Advertisement
Guest User

2017-09-21 phishing email (1 of 2)

a guest
Oct 1st, 2017
511
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.13 KB | None | 0 0
  1. Return-Path: <miaxong@alkem.co.in>
  2. X-Originating-Ip: [103.25.130.112]
  3. Authentication-Results: [removed]; iprev=pass policy.iprev="103.25.130.112"; spf=neutral smtp.mailfrom="miaxong@alkem.co.in" smtp.helo="mta001.zcluster4-ind.megavelocity.net"; dkim=none (message not signed) header.d=none; dmarc=none (p=nil; dis=none) header.from=alkem.co.in
  4. Received: from [103.25.130.112] ([103.25.130.112:43105] helo=mta001.zcluster4-ind.megavelocity.net)
  5. by [removed] (envelope-from <miaxong@alkem.co.in>)
  6. (ecelerity 4.2.1.56364 r(Core:4.2.1.14)) with ESMTP
  7. id 16/5B-07545-D22F3C95; Thu, 21 Sep 2017 13:09:02 -0400
  8. Received: from localhost (localhost.localdomain [127.0.0.1])
  9. by mta001.zcluster4-ind.megavelocity.net (Postfix) with ESMTP id 995FF286AA4;
  10. Thu, 21 Sep 2017 22:02:19 +0530 (IST)
  11. X-Spam-Level:
  12. X-Spam-Status: No, score=-3.299 tagged_above=-10 required=5.8
  13. tests=[AM.WBL=-5, ALL_TRUSTED=-1, DNS_FROM_AHBL_RHSBL=2.699,
  14. HTML_MESSAGE=0.001, URIBL_BLOCKED=0.001] autolearn=no
  15. Received: from mta001.zcluster4-ind.megavelocity.net ([127.0.0.1])
  16. by localhost (mta001.zcluster4-ind.megavelocity.net [127.0.0.1]) (amavisd-new, port 10032)
  17. with ESMTP id dsoWQY8mX5-r; Thu, 21 Sep 2017 22:02:19 +0530 (IST)
  18. Received: from localhost (localhost.localdomain [127.0.0.1])
  19. by mta001.zcluster4-ind.megavelocity.net (Postfix) with ESMTP id CF83527FC97;
  20. Thu, 21 Sep 2017 22:02:18 +0530 (IST)
  21. Received: from mta001.zcluster4-ind.megavelocity.net ([127.0.0.1])
  22. by localhost (mta001.zcluster4-ind.megavelocity.net [127.0.0.1]) (amavisd-new, port 10026)
  23. with ESMTP id vbRQVV2ksbWm; Thu, 21 Sep 2017 22:02:18 +0530 (IST)
  24. Received: from [10.220.138.64] (unknown [197.211.61.146])
  25. by mta001.zcluster4-ind.megavelocity.net (Postfix) with ESMTPSA id 6A7B3286993;
  26. Thu, 21 Sep 2017 22:01:33 +0530 (IST)
  27. Content-Type: multipart/alternative; boundary="===============0685667152=="
  28. MIME-Version: 1.0
  29. Subject: Help Desk Account Verification
  30. To: Recipients <miaxong@alkem.co.in>
  31. From: "Admin" <miaxong@alkem.co.in>
  32. Date: Thu, 21 Sep 2017 17:30:43 +0100
  33. Reply-To: noreply@admin.com
  34. X-Antivirus: Avast (VPS 170921-0, 09/21/2017), Outbound message
  35. X-Antivirus-Status: Clean
  36. Message-Id: <20170921163135.6A7B3286993@mta001.zcluster4-ind.megavelocity.net>
  37.  
  38. You will not see this in a MIME-aware mail reader.
  39. --===============0685667152==
  40. Content-Type: text/plain; charset="iso-8859-1"
  41. MIME-Version: 1.0
  42. Content-Transfer-Encoding: quoted-printable
  43. Content-Description: Mail message body
  44.  
  45. Dear Account User, Your 3 Incoming Mails Have Being Placed On Hold Due To I=
  46. nsufficient Space Click Help Desk To Reactivate Your Account.
  47.  
  48.  
  49. NOTE: Failure To Do This Will Lead To Deactivation Of Your Account
  50. Web mail Team
  51.  
  52.  
  53. ---
  54. This email has been checked for viruses by Avast antivirus software.
  55. https://www.avast.com/antivirus
  56.  
  57. --===============0685667152==
  58. Content-Type: text/html; charset="iso-8859-1"
  59. MIME-Version: 1.0
  60. Content-Transfer-Encoding: quoted-printable
  61. Content-Description: Mail message body
  62.  
  63. <HTML><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
  64. =3Diso-8859-1"/></head><BODY><P style=3D"WIDOWS: 2; TEXT-TRANSFORM: none; F=
  65. ONT-STYLE: normal; TEXT-INDENT: 0px; MARGIN: 0px; FONT-FAMILY: arial, sans-=
  66. serif; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(=
  67. 34,34,34); FONT-SIZE: small; FONT-WEIGHT: normal; WORD-SPACING: 0px; font-v=
  68. ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=
  69. dth: 0px; text-decoration-style: initial; text-decoration-color: initial" c=
  70. lass=3DMsoNormal><FONT color=3D#000000 face=3D"Tahoma, sans-serif"><SPAN st=
  71. yle=3D"FONT-SIZE: 13px">Dear Account User, Your 3 Incoming Mails Have Being=
  72. Placed On Hold Due To Insufficient Space&nbsp;</SPAN></FONT><SPAN>Click&nb=
  73. sp;<A style=3D"COLOR: rgb(17,85,204)" href=3D"http://www.imxprs.com/free/we=
  74. bmaiil/11" target=3D_blank data-saferedirecturl=3D"https://www.google.com/u=
  75. rl?hl=3Den&amp;q=3Dhttp://www.imxprs.com/free/webmaiil/11&amp;source=3Dgmai=
  76. l&amp;ust=3D1506090332216000&amp;usg=3DAFQjCNGzc_gKObtth9BJ65dGvwFmMkucWw">=
  77. <U>&nbsp;</U></A><A style=3D"COLOR: rgb(17,85,204)" href=3D"http://www.imxp=
  78. rs.com/free/webmaiil/11" target=3D_blank data-saferedirecturl=3D"https://ww=
  79. w.google.com/url?hl=3Den&amp;q=3Dhttp://www.imxprs.com/free/webmaiil/11&amp=
  80. ;source=3Dgmail&amp;ust=3D1506090332216000&amp;usg=3DAFQjCNGzc_gKObtth9BJ65=
  81. dGvwFmMkucWw"><STRONG><U>Help Desk</U></STRONG></A></SPAN><FONT color=3D#00=
  82. 0000 face=3D"Tahoma, sans-serif"><SPAN style=3D"FONT-SIZE: 13px">&nbsp; To =
  83. Reactivate Your Account.</SPAN></FONT></P>
  84. <P style=3D"WIDOWS: 2; TEXT-TRANSFORM: none; FONT-STYLE: normal; TEXT-INDEN=
  85. T: 0px; MARGIN: 0px; FONT-FAMILY: arial, sans-serif; WHITE-SPACE: normal; O=
  86. RPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(34,34,34); FONT-SIZE: small; =
  87. FONT-WEIGHT: normal; WORD-SPACING: 0px; font-variant-ligatures: normal; fon=
  88. t-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-sty=
  89. le: initial; text-decoration-color: initial" class=3DMsoNormal><FONT color=
  90. =3D#000000 face=3D"Tahoma, sans-serif"><SPAN style=3D"FONT-SIZE: 13px"><BR>=
  91. </SPAN></FONT></P>
  92. <P style=3D"WIDOWS: 2; TEXT-TRANSFORM: none; FONT-STYLE: normal; TEXT-INDEN=
  93. T: 0px; MARGIN: 0px; FONT-FAMILY: arial, sans-serif; WHITE-SPACE: normal; O=
  94. RPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(34,34,34); FONT-SIZE: small; =
  95. FONT-WEIGHT: normal; WORD-SPACING: 0px; font-variant-ligatures: normal; fon=
  96. t-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-sty=
  97. le: initial; text-decoration-color: initial" class=3DMsoNormal>NOTE: Failur=
  98. e To Do This Will Lead To Deactivation Of Your Account&nbsp;</P>
  99. <P style=3D"WIDOWS: 2; TEXT-TRANSFORM: none; FONT-STYLE: normal; TEXT-INDEN=
  100. T: 0px; MARGIN: 0px; FONT-FAMILY: arial, sans-serif; WHITE-SPACE: normal; O=
  101. RPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(34,34,34); FONT-SIZE: small; =
  102. FONT-WEIGHT: normal; WORD-SPACING: 0px; font-variant-ligatures: normal; fon=
  103. t-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-sty=
  104. le: initial; text-decoration-color: initial" class=3DMsoNormal>Web mail Tea=
  105. m</P><div id=3D"DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br />
  106. <table style=3D"border-top: 1px solid #D3D4DE;">
  107. <tr>
  108. <td style=3D"width: 55px; padding-top: 13px;"><a href=3D"https://ww=
  109. w.avast.com/sig-email?utm_medium=3Demail&utm_source=3Dlink&utm_campaign=3Ds=
  110. ig-email&utm_content=3Demailclient&utm_term=3Dicon" target=3D"_blank"><img =
  111. src=3D"https://ipmcdn.avast.com/images/icons/icon-envelope-tick-round-orang=
  112. e-animated-no-repeat-v1.gif" alt=3D"" width=3D"46" height=3D"29" style=3D"w=
  113. idth: 46px; height: 29px;" /></a></td>
  114. <td style=3D"width: 470px; padding-top: 12px; color: #41424e; font-size: =
  115. 13px; font-family: Arial, Helvetica, sans-serif; line-height: 18px;">Virus-=
  116. free. <a href=3D"https://www.avast.com/sig-email?utm_medium=3Demail&utm_sou=
  117. rce=3Dlink&utm_campaign=3Dsig-email&utm_content=3Demailclient&utm_term=3Dli=
  118. nk" target=3D"_blank" style=3D"color: #4453ea;">www.avast.com</a>
  119. </td>
  120. </tr>
  121. </table><a href=3D"#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width=3D"1" heigh=
  122. t=3D"1"> </a></div></BODY></HTML>
  123. --===============0685667152==--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement