A fraudulent email was sent to an address under the rock.ma domain, falsely claiming to include a Sw ...
show moreA fraudulent email was sent to an address under the rock.ma domain, falsely claiming to include a Swift payment copy for USD 134,000.00. The intent is to deceive the recipient into opening a malicious attachment or engaging with the sender. The email is part of a phishing and financial fraud attempt.
The email was sent from the IP 185.253.116.107, which is linked to biopharmahealth.co. This domain is not associated with our company, making this an unauthorized impersonation attempt.
Technical Details:
Return Path: [email protected]
Sender Domain: biopharmahealth.co
DKIM Signature: Passed for biopharmahealth.co.
SPF: Passed for IP 185.253.116.107.
ARC-Seal Header: Signs of relay impersonation.
Subject: RE: Swift copy attached for USD 134,000.00.
Attachments: Email contains a malicious attachment disguised as a Swift payment document.
show less
The message originated from the IP 196.251.93.10, associated with slot0.pakitchan.com, and falsely c ...
show moreThe message originated from the IP 196.251.93.10, associated with slot0.pakitchan.com, and falsely claims to be an official Admin Technical Support™® email.
Technical Details:
Return Path: [email protected]
Sender Domain: pakitchan.com
DKIM Signature: Failed for pakitchan.com, but passed for rock.ma, indicating email header manipulation.
SPF: Passed for IP 196.251.93.10, but using spoofed sender details.
SpamAssassin Score: 10.0 (High probability of spam/phishing)
Message Subject: IMPORTANT: Mailbox Termination Request on [email protected]
Fraudulent Call to Action: The email urges the recipient to click a malicious link: https://bafybeidrugrw...ipfs.dweb.link/#[email protected]
This link is likely an attempt to steal
show less
A phishing email was sent to an address under the rock.ma domain, falsely claiming that a password r ...
show moreA phishing email was sent to an address under the rock.ma domain, falsely claiming that a password renewal is required. The email originates from IP 2a0f:cdc6:500:769::2, using a fraudulent sender domain (4--865-1.sbs). This is an attempt to deceive users into providing login credentials.
Technical Details:
Return Path: [email protected]
Sender Domain: 4--865-1.sbs
Spoofed Identity: "Rock cPanel"
SPF Fail: softfail, the IP 2a0f:cdc6:500:769::2 is not authorized to send emails for 4--865-1.sbs.
Reverse DNS Check: Failed for 2a0f:cdc6:500:769::2
Message Subject: "Password Renewal Required For [email protected]"
Authentication Results:
SPF: Softfail
DMARC: Pass (for 4--865-1.sbs only)
IP Reverse Lookup: Failed
Spam Classification: Marked as unsure, but clear phishing indicators.
show less
This email was sent to an address under rock.ma, claiming to be from Andy Mooney, CEO of Fender, but ...
show moreThis email was sent to an address under rock.ma, claiming to be from Andy Mooney, CEO of Fender, but was actually sent from [email protected] via the IP 27.124.117.101.
The email falsely claims to discuss a pending purchase order, a common business email compromise (BEC) scam technique. The domain e-fiji.com is not associated with Fender.
Technical Details:
Return Path: [email protected]
Sender Domain: e-fiji.com (not related to Fender)
SPF Softfail: The IP 27.124.117.101 is not an authorized sender for e-fiji.com.
Message Subject: "Re: Hello Mohamed" (Generic to appear as a reply)
Impersonation Attempt: The email falsely claims to be from Andy Mooney, CEO of Fender, and uses a real Los Angeles address to appear legitimate.
show less
A suspicious email was received claiming to be from [email protected], but the return path shows ...
show moreA suspicious email was received claiming to be from [email protected], but the return path shows manipulation ([email protected]). The email originated from IP 115.124.28.217 (out28-217.mail.aliyun.com), which is a known Alibaba Cloud Mail Server often used for spam and phishing attempts.
The email includes multiple encoded attachments (temp4cj.png, [email protected]), which may contain malicious content.
SPF and DKIM passed, suggesting that either the sender domain was compromised or email relay abuse occurred.
