Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Phishing with html attachment:
- https://www.virustotal.com/gui/file/b933d91716a1b2ee4d23fea137f2920b8dd66a8fe5059ef64e94b493a2452bbf/detection
- Dear YOUR_NAME_HERE
- FYI
- Attached Purchase Order
- Best Regard
- Cathy, ZOU SHAN
- Account Receivable Service
- Finance Center
- ,
- Received: from MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) by
- MBX05A-IAD3.mex08.mlsrvr.com (172.29.17.23) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2 via Mailbox Transport; Mon, 22 Mar 2021 20:13:59 -0400
- Received: from MBX10C-ORD1.mex08.mlsrvr.com (172.29.9.35) by
- MBX05D-ORD1.mex08.mlsrvr.com (172.29.9.24) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2; Mon, 22 Mar 2021 19:13:58 -0500
- Received: from gate.forward.smtp.iad3b.emailsrvr.com (146.20.86.8) by
- MBX10C-ORD1.mex08.mlsrvr.com (172.29.9.35) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2 via Frontend Transport; Mon, 22 Mar 2021 19:13:58 -0500
- Return-Path: <010f01785c6e5438-7abf3242-1a88-4711-a04f-7c05a3ef3dda-000000@us-east-2.amazonses.com>
- X-Spam-Threshold: 95
- X-Spam-Score: 100
- Precedence: junk
- X-Spam-Flag: YES
- X-Virus-Scanned: OK
- X-Orig-To:
- X-Originating-Ip: [23.251.226.1]
- Authentication-Results: smtp36.gate.iad3b.rsapps.net; iprev=pass policy.iprev="23.251.226.1"; spf=pass smtp.mailfrom="010f01785c6e5438-7abf3242-1a88-4711-a04f-7c05a3ef3dda-000000@us-east-2.amazonses.com" smtp.helo="e226-1.smtp-out.us-east-2.amazonses.com"; dkim=pass header.d=cowtomo.com; dkim=pass header.d=amazonses.com; dmarc=none (p=nil; dis=none) header.from=cowtomo.com
- X-Suspicious-Flag: NO
- X-Classification-ID: a3908b9c-8b6c-11eb-b870-5254003a7283-2-1
- Received: from [23.251.226.1] ([23.251.226.1:40559] helo=e226-1.smtp-out.us-east-2.amazonses.com)
- by smtp36.gate.iad3b.rsapps.net (envelope-from <010f01785c6e5438-7abf3242-1a88-4711-a04f-7c05a3ef3dda-000000@us-east-2.amazonses.com>)
- (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=AES128-SHA256)
- id 4F/B1-07797-6C239506; Mon, 22 Mar 2021 20:13:58 -0400
- DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
- s=5zuyt3datpyvotobttesifzmx67arxgf; d=cowtomo.com; t=1616458438;
- h=From:Subject:To:Content-Type:MIME-Version:Date:Message-Id;
- bh=cm1D4njcxnYkjd1rO+1W4lol9bgpQZYE0F9H3PBY9JQ=;
- b=MSfo4/gov7NN9V3Yb6CDo/37/T538AXgOkKhb1lRwOIBba7cy1q1LmaUuegkd5B/
- hZbrGjWpzHDmW0hjPLyqnzCsAs0SXz5NvfGKhY049OwRGC2Mf53/Dm5QCqmx8RG1jv6
- ocEnB800cnW5uqImCX+XSRl09MffLPy8PSuIDx04=
- DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
- s=kra23psoka5qyyh6gdejiiuof3nluwuz; d=amazonses.com; t=1616458438;
- h=From:Subject:To:Content-Type:MIME-Version:Date:Message-Id:Feedback-ID;
- bh=cm1D4njcxnYkjd1rO+1W4lol9bgpQZYE0F9H3PBY9JQ=;
- b=Jb+XnZtsZRTlbb5nyx9Z5Z4FU9wKC4NAo4H33UAcUSCMKoIkqNA19Gif/1EU2Tsm
- UbjRcWR/r4PXvxZ+uH8qYMAIPKrw8oowCQSmOUlccTPW05+E+esnr/EtbKg7VKA5W64
- sucjxpIwZI4WRmj4pcHSbir02yLFvKeCwKJcN44M=
- From: "SHAN, Cathy" <[email protected]>
- Subject: Document Received Tuesday, March 23, 2021
- To:
- MIME-Version: 1.0
- Date: Tue, 23 Mar 2021 00:13:57 +0000
- Message-ID: <010f01785c6e5438-7abf3242-1a88-4711-a04f-7c05a3ef3dda-000000@us-east-2.amazonses.com>
- X-SES-Outgoing: 2021.03.23-23.251.226.1
- Feedback-ID: 1.us-east-2.9NyXB8MI88c5QChksqeGY5eTMWzewX8WIBllM4XLlzY=:AmazonSES
- X-MS-Exchange-Organization-Network-Message-Id: 358aa3c0-a465-45f2-4b63-08d8ed908e04
- X-MS-Exchange-Organization-SCL: 5
- X-MS-Exchange-Organization-AuthSource: MBX10C-ORD1.mex08.mlsrvr.com
- X-MS-Exchange-Organization-AuthAs: Anonymous
- Content-type: multipart/mixed;
- boundary="B_3699280153_2117323504"
- > This message is in MIME format. Since your mail reader does not understand
- this format, some or all of this message may not be legible.
- --B_3699280153_2117323504
- Content-type: multipart/alternative;
- boundary="B_3699280153_11104553"
- --B_3699280153_11104553
- Content-type: text/plain;
- charset="UTF-8"
- Content-transfer-encoding: 7bit
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement