Groups | Search | Server Info | Keyboard shortcuts | Login | Register


Groups > de.admin.net-abuse.mail > #8955

3xK Tech GmbH?

From Nico Hoffmann <oxensepp@gmx.de>
Newsgroups de.admin.net-abuse.mail
Subject 3xK Tech GmbH?
Date 2025-05-10 06:11 +0000
Organization Thermisches Gleichgewicht A.G.
Message-ID <slrn101trfk.5nr.oxensepp@haydn.lewonze.de> (permalink)

Show all headers | View raw


Hallo,

der Webmaster-Account meiner Domain wird bespammt. Der Spammer nutzt
dazu ein PHP-Kontaktformular auf der Webseite. Die Zugriffe kommen von
der IP 156.228.93.187 (beipielsweise).

Whois sagt, das gehört zu cloudinnovation.org, also einer der großen
Spamschleudern. Und die haben das betreffende AS weitervermietet an
einen Laden in Brandenburg, nämlich:

3xK Tech GmbH
Altenhofer Weg
16244 Schorfheide
Germany

AS: 200373
AS: 198571 

Leider ist das alles, was ich über 3xK Tech rauskriege. Vermutlich
irgenein kleiner Krauter, der 'irgendwas mit Internet' macht. 
Ist die Firma schonmal jemandem aufgefallen?


| From webmaster@xxx.yyy Sat May 10 07:47:57 2025
| Return-Path: <SRS0=OaewNs=X2=ws1.web.vrmd.de=u1406@xxx.yyy>
| X-Original-To: nico@localhost
| Delivered-To: nico@localhost
| Received: from mendelssohn.xxx.yyy (mendelssohn.xxx.yyy [127.0.0.1])
| 	by mendelssohn.localdomain (Postfix) with ESMTP id 649A98F8D28
| 	for <nico@localhost>; Sat, 10 May 2025 07:47:57 +0200 (CEST)
| Received: from pop3.variomedia.de [81.28.224.29]
| 	by mendelssohn.xxx.yyy with POP3 (fetchmail-6.4.39)
| 	for <nico@localhost> (single-drop); Sat, 10 May 2025 07:47:57 +0200 (CEST)
| Received: from mx1.mail.vrmd.de ([10.0.1.21])
| 	 by mb08.mail.vrmd.de (Cyrus 3.0.13-Debian-3.0.13-5) with LMTPA;
| 	 Sat, 10 May 2025 03:43:14 +0200
| X-Cyrus-Session-Id: cyrus-1254992-1746841394-2-14301092827443251312
| X-Sieve: CMU Sieve 3.0
| Envelope-to: webmaster@xxx.yyy
| Delivery-date: Sat, 10 May 2025 03:43:14 +0200
| Authentication-Results: mx1.mail.vrmd.de;
| 	iprev=pass (ws1.web.vrmd.de) smtp.remote-ip=81.28.232.66;
| 	spf=pass smtp.mailfrom=ws1.web.vrmd.de;
| 	dmarc=none header.from=xxx.yyy
| Received-SPF: pass (mx1.mail.vrmd.de: domain of ws1.web.vrmd.de designates 81.28.232.66 as permitted sender) client-ip=81.28.232.66; envelope-from=u1406@ws1.web.vrmd.de; helo=ws1.web.vrmd.de;
| Received: from ws1.web.vrmd.de ([81.28.232.66])
| 	by mx1.mail.vrmd.de with esmtps  (TLS1.3) tls TLS_AES_256_GCM_SHA384
| 	(Exim 4.95)
| 	(envelope-from <u1406@ws1.web.vrmd.de>)
| 	id 1uDZFC-009fYH-8d
| 	for webmaster@xxx.yyy;
| 	Sat, 10 May 2025 03:43:14 +0200
| Received: from u1406 by ws1.web.vrmd.de with local (Exim 4.95)
| 	(envelope-from <u1406@ws1.web.vrmd.de>)
| 	id 1uDZFC-00Ev4T-4S
| 	for webmaster@xxx.yyy;
| 	Sat, 10 May 2025 03:43:14 +0200
| To: webmaster@xxx.yyy
| Subject: Boost Your Online Presence with SEO and Social Media Solutions!
| From: E28-Forum <webmaster@xxx.yyy>
| Reply-to: bellfrost46078@gmail.com
| MIME-Version: 1.0
| X-Sender-IP: 156.228.93.187
| Content-Type: text/plain; charset=UTF-8
| Content-Transfer-Encoding: quoted-printable
| Message-Id: <E1uDZFC-00Ev4T-4S@ws1.web.vrmd.de>
| Date: Sat, 10 May 2025 03:43:14 +0200
| X-purgate: suspect.url-count
|  X-purgate-type: suspect.url-count
|  X-purgate-ID: 150741::1746841394-88CF1987-D16780D9/2/63680721944
|  X-purgate-Ad: Categorized by eleven eXpurgate (R) https://www.eleven.de
| X-Spam-Suspicion: No
|
| Hello
|
| At Your SEO & Digital Marketing Partner, we offer complete SEO and promotion solutions designed to enhance your visibility, traffic, and sales:

[...]

-- 
Dann halt nicht.

Back to de.admin.net-abuse.mail | Previous | NextNext in thread | Find similar


Thread

3xK Tech GmbH? Nico Hoffmann <oxensepp@gmx.de> - 2025-05-10 06:11 +0000
  Re: 3xK Tech GmbH? Nomen Nescio <nobody@dizum.com> - 2025-05-10 08:26 +0000
    Re: 3xK Tech GmbH? Nico Hoffmann <oxensepp@gmx.de> - 2025-05-10 10:51 +0000
      Re: 3xK Tech GmbH? Nico Hoffmann <oxensepp@gmx.de> - 2025-05-14 04:36 +0000
        Re: 3xK Tech GmbH? Nico Hoffmann <oxensepp@gmx.de> - 2025-05-14 04:41 +0000

csiph-web