Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Received: from PUYP216MB3089.KORP216.PROD.OUTLOOK.COM (2603:1096:301:155::7)
- by SE1P216MB1303.KORP216.PROD.OUTLOOK.COM with HTTPS; Sat, 24 May 2025
- 15:06:31 +0000
- Received: from DB9PR06CA0028.eurprd06.prod.outlook.com (2603:10a6:10:1db::33)
- by PUYP216MB3089.KORP216.PROD.OUTLOOK.COM (2603:1096:301:155::7) with
- Microsoft SMTP Server (version=TLS1_2,
- cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8769.24; Sat, 24 May
- 2025 15:06:29 +0000
- Received: from DB1PEPF000509EF.eurprd03.prod.outlook.com
- (2603:10a6:10:1db:cafe::90) by DB9PR06CA0028.outlook.office365.com
- (2603:10a6:10:1db::33) with Microsoft SMTP Server (version=TLS1_3,
- cipher=TLS_AES_256_GCM_SHA384) id 15.20.8746.29 via Frontend Transport; Sat,
- 24 May 2025 15:06:28 +0000
- Authentication-Results: spf=pass (sender IP is 159.183.181.112)
- smtp.mailfrom=em4475.colocrossing.com; dkim=pass (signature was verified)
- header.d=colocrossing.com;dmarc=pass action=none
- header.from=colocrossing.com;compauth=pass reason=100
- Received-SPF: Pass (protection.outlook.com: domain of em4475.colocrossing.com
- designates 159.183.181.112 as permitted sender)
- receiver=protection.outlook.com; client-ip=159.183.181.112;
- helo=wfbtbrth.outbound-mail.sendgrid.net; pr=C
- Received: from wfbtbrth.outbound-mail.sendgrid.net (159.183.181.112) by
- DB1PEPF000509EF.mail.protection.outlook.com (10.167.242.73) with Microsoft
- SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.8769.18
- via Frontend Transport; Sat, 24 May 2025 15:06:27 +0000
- X-IncomingTopHeaderMarker: OriginalChecksum:1152656A0887CFEA928894AB19FC21151C74C18764C6DD1EED07FB6C7254D7D0;UpperCasedChecksum:8DB8940A8ACFFDC646B4FBC432C0C7C2959A57816C6A1D7004EA8EEB27DA7AC9;SizeAsReceived:2127;Count:15
- DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=colocrossing.com;
- h=from:subject:mime-version:reply-to:to:content-type:
- content-transfer-encoding:cc:content-type:from:subject:to;
- s=s1; bh=FtewHVEmfuF90DkaSRWSrbtofCl0YU/cxfFiH9T7Dg0=;
- b=b6kWQGKXYZgIoditrvM95opaLFFJJ2XX5lstkRFRXMr8uH6xqxwFVDTVSFWP8XMVuwve
- 4sGz2rJk8ruuX40CEO3sPLM+QJKfVEdOVBkpmY0rYwmHHq2b5cShsA/eDE4vzhZeID6lmJ
- p3PMc6CmKZohJmbN4vbBSCnkncgrk7GivM4uW5P6OHCskEK+lIXI+1GSeR6RnutnztafY4
- 03A/Ud2stk5+QsYqpWD3B1paSMpMZCXnp4WnoNKy+6rwf+2JSUaXiA/kFgXlh3AoJ7AsEL
- itjp6NM87j1EKFg/6vaa7Dq9glYeatgQsa+LmBUSLVndiH9zV4/rrziq0JvakiAA==
- Received: by recvd-65f9dd5795-kx7sf with SMTP id recvd-65f9dd5795-kx7sf-1-6831E072-85
