Voilà: j'ai eu un message similaire; voici l'en-tête
Return-path: <cream@totalcreate.jp>
Delivery-date: Wed, 06 Feb 2019 08:41:30 +0100
Received: from mi006.mc1.hosteurope.de ([80.237.138.249])
by wp132.webpack.hosteurope.de running ExIM with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
id 1grHpq-0006bR-4d; Wed, 06 Feb 2019 08:41:30 +0100
Received: from totalcreate.jp ([61.126.6.12])
by mx0.webpack.hosteurope.de (mi006.mc1.hosteurope.de) with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256)
id 1grHpp-0005kb-Dq
for x@y; Wed, 06 Feb 2019 08:41:30 +0100
Received: from [] (unknown [45.231.120.114])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(Client did not present a certificate)
by totalcreate.jp (Postfix) with ESMTPSA id BF84EFC1148A
for <x@y>; Wed, 6 Feb 2019 16:41:23 +0900 (JST)
List-ID: nokrsy1jgibmz606lamsl69yd.yxa8dkm66kxuioeeetxa31b78qnk
List-Help:
<
http://www.totalcreate.jp/lists/?p=pref … ke3gw3tpj5>
X-Abuse-Reports-To: <abuse@totalcreate.jp>
X-Sender: <cream@totalcreate.jp>
Subject: x
List-Subscribe: <
http://totalcreate.jp/mailman/listinfo/socszvxxy>
From: <x@y>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:27.0) Gecko/20100101
Thunderbird/27.0
Abuse-Reports-To: abuse@mail.totalcreate.jp
To: x@y
Content-Transfer-Encoding: base64
Content-Type: text/plain; charset=UTF-8
X-aid: 1535146168
X-Sender-Info: cream@totalcreate.jp
Message-ID: <siv9qcp-sgjk7w-69@totalcreate.jp>
Date: Wed, 6 Feb 2019 08:41:24 +0100
Organization: Fxswgrduyusyf
X-HE-Virus-Scanned: Yes
X-HE-Spam-Level: +++++++++++++++++++++++++++++++
X-HE-Spam-Score: 31.4
X-HE-Spam-Report: Content analysis details: (31.4 points)
pts rule name description
---- ---------------------- --------------------------------------------------
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[45.231.120.114 listed in zen.spamhaus.org]
1.5 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server
[45.231.120.114 listed in dnsbl.sorbs.net]
0.7 LOCALPART_IN_SUBJECT Local part of To: address appears in Subject
0.5 HE_CPSD HE Phishing & Scam detected
[Sanesecurity.Phishing.Fake.Coin.27622.UNOFFICIAL(76c05dbc4b2469af90216e3b560f7694:4116)]
2.5 BITCOIN_SPAM_03 BitCoin spam pattern 03
5.0 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin
3.0 TO_NAME_SUBJ_NO_RDNS Recipient username in subject + no rDNS
7.5 HE_CPSD_SANE SPAM found by SaneSecurity signatures
2.5 BITCOIN_SPAM_02 BitCoin spam pattern 02
3.0 BITCOIN_SPAM_07 BitCoin spam pattern 07
1.6 FORGED_MUA_MOZILLA Forged mail pretending to be from Mozilla
X-SPAM-FLAG: Yes
X-HE-SPF: PASSED
Envelope-to: x@y
Noter que Host-Europe l'identifie comme spam d'extorsion.
rené
Dernière modification par ottr (07-02-2019 00:01:45)