicel.ca) is associated with IP 50.6.175.73, which is responsible for sending this phishing attempt.
Technical Details:
Return Path: [email protected]
Sender Domain: daicel.ca
DKIM Signature: Passed for daicel.ca.
SPF: Passed for IP 50.6.175.73.
ARC-Seal Header: Shows relays but confirms phishing attempt.
Message Subject: Important Notification Regarding Your Donation.
Reply-To Address: [email protected] (possible scam domain).
show less
A fraudulent email was sent to an address under the rock.ma domain, attempting to impersonate a legi ...
show moreA fraudulent email was sent to an address under the rock.ma domain, attempting to impersonate a legitimate business entity. The email originated from 140.205.208.146, claiming to be from edm.xmbagsss.com, and was signed via dkim=pass. The email used misleading subject lines and reply-to addresses ([email protected]) to deceive recipients into interacting with potentially harmful content.
Technical Details:
Return Path: [email protected]
Sender Domain: edm.xmbagsss.com
DKIM Signature: Passed for edm.xmbagsss.com.
SPF: Passed for IP 140.205.208.146.
ARC-Seal Header: Impersonation detected through mail relays.
Message Subject: Fraudulent marketing email with non-legitimate offers.
show less
A spam/phishing email was received at an address under the rock.ma domain, attempting to advertise a ...
show moreA spam/phishing email was received at an address under the rock.ma domain, attempting to advertise a product through misleading email practices. The email originated from mail.pindatas.com, and the sending server's IP was 47.241.190.139.
Technical Details:
Return Path: [email protected]
Sender Domain: mail.pindatas.com
DKIM Signature: Passed for mail.pindatas.com.
SPF: Passed for IP 47.241.190.139.
Message Subject: "Versatile Karaoke Machines for kids and adults".
Received from: alimail47.intl.sendcloud.org ([47.241.190.139]).
Reply-to Address: [email protected], indicating potential fraud.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email falsely warns about a password expiration and urges action. It passed SPF and DKIM for a domain unrelated to us (readlook.tk), and was sent from the IP 147.45.113.158.
Technical Details:
Return Path: [email protected]
Sender Domain: readlook.tk
DKIM Signature: Passed for readlook.tk
SPF: Softfail for kitazato.co.jp, does not designate 147.45.113.158 as a permitted sender.
Reverse DNS Lookup: Failed for 147.45.113.158
Message Subject: [***IMPORTANT***] Password Expiration Notice
Header Manipulation: The email falsely claims to be from kitazato.co.jp, but headers reveal readlook.tk as the real sender.
show less
A fraudulent email was sent to an address under the rock.ma domain, attempting to deceive the recipi ...
show moreA fraudulent email was sent to an address under the rock.ma domain, attempting to deceive the recipient by presenting a fake quotation request. The email originates from [email protected] with the subject line "Quotation", but this sender has no affiliation with rock.ma.
Technical Details:
Sender Email: [email protected]
Sender Domain: reipromises.com
Originating IP: 193.222.96.28
DKIM Signature: Passed for reipromises.com
SPF: Passed for IP 193.222.96.28
ARC-Seal Header: Possible impersonation detected
Message Subject: Quotation
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our host ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our hosting control panel. The email falsely claims that immediate action is required on a supposed cPanel account and includes fraudulent content. It passed SPF and DKIM verification for a domain unrelated to us (makesyourowncream.it.com) and was sent from the IP 209.135.168.190.
Technical Details:
Return Path: [email protected]
Sender Domain: makesyourowncream.it.com
DKIM Signature: Passed for makesyourowncream.it.com.
SPF: Passed for IP 209.135.168.190.
ARC-Seal Header: Shows impersonation through mail relays.
Message Subject: Immediate action required on panel (id: panel-a3450).
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email includes a fraudulent quotation request to mislead the recipient into interacting with a malicious attachment.
Technical Details:
Return Path: [email protected]
Sender Domain: malehgroup.cam
DKIM Signature: Passed for malehgroup.cam.
SPF: Passed for IP 113.30.190.121.
Reverse DNS Lookup: Failed, indicating a suspicious server.
ARC-Seal Header: Impersonation attempt detected through relays.
Message Subject: Quotation
show less
Fraud OrdersPhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.