- 2025-05-24 15:06:26.432241273 +0000 UTC m=+3949055.074353352
- Received: from virt (unknown)
- by geopod-ismtpd-25 (SG) with ESMTP
- id 3Y_H1oLJSBedwV7enogr1w
- for <MY PERSONAL EMAIL>;
- Sat, 24 May 2025 15:06:26.329 +0000 (UTC)
- Date: Sat, 24 May 2025 15:06:26 +0000
- From: Formal notification of system breaches in ColoCrossing infrastructure -
- demanding immediate action <[email protected]>
- Subject: Formal notification of system breaches in ColoCrossing infrastructure
- - demanding immediate action
- Message-ID: <ByR4HjoAsb3obIdgbSXOc78scbn7cP2F7B6PVW7k4c@virt>
- X-Mailer: SOFTACULOUS PHP/7.4.33
- Reply-To: [email protected]
- X-SG-EID: =?us-ascii?Q?u001=2EtESY9Cei0tOW=2FTH3Eip40b10ePUmuB5VSJQofg1+Eu6cN3+w6Q0bMloe9?=
- =?us-ascii?Q?n8QGhsNDuH0HDtx5Jdqn+DJeQefApAx5xyi7zn0?=
- =?us-ascii?Q?RPTUJz=2FfNGnhSDUCesO2ZgomHExVTclWuszKOPb?=
- =?us-ascii?Q?ZX1qIj15j30X2=2FPVuiwZ=2FZsa5L8yIaGTEIi824Z?=
- =?us-ascii?Q?3zTygIuPy3BF8YprBz2C0jGz77Pa987eiSsOamw?=
- =?us-ascii?Q?4pdBv5L4yQnV0HkI+Bs67wLMW7UkqXjNXg+qZD0?=
- =?us-ascii?Q?fGw68mBoo4RYDNaCADV4IC6h+Q3YLmsQujsY58v?=
- =?us-ascii?Q?d1KQRwNr9mdmflbqxOPbhbHVcET+HOIjpXv13Mx?=
- =?us-ascii?Q?Cqvn4AkwAEgFkPnkbODnaWyA=2FaFU9y3kQ=3D?=
- To: [MY PERSONAL EMAIL]
- X-Entity-ID: u001.7fQXO4F81G404jANlesL4w==
- Content-Type: multipart/alternative;
- boundary="b1_ByR4HjoAsb3obIdgbSXOc78scbn7cP2F7B6PVW7k4c"
- Content-Transfer-Encoding: 8bit
- X-IncomingHeaderCount: 15
- Return-Path: bounces+26807539-c34f-PERSONAL [email protected]
- X-MS-Exchange-Organization-ExpirationStartTime: 24 May 2025 15:06:28.0098
- (UTC)
- X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
- X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
- X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
- X-MS-Exchange-Organization-Network-Message-Id: 1f0cd954-bd60-46a0-347e-08dd9ad48f0b
- X-EOPAttributedMessage: 0
- X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
- X-MS-Exchange-Organization-MessageDirectionality: Incoming
- X-MS-PublicTrafficType: Email
- X-MS-TrafficTypeDiagnostic: DB1PEPF000509EF:EE_|PUYP216MB3089:EE_|SE1P216MB1303:EE_
- X-MS-Exchange-Organization-AuthSource: DB1PEPF000509EF.eurprd03.prod.outlook.com
- X-MS-Exchange-Organization-AuthAs: Anonymous
- X-MS-UserLastLogonTime: 5/24/2025 3:04:14 PM
- X-MS-Office365-Filtering-Correlation-Id: 1f0cd954-bd60-46a0-347e-08dd9ad48f0b
- X-MS-Exchange-EOPDirect: true
- X-Sender-IP: 159.183.181.112
- X-SID-PRA: [email protected]
- X-SID-Result: PASS
- X-MS-Exchange-Organization-SCL: 1
