Advertisement
wavellan

220180503_PHISHING_SCAM_2

May 3rd, 2018
252
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.34 KB | None | 0 0
  1. Received: from MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) by
  2. MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
  3. id 15.0.1293.2 via Mailbox Transport; Wed, 2 May 2018 01:57:38 -0500
  4. Received: from MBX10C-ORD1.mex08.mlsrvr.com (172.29.9.35) by
  5. MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) with Microsoft SMTP Server (TLS)
  6. id 15.0.1293.2; Wed, 2 May 2018 01:57:37 -0500
  7. Received: from gate.forward.smtp.iad3a.emailsrvr.com (204.232.172.40) by
  8. MBX10C-ORD1.mex08.mlsrvr.com (172.29.9.35) with Microsoft SMTP Server (TLS)
  9. id 15.0.1293.2 via Frontend Transport; Wed, 2 May 2018 01:57:37 -0500
  10. Return-Path: <asoriano@sacitec.com>
  11. X-Spam-Threshold: 95
  12. X-Spam-Score: 0
  13. X-Spam-Flag: NO
  14. X-Virus-Scanned: OK
  15. X-Orig-To: REMOVED
  16. X-Originating-Ip: [69.89.30.42]
  17. Authentication-Results: smtp37.gate.iad3a.rsapps.net; iprev=pass policy.iprev="69.89.30.42"; spf=neutral smtp.mailfrom="asoriano@sacitec.com" smtp.helo="gproxy3-pub.mail.unifiedlayer.com"; dkim=fail (signing key too small) header.d=sacitec.com; dmarc=none (p=nil; dis=none) header.from=sacitec.com
  18. X-Suspicious-Flag: YES
  19. X-Classification-ID: 184e32ea-4dd6-11e8-a2c9-525400dc5f6a-1-1
  20. Received: from [69.89.30.42] ([69.89.30.42:45436] helo=gproxy3-pub.mail.unifiedlayer.com)
  21. by smtp37.gate.iad3a.rsapps.net (envelope-from <asoriano@sacitec.com>)
  22. (ecelerity 4.2.1.56364 r(Core:4.2.1.14)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384)
  23. id F9/50-18186-06169EA5; Wed, 02 May 2018 02:57:37 -0400
  24. Received: from cmgw15.unifiedlayer.com (unknown [10.9.0.15])
  25. by gproxy3.mail.unifiedlayer.com (Postfix) with ESMTP id DDEF2400F1
  26. for REMOVED; Wed, 2 May 2018 00:57:35 -0600 (MDT)
  27. Received: from box847.bluehost.com ([66.147.244.147])
  28. by cmsmtp with ESMTP
  29. id Dlgbf5csBPNwFDlgbfBpXf; Wed, 02 May 2018 00:56:21 -0600
  30. X-Authority-Reason: nr=8
  31. DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sacitec.com
  32. ; s=default; h=Content-Type:MIME-Version:Message-Id:Date:Subject:To:From:
  33. Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description:
  34. Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:
  35. In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
  36. List-Post:List-Owner:List-Archive;
  37. bh=S8XksnRqAR50epUF+AD6vgKCHDor+MLpWUJ5Bml3Tmw=; b=Kr8rY40NGiIptMT89ALakPrzaS
  38. 1LV12hrJpGim6VVUsxYdyD5sAlMrZK8As8UELP8XFPSONx4DXUWtEYsX08TUX2aHxDcifamGgnW3i
  39. 13J5U0QNVqtewu0UinT9KFzGd;
  40. Received: from [106.198.13.64] (port=4038 helo=mail.sacitec.com)
  41. by box847.bluehost.com with esmtpa (Exim 4.89_1)
  42. (envelope-from <asoriano@sacitec.com>)
  43. id 1fDlhm-002FZE-FG
  44. for REMOVED; Wed, 02 May 2018 00:57:35 -0600
  45. From: "Peter Correa" <petercorrea@sacitec.com>
  46. To: REMOVED
  47. Subject:
  48. Date: Wed, 2 May 2018 09:57:33 +0300
  49. Message-ID: <7499126px9bg$nxg23xwr$7btsm2md$@sacitec.com>
  50. MIME-Version: 1.0
  51. X-Mailer: Microsoft Outlook 16.0
  52. Thread-Index: dF8uXzFndmFzMSlAKV8tdms0OXBfNQ==
  53. Content-Language: en-us
  54. X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
  55. X-AntiAbuse: Primary Hostname - box847.bluehost.com
  56. X-AntiAbuse: Original Domain - REMOVED
  57. X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
  58. X-AntiAbuse: Sender Address Domain - sacitec.com
  59. X-BWhitelist: no
  60. X-Source-IP: 106.198.13.64
  61. X-Exim-ID: 1fDlhm-002FZE-FG
  62. X-Source:
  63. X-Source-Args:
  64. X-Source-Dir:
  65. X-Source-Sender: (mail.sacitec.com) [106.198.13.64]:4038
  66. X-Source-Auth: asoriano@sacitec.com
  67. X-Email-Count: 1113
  68. X-Source-Cap: c2FjaXRlY2M7c2FjaXRlY2M7Ym94ODQ3LmJsdWVob3N0LmNvbQ==
  69. X-Local-Domain: yes
  70. X-MS-Exchange-Organization-Network-Message-Id: 388c7f1e-c969-44ee-835e-08d5aff9fd4e
  71. X-MS-Exchange-Organization-AVStamp-Mailbox: SMEXzs^g;1422500;0;This mail has
  72. been scanned by Trend Micro ScanMail for Microsoft Exchange;
  73. X-MS-Exchange-Organization-SCL: 0
  74. X-MS-Exchange-Organization-AuthSource: MBX10C-ORD1.mex08.mlsrvr.com
  75. X-MS-Exchange-Organization-AuthAs: Anonymous
  76. Content-type: multipart/alternative;
  77. boundary="B_3608195253_46525116"
  78.  
