I received a suspicious email from this IP with the sender [email protected]. The email ...
show moreI received a suspicious email from this IP with the sender [email protected]. The email appears to be a phishing or spam attempt. The full email header indicates unusual behavior, possibly an attempt to impersonate Microsoft Teams notifications. Please investigate.
show less
Received a phishing and spam email impersonating Harbor Freight and offering a fake Stanley tool set ...
show moreReceived a phishing and spam email impersonating Harbor Freight and offering a fake Stanley tool set reward.
The message used a compromised Microsoft 365 tenant (san19065962.onmicrosoft.com) and spoofed the domain harborphe.com.
Headers show the email was sent from IP 64.120.94.221 (SPF fail, no DKIM/DMARC) and contains multiple malicious redirect links (*.guerrad.shop).
show less
Received a phishing email claiming to offer an Omaha Steaks reward.
The sender spoofed a Microsoft ...
show moreReceived a phishing email claiming to offer an Omaha Steaks reward.
The sender spoofed a Microsoft 365 domain (mel20052843.onmicrosoft.com)
and the message included several malicious redirect links (*.guerrad.shop).
Headers show the email originated from 64.120.94.221 (SPF fail, no DKIM/DMARC).
show less
I received a phishing email pretending to be from Starbucks, trying to deceive the recipient into cl ...
show moreI received a phishing email pretending to be from Starbucks, trying to deceive the recipient into claiming a Yeti Rambler Tumbler through a fake giveaway link. The email contains links to suspicious sites and attempts to steal personal information from the recipient. The originating IP of the phishing email is 52.102.202.61
show less
This IP address is the origin of a phishing email impersonating USPS.
The message advertises a fak ...
show moreThis IP address is the origin of a phishing email impersonating USPS.
The message advertises a fake "USPS Mystery Box" and contains multiple malicious links hosted on randomly generated subdomains of guerrad.shop.
The sending domain was spoofed, and the message failed SPF and composite authentication checks.
Header analysis shows that 178.162.245.30 is the original untrusted sending IP, while the attacker attempted to route through a compromised Microsoft 365 tenant (gre19134148.onmicrosoft.com).
This IP is being used for phishing, email spam, and sender spoofing.
show less
Email sent from this IP was a phishing attempt trying to trick the recipient into providing personal ...
show moreEmail sent from this IP was a phishing attempt trying to trick the recipient into providing personal information or login credentials via fraudulent link
show less
Phishing email impersonating "Omaha Steaks".
Links inside message redirect to malicious domain link ...
show morePhishing email impersonating "Omaha Steaks".
Links inside message redirect to malicious domain linkdoitnows.work.
Sender domain spoofed: omahasteaksyfb.com.
Original sending IP 178.162.245.30 failed SPF and is not authorized for Microsoft 365 tenant sam20751067.onmicrosoft.com.
show less
Email di phishing ricevuta il 24 Novembre 2025 che dichiara un regalo gratuito Kiko Milano.
Mittent ...
show moreEmail di phishing ricevuta il 24 Novembre 2025 che dichiara un regalo gratuito Kiko Milano.
Mittente falso: [email protected]
Link sospetti: http://??.fsmoncton.com/...
SPF passa ma DKIM non è firmata, quindi mittente sospetto.
Raccomando di bloccare l’IP per attività di spam/phishing.
show less
Received a phishing email impersonating Google.
Subject: "Google"
From: "Google www.google.com" ...
show moreReceived a phishing email impersonating Google.
Subject: "Google"
From: "Google www.google.com" <[email protected]>
Reply-To: "Google www.google.com" <[email protected]>
Message body:
"Hello Google Beneficiary,
Kindly see additional e-mail below.
Thank you for using Google products and services!
Yours Sincerely,
The Google Team"
The message was sent through Gmail SMTP by a host connecting from IP 102.90.115.110 (MTN Nigeria).
The sender is attempting to impersonate Google and trick the recipient into following up via email.
Email header excerpt:
Received: from [192.168.0.126] ([102.90.115.110]) by smtp.gmail.com with ESMTPSA;
show less
Repeated failed login attempts to NAS admin account via HTTPS interface.
Login [Users] Failed to lo ...
show moreRepeated failed login attempts to NAS admin account via HTTPS interface.
Login [Users] Failed to log in via user account "admin". Source IP address: 91.92.241.115.
show less
Received an extortion email claiming to have hacked my system and requesting Bitcoin payment. The me ...
show moreReceived an extortion email claiming to have hacked my system and requesting Bitcoin payment. The message was sent from [email protected] and originated from 46.59.179.4 according to the email headers. Typical sextortion / blackmail spam.
Received: from 46.59.179.4.dynamic-pppoe.dt.ipv4.wtnet.de ([46.59.179.4]) by smtp-40.iol.local with ESMTP; Tue, 28 Oct 2025 20:48:16 +0100
Confidence of Abuse: 100%
show less
Email received on September 28, 2025, apparently from "[email protected]" containing a fa ...
show moreEmail received on September 28, 2025, apparently from "[email protected]" containing a fake invoice disguised as an official communication from Vivo (Telefônica Brasil). The email was misleading, with clear phishing intent: the message simulated a legitimate billing notice and included either a fraudulent attachment or malicious link. The IP address 200.142.128.52 (hostname darth.vivo.com.br) appeared in the sending path. Reported to help protect other users.
show less
Received a spoofed email pretending to be from my own Hotmail address. The message was not sent by m ...
show moreReceived a spoofed email pretending to be from my own Hotmail address. The message was not sent by me. The sender IP 154.209.208.203 is unauthorized and failed SPF and DMARC checks. Used domain: cybercorp.net
show less
PhishingEmail SpamSpoofing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.