Email spam with phishing-like traits. Sender IP 107.175.249.101 (mail.seyahatetsene.com) sent unsoli ...
show moreEmail spam with phishing-like traits. Sender IP 107.175.249.101 (mail.seyahatetsene.com) sent unsolicited promotional email advertising "ChannelMoa[.]com" streaming/IPTV reseller service to an unrelated recipient. Authentication failed: SPF=permerror, DKIM=none, DMARC=fail (No valid SPF, No valid DKIM, policy=none). Header From domain (seyahatetsene.com) shows suspicious disposable-looking pattern. Envelope recipient mismatch: To header targets [redacted]@shastayouthleadershipcamp.com while actual delivery goes to [redacted]@marcolodovichi.com. X-Recommended-Action header set to "reject" by receiving infrastructure. Content promotes paid streaming/reseller scheme with vague legitimacy claims and opt-in pretext. Email received 2026-07-23T10:53 UTC.
show less
Phishing email impersonating TEMU brand. Originating IP 185.176.220.116 (kabillaraos.shop) sends spo ...
show morePhishing email impersonating TEMU brand. Originating IP 185.176.220.116 (kabillaraos.shop) sends spoofed commercial emails with fake TEMU product offers. DKIM signed with rsa-sha1 (weakened), DomainKey present. Links redirect to http://top-items.shop (not temu.com) for credential harvesting. Hidden tracking pixel at getyourstar.online/track/. X-Recommended-Action header already flagged as reject by receiving infrastructure. SPF/DKIM/DMARC pass β deliberately configured malicious MTA. Domain kabillaraos.shop has no legitimate association with TEMU/Temu commerce platform.
show less
Phishing/BEC email received 2026-07-21. Sender IP 141.98.10.26 connected from host won0.deltametallc ...
show morePhishing/BEC email received 2026-07-21. Sender IP 141.98.10.26 connected from host won0.deltametallc.com (reverse DNS mismatch with sender domain goldensparktech.com). SPF=fail, DKIM=none, DMARC=none. X-Recommended-Action header set to "reject". Message impersonates a Chartered Accountant ("CA Nilesh Tailor") and carries a .rar attachment named "Payment AdviceMT103.rar" disguised as MT103 payment confirmation β typical BEC payload delivery pattern. Subject hijacks an existing purchase order thread ("Re: Calcium Chloride 77%-94% / PO-26-0321"). Recipient target: corporate mailbox. Recommended action: block 141.98.10.26 at perimeter, scan attachment in sandbox.
show less
Sender IP 135.84.80.55 (optin-55.transmail.net) sends unsolicited bulk recruiting email impersonatin ...
show moreSender IP 135.84.80.55 (optin-55.transmail.net) sends unsolicited bulk recruiting email impersonating Havas Group. Sender domain careersglobal.careers is owned by the spammer, not spoofed. DKIM passes for desk-mailer.zohodesk.com, SPF passes, DMARC=none. Email sent via Zoho Desk/ZeptoMail bulk infrastructure (transmail.net β spacemail.com). No affiliation between careersglobal.careers and Havas Group confirmed. Content is deceptive cold recruitment with no prior consent.
show less
Phishing email impersonating mail delivery failure notification. Sender domain meldoxin.com spoofs r ...
show morePhishing email impersonating mail delivery failure notification. Sender domain meldoxin.com spoofs recipient's domain "Admin marcolodovichi.com" to gain trust. Email contains malicious links to messenger.vendors.vu designed to harvest credentials. Part of a coordinated campaign using rotating sender domains with identical HTML payload. SPF/DKIM/DMARC all pass, indicating purpose-built abuse infrastructure. Headers preserved.
show less
IP 82.165.88.173 (Hostinger/eyelike.de) β Used as originating MTA for romance scam campaign. Source ...
show moreIP 82.165.88.173 (Hostinger/eyelike.de) β Used as originating MTA for romance scam campaign. Source IP in email headers (X-Source-IP: 82.165.88.173) reveals true sending origin before relay obfuscation through CloudFilter (35.89.44.35).
Campaign characteristics: Bulk love phishing with mismatched Reply-To domains, JPEG attachment for social engineering, X-Email-Count: 311 indicates mass mailing. Originates from shared hosting (br550.hostgator.com.br infrastructure) commonly abused by compromised scripts or rented VPS.
Despite 0% confidence score in your database, this IP shows clear abuse indicators: HELO mismatch (eyelike.de vs sender domain apaesalto.com.br), geographic inconsistency (EU server β BR hosting β US relay β EU recipient), and participation in coordinated romance scam pattern.
Recommend investigation of customer account behind this sending activity. Likely shared hosting compromise or abuse of legitimate customer for malicious campaigns.
show less
IP 35.89.44.35 (omta36.uswest2.a.cloudfilter.net) β Proofpoint/CloudFilter MTA hosted on Google Clou ...
show moreIP 35.89.44.35 (omta36.uswest2.a.cloudfilter.net) β Proofpoint/CloudFilter MTA hosted on Google Cloud (ASN 15169). Part of the 35.89.44.0/24 range, with neighboring IPs (.32 and .33) already flagged on AbuseIPDB with hundreds of reports for spam/phishing.
