An email impersonating our domain rock.ma was sent to one of our addresses, attempting to deceive us ...
show moreAn email impersonating our domain rock.ma was sent to one of our addresses, attempting to deceive users into taking fraudulent actions. The email falsely claims to address server errors and appears to be sent from a legitimate sender. However, the originating IP 2a00:1450:4864:20::541 is unauthorized for our domain. The email was flagged as suspicious due to its SPF and DKIM verification for aivirtualassistwork.com, which is unrelated to our domain.
Technical Details:
Return Path: [email protected]
Sender Domain: aivirtualassistwork.com
DKIM Signature: Passed for aivirtualassistwork.com.
SPF: Passed with 2a00:1450:4864:20::541 as the sender.
Subject: "Re: rock.ma Errors"
IP: 2a00:1450:4864:20::541
show less
A phishing email impersonating our domain rock.ma was sent to mislead users into clicking a maliciou ...
show moreA phishing email impersonating our domain rock.ma was sent to mislead users into clicking a malicious link under the pretext of "Delivery Issues." The email passed SPF and DKIM checks for rock.ma, but the IPs 217.61.209.232 and 152.89.218.38 are not authorized by our domain. The email contains deceptive content, including a link redirecting users to a malicious page hosted at https://ipfs.io. This activity constitutes unauthorized use of our domain and an attempt to harvest credentials or personal information.
Technical Details:
Return Path: [email protected]
Sender Domain: service.co.jp
DKIM Signature: Passed for rock.ma (unauthorized use).
SPF: Passed using IP 217.61.209.232.
URL: Redirects to phishing page hosted at https://ipfs.io/ipfs/bafybeiau4qkoe3roupjztfndldpkivxycpk247epsauaqkhka5ffrd7gzu/iQQogglialeon.html.
Subject: "Attention Required: rock.ma Delivery Issues 12/27/2024".
IP Relays:
Primary Sender: 217.61.209.232
Secondary Relay: 152.89.218.38
show less
A spam email was sent to [email protected], falsely claiming to offer "special offers" and providing d ...
show moreA spam email was sent to [email protected], falsely claiming to offer "special offers" and providing deceptive unsubscribe links. This email misrepresents its association with our domain rock.ma and uses IP 188.94.79.81 for delivery, which is not authorized by us. It also uses the misleading sender [email protected] and attempts to redirect recipients to potentially malicious links.
Technical Details:
Sender IP: 188.94.79.81
Sender Domain: businessdestination.smtp3.net
Reply-to: [email protected] (unverified).
SPF: Pass for 188.94.79.81 (unrelated domain).
DKIM: Pass for rock.ma (likely unauthorized).
Links in Email:
Newsletter: https://www.5secondi.it/newsletter/newsletterbn_05-01-2024.html
Unsubscribe: http://businessdestination.smtp3.net/admin/public/unsubscribe.php?g=69&[email protected]show less
A phishing email impersonating our domain (rock.ma) was received. The email attempted to mislead rec ...
show moreA phishing email impersonating our domain (rock.ma) was received. The email attempted to mislead recipients into engaging with fraudulent content, claiming to provide high-quality products and special offers. The email originated from an unauthorized IP (156.224.82.117) and used deceptive sender details. SPF, DKIM, and DMARC inconsistencies are evident in the headers, with unauthorized use of rock.ma and supe.labelprintingvirga.com.
Technical Details:
Return Path: [email protected]
Sender Domain: supe.labelprintingvirga.com
DKIM Signature: Failed for supe.labelprintingvirga.com, unauthorized use of rock.ma.
SPF: Passed, but the sender IP is unauthorized for rock.ma.
Malicious Content: Claims of special offers and fake product sales.
Subject: "[Spam] Special Offers, Limited-Time Promotions."
show less
This email was sent to [email protected], attempting to impersonate our organization and falsely claim ...
show moreThis email was sent to [email protected], attempting to impersonate our organization and falsely claim a copyright verification issue. The email encourages users to take action by clicking a fraudulent link.
The sender is spoofing Gmail, with the sender’s address listed as [email protected]. The email originated from an unauthorized IP address (79.175.80.240), which does not belong to our domain or authorized senders. The malicious link redirects to a fraudulent page designed to extract sensitive information from recipients.
Technical Details:
Return Path: [email protected]
Sender Domain: gmail.com
DKIM Signature: Passed for gmail.com.
SPF: Passed for IP 79.175.80.240.
Subject: "Notification: Verify Copyright of Content on Page Rock.ma".
Malicious Link: Embedded in the email, potentially leading to phishing.
IP Address: 79.175.80.240.
show less
A phishing email was sent to our domain (rock.ma) from an unauthorized sender impersonating Gmail. T ...
show moreA phishing email was sent to our domain (rock.ma) from an unauthorized sender impersonating Gmail. The email originated from the IPv6 address 2a04:2e00:201b::a and contained misleading content attempting to solicit a quick reply from the recipient. The sender address, [email protected], is unauthorized. The SPF check resulted in a soft fail, and the email includes suspicious and potentially harmful content.
Technical Details:
Return Path: [email protected]
Sender Domain: gmail.com
SPF: Soft fail for 2a04:2e00:201b::a.
IP Reverse Lookup: Failed for 2a04:2e00:201b::a.
Subject: "Quick reply please:!!!!"
Message-ID: <[email protected]>
Received Header: Shows mail originated from vps34802.servebyte.com.
show less
An unsolicited bulk email was received at an address under the rock.ma domain. The email impersonate ...
show moreAn unsolicited bulk email was received at an address under the rock.ma domain. The email impersonates a legitimate service and contains potentially harmful links. It passed SPF and DKIM checks for unrelated domains (indigolab.ru and mail.selcloud.ru) and originated from the IP address 5.8.75.168.
The email encourages the recipient to unsubscribe via a link, potentially redirecting to a phishing or malware site. The IP and domains are not authorized senders for rock.ma. The presence of bulk mailing headers such as Precedence: bulk and metadata such as List-Unsubscribe indicates this is part of a large spam campaign.
Technical Details:
Return Path: [email protected]
Sender Domain: indigolab.ru
DKIM Signature: Passed for mail.selcloud.ru and indigolab.ru (unauthorized).
SPF: Passed with IP 5.8.75.168.
Precedence: Bulk email.
URL: Includes unsubscribe link:
https://smtp.mail.selcloud.ru/list/unsubscribe/v2
Message ID: <[email protected]>
show less
This phishing email was sent to our domain rock.ma, originating from the unauthorized IP address 119 ...
show moreThis phishing email was sent to our domain rock.ma, originating from the unauthorized IP address 119.73.102.78. The email contains a fraudulent message, attempting to extort Bitcoin payments by falsely claiming email or account issues. The message uses deceptive tactics, including Arabic text and a fake Bitcoin wallet address, to manipulate recipients into sending funds.
Technical Details:
Return Path: <[email protected]>
Sender Domain: 2loveferret.jp
DKIM Signature: Passed for rock.ma (unauthorized use).
SPF: None for the sender domain.
Bitcoin Wallet Address in Message: bc1q3xkxh53mkpf6wkk906u0v4magd5rz9zx6nl6ce.
Subject: "[SPAM] Fw:"
IP: 119.73.102.78
Indicators:
Content flagged as spam by filters, including terms like "Bitcoin" and "BTC".
Listed in Spamhaus SBL-CSS.
show less
A phishing email was sent to an address under the domain rock.ma, attempting to impersonate our orga ...
show moreA phishing email was sent to an address under the domain rock.ma, attempting to impersonate our organization. The email, originating from the unauthorized IP 154.81.10.44, appears to be sent from szepllogistics.com. It contains deceptive content referencing logistics operations and includes reply-to and return-path headers that redirect to another domain (epllogistics.cn). The email passed SPF and DKIM checks for szepllogistics.com, but it fraudulently uses rock.ma in its headers.
Technical Details:
Return Path: [email protected]
Sender Domain: szepllogistics.com
DKIM Signature: Passed for szepllogistics.com.
SPF: Passed for IP 154.81.10.44.
X-Originating-IP: 113.116.237.169.
Message Subject: "Logistics cooperation."
Evidence of Spam/Phishing: Suspicious reply-to domain and misleading content attempting to establish fraudulent cooperation.
show less
A phishing email impersonating a legitimate business was sent to our domain's user under the pretext ...
show moreA phishing email impersonating a legitimate business was sent to our domain's user under the pretext of a "Final Offer RFQ." The email originated from an unauthorized IP address (213.139.205.188) linked to novelisis.com. While the email passed SPF and DKIM checks for the sending domain, its contents were misleading and included a fraudulent intent.
Technical Details:
Return Path: [email protected]
Sender Domain: novelisis.com
DKIM Signature: Passed for novelisis.com.
SPF: Passed with 213.139.205.188 as the sender.
Subject: "Final Offer RFQ"
IP: 213.139.205.188
Observed Behavior: The email attempted to mislead the recipient to engage with a potentially harmful or fraudulent response.
show less
A phishing email was sent to an address under the rock.ma domain, attempting to mislead recipients i ...
show moreA phishing email was sent to an address under the rock.ma domain, attempting to mislead recipients into engaging with a fraudulent business opportunity. The email passed SPF and DKIM checks for the domain xjcyd.com but was sent from an unauthorized IP (47.245.195.194). The sender impersonates legitimate businesses to deceive recipients into trusting the message.
Technical Details:
Return Path: [email protected]
Sender Domain: xjcyd.com
DKIM Signature: Passed for xjcyd.com.
SPF: Passed for IP 47.245.195.194.
Subject: "Open an amazing energy storage partnership opportunity!"
IP: 47.245.195.194
The email claims to offer a business partnership and includes misleading details to lure victims.
show less
A phishing email impersonating our domain rock.ma was received. It claims to represent the "Kristine ...
show moreA phishing email impersonating our domain rock.ma was received. It claims to represent the "Kristine Wellenstein Foundation" and includes a fraudulent fundraising project offer. The email was sent from the unauthorized IP address 151.115.59.245 and contains links to malicious or deceptive websites.
The sender used a compromised or spoofed domain whs.tc.edu.tw and claimed to reply to [email protected]. The email passed DKIM checks but was sent without authorization. This activity constitutes phishing and email spam targeting rock.ma.
Technical Details:
Return Path: [email protected]
Sender Domain: whs.tc.edu.tw (unauthorized use).
DKIM Signature: Passed for whs.tc.edu.tw.
SPF: Neutral for whs.tc.edu.tw.
Subject: "Fundraising Projekt und einem Spendenangebot"
IP: 151.115.59.245
Malicious Links: Directs users to potential phishing sites.
Message-ID: <0RhAAwdbBFoilCLzDARSDtcpK5BXUuTvFxFrhSE7Do@TINY-835954FD>
show less
A phishing email impersonating our domain rock.ma was received, attempting to deceive the recipient ...
show moreA phishing email impersonating our domain rock.ma was received, attempting to deceive the recipient into interacting with a fraudulent link and downloading malicious content. The sender used [email protected] while masquerading as our legitimate domain. The email falsely claims invoice-related updates and provides a malicious PDF link. The originating IP 198.23.221.40 was used to send this scam.
Technical Details:
Return Path: [email protected]
Sender Domain: duprexofffshore.com
DKIM Signature: Failed for duprexofffshore.com.
SPF: Pass for IP 198.23.221.40 (unauthorized usage).
Subject: Payments for 2024 invoices
URL: Malicious link points to:
https://290w0s1e40iw.freewebhostmost.com
IP: 198.23.221.40
show less
An email impersonating rock.ma was sent to a company address, attempting to mislead users into respo ...
show moreAn email impersonating rock.ma was sent to a company address, attempting to mislead users into responding to or interacting with the sender. The email pretended to be from a legitimate manager and included misleading subject lines. Although the email passed SPF and DKIM checks for gdprestaurantsupplies.com, the originating IP 198.74.52.183 is not associated with our domain and was used without authorization.
Technical Details:
Return Path: [email protected]
Sender Domain: gdprestaurantsupplies.com
Reply-To: [email protected] (mismatched).
DKIM Signature: Passed for gdprestaurantsupplies.com.
SPF: Passed with IP 198.74.52.183 as the sender.
Subject: (Panama) Exportación (misleading).
IP: 198.74.52.183.
show less
A phishing email was sent to our address [email protected], impersonating our organization. The sender ...
show moreA phishing email was sent to our address [email protected], impersonating our organization. The sender used deceptive tactics to mislead recipients. The email originated from an unauthorized IP (223.240.176.178) with a mismatched domain (fdmh.com) and reverse DNS lookup failure. This email attempts to mislead users into engaging with fake content.
Technical Details:
Return Path: [email protected]
Sender Domain: daimlerhldg.com (spoofed).
Reverse DNS: Failed for 223.240.176.178.
