OwlCyberSecurity - MANAGER
Edit File: 1745301038.M807619P4053964.premium128.web-hosting.com,S=10707,W=10879:2,
Return-Path: <sales@psisigmetech.com> Delivered-To: contact+spam@gourayafroid.com Received: from premium128.web-hosting.com by premium128.web-hosting.com with LMTP id ACWKIy4uB2jM2z0AAvhI2g (envelope-from <sales@psisigmetech.com>) for <contact+spam@gourayafroid.com>; Tue, 22 Apr 2025 01:50:38 -0400 Return-path: <sales@psisigmetech.com> Envelope-to: contact@gourayafroid.com Delivery-date: Tue, 22 Apr 2025 01:50:38 -0400 Received: from [192.227.217.197] (port=64181 helo=192-227-217-197-host.colocrossing.com) by premium128.web-hosting.com with esmtp (Exim 4.98.1) (envelope-from <sales@psisigmetech.com>) id 1u76Wd-0000000H0yS-3r2o for contact@gourayafroid.com; Tue, 22 Apr 2025 01:50:37 -0400 From: gourayafroid.com <sales@psisigmetech.com> To: contact@gourayafroid.com Date: 22 Apr 2025 07:49:50 +0200 Message-ID: <20250422074950.06212A4A1D5BE1F4@psisigmetech.com> MIME-Version: 1.0 Content-Type: text/html Content-Transfer-Encoding: quoted-printable X-Spam-Status: Yes, score=40.9 X-Spam-Score: 409 X-Spam-Bar: ++++++++++++++++++++++++++++++++++++++++ X-Spam-Report: Spam detection software, running on the system "premium128.web-hosting.com", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: VERIFY contact@gourayafroid.com. Take Immediate Action We've detected unusual activity associated with your account. To ensure your security, certain features have been restricted temporarily. Content analysis details: (40.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URI: bafkreif6pdnlt7y2yok4mvbmjyvy7wc43hpaty4lpac5evijmei7a2urzm.ipfs.dweb.link] 0.5 JMQ_SPF_NEUTRAL ASKDNS: SPF set to ?all [psisigmetech.com TXT:v=spf1 a mx ptr] [a:psisigmetech.com ip4:107.174.235.126] [?all] 0.1 URIBL_SBL_A Contains URL's A record listed in the Spamhaus SBL blocklist [URI: bafkreif6pdnlt7y2yok4mvbmjyvy7wc43hpaty4lpac5evijmei7a2urzm.ipfs.dweb.link/209.94.90.3] [URI: bafkreif6pdnlt7y2yok4mvbmjyvy7wc43hpaty4lpac5evijmei7a2urzm.ipfs.dweb.link/209.94.90.2] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [192.227.217.197 listed in sa-accredit.habeas.com] 0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [192.227.217.197 listed in sa-trusted.bondedsender.org] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [192.227.217.197 listed in bl.score.senderscore.com] 1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist [URI: bafkreif6pdnlt7y2yok4mvbmjyvy7wc43hpaty4lpac5evijmei7a2urzm.ipfs.dweb.link] 0.0 T_SPF_HELO_TEMPERROR SPF: test of HELO record failed (temperror) 0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict Alignment 3.0 KAM_DMARC_REJECT DKIM has Failed or SPF has failed on the message and the domain has a DMARC reject policy 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 T_MXG_EMAIL_FRAG BODY: URI with email in fragment 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.0 PDS_FROM_NAME_TO_DOMAIN From:name looks like To:domain 2.2 URI_DWEBIPFS References Interplanetary File System PtP content via dweb.link, likely phishing 0.0 PDS_FRNOM_TODOM_DBL_URL From Name to domain, double URL 3.9 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr 2) 0.0 PDS_FRNOM_TODOM_NAKED_TO Naked to From name equals to Domain 18 KAM_IPFS Abused Protocol for Distributed Content 2.0 RDNS_NONE Delivered to internal network by a host with no rDNS 0.0 URI_IPFS References Interplanetary File System PtP content, probable phishing 0.0 TO_NO_BRKTS_NORDNS_HTML To: lacks brackets and no rDNS and HTML only 1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 2.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50% [cf: 100] 5.0 KAM_SOMETLD_ARE_BAD_TLD .bar, .beauty, .buzz, .cam, .casa, .cfd, .club, .date, .guru, .link, .live, .monster, .online, .press, .pw, .quest, .rest, .sbs, .shop, .stream, .top, .trade, .wiki, .work, .xyz TLD abuse 0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe X-Spam-Flag: YES Subject: ***SPAM*** Attention: Unusual Sign-in Alert! [Action Required] <!DOCTYPE HTML> <html><head><title></title> <meta http-equiv=3D"X-UA-Compatible" content=3D"IE=3Dedge"> </head> <body style=3D"margin: 0.4em; font-size: 14pt;"><p><br class=3D"Apple-inter= change-newline"></p> <table width=3D"600" style=3D"border-radius: 10px; color: rgb(51, 51, 51); = text-transform: none; letter-spacing: