Detected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt ...
show moreDetected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt.vn). The bot attempts to access non-existent files with the '.bs_model' extension appended to valid WordPress URLs (e.g., /tag/xyz/.bs_model). This indicates a coordinated search for specific vulnerabilities, BetterStudio exploits, or previously planted backdoors
show less
Detected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt ...
show moreDetected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt.vn). The bot attempts to access non-existent files with the '.bs_model' extension appended to valid WordPress URLs (e.g., /tag/xyz/.bs_model). This indicates a coordinated search for specific vulnerabilities, BetterStudio exploits, or previously planted backdoors
show less
Detected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt ...
show moreDetected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt.vn). The bot attempts to access non-existent files with the '.bs_model' extension appended to valid WordPress URLs (e.g., /tag/xyz/.bs_model). This indicates a coordinated search for specific vulnerabilities, BetterStudio exploits, or previously planted backdoors
show less
Detected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt ...
show moreDetected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt.vn). The bot attempts to access non-existent files with the '.bs_model' extension appended to valid WordPress URLs (e.g., /tag/xyz/.bs_model). This indicates a coordinated search for specific vulnerabilities, BetterStudio exploits, or previously planted backdoors
show less
Detected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt ...
show moreDetected a distributed scan pattern from multiple IPs within the VNPT network (hostname: static.vnpt.vn). The bot attempts to access non-existent files with the '.bs_model' extension appended to valid WordPress URLs (e.g., /tag/xyz/.bs_model). This indicates a coordinated search for specific vulnerabilities, BetterStudio exploits, or previously planted backdoors
show less
Blocked 14 requests in less than one minute. The IP attempted to access multiple LiteSpeed cache Jav ...
show moreBlocked 14 requests in less than one minute. The IP attempted to access multiple LiteSpeed cache JavaScript files directly (/wp-content/litespeed/js/) without visiting any HTML pages and without a valid referrer. This behavior indicates an automated vulnerability scanner or a scraper probing for specific plugin assets/versions.
Origin: AWS.
Hostname: ec2-3-39-226-163.ap-northeast-2.compute.amazonaws.com
show less
I am reporting a phishing email received on June 21, 2025, that fraudulently claims to be a final wa ...
show moreI am reporting a phishing email received on June 21, 2025, that fraudulently claims to be a final warning from a cloud storage service. The message contains misleading content urging the recipient to click a button to โKeep Using Cloud Storage.โ The button leads to a suspicious URL hosted on Google Cloud Storage https://storage.googleapis.com/eefguyjdfoklgvlkwfgdd/eefguyjdfoklgvlkwfgdd.html#ODE0PA1CFS768RDLIY14V1076EYK6IRKLVR0VYIG
which may be used to steal login credentials or spread malware.
Technical Indicators
Return-Path: <[email protected]>
Received: from ibm.com (sardo.technomarc.site. [195.154.62.55])
Email Characteristics
The email uses fear tactics: claiming that โphotos and videos will be deleted.โ
It impersonates a cloud service without naming it directly.
The visual design mimics legitimate promotional or support emails.
There is no clear company branding, privacy policy, or verifiable footer.
show less
๐ Phishing Report: Fraudulent Email Impersonating Cloud Storage Service
Subject: โ ๏ธFinal Notice: Yo ...
show more๐ Phishing Report: Fraudulent Email Impersonating Cloud Storage Service
Subject: โ ๏ธFinal Notice: Your photos and videos will be deleted โ take actionโ ๏ธ
I am reporting a phishing email received on June 21, 2025, that fraudulently claims to be a final warning from a cloud storage service. The message contains misleading content urging the recipient to click a button to โKeep Using Cloud Storage.โ The button leads to a suspicious URL hosted on Google Cloud Storage https://storage.googleapis.com/eefguyjdfoklgvlkwfgdd/eefguyjdfoklgvlkwfgdd.html
which may be used to steal login credentials or spread malware.
show less
I received a fraudulent email from this IP address, pretending to be a package delivery company. The ...
show moreI received a fraudulent email from this IP address, pretending to be a package delivery company. The message attempts to trick the recipient into clicking on a link hosted on Storage.googleapis.com, with the goal of stealing personal or financial information. The email contains typical phishing techniques and HTML manipulation to evade filters.
show less
I received a fraudulent email from this IP address, pretending to be a package delivery company. The ...
show moreI received a fraudulent email from this IP address, pretending to be a package delivery company. The message attempts to trick the recipient into clicking on a link hosted on Storage.googleapis.com, with the goal of stealing personal or financial information. The email contains typical phishing techniques and HTML manipulation to evade filters.
show less
I received a fraudulent email from IP address 54.37.50.200, pretending to be a package delivery comp ...
show moreI received a fraudulent email from IP address 54.37.50.200, pretending to be a package delivery company. The message attempts to trick the recipient into clicking on a link hosted on Storage.googleapis.com, with the goal of stealing personal or financial information. The email contains typical phishing techniques and HTML manipulation to evade filters.
show less
I received a fraudulent email from IP address 91.99.80.101 (Hetzner Online), pretending to be a pack ...
show moreI received a fraudulent email from IP address 91.99.80.101 (Hetzner Online), pretending to be a package delivery company. The message attempts to trick the recipient into clicking on a link hosted on Storage.googleapis.com, with the goal of stealing personal or financial information. The email contains typical phishing techniques and HTML manipulation to evade filters.
show less
I received a fraudulent email from IP address 148.251.229.22 (Hetzner Online), pretending to be a pa ...
show moreI received a fraudulent email from IP address 148.251.229.22 (Hetzner Online), pretending to be a package delivery company. The message attempts to trick the recipient into clicking on a link hosted on Storage.googleapis.com, with the goal of stealing personal or financial information. The email contains typical phishing techniques and HTML manipulation to evade filters.
show less
PhishingEmail Spam
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.