ICS Labs identified malicious URL in email communication from IP 201.76.49.210, Subject: RE: PAP - E ...
show moreICS Labs identified malicious URL in email communication from IP 201.76.49.210, Subject: RE: PAP - ELISA ELLEN LIMA DOS SANTOS
show less
Received: from mail49210.delibird0003.locaweb.com.br (mail49210.delibird0003.locaweb.com.br [201.76. ...
show moreReceived: from mail49210.delibird0003.locaweb.com.br (mail49210.delibird0003.locaweb.com.br [201.76.49.210])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(Client did not present a certificate)
by a2-snowball3.uhserver.com (Postfix) with ESMTPS id 4cYtbb1LCnzKLKFJ
Sat, 27 Sep 2025 13:44:57 -0300 (-03)
show less
2023-09-14T22:33:39+02:00 ds01 postfix/smtpd[30128]: connect from mail49210.hm1479.locaweb.com.br[20 ...
show more2023-09-14T22:33:39+02:00 ds01 postfix/smtpd[30128]: connect from mail49210.hm1479.locaweb.com.br[201.76.49.210]
...
show less
received unsolicited smtp data stream:
Received: from mcbain0012.email.locaweb.com.br (189.126.112.1 ...
show morereceived unsolicited smtp data stream:
Received: from mcbain0012.email.locaweb.com.br (189.126.112.16) by mail4970.hm1479.locaweb.com.br id hi4qa82n8lg7 for <[email protected]>; Tue, 20 Jun 2023 02:09:56 -0300 (envelope-from <[email protected]>)
Received: from dragonite0050.email.locaweb.com.br (dragonite0050.email.locaweb.com.br [10.31.120.189])
by mcbain0012.email.locaweb.com.br (Postfix) with ESMTP id 8D1B88C052F;
Tue, 20 Jun 2023 02:19:40 -0300 (-03)
x-locaweb-id: M1D_wUnyMZuJFdOgXdd5GaN0cPLRzTSJ0aN6zPE3yM4RGa2K1_1QR0ArSaI3wl6Wgt5WI-qO6A2KHtVQ3igUAwdyKrAxj7gs3eV4kv6MBIU0tdTjSxVT8cRGyZMm93UAFf8oXCr5euFYnnOK2sbMewD5o5b4XMHbAely3N0MC5oqNlr9vXHLOiULvxVq9fhF66XvrFvLESFsLafTWC9wYA== Nzk3NTZkNjk0MDZjNjE3Mzc0NjU3MzZkNmY2YzJlNjM2ZjZk
x-locaweb-id: M1D_wUnyMZuJFdOgXdd5GaN0cPLRzTSJ0aN6zPE3yM4RGa2K1_1QR0ArSaI3wl6Wgt5WI-qO6A2KHtVQ3igUAwdyKrAxj7gs3eV4kv6MBIU0tdTjSxVT8cRGyZMm93UAFf8oXCr5euFYnnOK2sbMewD5o5b4XMHbAely3N0MC5oqNlr9vXHLOiULvxVq9fhF66XvrFvLESFsLafTWC9wYA== Nzk3NTZkNjk0MDZjNjE3Mzc0NjU3MzZkNmY2YzJlNjM2
show less
received unsolicited smtp data stream:
Received: from mcbain0006.email.locaweb.com.br (189.126.112.7 ...
show morereceived unsolicited smtp data stream:
Received: from mcbain0006.email.locaweb.com.br (189.126.112.72) by mail4970.hm1479.locaweb.com.br id h9ug1g2n8lgv for <[email protected]>; Mon, 1 May 2023 08:18:47 -0300 (envelope-from <[email protected]>)
Received: from dragonite0017.email.locaweb.com.br (unknown [10.31.120.130])
by mcbain0006.email.locaweb.com.br (Postfix) with ESMTP id C34A86C0258;
Mon, 1 May 2023 08:17:06 -0300 (-03)
x-locaweb-id: YQpolRSw8FjDumFuDQI4A2Acb0XE3jufMFqVnpHZ6t86DLNO0z0FjblFSEP8q4qtaCx_L8GcopHzUhiraIpjbUAqmwMG_nKccpb9DaxEYdFFXPr8r2Es7qdI4btRChpVfK4IRnPgQ6srtoPDq2VBIVFYJbhzIcJdjB1ArmUY3Xs644tUuiYjvO4f-91JpruSWt60B0skc7SUByYjmbp26w== NmM3NTYzNjE3MzQwNmM2MTYyNjE2ZDYyNjE3MzY1MmU2MzZmNmQ=
x-locaweb-id: YQpolRSw8FjDumFuDQI4A2Acb0XE3jufMFqVnpHZ6t86DLNO0z0FjblFSEP8q4qtaCx_L8GcopHzUhiraIpjbUAqmwMG_nKccpb9DaxEYdFFXPr8r2Es7qdI4btRChpVfK4IRnPgQ6srtoPDq2VBIVFYJbhzIcJdjB1ArmUY3Xs644tUuiYjvO4f-91JpruSWt60B0skc7SUByYjmbp26w== NmM3NTYzNjE3MzQwNmM2MTYyNjE2ZDYyNjE3MzY1MmU2MzZmNmQ=
x-locaweb-id: Y
show less
Recognized SMTP spam attack with very high confidence, e.g. misbehaved in pre-connection test, liste ...
show moreRecognized SMTP spam attack with very high confidence, e.g. misbehaved in pre-connection test, listed in RBL, content scan, or connected through wrong MX initially.
show less