This IP is part of an ongoing Pfcloud UG (AS51396) spam operation.
Observed sending unsolicited bu ...
show moreThis IP is part of an ongoing Pfcloud UG (AS51396) spam operation.
Observed sending unsolicited bulk email with subject lines such as
“Get paid for scrolling Facebook, Twitter & YouTube” and
“Social Media Worker – Full training provided.”
Headers show DKIM=pass (d=vitafirm.za.com; s=k1), SPF and DMARC also pass.
The emails contain tracking pixels and multiple click-through links hosted on vitafirm.za.com.
Mail is relayed through asp-relay-pe.jellyfish.systems (162.255.118.8).
Persistent pattern consistent with prior abuse reports from the same network.
show less
IP 176.65.149.5 is sending bulk spam via monte.selfsufficient.za.com, promoting fake “Vehicle Protec ...
show moreIP 176.65.149.5 is sending bulk spam via monte.selfsufficient.za.com, promoting fake “Vehicle Protection USA” auto warranties. Messages contain rotating subjects, redirect links on selfsufficient.za.com, and padded filler text to evade filters. Part of an ongoing coordinated spam campaign.
show less
Ongoing coordinated spam operation involving deceptive bulk marketing emails sent via Pfcloud infras ...
show moreOngoing coordinated spam operation involving deceptive bulk marketing emails sent via Pfcloud infrastructure (AS51396). This IP (176.65.149.25) has been observed sending multiple unsolicited messages in the last 24 hours, consistent with previous activity from this network. Messages contain tracking links, misleading subject lines, and appear tied to the same campaign previously reported from other Pfcloud IPs.
show less
Jellyfish Systems relay actively passing through spam from Pfcloud UG (AS51396, Germany).
Details ...
show moreJellyfish Systems relay actively passing through spam from Pfcloud UG (AS51396, Germany).
Details:
- Relaying multiple daily spam emails for domains:
- preciousmetals.sa.com
- checkclick.ru.com
- pillowfoam.za.com
- ninjaservice.sa.com
- Tracking/landing URLs:
- https://ninjaservice.sa.com/click.php?u=...
- https://pillowfoam.za.com/open.php?u=...
- Campaign uses tracking images/URLs to confirm recipients.
- Relay IP: 162.255.118.7 consistently appears in Received headers.
show less
Ongoing coordinated spam campaign originating from Pfcloud UG (AS51396, Germany) and relayed via Jel ...
show moreOngoing coordinated spam campaign originating from Pfcloud UG (AS51396, Germany) and relayed via Jellyfish Systems.
Details:
- Spam promoting diet supplements, fake surveys, and woodworking scams.
- Sending domain: checkclick.ru.com
- Tracking/landing URLs:
- https://checkclick.ru.com/click.php?u=9b3a...
- https://checkclick.ru.com/open.php?u=7de4...
- Campaign bypasses filters by rotating Pfcloud IPs and spam domains.
Relay: asp-relay-pe.jellyfish.systems (162.255.118.7)
show less
Ongoing coordinated spam campaign originating from Pfcloud UG (AS51396, Germany) and relayed via Jel ...
show moreOngoing coordinated spam campaign originating from Pfcloud UG (AS51396, Germany) and relayed via Jellyfish Systems.
Details:
- Spam promoting "USA Today American Pope Special Edition", diet pills, woodworking scams.
- Sending domain: preciousmetals.sa.com
- Tracking/landing URLs:
- https://preciousmetals.sa.com/click.php?u=5f4e...
- https://preciousmetals.sa.com/open.php?u=ab12...
- Campaign bypasses filters by rotating Pfcloud IPs and spam domains.
Relay: asp-relay-pe.jellyfish.systems (162.255.118.7)
Please investigate and take action.
show less
This IP is sending unsolicited bulk email (spam) promoting “FluffCo” products via the domain pillowf ...
show moreThis IP is sending unsolicited bulk email (spam) promoting “FluffCo” products via the domain pillowfoam.za.com.
Messages are relayed through asp-relay-pe.jellyfish.systems and contain identical HTML templates with tracking links.
DKIM, SPF, and DMARC all pass for pillowfoam.za.com.
Samples observed 2025-08-11 include subjects:
- "Give the Gift of Comfort this Holiday Season"
- "Sleep better with FluffCo"
Some messages include unrelated filler text (e.g., about the Bank of England) to evade spam filters.
show less
This IP attempted to spoof a domain I own by sending a forged email that failed both SPF and DKIM au ...
show moreThis IP attempted to spoof a domain I own by sending a forged email that failed both SPF and DKIM authentication. The message was detected and rejected according to my DMARC policy (p=reject).
Details:
- Date/Time: [Insert UTC timestamp from DMARC report]
- Reverse DNS: out13-89.antispamcloud.com
- ASN / Network Owner: OXILION B.V. (Netherlands) – Antispamcloud / Hornetsecurity outbound filtering network
- Message claimed "From:" address within bo3lter.com but originated from this unauthorized IP.
- SPF result: fail
- DKIM result: fail
- DMARC disposition: reject
This activity is indicative of a spoofing or phishing attempt. No authorized services use this IP to send mail on behalf of [redacted] (my domain).
show less
On 2025-08-06 at approximately 05:49 UTC, this IP was observed sending an email that forged the "Fro ...
show moreOn 2025-08-06 at approximately 05:49 UTC, this IP was observed sending an email that forged the "From" address of a domain I own. The email was rejected by the recipient's server (554 5.7.9 Message not accepted for policy reasons) and bounced back to my address.
