wavellan

20190210_PHISHING_SCAM_2

Feb 10th, 2019
258
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.75 KB | None | 0 0
  1. Received: from MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) by
  2. MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
  3. id 15.0.1367.3 via Mailbox Transport; Sun, 10 Feb 2019 18:37:09 -0600
  4. Received: from MBX04D-ORD1.mex08.mlsrvr.com (172.29.9.21) by
  5. MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) with Microsoft SMTP Server (TLS)
  6. id 15.0.1367.3; Sun, 10 Feb 2019 18:37:09 -0600
  7. Received: from gate.forward.smtp.ord1c.emailsrvr.com (108.166.43.128) by
  8. MBX04D-ORD1.mex08.mlsrvr.com (172.29.9.21) with Microsoft SMTP Server (TLS)
  9. id 15.0.1367.3 via Frontend Transport; Sun, 10 Feb 2019 18:37:09 -0600
  10. Return-Path: <[email protected]>
  11. X-Spam-Threshold: 95
  12. X-Spam-Score: 0
  13. X-Spam-Flag: NO
  14. X-Virus-Scanned: OK
  15. X-Orig-To: [email protected]
  16. X-Originating-Ip: [185.241.4.7]
  17. Authentication-Results: smtp26.gate.ord1c.rsapps.net; iprev=pass policy.iprev="185.241.4.7"; spf=fail smtp.mailfrom="[email protected]" smtp.helo="were"; dkim=none (message not signed) header.d=none; dmarc=none (p=nil; dis=none) header.from=domain.org
  18. X-Suspicious-Flag: NO
  19. X-Classification-ID: 298d4bb4-2d95-11e9-b86d-b8ca3a5bd12c-1-1
  20. Received: from [185.241.4.7] ([185.241.4.7:32784] helo=were)
  21. by smtp26.gate.ord1c.rsapps.net (envelope-from <[email protected]>)
  22. (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384)
  23. id 18/D6-05125-5B3C06C5; Sun, 10 Feb 2019 19:37:09 -0500
  24. Received: from oofioceupdaetowa by were with local (Exim 4.91)
  25. (envelope-from <[email protected]>)
  26. id 1grgUI-0006GG-4V
  27. for [email protected]; Thu, 07 Feb 2019 05:00:54 -0500
  28. Subject: IMPORTANT SECURITY ALERT
  29. X-PHP-Script: 185.241.4.37/inbox.php for 159.69.177.182
  30. X-PHP-Originating-Script: 1003:inbox.php
  31. Date: Thu, 7 Feb 2019 10:00:54 +0000
  32. From: domain Message Center <[email protected]>
  33. Message-ID: <[email protected]>
  34. X-Mailer: Microsoft Outlook Express 6.00.2600.0000
  35. MIME-Version: 1.0
  36. X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
  37. X-AntiAbuse: Primary Hostname - were
  38. X-AntiAbuse: Original Domain - domain.org
  39. X-AntiAbuse: Originator/Caller UID/GID - [1003 992] / [47 12]
  40. X-AntiAbuse: Sender Address Domain - domain.org
  41. X-Get-Message-Sender-Via: were: authenticated_id: oofioceupdaetowa/only user confirmed/virtual account not confirmed
  42. X-Authenticated-Sender: were: oofioceupdaetowa
  43. X-Source:
  44. X-Source-Args:
  45. X-Source-Dir:
  46. X-MS-Exchange-Organization-Network-Message-Id: 255e68a2-8017-449b-5652-08d68fb90e93
  47. X-MS-Exchange-Organization-AVStamp-Mailbox: SMEXzs^g;1480300;0;This mail has
  48. been scanned by Trend Micro ScanMail for Microsoft Exchange;
  49. X-MS-Exchange-Organization-SCL: 0
  50. X-MS-Exchange-Organization-AuthSource: MBX04D-ORD1.mex08.mlsrvr.com
  51. X-MS-Exchange-Organization-AuthAs: Anonymous
  52. Content-type: multipart/alternative;
  53. boundary="B_3632674070_2049477911"
  54.  
  55. > This message is in MIME format. Since your mail reader does not understand
  56. this format, some or all of this message may not be legible.
  57.  
  58. --B_3632674070_2049477911
  59. Content-type: text/plain;
  60. charset="UTF-8"
  61. Content-transfer-encoding: 7bit
  62.  
  63.  
  64.  
  65. This mail is from a trusted sender.
  66.  
  67.  
  68.  
  69.  
  70. Please confirm account [email protected] to enable a better service communication,
  71. and avoid mail delivery malfunction.
  72.  
  73.  
  74. Note: Office will always keep you posted of security updates.
  75.  
  76. Thanks and Regards,
  77. [email protected] (C) 2019 Secured Service. - This email was sent to [email protected]
  78.  
  79.  
  80. --B_3632674070_2049477911
  81. Content-type: text/html;
  82. charset="UTF-8"
  83. Content-transfer-encoding: quoted-printable
  84.  
  85. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
  86. <html>
  87. <head>
  88. <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
  89. <meta name=3D"GENERATOR" content=3D"MSHTML 11.00.10570.1001">
  90. </head>
  91. <body>
  92. <p><br class=3D"Apple-interchange-newline">
  93. <table class=3D"yiv6061570731ydp850c3b47yiv9171881082m_-8772752807624100762x_=
  94. ecxmyTable" style=3D"FONT-SIZE: 13px; FONT-FAMILY: new; WIDTH: 700px; WHITE-SP=
  95. ACE: normal; WORD-SPACING: 0px; BORDER-COLLAPSE: collapse; TEXT-TRANSFORM: n=
  96. one; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-ALIGN:=
  97. left; MIN-HEIGHT: 36px; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; LINE=
  98. -HEIGHT: 1.6em; BACKGROUND-COLOR: rgb(238,238,238); TEXT-INDENT: 0px; font-v=
  99. ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wid=
  100. th: 0px; text-decoration-style: initial; text-decoration-color: initial">
  101. <tbody>
  102. <tr>
  103. <th style=3D"BORDER-TOP: rgb(0,0,0) 0px solid; BORDER-RIGHT: rgb(0,0,0) 0px s=
  104. olid; WIDTH: 2px; BORDER-BOTTOM: rgb(0,0,0) 0px solid; COLOR: white; PADDING=
  105. -BOTTOM: 4px; PADDING-TOP: 4px; PADDING-LEFT: 4px; BORDER-LEFT: rgb(0,0,0) 0=
  106. px solid; PADDING-RIGHT: 4px; BACKGROUND-COLOR: rgb(2,151,64)">
  107. <br>
  108. </th>
  109. <td style=3D"BORDER-TOP: rgb(0,0,0) 0px solid; BORDER-RIGHT: rgb(0,0,0) 0px s=
  110. olid; BORDER-BOTTOM: rgb(0,0,0) 0px solid; PADDING-BOTTOM: 4px; PADDING-TOP:=
  111. 4px; PADDING-LEFT: 4px; BORDER-LEFT: rgb(0,0,0) 0px solid; PADDING-RIGHT: 4=
  112. px; BACKGROUND-COLOR: rgb(243,255,248)">
  113. <div class=3D"yiv6061570731ydp850c3b47yiv9171881082m_-8772752807624100762x_ec=
  114. xms-font-weight-regular yiv6061570731ydp850c3b47yiv9171881082m_-877275280762=
  115. 4100762x_ecxms-font-s yiv6061570731ydp850c3b47yiv9171881082m_-87727528076241=
  116. 00762x_ecxInfobarImmediateTextContainer yiv6061570731ydp850c3b47yiv917188108=
  117. 2m_-8772752807624100762x_ecxms-font-color-neutralDark">
  118. <span style=3D"FONT-FAMILY: arial, helvetica, sans-serif"><span style=3D"FONT-S=
  119. IZE: 12px">This mail is from a trusted sender.</span></span></div>
  120. </td>
  121. </tr>
  122. </tbody>
  123. </table>
  124. </p>
  125. <div style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helve=
  126. tica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSF=
  127. ORM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-=
  128. ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR=
  129. : rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-v=
  130. ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: =
  131. initial; text-decoration-color: initial">
  132. <div>&nbsp;</div>
  133. <div>
  134. <div style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helve=
  135. tica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSF=
  136. ORM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-=
  137. ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR=
  138. : rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-v=
  139. ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: =
  140. initial; text-decoration-color: initial">
  141. &nbsp;</div>
  142. <div style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helve=
