Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- █▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█
- █ SPAM EMAIL BODY WITH HEADERS █
- █▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█
- From - Sat Oct 31 16:24:43 2020
- X-Account-Key: account3
- X-UIDL: 1042748947.64783
- X-Mozilla-Status: 0001
- X-Mozilla-Status2: 00000000
- X-Mozilla-Keys:
- Return-Path: <bounce-2900-8879552-860-248@mjigjal.cn>
- Received: from mx2.mi.net ([unix socket])
- by stor3 (Cyrus 2.5.10-Debian-2.5.10-3) with LMTPA;
- Sat, 31 Oct 2020 15:04:00 +0200
- X-Sieve: CMU Sieve 2.4
- X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on stor3.stor3
- X-Spam-Level: ****
- X-Spam-Status: No, score=4.7 required=5.0 tests=BAYES_50,DKIM_SIGNED,
- DKIM_VALID,DKIM_VALID_AU,HTML_FONT_LOW_CONTRAST,HTML_MESSAGE,
- LOCAL_SPAM_MARKETING_3,LOCAL_SUNGLASSES,SPF_PASS shortcircuit=no
- autolearn=no autolearn_force=no version=3.4.2
- Received-SPF: pass (mjigjal.cn: 157.52.228.229 is authorized to use 'bounce-2900-8879552-860-248@mjigjal.cn' in 'mfrom' identity (mechanism 'ptr' matched)) receiver=mx3.mi.net; identity=mailfrom; envelope-from="bounce-2900-8879552-860-248@mjigjal.cn"; helo=ahq.mjigjal.cn; client-ip=157.52.228.229
- Authentication-Results: mx2.mi.net; dkim=pass (1024-bit key)
- header.i=noreply@mjigjal.cn; dkim-adsp=none
- Received: from ahq.mjigjal.cn (ahq.mjigjal.cn [157.52.228.229])
- by mx2.mi.net (Postfix) with ESMTP id E24B840F24D9
- for <urmom@mi.net>; Sat, 31 Oct 2020 15:03:58 +0200 (EET)
- DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=mjigjalcn; d=mjigjal.cn;
- h=Date:To:From:Reply-to:Subject:Message-ID:List-Unsubscribe:MIME-Version:Content-Type; i=noreply@mjigjal.cn;
- bh=bsG/PrY56SjuUp/XUdrdHFmFAgc=;
- b=cJDSVaU7G46T0nVLR0uJZBpH7yXdZ95q4Ie/4xYEXct+EL2gC87/pUx+Gj+0L+eQZR3N5Na9ruI2
- 7DH0kcLjdeGSnXEYWkohUcRiocu9fAdOTvIxIy0uWrvLWeYVV/mW2DcPuANA6OA4EGYcBcEIoEBx
- 4eLFH81rbOkOep9rkFw=
- DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=mjigjalcn; d=mjigjal.cn;
- b=VSAX42QxOUbQ6irlJryd5kTKz+VxQGUo5vy5G67eEsWp8RwbyOObYyIro1wEQPaOWTcX8iyjBD+4
- biD/v646lnFYSwRzhOBoLaHd/qulCIuvrr3TjUJRxooJN/2Lif9MQMBAMclUr77H+wQeiiSnpCO4
- k/t0jBIiTiWZwkGP2fs=;
- Received: by nnd.mjigjal.cn id hjm5im0e97cp for <urmom@mi.net>; Sat, 31 Oct 2020 09:04:35 -0700 (envelope-from <bounce-2900-8879552-860-248@mjigjal.cn>)
- Date: Sat, 31 Oct 2020 12:05:42 +0100
- To: "urmom@mi.net" <urmom@mi.net>
- From: Ray&Ban Sunglasses <noreply@mjigjal.cn>
- Reply-to: Ray&Ban Sunglasses <noreply@mjigjal.cn>
- Subject: Halloween Up to 80% Off Sunglasses!
