Phishing email impersonating American Express received from 103.77.247.223. The message attempted to ...
show morePhishing email impersonating American Express received from 103.77.247.223. The message attempted to lure the recipient into verifying a supposed fraudulent purchase and used a shortened t.co link associated with the phishing campaign. The source IP appears in the Received header as the originating host.
show less
Spam/advance-fee investment scam sent to a never-used catch-all address at my domain. Sender spoofed ...
show moreSpam/advance-fee investment scam sent to a never-used catch-all address at my domain. Sender spoofed [email protected]; SPF softfail, no DKIM, DMARC fail. Reply-To was a Gmail address. Message offered project financing from $5 million to $10 billion+.
show less
Unsolicited commercial email spam sent directly from 194.36.45.195 using HELO mx1.tlthiengioi.com. M ...
show moreUnsolicited commercial email spam sent directly from 194.36.45.195 using HELO mx1.tlthiengioi.com. Message advertised a supposed “Shield Home Assurance” plan and linked to tlthiengioi.com. The email used unrelated hidden conversational text about meetings, scheduling, and food, apparently to evade content filters. SPF, DKIM, and DMARC all passed for tlthiengioi.com, indicating authenticated spam rather than simple sender spoofing. Received 2026-08-04 at 14:38 UTC. Subject: “This plan has your home repairs fully handled.”
show less
Unsolicited AARP-impersonation email from mail.turboyadak.com. SPF, DKIM and DMARC passed for turboy ...
show moreUnsolicited AARP-impersonation email from mail.turboyadak.com. SPF, DKIM and DMARC passed for turboyadak.com, but the message used fake AARP branding, concealed filler text to evade filters, and a questionnaire link that redirected through an affiliate-tracking URL tagged aff_sub=aarp.
show less
Authenticated email spam and Delta/SkyMiles phishing impersonation. The message originated from 103. ...
show moreAuthenticated email spam and Delta/SkyMiles phishing impersonation. The message originated from 103.78.105.89 using the sender domain tomorrowahead.living. SPF, DKIM, and DMARC passed for that domain. The email falsely presented itself as “Skymiles Delta” and directed recipients to a landing page on tomorrowahead.living. SpamCop independently identified this IP as the originating mail server.
show less
Phishing email spoofing my own domain (bo3lter.com). Forged From/Return-Path using 62.60.130.165 (Pa ...
show morePhishing email spoofing my own domain (bo3lter.com). Forged From/Return-Path using 62.60.130.165 (ParsOnline, Iran) as the true source. Message falsely claims “email account deletion” and links to a credential-harvesting page on a compromised WordPress host:
https://mudiwahood.group/wp-includes/js/tinymce/skins/jsquery.html
SPF softfail, DKIM none, DMARC fail (policy=quarantine). Not sent via my legitimate mail provider's servers.
show less
Observed phishing email impersonating NatWest (subject “Bank of APIs - sign-in alert”) that links to ...
show moreObserved phishing email impersonating NatWest (subject “Bank of APIs - sign-in alert”) that links to bankofapis.com for credential harvesting. Email was relayed through asp-relay-pe.jellyfish.systems (IP 162.255.118.8). The message appears to use DKIM headers from natwest.com while the body has been tampered with (DKIM body hash mismatch and ARC failure), indicating DKIM-replay/header-reuse. Full raw message available: ****. Phone number used in scam: +1 (803) 250-7580.
show less
Phishing email impersonating Ledger (crypto hardware wallet company).
Sent from [email protected] ...
show morePhishing email impersonating Ledger (crypto hardware wallet company).
Sent from [email protected] via SendGrid (159.183.224.102).
Contains links to an Amazon S3 bucket that asks user to "verify recovery phrase."
This is a credential-harvesting attempt to steal crypto assets.
show less
Unsolicited marketing email (“Orangetheory Fitness” promos) sent from 93.99.104.216 (narvi.silentfra ...
show moreUnsolicited marketing email (“Orangetheory Fitness” promos) sent from 93.99.104.216 (narvi.silentframe.cyou) through relay asp-relay-pe.jellyfish.systems (162.255.118.8). Messages contained tracking links and images hosted at silentframe.cyou plus filler text. DKIM/SPF/DMARC passed, confirming the spam was sent via silentframe.cyou bulk-mail infrastructure.
show less
Spanish-language sextortion email demanding $750 to BTC bc1qd3ejt72l0rdjkdzz7g8zs0cfj326gsevhzkj0w w ...
show moreSpanish-language sextortion email demanding $750 to BTC bc1qd3ejt72l0rdjkdzz7g8zs0cfj326gsevhzkj0w within 48h. Claims undetectable driver-level trojan and threatens to share fabricated videos with contacts. Originating IP per headers: 144.48.163.44, relayed via asp-relay-pe.jellyfish.systems (162.255.118.8). Same wallet/content as two prior messages from different IPs/senders this week.
show less
Spanish-language sextortion email demanding $750 to BTC bc1qd3ejt72l0rdjkdzz7g8zs0cfj326gsevhzkj0w w ...
show moreSpanish-language sextortion email demanding $750 to BTC bc1qd3ejt72l0rdjkdzz7g8zs0cfj326gsevhzkj0w within 48h. Claims undetectable trojan/driver-level malware and threatens to share fabricated videos with contacts. Originating IP per headers: 190.5.161.18 (Megacable AR), relayed via asp-relay-pe.jellyfish.systems (162.255.118.7). Same wallet and content as a prior message from a different IP the previous day.
show less
Spanish-language sextortion scam email sent from this IP. Threatens to release fabricated compromisi ...
show moreSpanish-language sextortion scam email sent from this IP. Threatens to release fabricated compromising webcam videos unless $750 USD is paid to Bitcoin wallet bc1qd3ejt72l0rdjkdzz7g8zs0cfj326gsevhzkj0w within 48 hours. Claims to have installed a trojan and to monitor the recipient. Originating IP is a Claro/Telefónica mobile network (Central America). As of 09 Sep 2025, IP is listed on Barracuda Reputation Block List.
show less
Spam campaign from Pfcloud UG (AS51396).
Observed sending deceptive "T-Mobile Laptop Giveaway" ema ...
show moreSpam campaign from Pfcloud UG (AS51396).
Observed sending deceptive "T-Mobile Laptop Giveaway" emails.
Origin: 176.65.149.32 (yoke.syncy.sa.com).
Domain: syncy.sa.com with DKIM=pass, SPF & DMARC pass.
Messages contain tracking pixel and click-through URLs.
Relay: asp-relay-pe.jellyfish.systems (162.255.118.7).
Part of same ongoing spam operation using Pfcloud infrastructure.
show less
Ongoing spam campaign from Pfcloud UG (AS51396).
This IP (176.65.149.31) is used to send fraudulen ...
show moreOngoing spam campaign from Pfcloud UG (AS51396).
This IP (176.65.149.31) is used to send fraudulent giveaway emails ("O'Reilly Jump Starter", "Schumacher Gift").
Domain: portraits.ru.com, SPF/DKIM/DMARC pass.
Includes tracking pixel and click URLs hosted on portraits.ru.com.
Relayed through asp-relay-pe.jellyfish.systems (162.255.118.8).
Same campaign reported previously under other Pfcloud IPs/domains.
show less
This IP is actively sending spam tied to an ongoing Pfcloud/Jellyfish campaign.
Observed sending u ...
show moreThis IP is actively sending spam tied to an ongoing Pfcloud/Jellyfish campaign.
Observed sending unsolicited email promoting fake health remedies ("Japanese Moon Elixir" / thyroid cure).
Domain: biowave.sa.com, DKIM/SPF/DMARC all pass.
Messages include tracking pixels and multiple click-through links hosted on biowave.sa.com.
Relay path via asp-relay-pe.jellyfish.systems (162.255.118.7).
Part of a persistent spam/phishing operation.
show less
This IP is actively sending spam as part of the same Pfcloud UG (AS51396) / Jellyfish relay operatio ...
show moreThis IP is actively sending spam as part of the same Pfcloud UG (AS51396) / Jellyfish relay operation.
Recent samples include subjects like “Stop Scrubbing – Try This Simple Cleaning Device!” and other deceptive promotions.
Headers show DKIM=pass (d=patriotpower.ru.com; s=k1), SPF and DMARC pass.
Messages include tracking pixels and click URLs on patriotpower.ru.com.
Relayed via asp-relay-pe.jellyfish.systems (162.255.118.8).
Repeat abuse from this provider’s allocation.
show less
PhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.