- X-Microsoft-Antispam: BCL:0;ARA:1444111002|10300799035|9400799033|21080799006|461199028|13082799006|440099028|3412199025|4302099013|22062799003|1122599019|1360799030|1380799030|1370799030|1602099012;
- X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 May 2025 15:06:27.5653
- (UTC)
- X-MS-Exchange-CrossTenant-Network-Message-Id: 1f0cd954-bd60-46a0-347e-08dd9ad48f0b
- X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
- X-MS-Exchange-CrossTenant-AuthSource: DB1PEPF000509EF.eurprd03.prod.outlook.com
- X-MS-Exchange-CrossTenant-AuthAs: Anonymous
- X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
- X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
- X-MS-Exchange-Transport-CrossTenantHeadersStamped: PUYP216MB3089
- X-MS-Exchange-Transport-EndToEndLatency: 00:00:04.0114163
- X-MS-Exchange-Processed-By-BccFoldering: 15.20.8769.014
- X-Microsoft-Antispam-Mailbox-Delivery:
- wl:1;pcwl:1;ucf:0;jmr:0;ex:0;auth:1;dest:I;OFR:TrustedSenderList;ENG:(5062000308)(920221119095)(90000117)(920221120095)(90012020)(91020020)(91040095)(9050020)(9100341)(944500132)(2008001181)(4810010)(4910033)(9575002)(10195002)(9439006)(9310011)(9220031)(120001);
- X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MTtHRD0xO1NDTD0tMQ==
- X-Microsoft-Antispam-Message-Info:
- =?us-ascii?Q?K9vgs3sypAZBYUUlNPWENMXNurkuCGugwWtZH+Qy+WNT43PonhI+5EEyIFvk?=
- =?us-ascii?Q?3kI+sRlOrw9/WtoewDN+oHqjpzYYVPVYAsCbHerFjkPVO/VHWcZ+OF97u8Rq?=
- =?us-ascii?Q?LAQAbyI/bt5lBvRBBMAB3Y1beUpTgActu9LUxxr7uuEP0RwTGoEcOlrAIU3g?=
- =?us-ascii?Q?pBGbKtXYTf+rzzfJBHfEmgQNQ8b2ZtM2ZfKjkUkfA/wrLqK0cFc07C0sJT6e?=
- =?us-ascii?Q?XeojYlaQSy1PNuI7KR7dRFGaMdmTx67fFo3WC+fJ+6f4Xc7/5Vfc7tBpuVeI?=
- =?us-ascii?Q?WTnIpd1sVmKo6uTfHfM35kdkBXAI9MVde1dKGE45gPzXN33v1iQ1RVFwwUQX?=
- =?us-ascii?Q?8/2PNs/+pGzQvW52Up9mRGom/Sv/+p6YhU8DQYhHskvqmlh6lJNY1w3qBDyN?=
- =?us-ascii?Q?yoq8ihtRiIkxTB3nzNk/oUfZ21vjcqaE0rsvJ/ye8nZYCGcHgiTXH62S0Puy?=
- =?us-ascii?Q?YwuZllBYy6JE/gKhobhVSuSjyPJxDv1wOIDwY2klT3sHyv9reyc2qXqOAe1i?=
- =?us-ascii?Q?gi7F/jkYuHchr1wKE5wvGt6vh0ojIImjw3g83K3JaMtIaSTYHLEVTEIL7YG/?=
- =?us-ascii?Q?Hk41pd06g3tkbVR/5NXsEo9uSQXxE6MDhuNCa0Ru9JZlHj9d04inqHrb1o1t?=
- =?us-ascii?Q?WI04MrKW7liWA063Gby+o6Uq0+/eyY72nmkz3NsI6fuBZcrOrIspwZl3AJv3?=
- =?us-ascii?Q?DAzfNakpD8qF4zZjK9bB3ZS5RMAJ2jqH/Uiz86KLOOn+adkIiu4o9MFz7hfC?=
- =?us-ascii?Q?5JP9/SxJrCGpGywCOF/eoaz1AgCTpg9f3lbo0N/8N0QDbW/uVzDeRYVpoBY2?=
- =?us-ascii?Q?Tq1E+Ps/PFOv9toAb9XtjLlq+zecO3SeBfa6r7k1fzVP6Wn0t9CM0KId1bxl?=
- =?us-ascii?Q?wRs01amC4YfWvHjAsfX1JkHoyuEVpYGa8PBupFDuMcfEzuCsgfX79Kjl3ftN?=