  143. tica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSF=
  144. ORM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-=
  145. ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR=
  146. : rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-v=
  147. ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: =
  148. initial; text-decoration-color: initial">
  149. <br>
  150. Dear&nbsp;[email protected]&nbsp;,<br>
  151. <br>
  152. Please confirm account <font color=3D"#00ff00">[email protected]</font> to ena=
  153. ble a better service communication,<br>
  154. and avoid mail delivery malfunction.<span>&nbsp;</span><br>
  155. <br>
  156. </div>
  157. <div style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helve=
  158. tica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSF=
  159. ORM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-=
  160. ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR=
  161. : rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-v=
  162. ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: =
  163. initial; text-decoration-color: initial">
  164. <table width=3D"393">
  165. <tbody>
  166. <tr>
  167. <td style=3D"FONT-SIZE: 14px; BORDER-TOP: rgb(0,120,215) 1px solid; FONT-FAMI=
  168. LY: &quot;Segoe UI Semibold&quot;, &quot;Segoe WP Semibold&quot;, &quot;Sego=
  169. e UI&quot;, &quot;Segoe WP&quot;, Segoe, Tahoma, &quot;Microsoft Sans Serif&=
  170. quot;, Verdana, sans-serif; BORDER-RIGHT: rgb(0,120,215) 1px solid; WIDTH: 2=
  171. 00px; VERTICAL-ALIGN: middle; WHITE-SPACE: nowrap; BORDER-BOTTOM: rgb(0,120,=
  172. 215) 1px solid; COLOR: rgb(255,255,255); TEXT-ALIGN: center; PADDING-LEFT: 2=
  173. 0px; MIN-HEIGHT: 30px; BORDER-LEFT: rgb(0,120,215) 1px solid; MARGIN: 0px; L=
  174. INE-HEIGHT: 20px; PADDING-RIGHT: 20px; BACKGROUND-COLOR: rgb(0,120,215)">
  175. <a style=3D"TEXT-DECORATION: none; COLOR: rgb(255,255,255)" href=3D"https://mye=
  176. mailsrvrupgraade.z13.web.core.windows.net/" rel=3D"noreferrer" target=3D"_blank"=
  177. ><strong><u>Confirm [email protected]</u></strong></a></td>
  178. </tr>
  179. </tbody>
  180. </table>
  181. </div>
  182. <br style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helvet=
  183. ica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFO=
  184. RM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-A=
  185. LIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR:=
  186. rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-va=
  187. riant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: i=
  188. nitial; text-decoration-color: initial">
  189. <div style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helve=
  190. tica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSF=
  191. ORM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-=
  192. ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR=
  193. : rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-v=
  194. ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: =
  195. initial; text-decoration-color: initial">
  196. <strong>Note:</strong><span>&nbsp;</span>Office will always keep you posted=
  197. of security updates.</div>
  198. <div style=3D"FONT-SIZE: 13px; FONT-FAMILY: &quot;Helvetica Neue&quot;, Helve=
  199. tica, Arial, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSF=
  200. ORM: none; FONT-WEIGHT: 400; COLOR: rgb(38,40,42); FONT-STYLE: normal; TEXT-=
  201. ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR=
  202. : rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-v=
  203. ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: =
  204. initial; text-decoration-color: initial">
  205. <br>
  206. Thanks and Regards,<br>
  207. [email protected] (C) 2019 Secured Service. -<span>&nbsp;</span><span style=3D=
  208. "TEXT-DECORATION: none; COLOR: rgb(110,120,139)">This email was sent to
  209. <font color=3D"#26282a">[email protected]</font></span></div>
  210. </div>
  211. </div>
  212. </body>
  213. </html>
  214.  
  215.  
  216. --B_3632674070_2049477911--
Add Comment
Please, Sign In to add comment