IP: 165.16.161.230 South Africa Location: Midrand, Gauteng, South Africa
City:
Midrand
Region:
Gauteng
Country:
South Africa
Postal Code:
1693
Latitude:
-25.9584
Longitude:
28.1414
NetRange: 165.16.0.0 - 165.16.255.255
CIDR: 165.16.0.0/16
NetName: AFRINIC-ERX-165-16-0-0
NetHandle: NET-165-16-0-0-1
Parent: NET165 (NET-165-0-0-0-0)
NetType: Transferred to AfriNIC
OriginAS:
Organization: African Network Information Center (AFRINIC)
RegDate: 2010-11-03
Updated: 2010-11-17
Comment: This IP address range is under AFRINIC responsibility.
Comment: Please see http://www.afrinic.net/ for further details,
Comment: or check the WHOIS server located at whois.afrinic.net.
Ref: https://rdap.arin.net/registry/ip/165.16.0.0

ResourceLink: http://afrinic.net/en/services/whois-query
ResourceLink: whois.afrinic.net

OrgName: African Network Information Center
OrgId: AFRINIC
Address: Level 11ABC
Address: Raffles Tower
Address: Lot 19, Cybercity
City: Ebene
StateProv:
PostalCode:
Country: MU
RegDate: 2004-05-17
Updated: 2015-05-04
Comment: AfriNIC - http://www.afrinic.net
Comment: The African & Indian Ocean Internet Registry
Ref: https://rdap.arin.net/registry/entity/AFRINIC

ReferralServer: whois://whois.afrinic.net
ResourceLink: http://afrinic.net/en/services/whois-query

OrgAbuseHandle: GENER11-ARIN
OrgAbuseName: Generic POC
OrgAbusePhone: +230 4666616
OrgAbuseEmail: abusepoc@afrinic.net
OrgAbuseRef: https://rdap.arin.net/registry/entity/GENER11-ARIN

OrgTechHandle: GENER11-ARIN
OrgTechName: Generic POC
OrgTechPhone: +230 4666616
OrgTechEmail: abusepoc@afrinic.net
OrgTechRef: https://rdap.arin.net/registry/entity/GENER11-ARIN
DNS BlackList results:
Most recent complaints on 165.16.161.230
Complaint by Info :