- =?us-ascii?Q?PHMKyG/Dtpgs6P3/oE6kb93N5gJELJ5XbaN9FjYCmZ+D+3xGeDcfGZ+wp+VJ?=
- =?us-ascii?Q?MlAmWd+EXHcNxW02zZ4mRRbvX5c/VoDa5/kgLTcga0kbg/cyQ70/1GOK32wt?=
- =?us-ascii?Q?s5ohuRRD07uI8VCeKD3BVpIML7Y0VUoxGCm9pbvYICo8NLVZPV0TD9+lX4Vt?=
- =?us-ascii?Q?R4KXbG6xZ2WhYSPSfz+yVZ1P83i09JfnQktmEmuki2ACm7DkXLwHVMGHq7U0?=
- =?us-ascii?Q?CSapKSbNUW3Hz9QXXWSWIjqZ1B1AHGQMEEZTFa68CqX5/Yr+F6yQbQ0n/F9/?=
- =?us-ascii?Q?rYrkQhqmplo8qZMB2wL7zEKe7nuy3TQirnqyw7OGgZIi3DPrnc7jjB8TNzlD?=
- =?us-ascii?Q?jo0ymG6lBzmmE2lgj3AI8DyFi3V1m9QdwUOL8Lu9qtfJmEYM5n1QCqoDdvR4?=
- =?us-ascii?Q?rfva+npw2qokoVuxtqIEduyd5CizcOVuIL+pnVusf7pjWZwDnd7C8ykemZx0?=
- =?us-ascii?Q?4jBCcbGM2sQIIIlJlvB9MgrwNMcfDcn+36CucHFBi1idVQbPmSKVAVIEwWV/?=
- =?us-ascii?Q?kDc6MffBhmQlNG0+RM+GhnPdtFBf6KH5jdnJlnR2Az31Xkrg6D6ZS+aoOjkn?=
- =?us-ascii?Q?dbKFAcQRrV5LjaVwZ2NBjRuId7LLbIYzUOQHN2RXDnwhYmUNyDkXQsBT/+Xk?=
- =?us-ascii?Q?6BcvBTzQ5Wdc1iOzbvqIV3LmDEhqNOUSZ1V2Fy7wAu8TLS4pLRuJrgBmwIRc?=
- =?us-ascii?Q?9H09kBNnlUE5ILKJXMtSj9QAYe4Bi03M+xeBwA5pFfW3YdRlxedcgSpJoA4L?=
- =?us-ascii?Q?WwVi5wEBGHmvPWn1Vnl5VKtyAlDEksuQnsm5p7WksyjPHaVuv3h2k6Qm+FES?=
- =?us-ascii?Q?z5yoC/mLkoFlDs5KmRvEKzWsMeTR3zHmv0wRbkTxCk/FE4lYaKrpTtiWTpYP?=
- =?us-ascii?Q?Q69qIcqq5x2Od7LijiiRfW/vhL3nZvqk8ddvLZA/FNHBDdSkeBTVbIV/k7pT?=
- =?us-ascii?Q?UIK/FLc9b69SlOLCdXXxHGhOuRirBKS12ROlTaz2DdilRiV13f1rOKeFlOhE?=
- =?us-ascii?Q?SjJqfQWvCHvRHrcxLlrY/w4566y6k+NTJZKl8bgfREFA/nHvy4cKB7Ekw/8Z?=
- =?us-ascii?Q?+1A9Cz5teAr7pAQ/P2K4u/jZfhob8kbEZMYLzCH/xUsvonDl/25L83b0Bz9Q?=
- =?us-ascii?Q?aFHllY8GOuxYBg2YXh9qNw/D6Qun0N8yMIN0TboLaKjXJWoX8mlaw8yA8LTD?=
- =?us-ascii?Q?x0xcnf1clZCpfnrns218B1MveVsZ3V7kXrn0RyA3PumBWmRMtWCB6PE0dwoi?=
- =?us-ascii?Q?gV5qNZjZdhzH5oGJDlCCbEyciUOz9VN9anL0YksTwwkvLwKVIKL26CpueJr7?=
- =?us-ascii?Q?Rt99jQCNhX+N8wJ2kElHF4aApjc5qwQXW7kHjDQHbZzHvCyyDx5DHijL+o2l?=
- =?us-ascii?Q?OYL8cLLiGf3MNSK5/c8Hgh7IgowFTTjf8cYKGz3Lhzb4+h0qTuqnvBnRZSss?=
- =?us-ascii?Q?n8q7Jakl/4k=3D?=
- MIME-Version: 1.0
- --b1_ByR4HjoAsb3obIdgbSXOc78scbn7cP2F7B6PVW7k4c
- Content-Type: text/plain; charset=iso-8859-1
- Content-Transfer-Encoding: 8bit
- Dear representatives of ColoCrossing administration and users of hosting services,
- We hereby inform you of documented facts that testify to gross violations in the operation of your infrastructure:
- 1. Illegal content and lack of moderation- Numerous instances of:* Deepfake content using images of public figures and private citizens* Content that violates legislation on the protection of minors* Extremist and violent content.