Spam classification: 0.50 but highly suspicious based on analysis.
Immediate action is recommended to block or investigate further.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email claims to be from a legitimate source and contains fraudulent content. It was sent from the IPv6 address 2a06:dd00:1:4:1c0::1, attempting to spoof a legitimate company (kitz.co.jp) while using a fraudulent sender domain (uji-syoten.online).
Technical Details:
Return Path: [email protected]
Sender Domain: uji-syoten.online
Spoofed Domain: kitz.co.jp
SPF Fail: SPF softfail detected. The IP 2a06:dd00:1:4:1c0::1 is not designated as a permitted sender for uji-syoten.online.
Reverse DNS Check: Failed for 2a06:dd00:1:4:1c0::1.
Message Subject: [MRST Users] compressible single phase?
Authentication Results:
SPF: Softfail
DMARC: None
IP Reverse Lookup: Failed
Spam Score: Classified as unsure, but contains clear phishing indicators.
show less
An unsolicited email was sent to an address under the rock.ma domain, promoting unsolicited marketin ...
show moreAn unsolicited email was sent to an address under the rock.ma domain, promoting unsolicited marketing content. The email originated from techsurvi.net, using SendGrid's outbound mail servers.
Technical Details:
Return Path: [email protected]
Sender Domain: techsurvi.net
DKIM Signature: Passed for techsurvi.net.
SPF: Passed for IP 168.245.77.104.
ARC-Seal Header: Indicates relay through multiple mail systems.
Message Subject: Sell More on Amazon
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email falsely claims that the recipient's credentials are compromised and provides a malicious link to a phishing website.
The email originated from IP 87.120.120.174 and attempts to mislead recipients into clicking a fraudulent link hosted on freewebhostmost.com. The domain i-zak-jp.com was used in DKIM signing, but its verification failed, indicating spoofing.
Technical Details:
Return Path: [email protected]
Sender Domain: i-zak-jp.com (spoofed)
DKIM Signature: Failed for i-zak-jp.com
SPF: Passed for 87.120.120.174, meaning the sending server is authorized for the spoofed domain.
ARC Authentication: Failures detected in DKIM.
Phishing URL: bof8kpbyzc58p1lvxh7x.freewebhostmost.com/ew5e9ago2/qbcjvz2212a.html#[email protected]
Message Subject: [SPAM] Ticket #ITR-632078: Compromised Credentials for [email protected]show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate a busine ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate a business alert. The email contains misleading content suggesting it is an auto parts inquiry but is actually spam or fraudulent. The sender domain (gnhwtlq.com) does not belong to us and is attempting unauthorized contact. The email was relayed through a Chinese Alibaba mail server (out21-97.dm.aliyun.com), originating from the IP 115.124.21.97.
Technical Details:
Return Path: [email protected]
Sender Domain: gnhwtlq.com
Reply-To: [email protected] (possible fraud attempt)
DKIM Signature: Passed for gnhwtlq.com, which is unrelated to our domain.
SPF: Passed for IP 115.124.21.97.
Message Subject: "Auto Rubber Parts : Engine Mount, Shock Mount".
List-Unsubscribe Link: Leads to track.lzm66.com, possibly for email harvesting or further phishing.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate an offic ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate an official manufacturer or business entity. The email was sent from the IP 140.205.208.109 and passed SPF and DKIM verification for the unrelated domain vip.wendyzhongyingchem.ltd.
This constitutes an unauthorized impersonation and a fraudulent attempt to engage recipients.
Technical Details:
Return Path: random_NjAwMDAwMTU2MDMxNTc3MjczX2NsaWVudHNAcm9jay5tYSR2aXA=@vip.wendyzhongyingchem.ltd
Sender Domain: vip.wendyzhongyingchem.ltd
Reply-To: [email protected]
DKIM Signature: Passed for vip.wendyzhongyingchem.ltd.
SPF: Passed for IP 140.205.208.109.
Message Subject: "RE: Manufacturer of the CAUSTIC SODA" (likely a scam targeting businesses).
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email claims that the recipient has pending emails that require authentication and provides a malicious link (https://online.creatre.click/) to trick the user into entering credentials.
The email was sent from the IP 119.59.108.243 under the domain amorngroup.com, which has no connection to rock.ma. The SPF check for amorngroup.com passed, but the DMARC check failed. The message contained a fraudulent signature attempting to mislead the recipient.
Technical Details:
Return Path: [email protected]
Sender Domain: amorngroup.com
DKIM Signature: Passed for rock.ma, likely spoofed.
SPF: Passed for IP 119.59.108.243, but the domain is unrelated.
DMARC: Failed (p=QUARANTINE) for amorngroup.com.
Message Subject: [spam] Three (3) pending mails..
Fraudulent Link: https://online.creatre.click/[email protected]
Spam Filter Result: Marked as spam by email security tools.
show less
A phishing email was sent to an address under the rock.ma domain, fraudulently impersonating a busin ...
show moreA phishing email was sent to an address under the rock.ma domain, fraudulently impersonating a business request under the subject "NEW ORDER PRODUCT". The email originated from [email protected] and was relayed through an unauthorized server at 103.20.235.16. This email was likely an attempt to defraud our organization by misrepresenting an order request.
Technical Details:
Return Path: [email protected]
Sender Domain: maisondecoparis.com
Authenticated Sender: 191.101.130.138 (relay host)
DKIM Signature: Passed for maisondecoparis.com.
SPF: Passed for IP 103.20.235.16.
Message Subject: NEW ORDER PRODUCT
Relay Chain:
Initial transmission from 191.101.130.138.
Relayed through 103.20.235.16, which appears to be the final sending IP.
show less
An email was received at an address under the rock.ma domain, falsely claiming to be from Spectrason ...
show moreAn email was received at an address under the rock.ma domain, falsely claiming to be from Spectrasonics. The email appears to have been sent through Amazon SES (us-west-2.amazonses.com) and originated from IP 54.240.27.187. This is an unsolicited email attempting to impersonate an official entity.
Technical Details:
Return Path: 01010194df7921bd-0766bcce-25a0-42fc-98fe-aa96eb06c829-000000@us-west-2.amazonses.com
Sender Domain: spectrasonics.net
DKIM Signature: Passed for spectrasonics.net and amazonses.com
SPF: Passed for IP 54.240.27.187
ARC-Seal Header: Indicates relay through mail relays, potential abuse of Amazon SES services.
Message Subject: "LA Fire Relief - Help Our Friends"
Unsolicited Nature: No prior interaction with Spectrasonics or Amazon SES by rock.ma
show less
A phishing email was sent to [email protected], falsely claiming to be from Network Solutions Email Su ...
show moreA phishing email was sent to [email protected], falsely claiming to be from Network Solutions Email Support. This is an unauthorized attempt to deceive recipients into taking action based on false claims. The email originated from the IPv6 address 2a06:dd00:1:4:7d4::1, using the sender domain olgulf.org, which is unrelated to our domain.
Technical Details:
Return Path: [email protected]
Sender Domain: olgulf.org
Reverse DNS Lookup: Failed for 2a06:dd00:1:4:7d4::1
SPF Authentication: softfail (Indicates unauthorized sender)
Subject: "The Network Solutions Email Support For [email protected]"
Relayed through: hosting.xmyz.com
Email Headers confirm spoofing and suspicious routing.
show less
A spam email was sent to an address under the rock.ma domain without prior consent. The message adve ...
show moreA spam email was sent to an address under the rock.ma domain without prior consent. The message advertises Prestashop development services under the sender domain citytechsoftware.in, which is unrelated to rock.ma. The email was sent via Mailgun (IP 143.55.232.10), exploiting bulk mailing services to bypass spam filters.
Technical Details:
Return Path: [email protected]
Sender Domain: citytechsoftware.in
DKIM Signature: Passed for citytechsoftware.in, indicating bulk mail behavior.
SPF: Permanent error (permerror), suggesting misconfiguration or abuse.
ARC-Seal Header: Shows manipulation of authentication results.
Subject: "Looking for a Prestashop Developer?"
show less
A phishing email was sent to our domain (rock.ma), falsely claiming to contain a payment receipt. Th ...
show moreA phishing email was sent to our domain (rock.ma), falsely claiming to contain a payment receipt. The sender address ([email protected]) appears to be spoofed or compromised. The email was sent from 31.210.157.170 (mail.ilaytextile.com), and the message appears to be an attempt to scam recipients by tricking them into opening malicious attachments.
Technical Details:
Return Path: [email protected]
Sender Domain: ilaytextile.com
DKIM Signature: Passed for ilaytextile.com
SPF: Passed for IP 31.210.157.170
Subject: FW: Payment Receipt
Attachment: Potential malicious file included
Email Client Used: Roundcube Webmail/1.4.15
show less
A fraudulent email was received by an address under the rock.ma domain. The sender attempts to imper ...
show moreA fraudulent email was received by an address under the rock.ma domain. The sender attempts to impersonate a legitimate business transaction by fabricating a fake Purchase Order (PO2124R SITCVN). This is a clear attempt at phishing and fraud. The email was sent from IP 198.23.138.12, associated with bendplvs.com, a domain unrelated to us.
Technical Details:
Return Path: [email protected]
Sender Domain: bendplvs.com
DKIM Signature: Passed for bendplvs.com.
SPF: Passed for IP 198.23.138.12.
Message Subject: Purchase Order PO2124R SITCVN.
Spam Filtering: The message was flagged as uncertain spam (X-SpamExperts-Class: unsure).
show less
A fraudulent email was received, impersonating a shipping department and claiming a package was ship ...
show moreA fraudulent email was received, impersonating a shipping department and claiming a package was shipped. The email includes a phishing link to adbpdfonl1ne.freewebhostmost.com, designed to steal user credentials. The email spoofed a rock.ma email address in the return path and passed SPF validation using pakitchan.com.
Technical Details:
Return Path: [email protected]
Sender Domain: pakitchan.com
DKIM Signature: Failed for pakitchan.com, but spoofed headers to make it appear legitimate.
SPF: Passed for 87.120.121.73, showing it was sent from slot0.pakitchan.com.
SpamAssassin Score: 9.6 (HIGH RISK) – flagged as phishing/malware attempt.
Message Subject: "Your Package has been shipped" (Spam).
show less
A phishing email was sent to an address under the rock.ma domain, impersonating a supplier. The emai ...
show moreA phishing email was sent to an address under the rock.ma domain, impersonating a supplier. The email requests a "New Order" and includes an attachment, likely containing malicious content. It passed SPF and DKIM verification for an unrelated domain (novatron-cn.cam) and was sent from the IP 107.174.36.108.
Technical Details:
Return Path: [email protected]
Sender Domain: novatron-cn.cam
DKIM Signature: Passed for novatron-cn.cam.
SPF: Passed for IP 107.174.36.108.
Message Subject: Request for New Order.
Attachment: Suspicious file likely containing malware.
X-SPF-Fail: Detected by spam filters, marked as "unsure".
show less
An email was sent to an address under the rock.ma domain, attempting to impersonate our organization ...
show moreAn email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The message falsely claimed to be from rock.ma Support, using the email [email protected], but originated from the IP 94.198.54.130.
This is a phishing attempt aimed at misleading recipients into thinking the email was an official notification from rock.ma. The sender domain jarmar.net is unrelated to us, and the message includes fraudulent alert notifications.
Technical Details:
Return Path: [email protected]
Sender Domain: jarmar.net
DKIM Signature: Passed for jarmar.net.
SPF: Passed for IP 94.198.54.130.
Reply-To: [email protected] (attempting redirection).
Message Subject: Fake rock.ma notification alert.
show less
A phishing email was sent to an address under the rock.ma domain, falsely claiming a critical vulner ...
show moreA phishing email was sent to an address under the rock.ma domain, falsely claiming a critical vulnerability in the website. The sender impersonated a cybersecurity professional and attempted to trick the recipient into engaging in fraudulent communication.