This IP address is used to send spam blackmails. Return-Path: <fnegus@gsu.edu.tr> Delivered-To: info <fnegus@gsu.edu.tr>) for <info@>; Thu, 17 Oct 2019 08:28:10 +0200 Return-path: <fnegus@gsu.edu.tr> Envelope-to: info@ Delivery-date: Thu, 17 Oct 2019 08:28:10 +0200 Received: from viruswall.gsu.edu.tr ([194.27.192.39]:52976 helo=virus.gsu.edu.tr) (envelope-from <fnegus@gsu.edu.tr>) id 1iKzGa-0005N3-P1 for info@; Thu, 17 Oct 2019 08:28:10 +0200 X-AuditID: c21bc027-f9bff700000069e5-71-5da7ea2f5c88 Received: from mail.gsu.edu.tr (Unknown_Domain [194.27.192.61]) by virus.gsu.edu.tr (Symantec Messaging Gateway) with SMTP id 9D.BC.27109.F2AE7AD5; Thu, 17 Oct 2019 07:12:31 +0300 (EAT) To: undisclosed-recipients:; Received: from EXCHANGE2019.mail.gsu.edu.tr (194.27.192.61) by EXCHANGE2019.mail.gsu.edu.tr (194.27.192.61) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.397.3; Thu, 17 Oct 2019 07:13:11 +0300 Received: from EXCHANGE2019.mail.gsu.edu.tr ([fe80::545:4f95:6515:ae75]) by EXCHANGE2019.mail.gsu.edu.tr ([fe80::545:4f95:6515:ae75%13]) with mapi id 15.02.0397.003; Thu, 17 Oct 2019 07:13:11 +0300 From: FAHRI NEGUS <fnegus@gsu.edu.tr> Subject: =?utf-8?B?Okpha28gdmHFvm5vOyBPZGdvdm9yaSBzYWRh?= Thread-Topic: =?utf-8?B?Okpha28gdmHFvm5vOyBPZGdvdm9yaSBzYWRh?= Thread-Index: AdWEoCvXmdHrpDNbRNeK00fbCIjsjA== Date: Thu, 17 Oct 2019 04:13:10 +0000 Message-ID: <12d1930bf10649ad91c2906dd3048d3e@gsu.edu.tr> Reply-To: "jomi0004@comcast.net" <jomi0004@comcast.net> Accept-Language: en-US, tr-TR Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [165.16.161.230] Content-Type: multipart/alternative; boundary="_000_12d1930bf10649ad91c2906dd3048d3egsuedutr_" MIME-Version: 1.0 X-Brightmail-Tracker: H4sIAAAAAAAAA3VVe0xTVxj39Lb3VuDqpbwOBZZZp06T4UbMPDPqlmXLumzOPdyyzRAto4PG WlgvVXFbAogghU5Ai4gWFSkMmC/eIgp2CoKgRLE+KzDQ8VABeQ4Z7Ny2QDHZP1++/H7fd87v +/I79woJ0dX5YqFCFSFXq2RKCenEN/lUr3ljeXdu4JstsRBlxeWTqN78Coo+buSh7KMn+Kgp SSdACRVmgJKeWQBq2xdHoLHkIj4q0NcT6EL3AwKZC/R8lL5rrwDV9vQD1BVbwEPxhY0Ame+Y AJrs2A3Qrqv3KXR2Qkuh29o6gK49INHoyE0Snan8DBXdustDf/R+ih6eHydQTFMCQCmGXoDi C56R6PmFbID0eQ18VHaaQIUvVqCWlAMUun6+TICKDckkGkyaFKDRmyUCZO6rJ1FpUhqJHo0r UGNxKYUuHntKoaRjUSS6OYT1jNVm467DjQIUf0THR/eTKgmUU3+DROVxX6CMfTiZPHWWh4oe Wnioyvg7QE/+1QvQ/vT9JMq7fYFEia3HKdTbrKNQ6j+TBKpN7ecjs/4F+V4sJU3J7OFLy6IN PGl+4TAp3bvXR1qdn8iXpqZfo6RlA0ulDY9qgFRb1Q6kfSMWgTShLYonnazSCaQXrrYS0mep ekpaUzTGkzYeLhZ8Hkt977Q6WK5UbJOrl6/d7BRaeu4gEd5SCnacrxjnR4GBM0AL5gohswI+ SdHxtcBJKGLOAZhQ0Gkl3BlfaDjULrARYwDmnO4nOELE1AGYXLaey0lmEXx+qpfkcjfmHVgy mULamtfC6p4rhC33h7sm7lsP5eN63fMKK07j+jxdq/3MlXAg8S+KywHjB42xozwuJxgveK/j CM+mlIHZldcJW+4Bu9onsDghziVwpC7AVr4ZttWXA9vxrrDuYAc/GbhlOJyU4VCW4VCWgU8i mKXwVMVyW8kCuD+xjbLlr8Pdhw2UI34UUPnAfZtCrWG3y5RK/xBW4y8P1vhHqAuB7U0sKQe5 NRtNgBECiQvNqHMDRQLZNjZyqwnEAyFP4kEPnMTYvKCw4MhQGRu6Sa1RylmJO33rbwzT03CQ RrlFIqabH2PUbRpVybezSnkEfoWSV2iN3hgo8prmWA0brvhBEaZhN2nUStwL5syZ49DLaoK2 KlhWEaYyASgk8JVHYrPxlcGyyJ1ydZhNiAn4CPkSL9o7lgoUMSGyCPkWuTxcrp5i0/C+JJCu 6MSyXNXyEPmOHxXKiCkeN0aXYIZxZKyT+NFfZmG1no6EwzAL6FhfTIsd6Zfm8bPN4zm7ZGYk nnCuCcQAoQsebFUXt0s2XLaVVYTYpbnRg9yGXaZQqyxv2pUrFU2BDpL86J5yTvEU9ZIcb5sc 0Qw9JaUe9ANhcpchixDGlWTieOYyFy9aY11+No6PrLHfGkes8fEJLl4yGHE8nclFkzUajnBx 0mLJIkR8VZhKLvaiKzjJDHdxqEY1vXuxJ20+mhMomu9AcDOKfelfAnCDhwM+M6b4VfqnO7jL 24GdPSnur87Nnt0/M+zUn6AbGHnY8W70AeuS8Y9iZvMi+hvOLs520Lp4SM/nnO1qxxz27kt/ l4sFediZl9YO6cQFoxum+2aEBBgB/oScdIPagSEAC/PP8WD5UD8PxmjjSVg2Xk/B9IIYIRw1 Ngth56BpLtTu0zvBzOEWZ3ivucQFXnqqpWFXQRMNi68+oWFmjW4ebB6+PA8O6o4zsOrPPAYW X+5nYHNLoyu8Mt4ogp3HUtzgQHu0OzRP5HnCuPGTXrA5rcQLFjcOecG039K84dihYW+Y3qsT w+p7LT4wo7bVt5vzKA97tHeh1aMRsghHj77fZOQ8akftHj14xch51A7O8ujiBqtH7dT/eXSa ntqWOAqk5u+M7Km7m7o6rfa8JWhgZ6L7hmXpP1uCupsR/eGefJOHIcVc473oxtvEusVjOWtO 93lcnjzaUbRn3btxwcDydXDxwLDxg8pvWfmShoiPVpav3fHashfV2yc2f0yVBfUH+HwSvyRE NfaV87NVpb+ecN0o0/btdl6/sH2Pe0C5xXP9JtUBCZ8Nlb21jFCzsv8A8B4sSV4IAAA= X-Spam-Status: No, score=4.9 X-Spam-Score: 49 X-Spam-Bar: ++++ X-Ham-Report: Spam detection software, running on the system "skandij.avalon.hr", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root@localhost for details. Content preview: Zdravo! Ja sam haker koji ima pristup vašem operativnom sustavu. Također imam puni pristup vašem računu. Promatram te već nekoliko mjeseci. Činjenica je da ste bili zaraženi zlonamjernim softverom pute [...] Content analysis details: (4.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit (jomi0004[at]comcast.net) -0.0 SPF_PASS SPF: sender matches SPF record 1.2 HTML_OBFUSCATE_10_20 BODY: Message is 10% to 20% HTML obfuscation 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 LOTS_OF_MONEY Huge... sums of money 1.0 BITCOIN_SPAM_04 BitCoin spam pattern 04 2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From 0.0 PDS_BTC_ID FP reduced Bitcoin ID X-Spam-Flag: NO

Reported on: 20th, Oct. 2019

Please help us keep Internet safer and cleaner by leaving a descriptive comment about 165.16.161.230 IP address


DNSBL* - is a list of IP addresses published through the Internet Domain Name Service (DNS) either as a zone file that can be used by DNS server software, or as a live DNS zone that can be queried in real-time. DNSBLs are most often used to publish the addresses of computers or networks linked to spamming; most mail server software can be configured to reject or flag messages which have been sent from a site listed on one or more such lists.

WHOIS** - is a query/response protocol that is widely used for querying databases in order to determine the registrant or assignee of Internet resources, such as a domain name, an IP address block, or an autonomous system number. WHOIS lookups were traditionally performed with a command line interface application, and network administrators predominantly still use this method, but many simplified web-based tools exist. WHOIS services are typically communicated using the Transmission Control Protocol (TCP). Servers listen to requests on the well-known port number 43.

** Approximate Geographic Location - This is NOT the exact geographical location of the person/organization with the given IP address. However, this should still give you a good idea about the area/region where this person/orgranization is located.