Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Attaches a file called: voicemail.zip that packs a punch:
- https://www.virustotal.com/gui/file/0fb82d5e1c01fa65b116b115a33854cc0e974099fd8eda6e36ab5bce8ed464ae/detection
- IP Information:
- https://www.abuseipdb.com/report?ip=66.96.206.232
- MALWARE E-MAIL CONTENT:
- This letter is from a trusted source [email protected]
- You have a voicemail from 1 of your contact
- voicemail will be deleted after 02-12-2021.
- This letter with ID: 9e12C8 was sent from a Rackspace Representative .
- Rahul Sutar
- Received: from MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) by
- MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2 via Mailbox Transport; Mon, 8 Feb 2021 11:13:07 -0600
- Received: from MBX07C-ORD1.mex08.mlsrvr.com (172.29.9.29) by
- MBX05C-ORD1.mex08.mlsrvr.com (172.29.9.23) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2; Mon, 8 Feb 2021 11:13:06 -0600
- Received: from gate.forward.smtp.iad3a.emailsrvr.com (204.232.172.40) by
- MBX07C-ORD1.mex08.mlsrvr.com (172.29.9.29) with Microsoft SMTP Server (TLS)
- id 15.0.1497.2 via Frontend Transport; Mon, 8 Feb 2021 11:13:06 -0600
- Return-Path: <[email protected]>
- X-Spam-Threshold: 95
- X-Spam-Score: 0
- X-Spam-Flag: NO
- Authentication-Results: smtp9.gate.iad3a.rsapps.net x-tls.subject="/C=SG/ST=SG/L=Singapore/O=Product Development Solution Pte Ltd/OU=SG/CN=mail.pdsol.com"; auth=fail (cipher=AES256-GCM-SHA384)
- X-Virus-Scanned: OK
- X-Orig-To:
- X-Originating-Ip: [66.96.206.232]
- Authentication-Results: smtp9.gate.iad3a.rsapps.net; iprev=pass policy.iprev="66.96.206.232"; spf=pass smtp.mailfrom="[email protected]" smtp.helo="mail.pdsol.com"; dkim=none (message not signed) header.d=none; dmarc=none (p=nil; dis=none) header.from=pdsol.com
- X-Suspicious-Flag: NO
- X-Classification-ID: e79fbbb2-6a30-11eb-9503-52540097fc8c-1-1
- Received: from [66.96.206.232] ([66.96.206.232:25238] helo=mail.pdsol.com)
- by smtp9.gate.iad3a.rsapps.net (envelope-from <[email protected]>)
- (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=AES256-GCM-SHA384
- subject="/C=SG/ST=SG/L=Singapore/O=Product Development Solution Pte Ltd/OU=SG/CN=mail.pdsol.com")
- id 90/C2-04210-12171206; Mon, 08 Feb 2021 12:13:06 -0500
- Received: from PDSSGSINEX001.pds.local (192.168.0.27) by
- PDSSGSINEX001.pds.local (192.168.0.27) with Microsoft SMTP Server
- (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id
- 15.1.2106.2; Tue, 9 Feb 2021 01:13:00 +0800
- Received: from PDSSGSINEX001.pds.local ([::1]) by PDSSGSINEX001.pds.local
- ([::1]) with mapi id 15.01.2106.002; Tue, 9 Feb 2021 01:12:59 +0800
- From: Rahul Sutar <[email protected]>
- To: "[email protected]" <[email protected]>
- Subject: 1 Voicemail Recieved
- Thread-Topic: 1 Voicemail Recieved
- Thread-Index: AQHW/j2b7UryMbavIk6AcOonWhjYnQ==
- Date: Mon, 8 Feb 2021 17:12:41 +0000
- Message-ID: <[email protected]>
- Accept-Language: en-US, en-SG
- Content-Language: en-US
- X-MS-Has-Attach: yes
- X-MS-TNEF-Correlator:
- MIME-Version: 1.0
- X-MS-Exchange-Organization-Network-Message-Id: 2e76602e-ac21-403c-d48e-08d8cc54cd79
- X-MS-Exchange-Organization-AuthSource: MBX07C-ORD1.mex08.mlsrvr.com
- X-MS-Exchange-Organization-AuthAs: Anonymous
- Content-type: multipart/mixed;
- boundary="B_3695637674_1891044706"
- > This message is in MIME format. Since your mail reader does not understand
- this format, some or all of this message may not be legible.
- --B_3695637674_1891044706
- Content-type: multipart/alternative;
- boundary="B_3695637674_1781793316"
- --B_3695637674_1781793316
- Content-type: text/plain;
- charset="UTF-8"
- Content-transfer-encoding: 7bit
Add Comment
Please, Sign In to add comment