Welcome To Our Shell

Mister Spy & Souheyl Bypass Shell

Current Path : /home/ift/mails/30/

Linux ift1.ift-informatik.de 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
Upload File :
Current File : //home/ift/mails/30/1523851652.zrspam.307282_2018_04_16

From dirkeabqhrcbaumgartner@grovinpat.com  Mon Apr 16 06:07:32 2018
Return-Path: <dirkeabqhrcbaumgartner@grovinpat.com>
X-Original-To: cgabriel@ift-informatik.de
Delivered-To: cgabriel@ift-informatik.de
Received: by ift-informatik.de (Postfix, from userid 5555)
	id 128FA3D20001A; Mon, 16 Apr 2018 06:07:32 +0200 (CEST)
Received: from localhost by h2486555.stratoserver.net
	with SpamAssassin (version 3.4.0);
	Mon, 16 Apr 2018 06:07:32 +0200
From: =?UTF-8?Q?Dirk_Baumgartner?= <dirkeabqhrcbaumgartner@grovinpat.com>
To: <darjan.peric@ift-informatik.de>
Subject: *****SPAM***** =?UTF-8?Q?Kein_Warmwasser=3F_Warmwasserger=C3=A4t_f=C3=BCr_Armatur,_erhitzt_Wasser_gleich?=
Date: Mon, 16 Apr 2018 06:07:29 +0200
Message-Id: <MCPVJGINBTOCVUMDLDMBCHQWLRN@kmkzq.grovinpat.com>
X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
	h2486555.stratoserver.net
X-Spam-Flag: YES
X-Spam-Level: ******************
X-Spam-Status: Yes, score=18.8 required=5.0 tests=AXB_XM_FORGED_OL2600,
	BAYES_50,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FORGED_MUA_OUTLOOK,
	FORGED_OUTLOOK_TAGS,HTML_IMAGE_ONLY_12,HTML_MESSAGE,HTML_SHORT_LINK_IMG_1,
	MSGID_SPAM_CAPS,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_BRBL_LASTEXT,RCVD_IN_RP_RNBL,
	RDNS_NONE,URIBL_BLOCKED,URIBL_DBL_SPAM,URIBL_JP_SURBL,URIBL_SBL,URIBL_SBL_A
	autolearn=spam autolearn_force=no version=3.4.0
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_5AD42184.BC9AC270"

This is a multi-part message in MIME format.

------------=_5AD42184.BC9AC270
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Spam detection software, running on the system "h2486555.stratoserver.net",
has identified this incoming email as possible spam.  The original
message has been attached to this so you can view it or label
similar future email.  If you have any questions, see
@@CONTACT_ADDRESS@@ for details.

Content preview:  Kein Warmwasser? Warmwassergerät für Armatur, erhitzt Wasser
   gleich: http://h.grovinpat.com Hier können Sie sich abmelden: http://grovinpat.com/ub.php?e1x=qlb5785308kqyk9k019wttbqtx8bp4atecq
   Kein Warmwasser? Warmwassergerät für Armatur, erhitzt Wasser gleich [...]
   

Content analysis details:   (18.8 points, 5.0 required)

 pts rule name              description
---- ---------------------- --------------------------------------------------
 1.2 URIBL_JP_SURBL         Contains an URL listed in the JP SURBL blocklist
                            [URIs: grovinpat.com]
 0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was blocked.
                            See
                            http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                             for more information.
                            [URIs: grovinpat.com]
 1.7 URIBL_DBL_SPAM         Contains an URL listed in the DBL blocklist
                            [URIs: grovinpat.com]
 1.3 RCVD_IN_RP_RNBL        RBL: Relay in RNBL,
                            https://senderscore.org/blacklistlookup/
                          [207.150.183.101 listed in bl.score.senderscore.com]
 1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
             [Blocked - see <http://www.spamcop.net/bl.shtml?207.150.183.101>]
 0.1 URIBL_SBL_A            Contains URL's A record listed in the SBL blocklist
                            [URIs: grovinpat.com]
 1.6 URIBL_SBL              Contains an URL's NS IP listed in the SBL blocklist
                            [URIs: grovinpat.com]
 3.1 MSGID_SPAM_CAPS        Spam tool Message-Id: (caps variant)
 0.0 HTML_MESSAGE           BODY: HTML included in message
 2.1 HTML_IMAGE_ONLY_12     BODY: HTML: images with 800-1200 bytes of words
 0.8 BAYES_50               BODY: Bayes spam probability is 40 to 60%
                            [score: 0.5000]
-0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author's
                            domain
 0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature
 1.4 RCVD_IN_BRBL_LASTEXT   RBL: No description available.
                           [207.150.183.101 listed in bb.barracudacentral.org]
 0.0 HTML_SHORT_LINK_IMG_1  HTML is very short with a linked image
 0.8 RDNS_NONE              Delivered to internal network by a host with no rDNS
 0.1 FORGED_OUTLOOK_TAGS    Outlook can't send HTML in this format
 1.4 AXB_XM_FORGED_OL2600   Forged OE v. 6.2600
 1.9 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam.  If you wish to view
it, it may be safer to save it to a file and open it with an editor.


------------=_5AD42184.BC9AC270
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: attachment
Content-Transfer-Encoding: 8bit

Received: from taunt.grovinpat.com (unknown [207.150.183.101])
	by ift-informatik.de (Postfix) with ESMTP id 410D43D200019
	for <darjan.peric@ift-informatik.de>; Mon, 16 Apr 2018 06:07:30 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=dkim; d=grovinpat.com;
 h=Date:To:From:Message-ID:Subject:MIME-Version:List-Unsubscribe:Content-Type:Content-Transfer-Encoding; i=dirkeabqhrcbaumgartner@grovinpat.com;
 bh=G+P6a1x5+QgvPCNeREym+c707k4=;
 b=UGojCvHjofP71udqRMs7M/Y8wjs2POcB1qFX6SUmpUfXymV4T2exlMyCnaq/vh6hITuxk2581+VP
   x78l1stEoxNBgIliR+kPMmrWA5N6q3E2p/czGvxS1nrH4/99Ynm0/b6LvIjy09hgjYII7ZkK31gP
   6d5TnJS8LW/+aIKCnpc=
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=dkim; d=grovinpat.com;
 b=UWIDYrfpA7raDTwm5xuwuleROIaqWAhu5yOmi8I5+cV9lrVTDztQW7iNtB+CpBztaKDsv0jHf7c1
   o2rIpDUJz30aHRj8BN6Xav8t3rTzhBSHomXHOM93pszvV+4PBBgUPGSzaUqQHZIgUj5wRNbE2MJv
   6dJTuo+OB+sKHj0Qv4c=;
Date: Mon, 16 Apr 2018 06:07:29 +0200
To:  <darjan.peric@ift-informatik.de>
From: =?UTF-8?Q?Dirk_Baumgartner?= <dirkeabqhrcbaumgartner@grovinpat.com>
Message-ID: <MCPVJGINBTOCVUMDLDMBCHQWLRN@kmkzq.grovinpat.com>
Subject: =?UTF-8?Q?Kein_Warmwasser=3F_Warmwasserger=C3=A4t_f=C3=BCr_Armatur,_erhitzt_Wasser_gleich?=
MIME-Version: 1.0
X-Report-Abuse:  <http://grovinpat.com/aa.php?a=qlb5785308kqyk9k019wttbqtx8bp4atecq>
List-Unsubscribe:  <http://grovinpat.com/ub.php?b=qlb5785308kqyk9k019wttbqtx8bp4atecq>
Precedence: bulk
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-Type: multipart/alternative; boundary=b1_ynxs82hx1fzvtbw4n3qy0aaz.YdR7p2; charset="UTF-8"
Content-Transfer-Encoding: 8bit

--b1_ynxs82hx1fzvtbw4n3qy0aaz.YdR7p2
Content-Type: text/plain; format=flowed; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable


=0D
Kein Warmwasser? Warmwasserger=C3=A4t f=C3=BCr Armatur, erhitzt Wasser glei=
ch:=0D
http://h.grovinpat.com=0D
=0D
=0D
=0D
Hier k=C3=B6nnen Sie sich abmelden:=0D
http://grovinpat.com/ub.php?e1x=3Dqlb5785308kqyk9k019wttbqtx8bp4atecq=0D


--b1_ynxs82hx1fzvtbw4n3qy0aaz.YdR7p2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable


<!DOCTYPE html>=0D
<html>=0D
=0D
<head>=0D
</head><body>=0D
Kein Warmwasser? Warmwasserger=C3=A4t f=C3=BCr Armatur, erhitzt Wasser glei=
ch<br /><a style=3D"font-size:large; font-family:; " href=3D"http://h.grovi=
npat.com/"><img src=3D"http://ysc.grovinpat.com/00.jpg" style=3D"border-top=
-color:#cc0000; " /></a>=0D
<br /><a style=3D"font-size:16px; font-family:; " href=3D"http://h.grovinpa=
t.com/">DIGITALER=C2=A0Wassererhitzer: Innerhalb von 3 Sek. Wassertemperatu=
r bis zu 60 Grad</a>=0D
<br /><br /><br /><br />Boiler zu langsam? Gleich l=C3=A4uft Warmwasser f=
=C3=BCr H=C3=A4ndewaschen, Geschirrsp=C3=BClen<br /><br /><a href=3D"http:/=
/grovinpat.com/ub.php?pn=3Dqlb5785308kqyk9k019wttbqtx8bp4atecq" style=3D" f=
ont-size:12px; background-color:#ffffff;">Bitte um L=C3=B6schen der eingetr=
agenen E-Mail-Adresse aus dem Verteiler</a>=0D
<img src=3D"http://grovinpat.com/ob.php?e1x=3Dqlb5785308kqyk9k019wttbqtx8bp=
4atecq" />=0D
</body>=0D
</html>=

--b1_ynxs82hx1fzvtbw4n3qy0aaz.YdR7p2--

------------=_5AD42184.BC9AC270--


bypass 1.0, Devloped By El Moujahidin (the source has been moved and devloped)
Email: contact@elmoujehidin.net bypass 1.0, Devloped By El Moujahidin (the source has been moved and devloped) Email: contact@elmoujehidin.net