Advertisement
wavellan

20230326_PHISHING_SCAM_1

Mar 29th, 2023
97
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.54 KB | None | 0 0
  1. Top of the day to you, I'm Yuliia Kadulina Deputy Chairman of the Management Board, and Personal Finance Director @ Ukrsibbank Ukraine. I have a proposal for you. Kindly revert so I can fill you in on the details.
  2. Thanks,
  3. Yuliia
  4.  
  5.  
  6.  
  7.  
  8. Received: from DS0PR05MB9173.namprd05.prod.outlook.com (::1) by
  9. MWHPR0501MB3899.namprd05.prod.outlook.com with HTTPS; Sun, 26 Mar 2023
  10. 08:18:25 +0000
  11. Received: from BN8PR12CA0007.namprd12.prod.outlook.com (2603:10b6:408:60::20)
  12. by DS0PR05MB9173.namprd05.prod.outlook.com (2603:10b6:8:c7::16) with
  13. Microsoft SMTP Server (version=TLS1_2,
  14. cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6156.28; Sun, 26 Mar
  15. 2023 08:18:23 +0000
  16. Received: from BN8NAM12FT088.eop-nam12.prod.protection.outlook.com
  17. (2603:10b6:408:60:cafe::46) by BN8PR12CA0007.outlook.office365.com
  18. (2603:10b6:408:60::20) with Microsoft SMTP Server (version=TLS1_2,
  19. cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6178.41 via Frontend
  20. Transport; Sun, 26 Mar 2023 08:18:23 +0000
  21. Authentication-Results: spf=pass (sender IP is 201.163.109.235)
  22. smtp.mailfrom=tresguerras.com.mx; dkim=pass (signature was verified)
  23. header.d=tresguerras.com.mx;dmarc=pass action=none
  24. header.from=tresguerras.com.mx;compauth=pass reason=100
  25. Received-SPF: Pass (protection.outlook.com: domain of tresguerras.com.mx
  26. designates 201.163.109.235 as permitted sender)
  27. receiver=protection.outlook.com; client-ip=201.163.109.235;
  28. helo=proxqmail.tresguerras.com.mx; pr=C
  29. Received: from proxqmail.tresguerras.com.mx (201.163.109.235) by
  30. BN8NAM12FT088.mail.protection.outlook.com (10.13.182.177) with Microsoft SMTP
  31. Server id 15.20.6254.9 via Frontend Transport; Sun, 26 Mar 2023 08:18:22
  32. +0000
  33. Received: from proxqmail.tresguerras.com.mx (localhost [127.0.0.1])
  34. by proxqmail.tresguerras.com.mx (Proxmox) with ESMTP id 997766628F3;
  35. Sun, 26 Mar 2023 02:18:19 -0600 (CST)
  36. Received: from qmail.tresguerras.com.mx (unknown [10.10.10.153])
  37. by proxqmail.tresguerras.com.mx (Proxmox) with ESMTP id 890DF6628BB;
  38. Sun, 26 Mar 2023 02:18:19 -0600 (CST)
  39. Received: from localhost (localhost [127.0.0.1])
  40. by qmail.tresguerras.com.mx (Postfix) with ESMTP id 6B5711182F2A;
  41. Sun, 26 Mar 2023 02:18:19 -0600 (CST)
  42. Received: from qmail.tresguerras.com.mx ([127.0.0.1])
  43. by localhost (qmail.tresguerras.com.mx [127.0.0.1]) (amavisd-new, port 10032)
  44. with ESMTP id tM6Is6nclbLB; Sun, 26 Mar 2023 02:18:19 -0600 (CST)
  45. Received: from localhost (localhost [127.0.0.1])
  46. by qmail.tresguerras.com.mx (Postfix) with ESMTP id 61CB41182EA6;
  47. Sun, 26 Mar 2023 02:18:18 -0600 (CST)
  48. DKIM-Filter: OpenDKIM Filter v2.10.3 qmail.tresguerras.com.mx 61CB41182EA6
  49. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tresguerras.com.mx;
  50. s=548874FC-8C77-11ED-ACE0-6A993FC05161; t=1679818698;
  51. bh=HnrsNpx4H1tZ0Br9KYGCCBo+Y2+iROYDuFUNEVbBnWU=;
  52. h=Date:From:Message-ID:MIME-Version;
  53. b=igoOGDUAjRYXCzt7eknWRFA07w4SvOsQ8/n1nT7zGzMixJEG7YoLxNuLKacU0NQTz
  54. RMN5V0LFikxAWNSU6LeBi6C4L31Fj1lZwnB7eZC91hD/15XFB7Gfca9ck9kMTxfmY9
  55. gI03rFtnhIurARUxP/xvKUPQH4CfzzToGydcOACLHPl4qrfsNUPlgRdvY2d71d8dJt
  56. jcxhcc0LKWSWeTQk0MC8C4B7OfNEOcRCGdwgVGymxe226NikXbI6xiibsrJRPfLWuv
  57. h6uEJZs96/mxR5m5CyJgOizaejmv8wq3ER371JpoSqzM1pxdD7mV9eIK08liAn6VZ4
  58. +rmBdQWY4mZmQ==
  59. X-Virus-Scanned: amavisd-new at tresguerras.com.mx
  60. Received: from qmail.tresguerras.com.mx ([127.0.0.1])
  61. by localhost (qmail.tresguerras.com.mx [127.0.0.1]) (amavisd-new, port 10026)
  62. with ESMTP id ULnvHRTsDCzU; Sun, 26 Mar 2023 02:18:18 -0600 (CST)
  63. Received: from qmail.tresguerras.com.mx (qmail.tresguerras.com.mx [10.10.10.153])
  64. by qmail.tresguerras.com.mx (Postfix) with ESMTP id EB1A61182E50;