normal; overflow: hidden; font-family= : Arial, sans-serif; font-size: 14px; font-style: normal; font-weight: 400;= word-spacing: 0px; white-space: normal; border-collapse: collapse; max-wid= th: 600px; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); fon= t-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke= -width: 0px; text-decoration-thickness: initial;=20 text-decoration-style: initial; text-decoration-color: initial;"><tbody sty= le=3D"box-sizing: border-box;"><tr style=3D"box-sizing: border-box;"><td st= yle=3D"margin: 0px; padding: 20px; text-align: center; box-sizing: border-b= ox; background-color: rgb(0, 64, 133);"><font color=3D"#eeeeee" style=3D"bo= x-sizing: border-box;"><span style=3D"font-weight: bolder; box-sizing: bord= er-box;">VERIFY <span><span> </span><a style=3D"color: rgb(17, 85= , 204);" target=3D"_blank">contact@gourayafroid.com.</a></span></span></fon= t> <br style=3D"box-sizing: border-box;"></td></tr><tr style=3D"box-sizing: bo= rder-box;"><td style=3D"margin: 0px; padding: 30px; box-sizing: border-box;= "><h1 style=3D"text-align: center; color: rgb(0, 64, 133); line-height: 1.2= ; font-size: 24px; font-weight: 500; margin-top: 0px; margin-bottom: 20px; = box-sizing: border-box;">Take Immediate Action</h1> <p style=3D"color: rgb(51, 51, 51); text-transform: none; text-indent: 0px;= letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f= ont-style: normal; font-weight: 400; margin-top: 0px; word-spacing: 0px; wh= ite-space: normal; box-sizing: border-box; background-color: rgb(255, 255, = 255); font-variant-ligatures: normal; font-variant-caps: normal; text-decor= ation-style: initial; text-decoration-color: initial;"> We've detected unusual activity associated with your account. To ensure you= r security, certain features have been restricted temporarily.</p> <p style=3D"color: rgb(51, 51, 51); text-transform: none; text-indent: 0px;= letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f= ont-style: normal; font-weight: 400; margin-top: 0px; word-spacing: 0px; wh= ite-space: normal; box-sizing: border-box; background-color: rgb(255, 255, = 255); font-variant-ligatures: normal; font-variant-caps: normal; text-decor= ation-style: initial; text-decoration-color: initial;"> Please confirm this activity and restore your account functionality by veri= fying your email user id</p><p style=3D"margin: 30px 0px; text-align: cente= r; box-sizing: border-box;"> <a style=3D"padding: 12px 30px; border-radius: 5px; color: rgb(255, 255, 25= 5); font-size: 16px; font-weight: bold; box-sizing: border-box; background-= color: rgb(0, 64, 133);" href=3D"https://bafkreif6pdnlt7y2yok4mvbmjyvy7wc43= hpaty4lpac5evijmei7a2urzm.ipfs.dweb.link/#contact@gourayafroid.com" target= =3D"_blank" rel=3D"noreferrer"=20 data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://bafkreif6pdn= lt7y2yok4mvbmjyvy7wc43hpaty4lpac5evijmei7a2urzm.ipfs.dweb.link/%23%5B%5B-Em= ail-%5D%5D&source=3Dgmail&ust=3D1745385418948000&usg=3DAOvVaw0D= hQ0t0NeOq3TwMIDLenlG">Check Email</a></p> <p style=3D"color: rgb(51, 51, 51); text-transform: none; text-indent: 0px;= letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f= ont-style: normal; font-weight: 400; margin-top: 0px; word-spacing: 0px; wh= ite-space: normal; box-sizing: border-box; background-color: rgb(255, 255, = 255); font-variant-ligatures: normal; font-variant-caps: normal; text-decor= ation-style: initial; text-decoration-color: initial;"> If you believe this action was taken in error, please contact our support t= eam immediately.</p> <p style=3D"color: rgb(51, 51, 51); text-transform: none; text-indent: 0px;= letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f= ont-style: normal; font-weight: 400; margin-top: 0px; word-spacing: 0px; wh= ite-space: normal; box-sizing: border-box; background-color: rgb(255, 255, = 255); font-variant-ligatures: normal; font-variant-caps: normal; text-decor= ation-style: initial; text-decoration-color: initial;">Thank you for your c= ooperation.</p></td></tr> <tr style=3D"box-sizing: border-box;"><td style=3D"margin: 0px; padding: 15= px; text-align: center; color: rgb(119, 119, 119); font-size: 12px; box-siz= ing: border-box; background-color: rgb(247, 249, 252);"><p style=3D"margin-= top: 0px; box-sizing: border-box;">© 2025. All rights reserved.</p></t= d></tr></tbody></table></body></html>