- Message-ID: <09e2d7ab2ce6993206583b5ac2e7bb89@localhost>
- X-Priority: 3
- X-Mailer: Email Sending System
- X-Complaints-To: wqs2ka@163.com
- List-Unsubscribe: <http://peud.aicema.top/edmi/u.php?p=s6/rs/ycv/rw/s4/rs>
- X-MessageID: MTR8fHx8NDM1Mjd8fHx8d2VlZGVkQG1haWwuYmd8fHx8NHx8fHwxfHx8fDA%3D
- X-Report-Abuse: <http://peud.aicema.top/edmi/report_abuse.php?mid=MTR8fHx8NDM1Mjd8fHx8d2VlZGVkQG1haWwuYmd8fHx8NHx8fHwxfHx8fDA%3D>
- MIME-Version: 1.0
- Content-Type: multipart/alternative;
- boundary="b1_09e2d7ab2ce6993206583b5ac2e7bb89"
- --b1_09e2d7ab2ce6993206583b5ac2e7bb89
- Content-Type: text/plain; charset = "utf-8"
- Content-Transfer-Encoding: quoted-printable
- Halloween Up to 80% Off Sunglasses!
- Your email client cannot read this email.
- To view it online, please go here: http://peud.aicema.top/edmi/wb.php?p=3Ds=
- 6/s4/rs/ycv/rw/rs
- To stop receiving these emails:http://peud.aicema.top/edmi/u.php?p=3Ds6/rs/=
- ycv/rw/s4/rs
- --b1_09e2d7ab2ce6993206583b5ac2e7bb89
- Content-Type: text/html; charset = "utf-8"
- Content-Transfer-Encoding: quoted-printable
- <!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org=
- /TR/xhtml1/DTD/xhtml1-strict.dtd">
- <html><head>
- <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8">
- <meta name=3D"viewport" content=3D"width=3Ddevice-width, initial-scale=3D1.=
- 0">
- <style type=3D"text/css">
- #outlook a{padding:0}body{width:100%!important;-webkit-text-size-adjust:100=
- %;-ms-text-size-adjust:100%;margin:0;padding:0;background:#efefe9}.External=
- Class{width:100%}.ExternalClass,.ExternalClass p,.ExternalClass span,.Exter=
- nalClass font,.ExternalClass td,.ExternalClass div{line-height:100%}img{out=
- line:0;text-decoration:none;-ms-interpolation-mode:bicubic}a img{border:0}.=
- image_fix{display:block}p{margin:1em 0}table td{border-collapse:collapse;fo=
- nt-family:'Helvetica Neue',Arial,sans-serif;line-height:1.2}table{border-co=
- llapse:collapse;mso-table-lspace:0;mso-table-rspace:0;table-layout:fixed;ma=
- rgin:0 auto}a,a:link,a:visited,a:hover{color:#259fc4}.appleLinksExp a{color=
- :#a3a195;text-decoration:none}.appleLinksExpRed a{color:#db514f;text-decora=
- tion:none}@media only
- screen and (max-device-width:480px){*[class].super{padding:0 10px 10px 10p=
- x!important}*[class].mainFeature .center{text-align:center!important}*[clas=
- s].mainFeature .offerbutton-c{width:60%!important}*[class].mainFeature .tit=
- le a{font-size:22px!important;line-height:1.2!important}*[class].c-header{f=
- ont-size:30px!important}*[class].offerbutton-c{margin:0 auto!important;widt=
- h:100%!important}*[class].offerbutton-c{display:block!important}*[class].ex=
- p-c{font-size:12px!important;width:100%!important;line-height:1.4!important=
- ;padding-bottom:10px!important}*[class].offerbutton-c div{text-align:left!i=
- mportant}*[class].offerbutton-c div a{width:100%!important}*[class].offerLo=
- go-c{height:100px!important}*[class].offerLogo-c img{width:100px!important}=
- *[class].title,*[class].storeName,*[class].title
- a,*[class].storeName a{line-height:1!important}*[class].title a{font-size:=
- 15px!important;font-weight:500!important}*[class].title{padding-top:5px!imp=
- ortant}}
- =2ESTYLE4 {color: #999999}
- =2ESTYLE5 {color: #0000CC; text-decoration:underline}
- </style>
- <!--[if IEMobile 7]>
- <style type=3D"text/css"></style>
- <![endif]-->
- </head>
- <body style=3D"" class=3D"">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"margin: 0; padding: 0; width: 100%!important; line-height: 100%!impo=
- rtant; background: #efefe9;">
- <tr>
- <td align=3D"center" valign=3D"top" width=3D"100%" style=3D"background:#663=
- 379;line-height:0"><span class=3D"preHeader" style=3D"color:#663379;font-si=
- ze:1px">Check out the best deals from your favorite stores!</span></td>
- </tr>
- <tr>
- <td align=3D"center" valign=3D"top" width=3D"100%" style=3D"background:#663=
- 379;padding:10px 0"><a href=3D"http://peud.aicema.top/edmi/tl.php?p=3Ds6/s4=
- /rs/ycv/rw/rs//http%3A%2F%2Fpeud.aicema.top%2Fspecial%2Fsunglasses.html"> <=
- img width=3D"140" src=3D"http://peud.aicema.top/img/RetailMeNotLogoNL.png" =
- alt=3D"RetailMeNot" title=3D"RetailMeNot" /> </a></td>
- </tr>
- <tr>
- <td>
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0">
- <tr>
- <td align=3D"center" valign=3D"top" width=3D"600" class=3D"super" style=3D"=
- padding:20px 10px;box-sizing:border-box">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0">
- <tr>
- <td align=3D"center" class=3D"c-header" style=3D"font-size:32px;font-weight=
- :500;color:#222;padding:0 10px 30px 10px;line-height:1.2">Haloween's Best S=
- unglasses Deals!</td>
- </tr>
- <tr>
- <td width=3D"100%" class=3D"mainFeature" style=3D"padding-bottom:20px">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"width: 100%;">
- <tr>
- <td valign=3D"top" width=3D"100%" style=3D"width: 100%;">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"width: 100%;">
- <tr>
- <td width=3D"100%" style=3D"background:#fff;padding:20px 10px">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"width: 100%;">
- <tr>
- <td align=3D"center" class=3D"offerLogo-c" style=3D"width: 100%;"><a href=
- =3D"http://peud.aicema.top/edmi/tl.php?p=3Ds6/s4/rs/ycv/rw/rs//http%3A%2F%2=
- Fpeud.aicema.top%2Fspecial%2Fsunglasses.html" style=3D"color:#259fc4;text-d=
- ecoration:none"> <img width=3D"350" src=3D"http://peud.aicema.top/img/ho22D=
- pL.jpg" alt=3D"sunglasses" style=3D"display:block" title=3D"sunglasses" /><=
- /a></td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td width=3D"100%" style=3D"background:#fff;padding:15px 20px 0">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"width: 100%;">
- <tr>
- <td align=3D"left" class=3D"center" style=3D"background: #FFFFFF; width: 10=
- 0%; font-size: 18px;"><a href=3D"http://peud.aicema.top/edmi/tl.php?p=3Ds6/=
- s4/rs/ycv/rw/rs/Ugg%20Australia/http%3A%2F%2Fpeud.aicema.top%2Fspecial%2Fsu=
- nglasses.html" target=3D"_blank" title=3D"Ugg Australia" style=3D"color:#64=
- 6464;text-decoration:none">Ray Ban & Oakley Sunglasses</a></td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td width=3D"100%" style=3D"background:#fff;padding:15px 20px">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"width: 100%;">
- <tr>
- <td align=3D"left" class=3D"title center" style=3D"width: 100%; background:=
- #FFFFFF;"><a href=3D"http://peud.aicema.top/edmi/tl.php?p=3Ds6/s4/rs/ycv/r=
- w/rs//http%3A%2F%2Fpeud.aicema.top%2Fspecial%2Fsunglasses.html" target=3D"_=
- blank" style=3D"color:#259fc4;text-decoration:none;font-weight:500;font-siz=
- e:28px;line-height:1.3">All 80% Off RayBan Sunglasses Styles</a>></td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td align=3D"left" class=3D"exp-c center" style=3D"width: 50%; font-size: 1=
- 4px; background: #fff; padding: 0 20px;"><span class=3D"appleLinksExp"><b>E=
- xpires Soon!</b></span></td>
- </tr>
- <tr>
- <td width=3D"100%" style=3D"background:#fff;padding:20px;border-bottom:1px =
- solid #d1d0c9">
- <table align=3D"center" border=3D"0" cellpadding=3D"0" cellspacing=3D"0" st=
- yle=3D"width: 100%;">
- <tr>
- <td align=3D"right" class=3D"offerbutton-c" style=3D"width: 100%;">
- <div><a href=3D"http://peud.aicema.top/edmi/tl.php?p=3Ds6/s4/rs/ycv/rw/rs//=
- http%3A%2F%2Fpeud.aicema.top%2Fspecial%2Fsunglasses.html" style=3D"backgrou=
- nd-color: #259fc4; border-radius: 4px; color: #ffffff; display: inline-bloc=
- k; font-size: 18px; line-height: 40px; text-align: center; text-decoration:=
- none; width: 180px; -webkit-text-size-adjust: none; letter-spacing: 1px; f=
- ont-family: sans-serif;">Get Deal</a></div>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td align=3D"center" valign=3D"top" width=3D"100%" style=3D"width: 100%; pa=
- dding: 20px 0;">
- <div><a href=3D"http://peud.aicema.top/edmi/tl.php?p=3Ds6/s4/rs/ycv/rw/rs//=
- http%3A%2F%2Fpeud.aicema.top%2Fspecial%2Fsunglasses.html" style=3D"backgrou=
- nd-color: #efefe9; border: 2px solid #259fc4; border-radius: 4px; color: #2=
- 59fc4; display: inline-block; font-family: sans-serif; font-size: 24px; lin=
- e-height: 52px; text-align: center; text-decoration: none; width: 240px; -w=
- ebkit-text-size-adjust: none; mso-hide: all; letter-spacing: 1px;">See More=
- Deals</a></div>
- </td>
- </tr>
- <tr>
- <td class=3D"hb" style=3D"border-collapse:collapse!important;display:table-=
- cell!important;padding:20px 0 10px">
- <hr style=3D"background: #c9c9c9; border: 0; color: #c9c9c9; height: 2px;" =
- />
- </td>
- </tr>
- <tr>
- <td align=3D"center" style=3D"border-collapse:collapse!important;padding-to=
- p:20px"><img style=3D"display:block" src=3D"http://peud.aicema.top/img/foot=
- er-rmn.png" /></td>
- </tr>
- <tr>
- <td align=3D"center" style=3D"border-collapse:collapse!important;padding:20=
- px 0"><span><img width=3D"36" src=3D"http://peud.aicema.top/img/facebook-pr=
- intablel2013.png" alt=3D"facebook" /></span><span><img width=3D"36" src=3D"=
- http://peud.aicema.top/img/twitter-printablel2013.png" alt=3D"twitter" /></=
- span><span><img width=3D"36" src=3D"http://peud.aicema.top/img/gplus-printa=
- blel2013.png" alt=3D"g+" /></span><span> <img width=3D"36" src=3D"http://pe=
- ud.aicema.top/img/pinterest-printablel2013.png" alt=3D"pinterest" /></span>=
- </td>
- </tr>
- <tr>
- <td align=3D"center" style=3D"border-collapse:collapse!important;font-size:=
- 10px;color:#a3a195;padding:0 20px 2px 20px;line-height:1.3">If you do not w=
- ish to receive any further communications of this type, <a href=3D"http://p=
- eud.aicema.top/edmi/u.php?p=3Ds6/rs/ycv/rw/s4/rs"><span style=3D"color: #25=
- 9fc4; text-decoration: none;">unsubscribe</span></a></td>
- </tr>
- <tr>
- </tr>
- <tr>
- <td align=3D"center" style=3D"border-collapse:collapse!important;font-size:=
- 10px;color:#0000FF;line-height:1.6;padding:0 20px 2px 20px"><span class=3D"=
- STYLE4">Some of these deals feature products with limited quantities. Price=
- s and quantities may be subject to change by retailers at their discretion.=
- </span></td>
- </tr>
- <tr>
- </tr>
- <tr>
- <td align=3D"center" style=3D"border-collapse:collapse!important;font-size:=
- 10px;color:#0000FF;line-height:1.6;padding:0 20px 2px 20px"><span class=3D"=
- STYLE4">Disclaimer: The CAN-SPAM Act of 2003 establishes requirements for t=
- hose who send commercial email, spells out penalties for spammers and compa=
- nies whose products are advertised in spam if they violate the law, and giv=
- es consumers the right to ask mailers to stop spamming them. The above mail=
- is in accordance to the Can Spam act of 2003: There are no deceptive subje=
- ct lines and is a manual process through our efforts on World Wide Web. </s=
- pan></td>
- </tr>
- <tr>
- <td align=3D"center" style=3D"border-collapse:collapse!important;font-size:=
- 10px;color:#0000FF;line-height:1.6;padding:0 20px 20px 20px"><span class=3D=
- "STYLE4">Copyright 2017 <span class=3D"appleLinksExp">RetailMeNot, Inc., 30=
- 1 Congress Avenue Suite 700, Austin, TX, 78701 USA</span> </span></td>
- </tr>
- </table>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- </table>
- <div style=3D"display:none; white-space:nowrap; font:15px courier; color:#f=
- fffff;">- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -</=
- div>
- <img src=3D"http://peud.aicema.top/edmi/to.php?p=3Ds6/s4/rs/ycv/rw/rs" widt=
- h=3D"5" height=3D"2" alt=3D".">
- </body></html>
- --b1_09e2d7ab2ce6993206583b5ac2e7bb89--
- █▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█
- █ LINKS █
- █▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█
- http://aethon[.]zouqkuaijb[.]icu/Y2xpY2syMDExMDU/WU9VUk1PTUBNSS5ORVQ=/OTExMzk=_c21.html (link in email base64 encoded email of recipient)
- https://www[.]rbglsj[.]com/index.php?main_page=index&cPath=18 (fake ray ban shop)
- █▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█
- █ HOST █
- █▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█
- aethon.zouqkuaijb.icu [104.18.43.146]
- AS13335
- Country: US
- Registration Date: 2010-07-14
- Registrar: arin
- Owner: CLOUDFLARENET, US
- https://www.virustotal.com/gui/ip-address/104.18.43.146/relations
- rbglsj.com [172.87.223.61]
- AS26658
- Country: US
- Registration Date: 2014-04-17
- Registrar: arin
- Owner: HENGTONG-IDC-LLC, US
- https://www.virustotal.com/gui/ip-address/172.87.223.61/relations
- █▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█▀▀▀▀▀▀█
- █ REGISTRAR █
- █▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█▄▄▄▄▄▄█
- Domain Name: zouqkuaijb.icu
- Registrar: West263 International Limited
- Registrar URL: www.hkdns.hk
- Registered On: 2020-11-02
- Domain Name: rbglsj.com
- Registrar: Atak Domain Hosting Internet ve Bilgi Teknolojileri Limited Sirketi d/b/a Atak Teknoloji
- Registrar URL: www.atakdomain.com
- Registered On: 2020-11-02
Add Comment
Please, Sign In to add comment