Role in email chain: acts as intermediate OMTA. Received the message from the origin infrastructure (82.165.88.173 / eyelike.de) and forwarded it to the recipient's relay.
Email type: Romance scam / love phishing campaign. Send-path manipulation with mismatched Reply-To (sender domain apaesalto.com.br β Reply-To zohomail.eu). DKIM present but DMARC=none. Header X-Email-Count: 311 indicates bulk sending. JPEG attachment used to build false trust with the victim.
Pattern: abuse of CloudFilter as relay hop to obscure the true sending origin, leveraging the apparent legitimacy of Proofpoint infrastructure. Campaign likely originated from compromised/abused hosting (HostGator BR).
show less
Email fraud/spoofing (advance-fee/RFQ scam) impersonating PETRONAS (petronas.com). Envelope-from: sa ...
show moreEmail fraud/spoofing (advance-fee/RFQ scam) impersonating PETRONAS (petronas.com). Envelope-from: [email protected], HELO/connecting host: zihnyunrui.com β unrelated domain, not owned by Petronas. Authentication failed: dkim=none (invalid DKIM record), spf=fail (IP not authorized for petronas.com), dmarc=fail (policy=quarantine). Message-ID: <[email protected]>. Fake "Request For Quotation" (RFQ Ref: 6200238509) with a tight deadline (2026-07-14), signed by "Alsumood Group of Companies," Dubai β geographically inconsistent with Petronas' actual HQ. Includes a suspicious ZIP attachment (DOC-RFQ DESCRIPTION & INVITE-Number 6200238509.zip), likely malware or further phishing. Recipient mail server flagged it (X-Recommended-Action: reject).
show less
Phishing email spoofing Yamato Transport (Kuroneko Yamato), a Japanese courier service. Envelope-fro ...
show morePhishing email spoofing Yamato Transport (Kuroneko Yamato), a Japanese courier service. Envelope-from: [email protected]. Passed SPF/DKIM/DMARC for tgbvk.asia (throwaway domain, unrelated to yamato-transport.co.jp). Message-ID: <[email protected]>. Sent via Foxmail client. Fake "failed delivery" notice in Japanese asking recipient to pay a small redelivery fee and click a link to "reschedule delivery." Malicious link: hxxps://sourceture[.]pldqwsqd[.]cn/8Hg97ml/loginbab/ β likely credential/payment harvesting page. Recipient mail server flagged it internally (X-Recommended-Action: reject).
show less
Confirmed spam/beaconing source used for recipient validation testing. Received unsolicited message ...
show moreConfirmed spam/beaconing source used for recipient validation testing. Received unsolicited message with:
Empty/near-empty body (only timestamp repeated)
Failed SPF/DMARC authentication (From: [email protected])
No valid DKIM signature
Suspicious sender pattern (auto-generated address with numeric suffix)
Typical behavior for email list verification before selling "validated" addresses to commercial spammers. Message flagged internally by anti-spam system as high-risk/spam.
Evidence: SMTP logs confirm origin from this IP. DMARC failure reason: "No valid SPF, No valid DKIM". TLS connection with RSA-PSS 2048-bit server cert.
Recommend monitoring related IPs and ASN AS215540 if similar patterns continue.
show less
Banking phishing impersonating Banco BPM. Malicious IPs: 192.174.81.42 (SparkPost),
162.255.118.30 ...
show moreBanking phishing impersonating Banco BPM. Malicious IPs: 192.174.81.42 (SparkPost),
162.255.118.30 (SpaceEmail relay). Attack uses spoofed domain
(surveymonkeyuser.com β official SurveyMonkey) to bypass SPF/DKIM filters.
Payload: malicious links bpmit-servlzio.com/skn with threatening "account suspension"
text to induce urgent clicks. Infrastructure abuse: third parties (SparkPost via
Jellyfish Systems) used as relays to mask real origin.
Indicators: Subject typosquatting, divergent Reply-To ([email protected]),
embedded SurveyMonkey tracking pixels to confirm delivery.
Targeting Italian banking customers. IPs show spam patterns (X-Recommended-Action:
reject present but bypassed via TLS relay chain). Reporting for blacklisting and
infrastructure abuse.
show less
Sender IP of a phishing email and scam "looking for profit oriented ventures" pretending to be "SHK ...
show moreSender IP of a phishing email and scam "looking for profit oriented ventures" pretending to be "SHK Mubarak from Qatar" look for a foreigner that is capable of managing 200,000,000 U.S.D. Be aware, financial fraud.
show less
Used to send phishing email with a fake order and invoice with a malware attachment (.zip file) pret ...
show moreUsed to send phishing email with a fake order and invoice with a malware attachment (.zip file) pretending to be from "Mykaela Jones P. PeΓ±aflorida"
Assistant Admin
+971 54 723 9003
myka@geoconstructions[.]org
www[.]geoconstruction[.]org
show less
Third phishing campaign from this IP in 12 days, same Haraka MTA instance (hostname: 7b4c34bf3c9e, A ...
show moreThird phishing campaign from this IP in 12 days, same Haraka MTA instance (hostname: 7b4c34bf3c9e, Azure AS8075). Envelope-from <[email protected]>. Subject: "Reply Brief Due CASE-8332354". Impersonates U.S. District Court / "Judicial Notice System". DKIM=none, SPF=none, DMARC=none. Redirect via email.notify.thinkific.com. Message-ID: <[email protected]>. Delivered 2026-07-02T05:01:16Z. Previously reported from same IP on 2026-06-22 (PACER impersonation, envelope-from [email protected]) and from 4.149.180.180 on 2026-06-20 (SSA impersonation). Persistent bulk phishing operation on Azure infrastructure.
show less
Phishing/scam email sent via this IP (Azure-hosted, PHPMailer) spoofing sender domain amoriatv.com, ...
show morePhishing/scam email sent via this IP (Azure-hosted, PHPMailer) spoofing sender domain amoriatv.com, promoting an illegal IPTV reseller service ("FIFA World Cup 2026" offer, $89/24 months). Email failed SPF (softfail), DKIM (none), and DMARC (fail) authentication checks. Reply-To set to a personal Outlook address ([email protected]), inconsistent with a legitimate business sender. All CTA/tracking links point to a third-party redirect domain (nolm.us), not the advertised brand domain, a classic redirect-obfuscation pattern. Message-ID and headers indicate origin from an ephemeral Azure Codespaces instance, consistent with disposable spam infrastructure. Category: Phishing / Spam / Email spoofing.
show less
Unsolicited email sent to multiple addresses on our domain. The message impersonates a mailing list ...
show moreUnsolicited email sent to multiple addresses on our domain. The message impersonates a mailing list subscription confirmation ("BrightLeaf Studio"). Authentication failures: DMARC fail (no valid SPF, no valid DKIM), SPF softfail. Sender address [email protected] is a randomly generated Gmail account (variant of a previously reported sender from a different IP). Purpose appears to be email address harvesting via open tracking. Server flagged it as X-Recommended-Action: reject.
show less
Unsolicited email sent to multiple addresses on our domain. The message impersonates a mailing list ...
show moreUnsolicited email sent to multiple addresses on our domain. The message impersonates a mailing list subscription confirmation ("BrightLeaf Studio"). Authentication failures: DMARC fail (no valid SPF, no valid DKIM), SPF softfail. Sender address [email protected] is a randomly generated Gmail account. Email body contains no functional links. Purpose appears to be email address harvesting via open tracking. Server flagged it as X-Recommended-Action: reject.
show less
Phishing email impersonating PACER (Public Access to Court Electronic Records) / U.S. District Court ...
show morePhishing email impersonating PACER (Public Access to Court Electronic Records) / U.S. District Court. Sent from IP 4.149.180.197 via Haraka MTA (hostname: 7b4c34bf3c9e, same infrastructure as prior campaign from 4.149.180.180) with envelope-from <[email protected]>. Subject: "Notice of Filing Error CASE-3720648". DKIM=none, SPF=softfail, DMARC=fail. Email contained a fake federal court summons citing Rule 4 and Rule 12 FRCP, with a redirect link through legitimate platform email.notify.thinkific.com to evade filters. Delivered 2026-06-22T16:37:55Z. Message-ID: <[email protected]>. Same Haraka instance previously reported for SSA impersonation phishing (4.149.180.180).
show less
Phishing email impersonating the U.S. Social Security Administration (SSA). Sent from IP 4.149.180.1 ...
show morePhishing email impersonating the U.S. Social Security Administration (SSA). Sent from IP 4.149.180.180 via Haraka MTA (hostname: 7b4c34bf3c9e) with envelope-from <[email protected]>. Subject: "Statement Identity Protection Alert". All authentication records absent (DKIM=none, SPF=none, DMARC=none). Links in the HTML body point to hxxps://uflajunior[.]com/verification/index.html β a credential harvesting page mimicking SSA. Delivered to target on 2026-06-20T22:59:20Z. Message-ID: <[email protected]>.
show less
IP used to send unsolicited bulk email (spam) advertising "Magic Seven" email blasting corbett softw ...
show moreIP used to send unsolicited bulk email (spam) advertising "Magic Seven" email blasting corbett software. Sent via mail.atlas-groupe.net, SPF softfail, DKIM none, DMARC fail. Reply-To points to Brazilian domain [email protected]. Message-ID missing. Date: 2026-06-17.
show less
Phishing campaign impersonating Publicis Groupe (publicisgroupe.com) for fake recruitment. Sent via ...
show morePhishing campaign impersonating Publicis Groupe (publicisgroupe.com) for fake recruitment. Sent via Zoho Desk / ZeptoMail. Fraudulent domain: publicisgroupejoin.com (registered 2026-05-13). Zoho org ID: 926529353, Desk ticket: 1367867000005002221. From: [email protected]. DMARC FAIL on header.from=publicisgroupejoin.com. Same infrastructure also impersonates Omnicom Group (org slug: recruitmentomnicomgroup).
show less
PhishingEmail Spam
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.