Advertisement
Neonprimetime

Phishing Email: RE: New Order Madni trading

Aug 27th, 2015
376
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.37 KB | None | 0 0
  1. Phishing Email
  2. Reported by neonprimetime security
  3. http://neonprimetime.blogspot.com
  4.  
  5. *****
  6. From: blog@dawn.com [Madni trading]
  7. Subject: RE: New Order
  8. Attachment: new order.jar
  9. Body:
  10. Good Day
  11. Good to know about your products from one of your buyers,
  12. pleases check attach our new order kindly quote your best price to us on FOB basis.
  13.  
  14. Give me your minimum order
  15.  
  16. -Your Best Prices and FOB Port of loading.
  17. -Your estimated delivery time.
  18. -Your Mode of Payment. ( If by L/C or T/T )
  19.  
  20. Regards
  21. Best Regards
  22. Yount Lai
  23. Overseas Manager
  24. Guangdong Wellong Co.,Ltd
  25. Tel:+86-754-8252 5656 Fax:+86-754-8275 6565
  26. Add: No.8 Jinpu Road, Shantou, China-515061
  27.  
  28. E-Catalog Downloard
  29. hxxp://yun.baidu.com/share/link?shareid=3335906660&uk=358106616
  30.  
  31.  
  32. From "Madni trading" Thu Aug 27 06:24:20 2015
  33. Return-Path: <blog@dawn.com>
  34. Received-SPF: none (domain of dawn.com does not designate permitted sender hosts)
  35. X-Originating-IP: [203.130.1.248]
  36. Received: from [10.1.70.10] ([185.17.1.70]) by mail.dawn.com with ESMTP id OGLq4KkIWnYdNY5S (version=TLSv1 cipher=AES256-SHA bits=256 verify=NO); Thu, 27 Aug 2015 11:26:42 +0500 (PKT)
  37. X-Barracuda-Envelope-From: blog@dawn.com
  38. X-Barracuda-AUTH-User: blog@dawn.com
  39. X-Barracuda-Apparent-Source-IP: 185.17.1.70
  40. Content-Type: multipart/mixed; boundary="===============0547475730=="
  41. MIME-Version: 1.0
  42. Subject: Re: New Order
  43. To: Recipients <blog@dawn.com>
  44. X-ASG-Orig-Subj: Re: New Order
  45. From: "Madni trading" <blog@dawn.com>
  46. Date: Thu, 27 Aug 2015 07:24:20 +0100
  47. X-Barracuda-Connect: UNKNOWN[185.17.1.70]
  48. X-Barracuda-Start-Time: 1440656801
  49. X-Barracuda-Encrypted: AES256-SHA
  50. X-Barracuda-URL: http://203.130.1.248:8000/cgi-mod/mark.cgi
  51. X-Barracuda-BRTS-Status: 1
  52. X-Virus-Scanned: by bsmtpd at dawn.com
  53. X-Barracuda-Spam-Score: 0.64
  54. X-Barracuda-Spam-Status: No, SCORE=0.64 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=5.0 tests=BSF_SC0_MV0713, HTML_MESSAGE, MISSING_MID
  55. X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.21965
  56. Rule breakdown below
  57. pts rule name description
  58. ---- ---------------------- --------------------------------------------------
  59. 0.14 MISSING_MID Missing Message-Id: header
  60. 0.00 HTML_MESSAGE BODY: HTML included in message
  61. 0.50 BSF_SC0_MV0713 Custom rule MV0713
  62. Message-Id: <20150827062718.725A8211F4B@mail.dawn.com>
  63. Content-Length: 142665
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement