This IP was used as the originating sender of a phishing/spam email campaign impersonating a Japanes ...
show moreThis IP was used as the originating sender of a phishing/spam email campaign impersonating a Japanese toll road inquiry service (ETC-MEISAI). The message was crafted in Japanese, sent from a randomized .info domain (nmxtfz.info), and contained a fraudulent call-to-action button linking to a .cn domain (dsrzzi.jetgq.cn).
Email headers confirm 101.47.21.12 as the authenticated sending host (SPF pass). The mailer identified itself as Foxmail 6.13 [cn].
Received headers show routing through asp-relay-spacemail.jellyfish.systems before delivery. DKIM passed on the sending domain, suggesting an organized infrastructure reusing legitimate relay paths.
Category: Phishing / Spam
Sending domain: nmxtfz.info
Payload domain: dsrzzi.jetgq.cn
X-mailer: Foxmail 6, 13, 102, 15 [cn]
Target: Italian recipient, impersonated service in Japanese
show less
IP hosting an active phishing page harvesting email credentials. URL: https[:]//5co1nm3mr1[.]dynv6[. ...
show moreIP hosting an active phishing page harvesting email credentials. URL: https[:]//5co1nm3mr1[.]dynv6[.]net/Upl1nk31ng.html β page title "authentication..." confirms active credential collection. Linked from a phishing email impersonating a domain administrator. TLS cert issued April 24th 2026, domain created specifically for this campaign. Same AS202412 (Omegatech LTD) as sending IP 94.154.35.175.
show less
Phishing email impersonating domain administrator of marcolodovichi.com. Sender: b21.mail2web-hostin ...
show morePhishing email impersonating domain administrator of marcolodovichi.com. Sender: [email protected]. The email attempts to harvest credentials by directing the recipient to a fake confirmation page hosted on dynv6.net infrastructure. Email authentication: DKIM pass on verifiedupgrades.com, SPF pass, DMARC none. This IP (slot0.verifiedupgrades.com) was the originating server. Categories: phishing, spam.
show less
This IP serves out.fistermes.my, a fake unsubscribe/email address validation endpoint used as part o ...
show moreThis IP serves out.fistermes.my, a fake unsubscribe/email address validation endpoint used as part of a spam campaign infrastructure. The site presents an "Unsubscribe" button but is designed to confirm active recipient email addresses to the spammer. It actively blocks automated scanning tools (urlscan.io could not scan it), suggesting deliberate evasion of security analysis. Likely uses per-recipient tokenized URLs.
Redirect chain from spam email: mx.good-apollo.online/VXXNAVx/ [IP 134.209.203.253] β out.fistermes.my [this IP].
Notably, this IP shares the same /24 subnet (62.173.142.0/24) as 62.173.142.230, the sending MTA of the original spam (HELO: mx.wilde-wood.skin, domain zirenma.tech), suggesting shared infrastructure.
Message-ID: <[email protected]>
Date: Sun, 17 May 2026 16:26:23 +0300
Categories: spam, unsolicited bulk email
show less
This IP hosts mx.good-apollo.online, a throwaway redirector domain used as part of a spam campaign i ...
show moreThis IP hosts mx.good-apollo.online, a throwaway redirector domain used as part of a spam campaign infrastructure. Links embedded in unsolicited bulk email pointing to this host perform HTTP redirects to spam landing pages and email harvesting endpoints:
- mx.good-apollo.online/itrydUkS/ β trencraft.com/GpsAirTag/eu/ (spam landing page)
- mx.good-apollo.online/VXXNAVx/ β out.fistermes.my (fake unsubscribe/email validation endpoint)
The original spam was sent via IP 62.173.142.230 (HELO: mx.wilde-wood.skin) using throwaway domain zirenma.tech. SPF and DMARC pass for zirenma.tech, confirming the spam domain was deliberately set up by the sender.
Message-ID: <[email protected]>
Date: Sun, 17 May 2026 16:26:23 +0300
Categories: spam, unsolicited bulk email
show less
Received unsolicited spam email originating from this IP (62.173.142.230, HELO: mx.wilde-wood.skin). ...
show moreReceived unsolicited spam email originating from this IP (62.173.142.230, HELO: mx.wilde-wood.skin). The message was sent from a throwaway domain (zirenma.tech) with a forged "GPS Air Tag" product advertisement.
Email headers confirm SPF pass for zirenma.tech designating this IP as authorized sender. DMARC also passes (p=NONE) β indicating the spam domain was deliberately set up by the sender rather than being a spoofed address.
Message-ID: <[email protected]>
Date: Sun, 17 May 2026 16:26:23 +0300
Sending MTA hostname: mx.wilde-wood.skin
Categories: spam, unsolicited bulk email
show less
Spam campaign originating from clara.footwearnero.shop (46.245.164.54). The sender impersonates "USA ...
show moreSpam campaign originating from clara.footwearnero.shop (46.245.164.54). The sender impersonates "USA TODAY Home" via [email protected], a throwaway domain configured with DKIM/SPF/DMARC to bypass filters. Email contains tracking pixels and sponsored redirect links. Envelope-from: [redacted-id]-[redacted-id]-[redacted-id]-[redacted-id]-[redacted][email protected]. Received on 2026-05-09 12:06:31 UTC.
show less
This IP address (74.208.236.226) is associated with hosting or serving content used in a spam email ...
show moreThis IP address (74.208.236.226) is associated with hosting or serving content used in a spam email campaign.
The observed activity involves unsolicited bulk email containing links that redirect to subdomains of live-website.com (e.g. rogie.live-website.com), which appear to be used as tracking or redirection infrastructure.
The content is not part of any legitimate website service and is used in conjunction with spam messages sent without user consent.
The IP is part of a shared hosting environment and appears to be abused for hosting redirect/tracking endpoints in email-based spam campaigns.
Evidence includes full email headers and link redirection traces.
This IP has been observed in repeated abuse reports, suggesting ongoing misuse of hosting infrastructure.
show less
This IP address (172.59.25.86) appears to be the origin of unsolicited bulk email (spam).
The messa ...
show moreThis IP address (172.59.25.86) appears to be the origin of unsolicited bulk email (spam).
The message was sent from "[email protected]
" / "[email protected]
" and impersonates a newsletter ("Weekly Specials") that the recipient never subscribed to.
The email infrastructure shows SPF softfail and DMARC failure with no valid DKIM signature, indicating poor or intentionally misconfigured authentication.
The message includes a deceptive "unsubscribe" mechanism that appears to be fake or misleading.
The email was relayed through multiple servers, but the originating IP consistently points to abusive sending behavior.
This appears to be unsolicited commercial email (spam), potentially part of a bulk sending operation.
show less
SendGrid relay IP used to deliver OAuth phishing emails impersonating RingCentral voicemail service. ...
show moreSendGrid relay IP used to deliver OAuth phishing emails impersonating RingCentral voicemail service. Spoofed From headers using legitimate domains (reliabletrading.com, phoenixsportclub.com). Payload contains fraudulent Azure AD OAuth link (client_id: db5daefa-a900-4799-9c80-26820377d2f6) harvesting Microsoft tokens via fake Grammarly callback redirect. Two campaigns confirmed: 2026-04-30 (159.183.114.111) and 2026-05-06 (this IP). SendGrid message ID: recvd-f4945cc46-vhpxs-1-69FB8786-5B.
show less
Authenticated sender IP used to inject spam into mail.gigaconstruct.org (161.97.161.29) on 2026-05-0 ...
show moreAuthenticated sender IP used to inject spam into mail.gigaconstruct.org (161.97.161.29) on 2026-05-01 at 21:53:59 UTC. Message was an advance-fee fraud / private placement scam (subject: "PRIVATE PLACEMENT OPPORTUNITY"). Sending domain gigaconstruct.org (registered 2026-04-02) is listed on Spamhaus DBL, Spamhaus ZEN, Barracuda and 6 other blacklists.
show less
Mail server for domain gigaconstruct.org, used to send advance-fee fraud / private placement scam em ...
show moreMail server for domain gigaconstruct.org, used to send advance-fee fraud / private placement scam email on 2026-05-01 at 21:53:59 UTC. Sending domain (gigaconstruct.org, registered 2026-04-02, no website) is listed on Spamhaus DBL, Spamhaus ZEN, Barracuda, Abusix and 5 other blacklists. Reply-To mismatches From domain ([email protected] vs [email protected]).
show less
Confirmed Business Email Compromise (BEC) / Phishing campaign.
Target: TAQA T&D Group (Abu Dhabi Na ...
show moreConfirmed Business Email Compromise (BEC) / Phishing campaign.
Target: TAQA T&D Group (Abu Dhabi National Energy Company).
Attack Vector: Sophisticated spoofing using a "zombie" domain (nobuns.com, 18yo, no website) with valid SPF/DKIM/DMARC to bypass filters.
Key Indicators:
- Source IP: 141.0.139.167 (Svorka AS, Norway)
- From: [email protected] (Domain unrelated to claimed org)
- Reply-To: [email protected] (Suspicious TLD)
- Content: Fraudulent vendor onboarding request for fake procurement portal.
Note: IP already has 11 prior reports on AbuseIPDB. This is a coordinated campaign, not a compromised residential user.
show less
Phishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Ca ...
show morePhishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Capital One while spoofing lsu.edu domain. Email claims fraudulent card activity, directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
- Timestamp: 2026-05-05 14:40:18 UTC
- Protocol: SMTP (TCP connection completed)
- Originating IP: 194.152.34.222 (NOT affiliated with lsu.edu)
- Spoofed Domain: lsu.edu (From: [email protected])
- Auth: SPF softfail, DMARC fail (policy=none)
Note: NOT spoofed packet attack. Legitimate TCP SMTP connection from compromised host. Same campaign as 196.189.51.242, 211.194.14.110, 128.22.140.171, 45.184.59.213, 91.210.251.231, 81.250.152.43. Campaign rotates spoofed domains (yale.edu, latech.edu, lsu.edu) to evade filters.
show less
Phishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Ca ...
show morePhishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Capital One while spoofing latech.edu domain. Email claims fraudulent card activity, directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
- Timestamp: 2026-05-05 13:31:37 UTC
- Protocol: SMTP (TCP connection completed)
- Originating IP: 81.250.152.43 (wanadoo.fr residential line, NOT affiliated with latech.edu)
- Spoofed Domain: latech.edu (From: [email protected])
- Auth: SPF softfail, DMARC fail (policy=none)
Note: NOT spoofed packet attack. Legitimate TCP SMTP connection from compromised host. Already had ~2 prior AbuseIPDB reports. Same campaign as 196.189.51.242, 211.194.14.110, 128.22.140.171, 45.184.59.213, 91.210.251.231. Campaign rotates spoofed domains (yale.edu, latech.edu) and geographic origins.
show less
Phishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Ca ...
show morePhishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Capital One while spoofing yale.edu domain. Email claims fraudulent card activity, directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
- Timestamp: 2026-05-05 13:14:18 UTC
- Protocol: SMTP (TCP connection completed)
- Originating IP: 91.210.251.231 (office.corbina.com.ua, NOT affiliated with yale.edu)
- Spoofed Domain: yale.edu (From: [email protected])
- Auth: SPF softfail, DMARC fail (quarantine)
Note: NOT spoofed packet attack. Legitimate TCP SMTP connection from compromised host. Already had ~13-15 prior AbuseIPDB reports. Same campaign as 196.189.51.242, 211.194.14.110, 128.22.140.171, 45.184.59.213. Campaign rotates spoofed domains (yale.edu, latech.edu).
show less
Phishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Ca ...
show morePhishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Capital One while spoofing latech.edu domain. Email claims fraudulent card activity, directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
- Timestamp: 2026-05-05 13:05:18 UTC
- Protocol: SMTP (TCP connection completed)
- Originating IP: 45.184.59.213 (NOT affiliated with latech.edu)
- Spoofed Domain: latech.edu (From: [email protected])
- Auth: SPF softfail, DMARC fail (policy=none)
Note: NOT spoofed packet attack. Legitimate TCP SMTP connection from compromised host. Same campaign as 196.189.51.242, 211.194.14.110, 128.22.140.171. Campaign rotates spoofed domains (yale.edu, latech.edu).
show less
Phishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Ca ...
show morePhishing campaign with email domain spoofing. This IP actively sent phishing emails impersonating Capital One while spoofing yale.edu domain. Email claims fraudulent card activity, directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
- Timestamp: 2026-05-05 12:36:20 UTC
- Protocol: SMTP (TCP connection completed)
- Originating IP: 128.22.140.171 (VPS ablenetvps.ne.jp, NOT yale.edu)
- Spoofed Domain: yale.edu (From: [email protected])
- Auth: SPF softfail, DMARC fail (quarantine)
Note: NOT spoofed packet attack. Legitimate TCP SMTP connection. Already had 14 prior AbuseIPDB reports. Same campaign as 196.189.51.242 and 211.194.14.110.
show less
Attack Type: Phishing campaign with email domain spoofing
Description: This IP (211.194.14.110) a ...
show moreAttack Type: Phishing campaign with email domain spoofing
Description: This IP (211.194.14.110) actively sent phishing emails impersonating Capital One while spoofing the yale.edu domain in the From header. The email claims fraudulent card activity and directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
Timestamp: 2026-05-05 12:26:50 UTC
Protocol: SMTP (TCP connection completed - three-way handshake verified)
Originating IP: 211.194.14.110 (actual mail server, NOT affiliated with yale.edu)
Spoofed Domain: yale.edu (in From header: [email protected])
Authentication: SPF softfail, DMARC fail (policy=quarantine)
Malicious Payload: HTML phishing template with credential harvesting link
Note: This is NOT a spoofed packet attack. The TCP SMTP connection originated legitimately from this IP. The IP is the actual sender of malicious content, while yale.edu is a victim of domain spoofing. Same phishing campaign as reported IP 196.189.51.242.
show less
Attack Type: Phishing campaign with email domain spoofing
Description: This IP (196.189.51.242) a ...
show moreAttack Type: Phishing campaign with email domain spoofing
Description: This IP (196.189.51.242) actively sent phishing emails impersonating Capital One while spoofing the yale.edu domain in the From header. The email claims fraudulent card activity and directs victims to malicious site (nirmanroyals.promising.co.in/ink.html).
Technical Details:
Timestamp: 2026-05-05 12:08:33 UTC
Protocol: SMTP (TCP connection completed - three-way handshake verified)
Originating IP: 196.189.51.242 (actual mail server, NOT affiliated with yale.edu)
Spoofed Domain: yale.edu (in From header: [email protected])
Authentication: SPF softfail, DMARC fail (policy=quarantine)
Malicious Payload: HTML phishing template with credential harvesting link
Note: This is NOT a spoofed packet attack. The TCP SMTP connection originated legitimately from this IP. The IP is the actual sender of malicious content, while yale.edu is a victim of domain spoofing.
show less
SpoofingExploited HostPhishing
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.