  79. > This message is in MIME format. Since your mail reader does not understand
  80. this format, some or all of this message may not be legible.
  81.  
  82. --B_3608195253_46525116
  83. Content-type: text/plain;
  84. charset="UTF-8"
  85. Content-transfer-encoding: 7bit
  86.  
  87. Good morning REMOVED
  88.  
  89.  
  90.  
  91.  
  92.  
  93.  
  94.  
  95. https://goo.gl/8p4nbT
  96.  
  97.  
  98.  
  99.  
  100.  
  101.  
  102.  
  103.  
  104.  
  105. Peter
  106.  
  107.  
  108. --B_3608195253_46525116
  109. Content-type: text/html;
  110. charset="UTF-8"
  111. Content-transfer-encoding: quoted-printable
  112.  
  113. <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-microsof=
  114. t-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" xmlns:m=
  115. =3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http://www.w3.org=
  116. /TR/REC-html40">
  117. <head>
  118. <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
  119. <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
  120. <style><!--
  121. /* Font Definitions */
  122. @font-face
  123. {font-family:"Cambria Math";
  124. panose-1:2 4 5 3 5 4 6 3 2 4;}
  125. @font-face
  126. {font-family:Calibri;
  127. panose-1:2 15 5 2 2 2 4 3 2 4;}
  128. /* Style Definitions */
  129. p.MsoNormal, li.MsoNormal, div.MsoNormal
  130. {margin:0cm;
  131. margin-bottom:.0001pt;
  132. font-size:11.0pt;
  133. font-family:"Calibri","sans-serif";}
  134. a:link, span.MsoHyperlink
  135. {mso-style-priority:99;
  136. color:#0563C1;
  137. text-decoration:underline;}
  138. a:visited, span.MsoHyperlinkFollowed
  139. {mso-style-priority:99;
  140. color:#954F72;
  141. text-decoration:underline;}
  142. span.EmailStyle17
  143. {mso-style-type:personal-compose;
  144. font-family:"Calibri","sans-serif";
  145. color:windowtext;}
  146. .MsoChpDefault
  147. {mso-style-type:export-only;
  148. font-family:"Calibri","sans-serif";}
  149. @page WordSection1
  150. {size:612.0pt 792.0pt;
  151. margin:2.0cm 42.5pt 2.0cm 3.0cm;}
  152. div.WordSection1
  153. {page:WordSection1;}
  154. --></style><!--[if gte mso 9]><xml>
  155. <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
  156. </xml><![endif]--><!--[if gte mso 9]><xml>
  157. <o:shapelayout v:ext=3D"edit">
  158. <o:idmap v:ext=3D"edit" data=3D"1" />
  159. </o:shapelayout></xml><![endif]-->
  160. </head>
  161. <body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
  162. <div class=3D"WordSection1">
  163. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  164. :Verdana">Good morning REMOVED<o:p></o:p></span></p>
  165. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  166. :Verdana"><o:p>&nbsp;</o:p></span></p>
  167. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  168. :Verdana"><o:p>&nbsp;</o:p></span></p>
  169. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  170. :Verdana"><o:p>&nbsp;</o:p></span></p>
  171. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  172. :Verdana"><a href=3D"https://goo.gl/8p4nbT">https://goo.gl/8p4nbT</a><o:p></o:=
  173. p></span></p>
  174. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  175. :Verdana"><o:p>&nbsp;</o:p></span></p>
  176. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  177. :Verdana"><o:p>&nbsp;</o:p></span></p>
  178. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  179. :Verdana"><o:p>&nbsp;</o:p></span></p>
  180. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  181. :Verdana"><o:p>&nbsp;</o:p></span></p>
  182. <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:12.2pt;font-family=
  183. :Verdana">Peter<o:p></o:p></span></p>
  184. </div>
  185. </body>
  186. </html>
  187.  
  188.  
  189. --B_3608195253_46525116--
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement