Loading threats
SMTP message body contained the string t_Smtp.LocalIP, a pattern commonly used by automated relay-testing tools to verify message delivery or identify the responding server’s local IP during open-relay validation. In honeypot environments, this marker typically indicates scripted testing rather than legitimate email content and is often associated with spam bot or relay-probe activity.
| IP Address | Risk | Events | Sessions | Country | ASN | Last Seen |
|---|---|---|---|---|---|---|
| 178.16.54.139 | 92% | 44,573 | 44,503 | 🇳🇱 NL | AS202412 | 2026-03-14 |
| 91.224.92.177 | 96% | 1,018 | 825 | 🇬🇧 GB | AS209605 | 2026-04-17 |
| 158.94.211.108 | 97% | 819 | 89 | 🇺🇸 US | AS202412 | 2026-02-24 |
| 158.94.209.131 | 100% | 812 | 730 | 🇳🇱 NL | AS202412 | 2026-04-09 |
| 158.94.211.67 | 98% | 758 | 118 | 🇺🇸 US | AS202412 | 2026-03-19 |
| 158.94.209.145 | 99% | 576 | 102 | 🇳🇱 NL | AS202412 | 2026-03-08 |
| 178.16.52.2 | 98% | 537 | 90 | 🇩🇪 DE | AS202412 | 2026-03-30 |
| 41.193.154.189 | 96% | 533 | 113 | 🇿🇦 ZA | AS11845 | 2026-04-15 |
| 158.94.211.35 | 98% | 427 | 106 | 🇺🇸 US | AS202412 | 2026-03-20 |
| 158.94.211.69 | 93% | 420 | 36 | 🇺🇸 US | AS202412 | 2026-02-18 |
| 158.94.209.116 | 97% | 415 | 67 | 🇳🇱 NL | AS202412 | 2026-04-01 |
| 91.92.241.115 | 95% | 396 | 83 | 🇳🇱 NL | AS202412 | 2026-04-14 |
| 45.92.33.82 | 97% | 384 | 73 | 🇬🇷 GR | AS9009 | 2026-04-08 |
| 185.169.4.178 | 95% | 380 | 46 | 🇬🇧 GB | AS209605 | 2026-03-09 |
| 158.94.211.202 | 94% | 376 | 59 | 🇺🇸 US | AS202412 | 2026-03-27 |
| 146.70.146.50 | 97% | 372 | 145 | 🇦🇹 AT | AS9009 | 2026-03-26 |
| 141.98.10.37 | 99% | 368 | 98 | 🇱🇹 LT | AS209605 | 2026-04-10 |
| 178.16.54.171 | 99% | 358 | 149 | 🇳🇱 NL | AS202412 | 2026-04-15 |
| 158.94.210.111 | 95% | 348 | 56 | 🇳🇱 NL | AS202412 | 2026-04-16 |
| 158.94.211.56 | 97% | 340 | 59 | 🇺🇸 US | AS202412 | 2026-03-20 |