This IP was identified as the SMTP client IP (true session origin) connecting to the MTA v22388681.s ...
show moreThis IP was identified as the SMTP client IP (true session origin) connecting to the MTA v22388681.sin01.serveradd.com (101.100.220.53) used in the same campaign.
show less
Timestamp: 2026-04-09 04:08 UTC
Port: 25 (SMTP)
Categories: Phishing, BEC (Business Email Compromi ...
show moreTimestamp: 2026-04-09 04:08 UTC
Port: 25 (SMTP)
Categories: Phishing, BEC (Business Email Compromise / CEO Fraud)
This IP acted as the originating MTA in a phishing campaign targeting a company's finance department. The email impersonated an internal contact and requested an urgent same-day bank transfer. Reply-To header was redirected to [email protected] to intercept responses. Attachment was a programmatically generated PDF invoice (ReportLab/Python, author anonymised). Sender domain techcom.group was created specifically for this campaign. SMTP session ID: 1wAnFP-00000008gu7-1TMv.
show less
Fraud OrdersPhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.