- 2. Critical security vulnerabilities- Multiple attack vectors have been identified that allow:* Gain unauthorized root access to client servers* Bypass authentication and authorization systems
- 3. Misuse of infrastructure for illegal purposes- There are cases of exploitation of your resources for:* Organizing botnets and distributing malware* Providing anonymization of illegal activities via Tor-nodes, as well as XRay/WireGuard/X-UI/OpenVPN protocols.
- Requirements for the administration of ColoCrossing, as well as users who have stored such content:- Contact us- Pay us for our silence so that we don't hand over logs/emails/ip addresses and other information proving violations.- Resolve problems with similar content, we can help with this for an additional fee.
- User Recommendations:Until confirmation that the above violations have been remedied, we strongly recommend that you refrain from:- Storing sensitive data on the platform- Conducting financial transactions through ColoCrossing as well as HostPapa Inc. services.- Using hosting services for mission-critical projects
- To confirm remediation of breaches and for more information:Telegram: https://u26807539.ct.sendgrid.net/ls/click?upn=u001.ybbkgpTuDk3WhCBcxHXUDRUbBt1NTM1LkEA-2Fs3JaxDmBPAjQu-2Bh6t-2BKzZUapYePV8g2-2Fxn1RhHKI-2Bp76LtzKi2MNb4-2BHlh0b2hVDNgkJLe8-3D3AIf_EReLYMw1Orpd5wPsC43nsVpbTwYDDaJS7sjiZMA2X9IVCfzs3MZPVHb8bNuw-2B-2B4qLIDaLxZJ08mxgPLJKGNRPSFCmuTSSgVHnVEuDPzS5q8CCMwp3Cf1kS6N4hwA3EawDBv6oM0pT2QYVTWtbHgqtvbTy1QDMXSCEMXIyz1jp4kSkor0rq-2BoQd2N3Fk3T4G09MdIYt0V1ynaa9NdjiZI5A-3D-3D https://u26807539.ct.sendgrid.net/ls/click?upn=u001.ybbkgpTuDk3WhCBcxHXUDRUbBt1NTM1LkEA-2Fs3JaxDkR2ysecaKUOLscByrTkhn9FRZw_EReLYMw1Orpd5wPsC43nsVpbTwYDDaJS7sjiZMA2X9IVCfzs3MZPVHb8bNuw-2B-2B4qYyccZoacvV5FdNazZab07ybSl7R7PYQuDqsUp4saSVa96OO6RYY8asmBnWhH7GQFZeAjYBEKuROAwjXGGh3mlSPM7KOqDyHbylVR361Mz3ZRyoQGHy3h3xxYGxbgPyGzoEIjoTaxFSKuew7a3MVnJQ-3D-3D
- Please note that in the absence of an adequate response within the established timeframe, a full whistleblowing procedure will be initiated to inform all stakeholders of the identified violations, including:- Regulators of relevant jurisdictions- Media- Professional community
- --b1_ByR4HjoAsb3obIdgbSXOc78scbn7cP2F7B6PVW7k4c
- Content-Type: text/html; charset=us-ascii
- Content-Transfer-Encoding: 7bit
- <meta http-equiv="Content-Type" content="text/html; charset=us-ascii"><p>Dear representatives of ColoCrossing administration and users of hosting services,</p>
- <p>We hereby inform you of documented facts that testify to gross violations in the operation of your infrastructure:</p>
- <p><strong>1. Illegal content and lack of moderation</strong><br>- Numerous instances of:<br>* Deepfake content using images of public figures and private citizens<br>* Content that violates legislation on the protection of minors<br>* Extremist and violent content.</p>
- <p><strong>2. Critical security vulnerabilities</strong><br>- Multiple attack vectors have been identified that allow:<br>* Gain unauthorized root access to client servers<br>* Bypass authentication and authorization systems</p>
- <p><strong>3. Misuse of infrastructure for illegal purposes</strong><br>- There are cases of exploitation of your resources for:<br>* Organizing botnets and distributing malware<br>* Providing anonymization of illegal activities via Tor-nodes, as well as XRay/WireGuard/X-UI/OpenVPN protocols.</p>
- <p><strong>Requirements for the administration of ColoCrossing, as well as users who have stored such content:</strong><br>- Contact us<br>- Pay us for our silence so that we don't hand over logs/emails/ip addresses and other information proving violations.<br>- Resolve problems with similar content, we can help with this for an additional fee.</p>
- <p><strong>User Recommendations:</strong><br>Until confirmation that the above violations have been remedied, we strongly recommend that you refrain from:<br>- Storing sensitive data on the platform<br>- Conducting financial transactions through ColoCrossing as well as HostPapa Inc. services.<br>- Using hosting services for mission-critical projects</p>
- <p>To confirm remediation of breaches and for more information:<br>Telegram: <a href="https://u26807539.ct.sendgrid.net/ls/click?upn=u001.ybbkgpTuDk3WhCBcxHXUDRUbBt1NTM1LkEA-2Fs3JaxDkR2ysecaKUOLscByrTkhn9LImu_EReLYMw1Orpd5wPsC43nsVpbTwYDDaJS7sjiZMA2X9IVCfzs3MZPVHb8bNuw-2B-2B4qfRUH6-2FuoMnkXoTzT5c1njtwAVtzAqaqhic0MBjUYpxsUAA-2BqZ0iRyQKko7bVC3Q7jchtOp-2FF7jLLQkFGnZ6RpJrTPcvTWg1XScfeyIcloDrEXdmt1dSuRXZOuRl9WI3SgjCjSpLWKvZsAGUqpBNEIA-3D-3D">https://t.me/ransombotbot<br>Telegram: https://t.me/ransombotbot<br>Telegram: https://t.me/ransombotbot<br></a></p>
- <p>Please note that in the absence of an adequate response within the established timeframe, a full whistleblowing procedure will be initiated to inform all stakeholders of the identified violations, including:<br>- Regulators of relevant jurisdictions<br>- Media<br>- Professional community</p>
- <img src="https://u26807539.ct.sendgrid.net/wf/open?upn=u001.J9AvAzKVaQSod57mK5FqT2p-2BxWjcNU5C50SsY1bl4-2Bapwb4GdJKMzJANbD4nLxQNdROPohIyzk3JP1t9wC5WnvSDtGSFHaHSQgEohE41CfZefZsA2Ydp9W5MCIxOKlGPjczrgIfhbDjB1NpLQ-2BZnALZgN9qibaLBDyxwhdSCtE7Kl98OMSuQeAAyzV0oBzFfkCtPNNNi0-2BohrhEc1aevgA-3D-3D" alt="" width="1" height="1" border="0" style="height:1px !important;width:1px !important;border-width:0 !important;margin-top:0 !important;margin-bottom:0 !important;margin-right:0 !important;margin-left:0 !important;padding-top:0 !important;padding-bottom:0 !important;padding-right:0 !important;padding-left:0 !important;">
- --b1_ByR4HjoAsb3obIdgbSXOc78scbn7cP2F7B6PVW7k4c--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement