An email was sent to an address under the rock.ma domain, attempting to impersonate our organization ...
show moreAn email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The message claims to be an important notification from our email system but originates from pakitchan.com. The email is fraudulent, as rock.ma does not use pakitchan.com for notifications. The attack appears to be an attempt to phish credentials or mislead recipients.
Technical Details:
Offending IP: 87.120.121.75
Return Path: [email protected]
Sender Domain: pakitchan.com
DKIM Signature: Fails for pakitchan.com.
SPF: Passes, but using a domain not related to rock.ma.
DMARC: Fails (p=NONE, sp=NONE).
Spam Score: 8.5 (classified as spam by SpamAssassin).
Spamhaus Listings: The domain pakitchan.com and IP are flagged in Spamhaus for phishing-related activities.
show less
A phishing email was sent to [email protected], impersonating a cPanel Supportโข notification to mislead th ...
show moreA phishing email was sent to [email protected], impersonating a cPanel Supportโข notification to mislead the recipient into clicking a fraudulent link and potentially providing credentials. The email falsely claims that the recipient must accept new terms to avoid disconnection.
The email originates from the IP 87.120.121.74, belonging to pakitchan.com, which has been flagged by Spamhaus for phishing activity. The DKIM signature for pakitchan.com failed, and SPF shows it as a permitted sender, but DMARC validation failed.
Technical Details:
Return Path: [email protected]
Sender Domain: pakitchan.com
DKIM Signature: Failed for pakitchan.com.
SPF: Passed for IP 87.120.121.74.
ARC-Message-Signature: Confirmed forgery attempts.
Subject: Fake cPanel notification claiming required action.
Phishing Link: https://fe901a326ecd2693c.freewebhostmost.com/ecd2693c8/fe9081e.html#[email protected]show less
A phishing email was sent to an address under the rock.ma domain, impersonating our organization. Th ...
show moreA phishing email was sent to an address under the rock.ma domain, impersonating our organization. The email attempts to promote a fraudulent product while passing as legitimate communication. It passed SPF and DKIM checks for an unrelated domain (wheatsearch.com.cn) and was sent from the IP 115.124.21.100.
Technical Details:
Return Path: [email protected]
Sender Domain: wheatsearch.com.cn
DKIM Signature: Passed for wheatsearch.com.cn.
SPF: Passed for IP 115.124.21.100.
ARC-Seal Header: Impersonation attempt detected.
Message Subject: To Know Our Innovative Multi-Port VR Cable for an Optimal VR Gaming Experience - <28/01/2025 13:48:55>.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email falsely presented a purchase inquiry to mislead recipients into interacting with fraudulent content. The email originated from the IP address 91.199.160.238 and used a domain unrelated to us (swiftsail.info).
Technical Details:
Return Path: [email protected]
Sender Domain: swiftsail.info
DKIM Signature: Passed for swiftsail.info.
SPF: Passed for IP 91.199.160.238.
Message Subject: New Purchase Inquiry Price List.
Authentication Headers: Show alignment of DKIM and SPF, but the domain and message are fraudulent.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to impersonate our organization. The email claims to represent vanreilforklifts.nl and includes fraudulent content. The DKIM signature for vanreilforklifts.nl failed, and the email appears to have originated from the IP 185.113.8.196.
Technical Details:
Return Path: [email protected]
Sender Domain: vanreilforklifts.nl
DKIM Signature: Failed for vanreilforklifts.nl.
SPF: Passed for IP 185.113.8.196.
ARC-Seal Header: Indicates failed validation for DKIM.
Message Subject: AW: AW: BYSTRONIC Order 25370398-SWIFT
show less
A phishing email impersonating the domain rock.ma was received, claiming to be a fax notification an ...
show moreA phishing email impersonating the domain rock.ma was received, claiming to be a fax notification and urging the recipient to click a malicious link. The email passed SPF checks and contained a DKIM signature for rock.ma, but originated from an unauthorized IP (176.96.131.135). The email contains links redirecting to a malicious page (https://bafkreidaf6ow4y6c7b3vz6nhzmpdnlt7yqwizjrqp6ejk52iqm6vterzsi.ipfs.flk-ipfs.xyz/#[email protected]), posing as a fax service.
Technical Details:
Return Path: [email protected]
Sender Domain: rock.ma (unauthorized use).
SPF: Failed for 176.96.131.135.
URL: Redirects to a phishing site impersonating a fax service.
Subject: "Fax from +1 509-663-**** (2 pages)"
IP: 176.96.131.135
show less
An unauthorized email was sent to one of our domain users, impersonating rock.ma. The email pretends ...
show moreAn unauthorized email was sent to one of our domain users, impersonating rock.ma. The email pretends to originate from a legitimate source and attempts to deceive users into taking fraudulent action. The IP 2a06:dd00:20:0:1d3::1 is identified as the sender and failed SPF checks, indicating a spoofing attempt. The sender email domain (azordoiagas.com) and content headers suggest phishing and spam activity.
Technical Details:
Return Path: [email protected]
Sender Domain: azordoiagas.com
SPF: Softfail for IP 2a06:dd00:20:0:1d3::1.
Message-ID: <[email protected]>
Subject: Encoded text (malformed UTF-8 headers).
Authentication Results:
SPF failed for azordoiagas.com.
DMARC policy is missing or misconfigured for the sender domain.
show less
A phishing email was sent using the domain rock.ma in the Return-Path field without authorization. T ...
show moreA phishing email was sent using the domain rock.ma in the Return-Path field without authorization. This email falsely claims to be related to Orange and includes suspicious attachments (Invitatio.avi) and misleading links. As the legitimate owner of rock.ma, we confirm that this email was not sent from our servers and represents unauthorized use of our domain.
Technical Details:
Return Path: [email protected]
Sender Domain: mms.orange.fr (spoofed).
DKIM Signature: Passed for rock.ma and wanadoo.fr (unauthorized use).
SPF: Passed with IP 2a01:71c1:209:1:232::1 as the sender.
Attachments: Email contains a .avi file (Invitatio.avi) and other potentially malicious content (.gif).
Recipient: Sent to [email protected], a valid mailbox under our domain.
Evidence: Email headers confirm the IP used for sending the phishing email, impersonating our domain.
show less
An unsolicited phishing email was sent to our rock.ma domain, originating from an unauthorized IP ad ...
show moreAn unsolicited phishing email was sent to our rock.ma domain, originating from an unauthorized IP address 8.219.35.44. The email attempts to promote a product and includes a deceptive unsubscribe link (track.lzm66.com), which redirects users to potentially malicious pages. The sender impersonates a legitimate contact (Sunny) and leverages fake SPF, DKIM, and DMARC validation to bypass spam filters.
Technical Details:
Return Path: [email protected].
Sender Domain: wujr5.com.
Reply-To: [email protected].
DKIM Signature: Passed for wujr5.com.
SPF: Passed with 8.219.35.44 as the designated sender.
Subject: "Find Out About Our Distinct Mini Displayport Cable Adapter..."
URL: Malicious tracking link: https://track.lzm66.com/track.php?event=unsubscribe&emailId=....
Feedback-ID: Impersonates promotional email headers.
show less
An email was received attempting to impersonate our domain (rock.ma) and mislead recipients into bel ...
show moreAn email was received attempting to impersonate our domain (rock.ma) and mislead recipients into believing it was legitimate. The sender ([email protected]) included a large recipient list, potentially targeting multiple individuals or organizations. This email contains no specific call to action, but its unsolicited nature and vague subject ("Hallo") suggest phishing or spam activity.
Technical Details:
Return Path: [email protected]
Sender Domain: gmail.com (misused)
DKIM Signature: Passed for gmail.com.
SPF: Passed for 2607:f8b0:4864:20::741.
Message ID: <CA+QsNPU4cDRg4KVipHZHG70dg989uAsqfs67b+tsSp+A9T3ejQ@mail.gmail.com>
IP Address: 2607:f8b0:4864:20::741
Subject: "Hallo"
show less
A phishing email was received impersonating the domain rock.ma. The email appears to originate from ...
show moreA phishing email was received impersonating the domain rock.ma. The email appears to originate from Gmail ([email protected]) but was sent to multiple recipients, including [email protected], as part of a spam campaign. The content is vague and deceptive, likely aimed at harvesting information or misleading the recipient into taking further action.
Technical Details:
Return Path: [email protected].
Sender IP: 2607:f8b0:4864:20::236.
DKIM: Passed for gmail.com (misuse for spamming).
SPF: Passed for 2607:f8b0:4864:20::236.
Subject: Generic "Hi" message, indicative of a spam or phishing attempt.
Recipients: Includes multiple recipients unrelated to rock.ma, such as [email protected] and [email protected].
Headers: Indicate use of Google's mail servers, but the sender behavior is consistent with spam or phishing campaigns.
show less
A phishing email was received, impersonating our domain rock.ma, attempting to deceive recipients in ...
show moreA phishing email was received, impersonating our domain rock.ma, attempting to deceive recipients into engaging with malicious content. The email originated from an unauthorized IP address (2a00:1450:4864:20::642), which is associated with Google Ireland Limited. Notably, this IP has been reported for abusive activities multiple times, with 82 reports from 13 distinct sources, the most recent being a month ago.
ABUSEIPDB
Technical Details:
Return Path: [email protected]
Sender Email: [email protected]
Subject: "Hey"
Recipients: Multiple, including [email protected]
DKIM Signature: Passed for gmail.com
SPF: Passed with 2a00:1450:4864:20::642 as the sender
Content: The email contains a generic greeting without specific details, which is a common tactic in phishing attempts to elicit a response from the recipient.
show less
A phishing email was received, impersonating the domain intl.presonus.com, claiming an "Outstanding ...
show moreA phishing email was received, impersonating the domain intl.presonus.com, claiming an "Outstanding Payment" to mislead recipients. The email originates from the unauthorized IP 103.233.1.227 and attempts to establish credibility by spoofing the sender address and using a fraudulent reply-to address [email protected]. The domain intl.presonus.com has no valid MX records, further confirming the unauthorized nature of this email.
Technical Details:
Return Path: [email protected]
Sender Domain: intl.presonus.com (unauthorized use).
Reply-To Address: [email protected].
IP: 103.233.1.227
Subject: "Outstanding payment"
Email Agent: Roundcube Webmail/1.4.15.
Authentication Failures:
SPF: Neutral (no valid SPF for domain).
DMARC: None.
show less
An email impersonating our domain rock.ma was received, targeting our clients with misleading and po ...
show moreAn email impersonating our domain rock.ma was received, targeting our clients with misleading and potentially harmful content. The sender ([email protected]) is unauthorized and uses deceptive practices to impersonate legitimate communications.
The email originates from the IP 2a01:111:f403:2e0d::824, which passed SPF and DKIM checks for the domain hotmail.com, but the content and intent are clearly fraudulent.
Technical Details:
Return Path: [email protected]
Sender Domain: hotmail.com
DKIM Signature: Passed for hotmail.com.
SPF: Passed with 2a01:111:f403:2e0d::824 as the sender.
Subject: "Enguriy multiswitches - Lnbs -diseqswitch- Connector"
IP: 2a01:111:f403:2e0d::824
show less
A phishing email was received targeting our domain rock.ma. The sender impersonates "Meta for Busine ...
show moreA phishing email was received targeting our domain rock.ma. The sender impersonates "Meta for Business" and claims that an account will be disabled, urging users to click on a link or reply to resolve the issue. The email originated from the IP 2a01:111:f403:2c14::827, which is unauthorized for this purpose.
Technical Details:
Return Path: [email protected]
Sender Domain: hotmail.com.br
DKIM Signature: Passed for hotmail.com.br.
SPF: Passed with IP 2a01:111:f403:2c14::827.
