WordPress WordFence rerporting: 144.126.129.197 (United States)
Blocked for Known malicious User-Ag ...
show moreWordPress WordFence rerporting: 144.126.129.197 (United States)
Blocked for Known malicious User-Agents
show less
HackingBrute-ForceBad Web BotExploited HostWeb App Attack
WordPress WordFence rerporting: 5.175.234.40 (United States)
Blocked for WordPress New Install File ...
show moreWordPress WordFence rerporting: 5.175.234.40 (United States)
Blocked for WordPress New Install File Probing
show less
HackingBrute-ForceBad Web BotExploited HostWeb App Attack
WordPress WordFence rerporting: 20.55.73.223 (United States)
Blocked for Exchange Proxy(Not?)Shell ...
show moreWordPress WordFence rerporting: 20.55.73.223 (United States)
Blocked for Exchange Proxy(Not?)Shell CVE-2022–41040 and CVE-2022–41082
show less
HackingBrute-ForceBad Web BotExploited HostWeb App Attack
WordPress WordFence rerporting: 144.126.133.71 (United States)
Blocked for WordPress New Install Fi ...
show moreWordPress WordFence rerporting: 144.126.133.71 (United States)
Blocked for WordPress New Install File Probing
show less
HackingSQL InjectionBrute-ForceBad Web BotWeb App Attack
Reported by BadBot plug-in on WordPress:
The reason is: "Exceeded the maximum number of page not ...
show moreReported by BadBot plug-in on WordPress:
The reason is: "Exceeded the maximum number of page not found errors per minute for a crawler.".
The duration of the block is 5 days.
User IP: 5.175.234.40
User hostname: 5.175.234.40
User location: Germany
show less
Received Thu, Sep 4, 2025 14:35:42 +0000 (UTC). Unsolicited commercial email promoting “Residential/ ...
show moreReceived Thu, Sep 4, 2025 14:35:42 +0000 (UTC). Unsolicited commercial email promoting “Residential/Commercial cost estimates, take-offs and architecture work,” with prior thread quotes (Aug 8 & Aug 21) and a “quick follow-up” push to send plans for pricing/turnaround. No prior relationship; this is unwanted solicitation.
Auth: SPF pass, DKIM pass (d=gmail.com; s=20230601), DMARC pass (p=none). Evidence points to abuse from a Gmail account (no spoofing). Sending IP (to Yahoo): 209.85.166.48 (mail-io1-f48.google.com). Authenticated client to Gmail: 34.16.118.141 (googleusercontent). Host owner: Google LLC.
show less
Unsolicited email received Thu, 04 Sep 2025 12:26:16 +0000 with subject “sevenport25” and a gibberis ...
show moreUnsolicited email received Thu, 04 Sep 2025 12:26:16 +0000 with subject “sevenport25” and a gibberish body (“lttli”). From header: AM [email protected]
Appears to be bulk/probe mail with no legitimate purpose.
Header shows X-Originating-IP 18.208.22.140 (EHLO repost01.tmes.trendmicro.com); next hop from 5.230.114.143 via Trend Micro Email Security. Auth results: SPF=pass (hicomauto.com), DKIM=unknown (no valid signature), DMARC=pass (p=NONE, aligned via SPF).
show less
Received Thu, Sep 4, 2025 06:15:55 -0700 (per Gmail). Unsolicited commercial email advertising a “jo ...
show moreReceived Thu, Sep 4, 2025 06:15:55 -0700 (per Gmail). Unsolicited commercial email advertising a “job-coaching” course with tracking tags and one-click unsubscribe via services.msgsndr.com. Auth results: SPF=pass for lc.theinsidegamecoaching.com via 159.112.249.39; DKIM=pass for lc.theinsidegamecoaching.com and mailgun.org; DMARC=fail for header.from=dsn-it.com (domain misalignment), indicating an inauthentic/spoofed “From”. “Sender” header points to lc.theinsidegamecoaching.com. Routing shows Mailgun MTA m249-39.rdns-1.mailgun.net (159.112.249.39). Appears non-compliant with CAN-SPAM (15 U.S.C. §7701 et seq.) as unsolicited advertising with misleading origin; DMARC alignment failure per RFC 7489; practices inconsistent with RFC 5322 header integrity. Full headers supplied to the host for action.
show less
Received Wed, Sep 3, 2025 13:20:56 -0700 (PDT) by Google MX. Sending IP: 82.165.159.134 (mout-xforwa ...
show moreReceived Wed, Sep 3, 2025 13:20:56 -0700 (PDT) by Google MX. Sending IP: 82.165.159.134 (mout-xforward.perfora.net). Auth client: 3.13.213.230 via mrelay.perfora.net [74.208.5.2]. Host/owner: IONOS (perfora.net). Abuse contact: [email protected]
Message is unsolicited address-verification/marketing: “checking if this is your correct address” and offering a “gift account” on an AI business builder with a login link if I reply. This is classic list-harvesting and reply-bait spam. X-Spam-Flag: YES; UI-OutboundReport shows junk score.
SPF=pass; DKIM=pass (d=pushbuttonaisalesbuilder.com; s=s1-ionos); DMARC=pass (p=QUARANTINE). Despite auth passing, the content is unsolicited. Violations: CAN-SPAM (15 U.S.C. §7701 et seq.—unsolicited commercial email, deceptive solicitation). RFC 5321 §4.1.1.1: non-FQDN HELO “Macbook.local”. Please investigate and terminate abusive use of these systems.
show less
Received Sep 2, 2025 at 07:01–07:03 PDT. Unsolicited commercial email advertising a “$29 Beta Test” ...
show moreReceived Sep 2, 2025 at 07:01–07:03 PDT. Unsolicited commercial email advertising a “$29 Beta Test” job-coaching course (“The Inside Game”), sent via Mailgun infra m249-39.rdns-1.mailgun.net [159.112.249.39] using lc.theinsidegamecoaching.com as envelope sender while header From is dsn-it.com. Auth: SPF pass; DKIM pass (lc.theinsidegamecoaching.com, mailgun.org); DMARC fail for header.from=dsn-it.com (identifier misalignment). This mismatch suggests deceptive header alignment/spoofing. Content includes tracking/one-click unsubscribe but no physical postal address. Likely violations: CAN-SPAM (15 U.S.C. §7704) for misleading header info and missing valid postal address; DMARC misalignment per RFC 7489; questionable RFC 5322 From alignment. Please investigate and stop abuse. Hosting provider: Sinch Mailgun (Mailgun Technologies, Inc.); abuse contact: [email protected]
.
show less
Received 2025-09-01 22:42:47 +0000. Malicious email posing as “Cloud Alert” from twitch.tv with HTML ...
show moreReceived 2025-09-01 22:42:47 +0000. Malicious email posing as “Cloud Alert” from twitch.tv with HTML image-map only; links redirect to reggaealaska[.]com. Sending IP: 8.219.35.136 (out35-136.sg.b.dm.aliyun.com — Alibaba Cloud). Also seen in path: 54.240.26.35 (a26-35.smtp-out.us-west-2.amazonses.com — Amazon SES).
Auth results inconsistent across hops: Yahoo shows SPF=pass and DKIM/DMARC=pass; Microsoft shows DKIM=fail for twitch.tv/amazonses and DMARC=fail, with ARC overrides noted. Indicators of spoofing/replay and brand impersonation. Duplicate Message-ID headers violate RFC 5322 §3.6; deceptive header/content likely violates CAN-SPAM (15 U.S.C. §7701 et seq.) and may constitute attempted wire fraud (18 U.S.C. §1343).
show less