Header evidence shows:
Received: from [45.81.23.6] ([76.64.92.155]) by cmsmtp with SMTP
Message-ID: <RRBJN37U-JS2D-83KC-PX27-5TE7I0HS3SUW@>
The message had no SPF, DKIM, or DMARC pass results. It appears to be part of a spoofing/spam campaign. The IP belongs to Bell Canada (AS577). Abuse contact: [email protected].
show less
This IP attempted to spoof one of my domain by sending a forged email that failed both SPF and DKIM ...
show moreThis IP attempted to spoof one of my domain by sending a forged email that failed both SPF and DKIM checks. The DKIM signature indicated 'balkanag.com' but the sending IP was 185.201.17.90 (out13-90.antispamcloud.com).
show less
This IP is actively delivering deceptive email spam to multiple aliases at our domain. Messages come ...
show moreThis IP is actively delivering deceptive email spam to multiple aliases at our domain. Messages come from domains under "tupperware.ru.com" and claim to be a complimentary copy of “USA TODAY MLS AT 30.”
Subject: USA TODAY MLS AT 30
From: [email protected] or [email protected]
Links: multiple http://tupperware.ru.com/[ID] URLs + 1x1 tracking pixels
Looks like a follow-up to previous dictionary attacks reported by Project Honey Pot. They're now sending valid messages to guessed aliases. Message headers show:
- DKIM/SPF/DMARC: Pass (domain is configured for deliberate abuse)
- Source IP: 176.65.148.127
- Host: william.tupperware.ru.com
- Server: likely hosted by MivoCloud
Spam includes embedded links, tracking images, and obfuscated paths, likely phishing or malware landing pages.
This campaign is ongoing and coordinated.
show less
Received via SMS spam an alert to go to: https://cutt.ly/en, a phishing site. From looking at other ...
show moreReceived via SMS spam an alert to go to: https://cutt.ly/en, a phishing site. From looking at others' comments it seems this domain has been active in this capacity for over a month.
show less
Ditto to previous comment: Phishing activity which came in via SMS spam and directed readers to htt ...
show moreDitto to previous comment: Phishing activity which came in via SMS spam and directed readers to https://cutt.ly.
show less
192.238.132.114 is from jbwrt.com which is the "go to" URL in a financial fraud message received on ...
show more192.238.132.114 is from jbwrt.com which is the "go to" URL in a financial fraud message received on X.
show less
Spam for a cheese company. IP is allocated to "Constant Contact" and they're supposedly in the legi ...
show moreSpam for a cheese company. IP is allocated to "Constant Contact" and they're supposedly in the legit email marketing business, but I certainly don't recall signing some fromagerie.
show less
This IP is the go to site/landing page for an SMS spam message.
"U.S. Customs: You have a USPS pa ...
show moreThis IP is the go to site/landing page for an SMS spam message.
"U.S. Customs: You have a USPS parcel being cleared, due to the detection of an invalid zip code address, the parcel can not be cleared, the parcel is temporarily detained, please confirm the zip code address information in the link within 24 hours."
https://us-usps-vmmpt.top/i
show less
Sophia would like to meet with you amy.
Sophia (21 years)
Relationship Status: Single
Build: ...
show moreSophia would like to meet with you amy.
Sophia (21 years)
Relationship Status: Single
Build: normal
Height: 169cm
Distance to City: 13km
You have received
a message from Sophia.
show less
Hi amy, Sophia would like to meet with you!
Sophia (21 years)
Relationship Status: Single
Build ...
show moreHi amy, Sophia would like to meet with you!
Sophia (21 years)
Relationship Status: Single
Build: normal
Height: 169cm
Distance to City: 13km
You have received
a message from Sophia.
show less
SpamAssassin (score: 4.4)
RBL: ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due ...
show moreSpamAssassin (score: 4.4)
RBL: ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ [46.246.97.243 listed in zen.spamhaus.org] (score: N/A)
RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [46.246.97.243 listed in bl.score.senderscore.com] (score: N/A)
Contains an URL listed in the URIBL greylist [URI: list-manage.com] (score: 1.1)
ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ [URI: an-naseeha.us1.list-manage.com] [URI: tacamp.com] [URI: datacamp.onelink.me] [URI: an-naseeha.com]
Message ID: [email protected]
Subject: Liz Buys Homes Fast dQMF
show less
SpamAssassin (score: -0.5)
ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked due to u ...
show moreSpamAssassin (score: -0.5)
ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ [URI: s3.amazonaws.com] [URI: www.httpsimage.com] [URI: www.www.com] [URI: datacamp.onelink.me] [URI: auth.jino.ru] [URI: www.an-naseeha.com] [URI: datacamp.com] [URI: portablenorthpole.com] [URI: kanvasdor.com] [URI: an-naseeha.us1.list-manage.com] [URI: an-naseeha.com] [URI: jino.ru] [URI: tacamp.com] [URI: cp.jino.ru] [URI: www.datacamp.com] (score: N/A)
RBL: ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ [46.246.98.82 listed in zen.spamhaus.org] (score: N/A)
Contains an URL listed in the URIBL blacklist [URI: kanvasdor.com] [URI: www.com] (score: 1.7)
Message ID [email protected]
Subject Were you injured in a motor vehicle accident? Get Help Now! kgYE
From: [email protected]show less
Email Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.