Subject: "URGENT: Your account and page will be disabled (Account ID: 566020690087843)"
Reply-To: Meta Legal For Business <[email protected]>
Message Intent: Fraudulent, attempting to steal sensitive information by creating urgency.
show less
An unsolicited email was sent to our domain (rock.ma) from the unauthorized IP 51.83.98.159. The sen ...
show moreAn unsolicited email was sent to our domain (rock.ma) from the unauthorized IP 51.83.98.159. The sender claimed to offer services for website redesign/upgrade, falsely referencing our domain. The email passed SPF and DKIM checks for the sender's domain (i24tech.com) but included misleading content suggesting a direct response.
The email was sent via the following relay path:
Originating IP: 49.36.185.210
Mail Server: vps-243b0fc1.vps.ovh.net (51.83.98.159)
No prior consent was given to receive such emails. This appears to be a fraudulent or spam attempt targeting the recipient's domain.
Technical Evidence:
Return Path: [email protected]
Sender Domain: i24tech.com
Subject: "Re: rock.ma - Upgrade/Re-Design of your current website"
SPF: Passed for IP 51.83.98.159.
DKIM: Passed for i24tech.com.
show less
A phishing email was received, impersonating an employee of dasholding.ae and requesting an RFQ (Req ...
show moreA phishing email was received, impersonating an employee of dasholding.ae and requesting an RFQ (Request for Quotation). The email originated from an unauthorized IP address 192.3.3.131, which failed reverse DNS lookup and SPF checks. The sender domain does not align with the relay server firmflat.com. This is a clear attempt to deceive recipients and potentially engage in fraudulent transactions.
Technical Details:
Return Path: [email protected]
Sender Domain: dasholding.ae
SPF: Softfail for IP 192.3.3.131.
Reverse DNS: Failed for IP 192.3.3.131.
Message Subject: "RFQ - PR No: 10152025"
Content-Type: HTML, typical of phishing attempts.
show less
An email impersonating the rock.ma domain was sent, attempting to deceive the recipient into believi ...
show moreAn email impersonating the rock.ma domain was sent, attempting to deceive the recipient into believing it was from a legitimate sender. The email contained a suspicious subject and urged the recipient to take action. The IP address 34.236.127.150 was used to relay the email, with the sender misusing SPF and DKIM records to appear legitimate.
Technical Details:
Return Path: [email protected]
Sender Domain: oss.com.pe
SPF: Passed for IP 34.236.127.150, although unauthorized for rock.ma.
DKIM: Passed for oss.com.pe but used inappropriately.
Message Subject: Guten Tag, RockMa
URL: No direct phishing URL detected in content, but the nature of the email strongly suggests fraudulent intent.
show less
A phishing email impersonating the rock.ma domain was sent to one of our addresses. The email origin ...
show moreA phishing email impersonating the rock.ma domain was sent to one of our addresses. The email originated from the unauthorized IP 57.128.228.145 and claims to be from HostingSEO24. It includes a misleading subject line in Arabic and links to an unsubscribe URL from hostingseo24.com. The email appears to have passed SPF and DKIM checks for the domain hostingseo24.com but is fraudulent and unrelated to our organization.
Technical Details:
Return Path: [email protected]
Sender Domain: hostingseo24.com
DKIM Signature: Passed for hostingseo24.com (unauthorized use).
SPF: Passed for IP 57.128.228.145.
Subject: Contains misleading Arabic text referencing rock.ma.
IP: 57.128.228.145
Malicious URL: Links to unsubscribe action on hostingseo24.com
show less
This phishing email targeted a rock.ma recipient and attempted to mislead the user with deceptive co ...
show moreThis phishing email targeted a rock.ma recipient and attempted to mislead the user with deceptive content. It included DKIM and SPF signatures to bypass spam filters but originated from an unauthorized IP address (27.64.123.12). The email contained vague but manipulative content and included a suspicious message promoting unrelated evaluation of technical and gender neutrality.
Technical Details:
Return Path: [email protected]
Sender Domain: gmail.com
DKIM Signature: Passed for gmail.com.
SPF: Passed with IP 27.64.123.12.
Message Subject: Posing as a technical evaluation email.
