Received: from qyjpvv.altris.com (147.182.149.77) From: Aktuelle Nachrichten<reply@lidl.ru!>;<service@stayfriends.de> Subject: BILD untersucht die Wahrheit über das geheime System zum Geld verdienen Date: Fri, 22 Oct 2021 22:5x:xx +0000
Рубрика: digitalocean.com
phishing server
nfcusupportportal.com has address 137.184.10.240
Abused / misconfigured newsletter service (listbombing)
The host at this IP address is being (ab)used to «listbomb» email addresses: From: aidsmap bulletins <bulletins@bulletins.aidsmap.com> Subject: Coming soon: news from the 18th European AIDS Conference Problem description ============================ Spammers signed up for the bulk email service using the victim’s email address. As a result, the victim is being «listbombed» with transactional messages and… Читать далее Abused / misconfigured newsletter service (listbombing)
spam emitter @64.227.190.219
Received: from mail.mutsusa.com (64.227.190.219) From: «Jacob Hansen» <contact@mutsusa.com> Subject: [], du kan ta ut pengene dine i dag Date: Thu, 21 Oct 2021 03:2x:xx -0700
phishing server
verlfy-citizens03.com has address 104.131.79.157 104.131.79.157|53rd-online.com|2021-10-17 01:40:58 104.131.79.157|53rd-secure.com|2021-10-20 02:20:50 104.131.79.157|citizens3.com|2021-10-17 01:21:09 104.131.79.157|online-citizens.com|2021-10-15 15:21:31 104.131.79.157|online-user0.com|2021-10-14 16:16:16 104.131.79.157|verfy04-identity.com|2021-10-19 17:26:04 104.131.79.157|verlfy-citizens03.com|2021-10-20 19:55:59 104.131.79.157|web-secrue03.com|2021-10-17 01:11:01
Spamvertised website
Received: from mhkg.mta3.appspot.com (20.185.239.150) From: Facebook <[]@facebook.com> Subject: Tell us about your experience with Facebook being down and get $90 promo reward Date: Mon, 18 Oct 2021 18:11:41 +0200 https://dinoperks.page.link/rK6c 74.125.192.101 https://binocularsti.com/[] 165.227.177.110 https://distinctpedestrian.com/?s1=[]&s2=[]&s3=3410&s4=1638&ow=&s10=862 172.67.200.31 https://konicpirg.com/[] 172.67.187.213 https://waveyup.com/click?s2=[]&s1=[]&s3=3410&trvid=10496&s4=1638&ow=8 34.234.154.208 https://icelnkr.com/?a=310&c=457&s2=p[ 3.222.214.90 https://www.getzbuds.com/jtn3/?tracking1=XCI1S&tracking2=&tracking3=[]&tracking4=[] 104.21.54.210
Abused / misconfigured newsletter service (listbombing)
The host at this IP address is being (ab)used to «listbomb» email addresses: From: aidsmap bulletins <bulletins@bulletins.aidsmap.com> Subject: aidsmap news: Some people with HIV may have weaker response to COVID-19 vaccines, 19 October 2021 Problem description ============================ Spammers signed up for the bulk email service using the victim’s email address. As a result, the victim… Читать далее Abused / misconfigured newsletter service (listbombing)
phishing server
usps-invoice.gq has address 137.184.112.42 usps-invoice.cf has address 137.184.112.42 usps-invoice.ga has address 137.184.112.42 usps-invoice.tk has address 137.184.112.42 uspsmail.team has address 137.184.112.42 swisscom-abonements.cf has address 137.184.112.42 swisscom-abonements.tk has address 137.184.112.42 swisscom-abonnements.gq has address 137.184.112.42 santanderbanks.tk has address 137.184.112.42 swisscom-abonnements.cf has address 137.184.112.42 maincloud.ga has address 137.184.112.42 swisscome-network.gq has address 137.184.112.42 swisscom-abonements.ml has address 137.184.112.42 swisscome-network.tk has address… Читать далее phishing server
affiliate spam @erafinans.no
Received: from s22020.in.dimiwuh.eu (212.236.220.20) From: Era Finans på vegne av Travelwop <info@in.dimiwuh.eu> Subject: Refinansiering av smålån og kredittkort Date: Fri, 15 Oct 2021 06:3x:xx +0000 http://in.dimiwuh.eu/r?up=[] 188.95.249.200 http://rls.go2cloud.org/aff_c?offer_id=108&aff_id=1&url_id=230&aff_sub2=1294&aff_sub3=[]&aff_sub4=[] 34.198.147.111 https://erafinans.no/?campaign=830&clickid=[]&affid=123456 159.65.196.24
Spamvertised website
Received: from gotogml.com (gotogml.com. [185.122.223.223]) From: 🔔Gemeentelijk Energie <[]@gotogml.com> Date: Fri, 08 Oct 2021 09:1x:xx +0000 Subject: Nieuw in uw gemeente: bespaar via het Gemeentelijke Energie Collectief http://crystals.com.de/rd/[] 167.99.241.152 https://laudypauty.com/[] 209.159.146.166 https://sendt.go2cloud.org/aff_c?offer_id=2893&aff_id=1482&aff_sub=472864&aff_sub2=[]&aff_sub3=31 18.202.12.61