Perfectly shaped E-Mail with Attachment trying to look like a pdf, but is most probably a trojan or ...
show morePerfectly shaped E-Mail with Attachment trying to look like a pdf, but is most probably a trojan or another malware according to virustotal (Mal/DrodRar-A)
show less
Authentication-Results: spf=none (sender IP is 149.202.44.208)
smtp.mailfrom=cbbc.com; sbb.ch; dki ...
show moreAuthentication-Results: spf=none (sender IP is 149.202.44.208)
smtp.mailfrom=cbbc.com; sbb.ch; dkim=none (message not signed)
header.d=none;sbb.ch; dmarc=none action=none
header.from=cbbc.com;compauth=fail reason=001
Received-SPF: None (protection.outlook.com: cbbc.com does not designate
permitted sender hosts)
Received: from vps-c9a55490.vps.ovh.net (149.202.44.208) by
DB5EUR01FT007.mail.protection.outlook.com (10.152.4.107) with Microsoft SMTP
Server id 15.20.4352.24 via Frontend Transport; Sun, 25 Jul 2021 08:02:04
+0000
Received: from ip-129-130.dataclub.info (localhost [127.0.0.1])
by vps-c9a55490.vps.ovh.net (Postfix) with ESMTP id 7F7F36C2C69
for <anonymized>; Thu, 22 Jul
show less
grep -c 91.191.209.149 /var/log/mail.log
2985 connection tried in 24h with different Mail address ...
show moregrep -c 91.191.209.149 /var/log/mail.log
2985 connection tried in 24h with different Mail addresses
show less
Received: from [197.220.169.135] (unknown [197.220.169.135]) by mailhub.bf-net.ch (Postfix) with ESM ...
show moreReceived: from [197.220.169.135] (unknown [197.220.169.135]) by mailhub.bf-net.ch (Postfix) with ESMTP id F3515BE9A8 for <"masked"@urs-mueller.ch>; Mon, 19 Apr 2021 16:23:38 +0200 (CEST)
Received: from [150.203.178.57] (helo=pwtho.pgzrfzh.co.jp) by with esmtpa (Exim 4.86_1) (envelope-from ) id 603ACD7A33A1 for [email protected]; Mon, 19 Apr 2021 15:23:38 +0100
Received: from [19.58.91.117] (helo=ithn.o3.e.notification.intuit.com) by (Postfix) with ESMTP (envelope-from ) id HjoKeQUlMXL1Z.588 for [email protected]; Mon, 19 Apr 2021 15:23:38 +0100
<841215.20210419152338@KYMYTAE.WUTAROT.o3.e.notification.intuit.com>
E-Mail contains MS-Excel xls-Binary with Hash:
02521f0bb91b4c74d1590b85254f26f0d258cd780393010593ae6daaa5993753
Hash says it's most probably Dridex / Trojan / Downloader.
show less
Received: from xm0.817.plxo.ml (xm0.817.plxo.ml [157.230.84.182]) (using TLSv1.2 with cipher ECDHE-R ...
show moreReceived: from xm0.817.plxo.ml (xm0.817.plxo.ml [157.230.84.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by xxx_masked_xxx.bf-net.ch (Postfix) with ESMTPS id AAD7CBEA1A for <[email protected]>; Tue, 16 Mar 2021 06:56:38 +0100 (CET)
<[email protected]>
show less
Received: from [91.196.231.214] (unknown [91.196.231.214])
by xxxxxxxx.bf-net.ch (Postfix) ...
show moreReceived: from [91.196.231.214] (unknown [91.196.231.214])
by xxxxxxxx.bf-net.ch (Postfix) with ESMTP id D78CDBEA1A
Bitcoin blackmailing
show less
701 attempts in 4 hours !
Tried to tell the noc at [email protected]
unknown[87.246.7.226]: SASL LOGIN au ...
show more701 attempts in 4 hours !
Tried to tell the noc at [email protected]
unknown[87.246.7.226]: SASL LOGIN authentication failed: authentication failure
show less
Brute-Force
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.