This IP address is tracking opens in spam sen by OMICS, a publisher of «open-access» journals that solicits contributions and (by implication) fees and/or subscriptions through spam sent to scraped, purchased, or appended email addresses.
At the end of the email are two bits of code that are not visible in the email as rendered in most email clients. These bits of code contain links to servers that track «opens» for the email. Both links are shown below, with tagging information removed so that they do not identify the specific spamrap that received his email.
The first link timed out when we teested it—the IP address 22.214.171.124 is dead. The second link did not time out—it is live and recording opens.
Two possible reasons for this occur to us. This might be a simple cut-and-paste error in creation of the spam email. And it might be that OMICS is reacting against an ISP that disconnected service to them by making sure that the IP address(es) coninue to appear in their spam emails, preventing blocklistings and reputation services from ageing those IP addresses out of their systems.
Linode: You host the live IP address below, the subject of this SBL listing. Please shut down that VPS and all other services to this customer. Be aware that the customer uses many business names and contacts to obtain service, and might have multiple accounts or reappear under a new name and open new Services.
Received: from ping1.host6.trans.vcomweb.net (ping1.host6.trans.vcomweb.net [126.96.36.199])
Date: Mon, 21 Mar 2022 05:##:## +0000
From: «Clinics in Surgery™ (Impact Factor ##)» <email@example.com>
Reply-To: «Clinics in Surgery™ (Impact Factor ##)» <firstname.lastname@example.org>
Subject: Short Article Submissions: <x>
Greetings for the Day!!
We understand your priorities and professional commitments. It would
not be appropriate at this point in time to overburden you by asking
you to write/contribute a full-length manuscript.
[ NOTE: Responses must be sent to Reply-to email address; no submission
weblink is provided. ]
<img data-connectorsauthtoken=»1″ data-<x>=»/<x>/<x>»
data-<x>=»» data-<x>=»External» height=»1″
src=»https://outlook.office.com/actions/ei?u=http%3A%2F%2F188.8.131.52%2Fmail%2Findex.php%2Fcampaigns%2F<x>%2Ftrack-opening%2F<x>;d=<x>%3A<x>» width=»1″ />
</span><img width=»1″ height=»1″ src=»http://184.108.40.206/mail/index.php/campaigns/<x>/track-opening/<x>» alt=»» />
NetRange: 220.127.116.11 — 18.104.22.168
Parent: NET45 (NET-45-0-0-0-0)
NetType: Direct Allocation
OriginAS: AS3595, AS21844, AS6939, AS8001
Organization: Linode (LINOD)
Comment: Linode, LLC
Address: 249 Arch St
OrgNOCName: Linode Network Operations
OrgAbuseName: Linode Abuse Support
OrgTechName: Linode Network Operations