  65. Sun, 26 Mar 2023 02:18:16 -0600 (CST)
  66. Date: Sun, 26 Mar 2023 02:18:16 -0600 (CST)
  67. From: Yuliia Kadulina <[email protected]>
  68. Reply-To: Yuliia Kadulina <[email protected]>
  69. Message-ID: <1022957916.10530756.1679818696917.JavaMail.zimbra@tresguerras.com.mx>
  70. Subject: Ps rply!
  71. MIME-Version: 1.0
  72. X-Originating-IP: [10.10.10.153]
  73. X-Mailer: Zimbra 8.8.15_GA_4484 (zclient/8.8.15_GA_4484)
  74. Thread-Index: 7clGjkTb9uryrKBRmFOTsuwwJbSmEw==
  75. Thread-Topic: Ps rply!
  76. To: Undisclosed recipients:;
  77. Return-Path: [email protected]
  78. X-MS-Exchange-Organization-ExpirationStartTime: 26 Mar 2023 08:18:22.5948
  79. (UTC)
  80. X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
  81. X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
  82. X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
  83. X-MS-Exchange-Organization-Network-Message-Id:
  84. fb38986e-a01c-4dc6-e12a-08db2dd2aa42
  85. X-EOPAttributedMessage: 0
  86. X-EOPTenantAttributedMessage: 0d4bfd0a-5b8b-4c86-b245-3f11f8ea539a:0
  87. X-MS-Exchange-Organization-MessageDirectionality: Incoming
  88. X-MS-PublicTrafficType: Email
  89. X-MS-TrafficTypeDiagnostic: BN8NAM12FT088:EE_|DS0PR05MB9173:EE_
  90. X-MS-Exchange-Organization-AuthSource:
  91. BN8NAM12FT088.eop-nam12.prod.protection.outlook.com
  92. X-MS-Exchange-Organization-AuthAs: Anonymous
  93. X-MS-Office365-Filtering-Correlation-Id: fb38986e-a01c-4dc6-e12a-08db2dd2aa42
  94. X-MS-Exchange-Organization-SCL: 5
  95. X-Forefront-Antispam-Report:
  96. CIP:201.163.109.235;CTRY:MX;LANG:en;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:proxqmail.tresguerras.com.mx;PTR:qmail.tresguerras.com.mx;CAT:SPM;SFS:(13230028)(451199021)(109986019)(36756003)(22186003)(1096003)(5660300002)(83380400001)(7696005)(426003)(120186005)(26005)(336012)(58800400005)(2860700004)(2616005)(8676002)(6266002)(7636003)(7116003)(86362001)(356005)(33964004)(3480700007)(4300700001)(17300700004);DIR:INB;
  97. X-Microsoft-Antispam: BCL:0;
  98. X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Mar 2023 08:18:22.3605
  99. (UTC)
  100. X-MS-Exchange-CrossTenant-Network-Message-Id: fb38986e-a01c-4dc6-e12a-08db2dd2aa42
  101. X-MS-Exchange-CrossTenant-Id: 0d4bfd0a-5b8b-4c86-b245-3f11f8ea539a
  102. X-MS-Exchange-CrossTenant-AuthSource:
  103. BN8NAM12FT088.eop-nam12.prod.protection.outlook.com
  104. X-MS-Exchange-CrossTenant-AuthAs: Anonymous
  105. X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
  106. X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS0PR05MB9173
  107. X-MS-Exchange-Transport-EndToEndLatency: 00:00:03.6423555
  108. X-MS-Exchange-Processed-By-BccFoldering: 15.20.6178.041
  109. X-Microsoft-Antispam-Mailbox-Delivery:
  110. ucf:0;jmr:0;auth:0;dest:J;OFR:SpamFilterAuthJ;ENG:(910001)(944506478)(944626604)(920097)(930097)(3100021);RF:JunkEmail;
  111. X-Microsoft-Antispam-Message-Info:
  112.  
  113. Content-type: multipart/alternative;
  114. boundary="B_3762942763_2060836812"
  115.  
  116. > This message is in MIME format. Since your mail reader does not understand
  117. this format, some or all of this message may not be legible.
  118.  
  119. --B_3762942763_2060836812
  120. Content-type: text/plain;
  121. charset="UTF-8"
  122. Content-transfer-encoding: 7bit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement