Using hacked servers/accounts to send fraud spam: skynelworldwide.com (hosting mail service)

skynelworldwide.com. 599 IN A 34.102.136.180
skynelworldwide.com. 3599 IN MX 0 skynelworldwide-com.mail.protection.outlook.com.
skynelworldwide-com.mail.protection.outlook.com. 9 IN A 104.47.21.36
skynelworldwide-com.mail.protection.outlook.com. 9 IN A 104.47.20.36

Received: from host1.hostingphilippines.com (unknown [64.91.226.65])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by xx; Fri, 20 Nov 2020 04:22:05 -0500 (EST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=grassartcollection.com; s=default; h=Date:Reply-To:MIME-Version:
Content-Type:To:Subject:From:Sender:Message-ID:Cc:Content-Transfer-Encoding:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id:
List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;
bh=xx
Received: from [185.65.134.169] (port=xx helo=WIN-ETGQQT9LA10)
by host1.hostingphilippines.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.93)
(envelope-from <amy@skynetworldwide.com>)
id xx; Fri, 20 Nov 2020 04:22:03 -0500
From: «Amy Lewis» <amy@skynetworldwide.com>
To: «xx
Content-Type: multipart/alternative; boundary=»xx»
MIME-Version: 1.0
Reply-To: «Amy Lewis» <amy@skynelworldwide.com>
Date: Fri, 20 Nov 2020 01:22:02 -0800
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname — host1.hostingphilippines.com
X-AntiAbuse: Original Domain — xx
X-AntiAbuse: Originator/Caller UID/GID — x
X-AntiAbuse: Sender Address Domain — skynetworldwide.com
X-Get-Message-Sender-Via: host1.hostingphilippines.com: authenticated_id: office@grassartcollection.com
X-Authenticated-Sender: host1.hostingphilippines.com: office@grassartcollection.com
X-Source:
X-Source-Args:
X-Source-Dir:
Subject: [Admin Notice] — Bill notice

This is a multi-part message in MIME format

—xxx
Content-Type: text/plain; charset=»utf-8″
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Hi ,
RE: Balance Due: $140.34=20
Hope you’re doing well. I have sent a number of mails regarding the a=
mount owed. We have received no response till date. We kindly urge you=
to settle the outstanding amount as soon as posisble to avoid any leg=
al action.=20

Feel free to contact me if you need any further information. =20

Thanks,
Amy Lewis
Accounting Department

SKYNET USA LLC

Office 631.464.3847

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *