Advertisement
wavellan

20180219_Phishing_1

Feb 19th, 2018
619
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.06 KB | None | 0 0
  1. https://goo.gl/KozZ6K
  2.  
  3. Received: from MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) by
  4. MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
  5. id 15.0.1293.2 via Mailbox Transport; Mon, 19 Feb 2018 10:49:37 -0600
  6. Received: from MBX03D-ORD1.mex08.mlsrvr.com (172.29.9.18) by
  7. MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
  8. id 15.0.1293.2; Mon, 19 Feb 2018 10:49:37 -0600
  9. Received: from gate.forward.smtp.ord1c.emailsrvr.com (108.166.43.128) by
  10. MBX03D-ORD1.mex08.mlsrvr.com (172.29.9.18) with Microsoft SMTP Server (TLS)
  11. id 15.0.1293.2 via Frontend Transport; Mon, 19 Feb 2018 10:49:37 -0600
  12. Return-Path: <jolynn56468@monchera.com.br>
  13. X-Spam-Threshold: 95
  14. X-Spam-Score: 100
  15. Precedence: junk
  16. X-Spam-Flag: YES
  17. X-Virus-Scanned: OK
  18. X-Orig-To: REMOVED
  19. X-Originating-Ip: [201.76.49.171]
  20. Authentication-Results: smtp25.gate.ord1c.rsapps.net; iprev=pass policy.iprev="201.76.49.171"; spf=pass smtp.mailfrom="jolynn56468@monchera.com.br" smtp.helo="hm1480-40.locaweb.com.br"; dkim=none (message not signed) header.d=none; dmarc=none (p=nil; dis=none) header.from=monchera.com.br
  21. X-Classification-ID: ddfa0c78-1594-11e8-9b17-0026b952bd60-1-1
  22. Received: from [201.76.49.171] ([201.76.49.171:1429] helo=hm1480-40.locaweb.com.br)
  23. by smtp25.gate.ord1c.rsapps.net (envelope-from <jolynn56468@monchera.com.br>)
  24. (ecelerity 4.2.1.56364 r(Core:4.2.1.14)) with ESMTP
  25. id B0/76-14786-0200B8A5; Mon, 19 Feb 2018 11:49:36 -0500
  26. Received: from mcbain0016.correio.biz (201.76.49.39) by hm1480-1.locaweb.com.br id hhc020169rkf for <REMOVED>; Mon, 19 Feb 2018 13:49:35 -0300 (envelope-from <jolynn56468@monchera.com.br>)
  27. Received: from proxy.email-ssl.com.br (bartr0002.email.locaweb.com.br [10.30.70.45])
  28. by mcbain0016.correio.biz (Postfix) with ESMTP id 10F4EAA0341
  29. for <REMOVED>; Mon, 19 Feb 2018 13:49:35 -0300 (BRT)
  30. x-locaweb-id: _yT_bR3mXTKAFWv_oFdUIENTFvuA4cpA2j8185u_j2j2iCk3PIADNluxPiNEdJNbnjYtCibkd-Xm5zD4AM5xvyh8x4jnZ6KgZXNpst7VuZJTwAzim-mq8lGyeZ8LQCAlRP9iuoQh01DN0rqEJAK_7xhduAPpgBcp9Ue9pKzJ68PY_NXHJvZXCcY0wZmcCn2oMg0ZPCrdvIkG5_AphtpjJ0G64-VfXqpMb6yWHoJmJ7Q= NmQ2MTc1NzI2ZjYyNjk2ZTY5NDA2ZDZmNmU2MzY4NjU3MjYxMmU2MzZmNmQyZTYyNzI=
  31. X-LocaWeb-COR: locaweb_2009_x-mail
  32. X-AuthUser: maurobini@monchera.com.br
  33. Received: from smtp.monchera.com.br (177-104-241-250.provecom.com.br [177.104.241.250])
  34. (Authenticated sender: maurobini@monchera.com.br)
  35. by proxy.email-ssl.com.br (Postfix) with ESMTPSA id 5C1A04C056D
  36. for <REMOVED>; Mon, 19 Feb 2018 13:49:32 -0300 (BRT)
  37. From: jolynn56468 <jolynn56468@monchera.com.br>
  38. To: <REMOVED>
  39. Subject:
  40. Date: Mon, 19 Feb 2018 16:51:33 +0000
  41. Message-ID: <7759801xepk0$k8by4qmy$cw1hkn3m$@monchera.com.br>
  42. MIME-Version: 1.0
  43. X-Mailer: Microsoft Outlook 16.0
  44. Thread-Index: Xm0jNDApbnApKCpudzBtLTY1XnJleQ==
  45. Content-Language: en-us
  46. X-MS-Exchange-Organization-Network-Message-Id: f656ec2c-c0e4-43d9-8796-08d577b8c2f4
  47. X-MS-Exchange-Organization-AVStamp-Mailbox: SMEXzs^g;1397500;0;This mail has
  48. been scanned by Trend Micro ScanMail for Microsoft Exchange;
  49. X-MS-Exchange-Organization-SCL: 5
  50. X-MS-Exchange-Organization-AuthSource: MBX03D-ORD1.mex08.mlsrvr.com
  51. X-MS-Exchange-Organization-AuthAs: Anonymous
  52. Content-type: multipart/alternative;
  53. boundary="B_3601915953_1203068143"
  54.  
  55. > This message is in MIME format. Since your mail reader does not understand
  56. this format, some or all of this message may not be legible.
  57.  
  58. --B_3601915953_1203068143
  59. Content-type: text/plain;
  60. charset="UTF-8"
  61. Content-transfer-encoding: 7bit
  62.  
  63. Hi REMOVED
  64.  
  65.  
  66.  
  67. https://goo.gl/KozZ6K
  68.  
  69.  
  70.  
  71.  
  72. Thank you!
  73.  
  74.  
  75.  
  76. --B_3601915953_1203068143
  77. Content-type: text/html;
  78. charset="UTF-8"
  79. Content-transfer-encoding: quoted-printable
  80.  
  81. <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-microsof=
  82. t-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" xmlns:m=
  83. =3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http://www.w3.org=
  84. /TR/REC-html40">
  85. <head>
  86. <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
  87. <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
  88. <style><!--
  89. /* Font Definitions */
  90. @font-face
  91. {font-family:"Cambria Math";
  92. panose-1:2 4 5 3 5 4 6 3 2 4;}
  93. @font-face
  94. {font-family:Calibri;
  95. panose-1:2 15 5 2 2 2 4 3 2 4;}
  96. /* Style Definitions */
  97. p.MsoNormal, li.MsoNormal, div.MsoNormal
  98. {margin:0cm;
  99. margin-bottom:.0001pt;
  100. font-size:11.0pt;
  101. font-family:"Calibri","sans-serif";}
  102. a:link, span.MsoHyperlink
  103. {mso-style-priority:99;
  104. color:#0563C1;
  105. text-decoration:underline;}
  106. a:visited, span.MsoHyperlinkFollowed
  107. {mso-style-priority:99;
  108. color:#954F72;
  109. text-decoration:underline;}
  110. span.EmailStyle17
  111. {mso-style-type:personal-compose;
  112. font-family:"Calibri","sans-serif";
  113. color:windowtext;}
  114. .MsoChpDefault
  115. {mso-style-type:export-only;
  116. font-family:"Calibri","sans-serif";}
  117. @page WordSection1
  118. {size:612.0pt 792.0pt;
  119. margin:2.0cm 42.5pt 2.0cm 3.0cm;}
  120. div.WordSection1
  121. {page:WordSection1;}
  122. --></style><!--[if gte mso 9]><xml>
  123. <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
  124. </xml><![endif]--><!--[if gte mso 9]><xml>
  125. <o:shapelayout v:ext=3D"edit">
  126. <o:idmap v:ext=3D"edit" data=3D"1" />
  127. </o:shapelayout></xml><![endif]-->
  128. </head>
  129. <body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
  130. <div class=3D"WordSection1">
  131. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.3pt;font-family=
  132. :Verdana">Hi REMOVED</p>
  133. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.3pt;font-family=
  134. :Verdana"><o:p>&nbsp;</o:p></span></p>
  135. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:10.3pt;font-family=
  136. :Verdana"><a href=3D"https://goo.gl/KozZ6K">https://goo.gl/KozZ6K</a><o:p></o:=
  137. p></span></p>
  138. <p class=3D"MsoNormal"><span style=3D"font-size:10.3pt;font-family:Verdana"><o:=
  139. p>&nbsp;</o:p></span></p>
  140. <p class=3D"MsoNormal"><span style=3D"font-size:10.3pt;font-family:Verdana"><o:=
  141. p>&nbsp;</o:p></span></p>
  142. Thank you!<br>
  143. <o:p></o:p></span>
  144. <p></p>
  145. <p class=3D"MsoNormal"><span style=3D"font-size:10.3pt;font-family:Verdana"><o:=
  146. p></o:p></span></p>
  147. </div>
  148. </body>
  149. </html>
  150.  
  151.  
  152. --B_3601915953_1203068143--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement