Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- This malware laced e-mail contains a file called Video.zip:
- https://www.virustotal.com/gui/file/4a4af0c317db9027a4461ea42fbd799d53f1330c572bd69518bc45e77b7fde1d/detection
- Watch the attached video of your so called friend saying horrible things about you. After this you should mind who you trust and what you say around people.
- if you want more details dont hesitate to write me . take heart.
- you can call me Henry.
- Received: from MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) by
- MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2 via Mailbox Transport; Thu, 4 Feb 2021 11:18:22 -0600
- Received: from MBX03C-ORD1.mex08.mlsrvr.com (172.29.9.17) by
- MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2; Thu, 4 Feb 2021 11:18:22 -0600
- Received: from gate.forward.smtp.ord1c.emailsrvr.com (108.166.43.128) by
- MBX03C-ORD1.mex08.mlsrvr.com (172.29.9.17) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2 via Frontend Transport; Thu, 4 Feb 2021 11:18:22 -0600
- Return-Path: <[email protected]>
- X-Spam-Threshold: 95
- X-Spam-Score: 0
- X-Spam-Flag: NO
- X-Virus-Scanned: OK
- X-Orig-To:
- X-Originating-Ip: [207.194.236.18]
- Authentication-Results: smtp18.gate.ord1c.rsapps.net; iprev=pass policy.iprev="207.194.236.18"; spf=pass smtp.mailfrom="[email protected]" smtp.helo="mail.mottelectric.com"; dkim=none (message not signed) header.d=none; dmarc=pass (p=none; dis=none) header.from=mottelectric.com
- X-Suspicious-Flag: NO
- X-Classification-ID: fb469658-670c-11eb-aef7-bc305bf00c68-1-1
- Received: from [207.194.236.18] ([207.194.236.18:4485] helo=mail.mottelectric.com)
- by smtp18.gate.ord1c.rsapps.net (envelope-from <[email protected]>)
- (ecelerity 4.2.38.62370 r(:)) with ESMTP
- id F8/F4-12733-D5C2C106; Thu, 04 Feb 2021 12:18:22 -0500
- Received: from MOTTMAIL03.mott.local (192.168.0.77) by MOTTMAIL03.mott.local
- (192.168.0.77) with Microsoft SMTP Server (version=TLS1_2,
- cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.529.5; Thu, 4 Feb 2021
- 09:18:20 -0800
- Received: from MOTTMAIL03.mott.local ([fe80::acc7:9f5d:e56f:c535]) by
- MOTTMAIL03.mott.local ([fe80::acc7:9f5d:e56f:c535%11]) with mapi id
- 15.02.0529.008; Thu, 4 Feb 2021 09:18:20 -0800
- From: Henry Siemens <[email protected]>
- To: "[email protected]" <[email protected]>
- Subject: video
- Thread-Topic: video
- Thread-Index: AQHW+xin1M/OXJY8nEa1jidfGudiRQ==
- Date: Thu, 4 Feb 2021 17:10:35 +0000
- Message-ID: <[email protected]>
- Accept-Language: en-US, en-CA
- Content-Language: en-US
- X-MS-Has-Attach: yes
- X-MS-TNEF-Correlator:
- MIME-Version: 1.0
- X-MS-Exchange-Organization-Network-Message-Id: fff99643-fb7f-4296-28ea-08d8c930dfe2
- X-MS-Exchange-Organization-AuthSource: MBX03C-ORD1.mex08.mlsrvr.com
- X-MS-Exchange-Organization-AuthAs: Anonymous
- Content-type: multipart/mixed;
- boundary="B_3695447588_803671167"
- > This message is in MIME format. Since your mail reader does not understand
- this format, some or all of this message may not be legible.
- --B_3695447588_803671167
- Content-type: multipart/alternative;
- boundary="B_3695447588_843012626"
- --B_3695447588_843012626
- Content-type: text/plain;
- charset="UTF-8"
- Content-transfer-encoding: 7bit
Add Comment
Please, Sign In to add comment