Content: French-language phishing with suspicious subject line magasin d039insAf16.
IP Address: Unauthorized IP 223.240.176.178.
SpamEvidence: Detected as phishing due to reverse DNS failure and mismatched domain headers.
show less
A phishing email impersonating our domain rock.ma was sent, misleading recipients into believing it ...
show moreA phishing email impersonating our domain rock.ma was sent, misleading recipients into believing it was a genuine "RFQ" (Request for Quote). The email originated from an unauthorized server at 198.74.52.183, masquerading as [email protected] and signing with a DKIM key for gdprestaurantsupplies.com. SPF validation failed for the originating domain.
The message urges recipients to respond, which aligns with phishing attempts or malicious activities.
Technical Details:
Sender Address: [email protected]
Reply-To: [email protected]
Originating IP: 198.74.52.183
SPF: Softfail for downundermanagement.com.au
DKIM: Passed for gdprestaurantsupplies.com (likely compromised).
Subject: RFQ: Quick Order
The IP 198.74.52.183 is not authorized to send mail on behalf of rock.ma or related domains.
show less
A phishing email claiming to be a DHL delivery notification was sent to our domain rock.ma. The emai ...
show moreA phishing email claiming to be a DHL delivery notification was sent to our domain rock.ma. The email uses fraudulent sender information and deceptive content to trick recipients into downloading attachments or clicking malicious links.
Technical Details:
Return Path: [email protected]
Sender Domain: bio-services.net
Originating IP: 155.94.209.11
SPF: Softfail for bio-services.net
Malicious Content: The subject references "DHL Notification de livraison de colis" with attachments potentially containing harmful content.
Received-SPF: Softfail from 2607:5500:3000:769::2
Target: [email protected]show less
A phishing email was sent to rock.ma addresses, impersonating our domain. The message claims to offe ...
show moreA phishing email was sent to rock.ma addresses, impersonating our domain. The message claims to offer a "Website Upgrade Opportunity" and urges recipients to interact with the content. The email appears to have passed DKIM and SPF verification, but it was sent from an unauthorized IP (2607:f8b0:4864:20::642). The email headers reveal the sender domain as wordpres.in, which is not affiliated with us.
Technical Details:
Return Path: [email protected]
Sender Domain: wordpres.in
DKIM Signature: Passed for wordpres.in.
SPF: Passed with 2607:f8b0:4864:20::642 as sender IP.
Subject: "Website Upgrade Opportunity"
Body: Deceptive content about a website upgrade.
show less
The IP 82.165.181.188 was detected sending spoofed phishing emails impersonating the domain fairmont ...
show moreThe IP 82.165.181.188 was detected sending spoofed phishing emails impersonating the domain fairmont.com. The forged sender address [email protected] bypassed initial filters but failed SPF and DMARC alignment checks, indicating unauthorized use of the domain. The email header revealed anomalies in the Return-Path and Received fields, showing mismatched servers and routing inconsistencies. The message contained a malicious HTML attachment encoded in base64 to bypass detection mechanisms. Upon decoding, the attachment revealed embedded scripts that attempt to load external resources, likely for credential harvesting or delivering malicious payloads. The behavior matches common patterns observed in phishing and spoofing campaigns targeting users to extract sensitive information.
show less
A spam email was sent using an address that impersonates our domain (rock.ma) with the sender SRS0=C ...
show moreA spam email was sent using an address that impersonates our domain (rock.ma) with the sender [email protected]. The email falsely claims to identify errors on our website and solicits a response to improve Google rankings.
The email shows suspicious SPF pass and spoofed DKIM headers for outlook.com and rock.ma. It originated from the IP 217.61.209.232, which does not belong to our mail servers.
Technical Details:
Sender Address: [email protected]
Return Path: [email protected]
SPF: Passed for IP 217.61.209.232.
DKIM: Failed for outlook.com, passed for spoofed rock.ma.
Message Subject: [spam] Re: issues on your Website.
Content: Solicitation claiming website errors for clickbait purposes.
show less
A phishing email targeting rock.ma impersonates a mailbox administrator, claiming the recipient's em ...
show moreA phishing email targeting rock.ma impersonates a mailbox administrator, claiming the recipient's email account will be deactivated. The malicious email includes a fake "STOP DEACTIVATION" link directing users to a fraudulent site hosted at:
https://ipfs.io/ipfs/QmYTyZJfEiXppxxCwGS5T5DP7WiyK3SrCiqosL6U6pWti5#[email protected]
The IP 109.248.199.188 is responsible for distributing this fraudulent email.
Technical Details:
Sender Address: [email protected]
Return Path: [email protected]
SPF: Softfail for toushin0927.co.jp on IP 109.248.199.188.
Subject: Request for deactivation 12/17/2024 2:29:37 a.m.
Content: Fraudulent email falsely claiming account deactivation to trick users into clicking the malicious link.
Malicious Link: https://ipfs.io/ipfs/QmYTyZJfEiXppxxCwGS5T5DP7WiyK3SrCiqosL6U6pWti5#[email protected].
show less
The email falsely claims that the password for the mailbox [email protected] is set to expire and urge ...
show moreThe email falsely claims that the password for the mailbox [email protected] is set to expire and urges the recipient to click a malicious link to "KEEP MY PASSWORD." The phishing link points to:
https://ipfs.io/ipfs/bafkreicfdjz6ryrzf2eqbbzdidpomgutps2sn4qg7n4xihh5ciybuur7je#[email protected]
The email is delivered via IP: 92.204.134.55 through an unauthorized mail server, spoofing Rock Roundcube_CPanel. The headers also show suspicious handoff from another IP: 45.88.186.35.
Technical Evidence:
Sender: [email protected] (spoofed).
Phishing Link: Hosted on ipfs.io.
Server Handoff:
92.204.134.55 → 45.88.186.35.
SPF: Pass (spoofed).
DKIM: Valid for rock.ma.
show less
This phishing email impersonates rock.ma and claims to be a message about "undelivered mail" with 3 ...
show moreThis phishing email impersonates rock.ma and claims to be a message about "undelivered mail" with 3 pending messages. The email attempts to lure recipients into clicking a malicious link hosted on:
https://f6u7uly-n00e-nob30011le-roadsafesafe.glitch.me#[email protected].
The email is delivered from the IPv6 address 2a01:8640:e::79e5:4278, which is not authorized for the rock.ma domain. SPF validation passed, but reverse DNS failed, indicating suspicious behavior.
Technical Details:
Sender Address: [email protected] (spoofed).
Return Path: [email protected].
SPF: Passed, but reverse DNS failed for 2a01:8640:e::79e5:4278.
DKIM: Failed for tlabs-za.com.
DMARC: Failed (misalignment with tlabs-za.com).
Malicious Link:
https://f6u7uly-n00e-nob30011le-roadsafesafe.glitch.me#[email protected].
The message attempts to impersonate a "Rock Mail Administrator" to appear legitimate.
show less
This phishing email impersonates the domain rock.ma and claims to provide a voicemail message for mu ...
show moreThis phishing email impersonates the domain rock.ma and claims to provide a voicemail message for [email protected]. The email is designed to trick the recipient into accessing malicious links. The IP address 178.215.236.91 was used to deliver the fraudulent content, and SPF validation failed for this IP, indicating an unauthorized sender.
Technical Details:
Sender Address: [email protected]
SPF Result: Fail for IP 178.215.236.91 (not designated as a permitted sender).
Reverse DNS: Failed for 178.215.236.91.
Subject: "VoiceMessage to [email protected]"
Malicious Links:
https://cloudflare-ipfs.com/ipfs/...
https://bafkreifyggqqozk6al2khe3cz3kphoeuhiztfet6pmjnxalndvdadvzobe.ipfs.flk-ipfs.xyz#[email protected]
Attachments: Embedded image file (used to enhance legitimacy).
show less
A phishing email was sent attempting to impersonate the domain rock.ma, falsely claiming to deliver ...
show moreA phishing email was sent attempting to impersonate the domain rock.ma, falsely claiming to deliver a DocuSign document for review. The email links to a malicious page hosted at https://round-cube-logging.vercel.app/[email protected].
The message includes spoofed DKIM headers for kieters.cfd, and the IP 185.239.48.176 was responsible for delivering the fraudulent content.
Technical Details:
Sender Address: [email protected]
Return Path: [email protected]
SPF: Passed for IP 185.239.48.176.
DKIM: Passed for kieters.cfd.
Content: Fraudulent “DocuSign document awaiting review” email.
Malicious Link: https://round-cube-logging.vercel.app/[email protected].
show less
PhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.