Technical Details:
Return Path: [email protected]
Sender Domain: gmail.com
Spoofed Domain: rock.ma (attempted impersonation)
DKIM Signature: Passed for gmail.com.
SPF: Passed for IP 217.61.209.232.
Subject: "Found CRITICAL Vulnerability in your website: rock.ma"
Email contained suspicious base64-encoded content to evade detection.
show less
An unsolicited email was sent to an address under the rock.ma domain, impersonating a legitimate bus ...
show moreAn unsolicited email was sent to an address under the rock.ma domain, impersonating a legitimate business (nepetrochemicals.com) to request a quotation. The sender’s IP (185.222.57.91) is unauthorized to send emails for nepetrochemicals.com, as indicated by the SPF softfail and failed reverse DNS lookup.
Technical Indicators:
Return Path: [email protected]
Sender Domain: nepetrochemicals.com
SPF Authentication: softfail (IP not authorized for the sender’s domain).
Reverse DNS Lookup: Failed for 185.222.57.91.
Message Subject: Request for Quotation (likely social engineering attempt).
Email Signed Headers: None (indicating possible spoofing).
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate HSBC. Th ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate HSBC. The email fraudulently claims to provide a payment advice and urges the recipient to click a malicious link. It was sent from the IP 87.120.121.76, which is associated with pakitchan.com, a domain flagged in multiple spam and phishing databases (Spamhaus SBL, URIBL, etc.).
Technical Details:
Return Path: [email protected]
Sender Domain: pakitchan.com (fails DKIM authentication)
DKIM Signature: Failed for pakitchan.com, Passed for rock.ma
SPF: Passed for pakitchan.com, allowing spoofing via rock.ma
ARC Authentication: Passed for rock.ma, fails for pakitchan.com
SpamAssassin Score: 12.5 (marked as spam, high likelihood of fraud)
Malicious URL: https://6c58acd3a5aa6bc12b4527.freewebhostmost.com/c12b4527/029d58ee.html#[email protected]
Subject: [SPAM] Payment Advice to [email protected]show less
A phishing email was sent to an address under the rock.ma domain, falsely claiming that the recipien ...
show moreA phishing email was sent to an address under the rock.ma domain, falsely claiming that the recipient’s Meta Business account would be disabled. The email uses a fraudulent sender address ([email protected]) while pretending to be from Meta Legal For Business.
The email was relayed through Outlook’s servers (outbound.protection.outlook.com), and the sending IP 2a01:111:f403:d10d:: successfully passed SPF, DKIM, and DMARC for hotmail.com, despite being a phishing attempt.
Technical Details:
Return Path: [email protected]
Sender Name: Meta for Business
Subject: URGENT: Your account and page will be disabled (Account ID: 566020690087843)
Reply-To: Meta Legal For Business <[email protected]>
Sending Domain: hotmail.com
DKIM-Signature: Passed for hotmail.com.
SPF: Passed for 2a01:111:f403:d10d::.
ARC-Authentication-Results: Shows inconsistencies suggesting manipulation.
show less
A phishing email was sent to an address under the rock.ma domain, impersonating Meta for Business an ...
show moreA phishing email was sent to an address under the rock.ma domain, impersonating Meta for Business and falsely claiming an account-related issue. The email was sent from the IP 2a01:111:f403:2c17::819 via an Outlook.com server, with a fraudulent sender identity Meta for Business <[email protected]>.
The email urges the recipient to take immediate action under false pretenses. It passed SPF and DKIM validation for hotmail.com, but the sender’s address does not belong to Meta. This is an impersonation attempt aimed at obtaining unauthorized access to accounts.
Technical Details:
Return Path: [email protected]
Sender Domain: hotmail.com
DKIM Signature: Passed for hotmail.com
SPF: Passed for 2a01:111:f403:2c17::819
ARC-Seal Header: Impersonation attempt detected
Message Subject: URGENT: Your account and page will be disabled (Account ID: 566020690087843)
show less
PhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.