IP: The sending IP, 27.64.123.12, appears unauthorized and suspicious.
show less
An email was received from the address [email protected], using a government domain to misl ...
show moreAn email was received from the address [email protected], using a government domain to mislead recipients into believing the email is legitimate. The sender impersonates a government official, and the subject suggests an urgent financial matter ("REMINDER: Monthly Outstanding Bill"). The email contains deceptive information and links to a malicious reply-to address, [email protected], which is unrelated to the sender domain. This constitutes phishing and misuse of a trusted domain.
Technical Details:
Return Path: [email protected]
Sender Domain: ctdkppolice.gov.pk
Reply-To: [email protected]
SPF: Passed for 103.240.220.37.
Mail User-Agent: Roundcube Webmail/1.6.9.
Subject: "REMINDER: Monthly Outstanding Bill."
IP Address: 103.240.220.37
show less
A phishing email was received impersonating Dropbox, attempting to deceive the recipient into updati ...
show moreA phishing email was received impersonating Dropbox, attempting to deceive the recipient into updating their payment method through fraudulent links. The email claims to originate from Dropbox ([email protected]) but was sent from an unauthorized IP (64.74.161.198). The email contains suspicious content designed to extract sensitive user information and failed SPF checks.
Technical Details:
Return Path: [email protected]
Sender Domain: dropbox.com (unauthorized use).
SPF: Softfail - 64.74.161.198 is not a permitted sender for dropbox.com.
Subject: Action Requested: Update your payment method.
IP: 64.74.161.198.
show less
A phishing email impersonating Meta/Instagram was received, attempting to trick recipients into clic ...
show moreA phishing email impersonating Meta/Instagram was received, attempting to trick recipients into clicking a fraudulent verification link. The email claims the recipient has received a "blue badge" verification on Instagram and urges them to click on a malicious link to finalize the process. The email passed SPF and DKIM checks for the domain rock.ma, but it was sent from an unauthorized IP (217.61.209.232).
Technical Details:
Return Path: [email protected] (spoofed).
Sender Domain: Impersonates Meta/Instagram.
DKIM Signature: Passed for rock.ma (unauthorized use).
SPF: Passed with 217.61.209.232 as the sender.
Subject: "Authentification en ligne"
URL: Leads to a fraudulent site: bio.site/aprovalsbussines.
IP: 217.61.209.232
show less
An unsolicited phishing email was sent to an address under the domain rock.ma, promoting a fraudulen ...
show moreAn unsolicited phishing email was sent to an address under the domain rock.ma, promoting a fraudulent website upgrade opportunity. The email impersonates a sender ([email protected]) and includes misleading content to potentially scam recipients. The originating IP 2607:f8b0:4864:20::643 is unauthorized to use our domain.
Technical Details:
Return Path: [email protected]
Sender Domain: wordpres.in
DKIM Signature: Passed for wordpres.in (likely spoofed).
SPF: Passed for 2607:f8b0:4864:20::643.
URL: Promotes a suspicious service falsely associated with us.
Subject: "Website Upgrade Opportunity"
IP: 2607:f8b0:4864:20::643
show less
A phishing email was sent to impersonate the domain rock.ma and the company Mahalo Ukuleles, request ...
show moreA phishing email was sent to impersonate the domain rock.ma and the company Mahalo Ukuleles, requesting sensitive financial information and payment details. The email claims the recipient has unpaid invoices and asks for a list of transactions to remit payment. The email also includes a fraudulent link to the Mahalo Ukuleles website.
Technical Details:
Return Path: [email protected] (unauthorized use).
Sender Domain: alumni.carleton.ca impersonating rock.ma.
DKIM Signatures: Passed for rock.ma and alumni.carleton.ca.
SPF: Passed for 217.61.209.232 as the sender.
Message Content: Fraudulent request for payment under the guise of Mahalo Ukuleles, referencing unpaid invoices.
IP Address: 217.61.209.232 (mail server used for sending this email).
Phishing Link: Redirects recipients to fake financial pages.
show less
Fraud OrdersPhishingEmail Spam
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.