This IP connected via SMTP and sent an email impersonating a company executive, using a free webmail ...
show moreThis IP connected via SMTP and sent an email impersonating a company executive, using a free webmail address (gmx.com) that does not match the claimed sender's identity. The email included a business-themed RTF attachment, a common vector for macro-based malware or document exploits, consistent with a Business Email Compromise (BEC) / spoofing attempt.
Connection log:
[2026/9/18 08:48:59] SMTP service accepted connection from 212.227.17.22
[2026/9/18 08:49:01] 212.227.17.22 requested SMTP service - claimed sender: [email protected]show less
Phishing email disguised as an e-invoice issuance notice, impersonating
a Taiwanese vendor ("台灣連線股份 ...
show morePhishing email disguised as an e-invoice issuance notice, impersonating
a Taiwanese vendor ("台灣連線股份有限公司"). Email includes a zip
attachment (20260911.547281.6E9A31FC84BCC.zip) blocked by Outlook as
potentially unsafe - likely malware delivery vector, not just credential
phishing. Also contains a suspicious link with a long encoded parameter
string, possibly abusing/impersonating a legitimate Taiwan e-invoice
platform domain (tradevan.com.tw).
Sender: liu***@wwwhimail.com (random/spoofed domain).
Source IP 149.72.120.130 is SendGrid (Twilio) shared bulk email
infrastructure, likely an abused sender account. Also reporting to
SendGrid abuse team separately.
Timezone: UTC+8
show less
Unsolicited bulk commercial email (B2B cold outreach / spam) promoting
"AI-powered export customer ...
show moreUnsolicited bulk commercial email (B2B cold outreach / spam) promoting
"AI-powered export customer acquisition" services targeting LED
industry manufacturers. Not phishing - no credential harvesting or
brand impersonation, just unsolicited mass marketing.
Sender: jam***@edmreply.com (edmreply.com is a known third-party
EDM/bulk email sending platform).
Source IP 47.74.243.199 is an Alibaba Cloud (Singapore) instance,
likely used as a dedicated bulk-mail sending host.
Timezone: UTC+8
show less
Phishing email impersonating SAISON CARD (inconsistent branding -
email body actually references "J ...
show morePhishing email impersonating SAISON CARD (inconsistent branding -
email body actually references "JALAN" membership, suggesting a
reused/misconfigured phishing kit template).
Sender: occ***@74kjg8vr.gxbr678.com (random-string throwaway domain).
Email urges recipient to "confirm registration info" within 7 days
via embedded button, classic credential harvesting tactic.
Source IP 20.200.188.136 is a Microsoft Azure-hosted instance,
likely a rented host used specifically to send this phishing mail.
Timezone: UTC+8
show less
Phishing email impersonating HiNet (Chunghwa Telecom) mail service,
claiming pending IMAP/POP messa ...
show morePhishing email impersonating HiNet (Chunghwa Telecom) mail service,
claiming pending IMAP/POP messages to lure recipient into clicking
a shortened link (tinyurl.com/webtwteletw).
Sender: lor***@domizialucilla.edu.it (likely compromised .edu.it
mailbox, possibly hosted on Google Workspace).
Source IP 209.85.216.101 is shared Google outbound mail
infrastructure, not the attacker's dedicated host.
show less
Phishing email impersonating HiNet (Chunghwa Telecom) mail service,
claiming pending IMAP/POP messa ...
show morePhishing email impersonating HiNet (Chunghwa Telecom) mail service,
claiming pending IMAP/POP messages to lure recipient into clicking
a shortened link (tinyurl.com/webtwteletw).
Sender: lor***@domizialucilla.edu.it (likely compromised .edu.it
mailbox, possibly hosted on Google Workspace).
Source IP 209.85.216.101 is shared Google outbound mail
infrastructure, not the attacker's dedicated host.
Timezone: UTC+8
show less
Phishing email impersonating American Express Japan, sender domain
spoofed (flbhxp.sxrtgc[.]com) wi ...
show morePhishing email impersonating American Express Japan, sender domain
spoofed (flbhxp.sxrtgc[.]com) with display name "American Express Japan".
Email requests recipient to "reconfirm account information" - classic
credential harvesting attempt.
Source IP 35.219.154.139 appears to be a Google Cloud Platform (GCP)
instance, likely a rented host used to send phishing mail rather than
shared legitimate infrastructure.
Timezone: UTC+8
show less
Unauthorized SMTP connection attempts with forged sender addresses
from our own domain (sender veri ...
show moreUnauthorized SMTP connection attempts with forged sender addresses
from our own domain (sender verification failed). All attempts rejected.
2026/09/16 08:08:12 SMTP rejected connection from 51.79.243.162
- sender (inf***@ourdomain.tld) failed local sender verification
2026/09/16 08:08:24 SMTP rejected connection from 51.79.243.162
- sender (adm***@ourdomain.tld) failed local sender verification
Timezone: UTC+8
show less
SpoofingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.