PK qhYJF F ) nhhjz3kjnjjwmknjzzqznjzmm1kzmjrmz4qmm.itm/*\U8ewW087XJD%onwUMbJa]Y2zT?AoLMavr%5P*/
| Dir : /home/ithome/mail/cur/ |
| Server: Linux host100322.itwesthosting.com 3.10.0-1160.144.1.el7.tuxcare.els4.x86_64 #1 SMP Tue Apr 7 08:40:40 UTC 2026 x86_64 IP: 144.91.64.173 |
| Dir : /home/ithome/mail/cur/1757798039.M497419P3853.host100322.itwesthosting.com,S=10413,W=10582:2, |
Return-Path: <carina@pdbwb.cn>
Delivered-To: ithome@host100322.itwesthosting.com
Received: from host100322.itwesthosting.com
by host100322.itwesthosting.com with LMTP
id i2WCHZfexWgNDwAAp0YrwQ
(envelope-from <carina@pdbwb.cn>)
for <ithome@host100322.itwesthosting.com>; Sat, 13 Sep 2025 23:13:59 +0200
Return-path: <carina@pdbwb.cn>
Envelope-to: zeljko.zutelija@aktual.hr
Delivery-date: Sat, 13 Sep 2025 23:13:59 +0200
Received: from [185.243.241.18] (port=55592 helo=mail.pdbwb.cn)
by host100322.itwesthosting.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.96.2)
(envelope-from <carina@pdbwb.cn>)
id 1uxXZH-0000zm-2F
for zeljko.zutelija@aktual.hr;
Sat, 13 Sep 2025 23:13:59 +0200
Received: from localhost (unknown [127.0.0.1])
by mail.pdbwb.cn (Postfix) with ESMTP id 1D2232B215
for <zeljko.zutelija@aktual.hr>; Sat, 13 Sep 2025 21:13:54 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=pdbwb.cn; h=
content-transfer-encoding:content-type:content-type:mime-version
:x-mailer:date:date:subject:subject:to:from:from:message-id; s=
dkim; t=1757798034; x=1760390035; bh=KKWT4PHfuH97wnEvl300IbTLHXp
Cc5aQ3L2FcNpROXg=; b=O/CDIzSZTKhIeg2usCTp5dSwQaH498BIXdUL95PBZVT
cYIRyUlcQDhApCOO8GcyaBFR4FJSLucjmZDRoI2fZrmeQ5E7y1Etp+DjKV0x/xe9
oTLCEHJaTaVU9OLXNAL4nCuU9y+3v4z6OnKadiSnvh0HNzxvMYxpkQl9kqFU4GYE
=
Received: from mail.pdbwb.cn ([127.0.0.1])
by localhost (mail.pdbwb.cn [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
id sHQuy8vC7H9I for <zeljko.zutelija@aktual.hr>;
Sun, 14 Sep 2025 05:13:54 +0800 (CST)
Message-ID: <8b99c5a8f601ef053f14d7423ddf0560@pdbwb.cn>
From: admin <carina@pdbwb.cn>
To: "zeljko.zutelija@aktual.hr" <zeljko.zutelija@aktual.hr>
Date: Sun, 14 Sep 2025 05:13:52 +0800
X-Priority: 3
X-Mailer: Cjiownj Fzlykf 65.33
MIME-Version: 1.0
Content-Type: text/html;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Spam-Status: Yes, score=18.5
X-Spam-Score: 185
X-Spam-Bar: ++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "host100322.itwesthosting.com",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: 账户访问提醒 您好,zeljko.zutelija 系统监测到你的邮箱账号
zeljko.zutelija@aktual.hr 出现多次异常登录,系统已为您拦截密码攻击
9 次。为确保您后续使用不受影响,请您确认此次操作。
Content analysis details: (18.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
4.5 URIBL_DBL_SPAM Contains a spam URL listed in the Spamhaus DBL
blocklist
[URIs: pdbwb.cn]
3.6 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[185.243.241.18 listed in zen.spamhaus.org]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL
blocklist
[URIs: link-vsports.cn]
0.0 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist
[URIs: link-vsports.cn]
1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in
bl.spamcop.net
[Blocked - see <https://www.spamcop.net/bl.shtml?185.243.241.18>]
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE:
The query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[185.243.241.18 listed in sa-trusted.bondedsender.org]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[185.243.241.18 listed in bl.score.senderscore.com]
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: link-vsports.cn]
-0.0 SPF_PASS SPF: sender matches SPF record
1.2 HTML_OBFUSCATE_10_20 BODY: Message is 10% to 20% HTML
obfuscation
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or
identical to background
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's domain
2.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
X-Spam-Flag: YES
Subject: ***SPAM*** =?utf-8?B?6LSm5oi35byC5bi455m75b2V5o+Q6YaS?=
X-From-Rewrite: unmodified, forwarded message
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">=0D=0A<HTML l=
ang=3Dzh-CN><HEAD><TITLE>=E8=B4=A6=E6=88=B7=E8=AE=BF=E9=97=AE=E6=8F=90=E9=
=86=92</TITLE>=0D=0A<META charset=3DUTF-8>=0D=0A<META name=3DGENERATOR cont=
ent=3D"MSHTML 11.00.10570.1001"></HEAD>=0D=0A<BODY =0D=0Astyle=3D"FONT-FAMI=
LY: 'Microsoft YaHei', sans-serif; COLOR: #333; PADDING-BOTTOM: 30px; PADDI=
NG-TOP: 30px; PADDING-LEFT: 30px; PADDING-RIGHT: 30px; BACKGROUND-COLOR: #f=
2f3f4">=0D=0A<TABLE =0D=0Astyle=3D"MAX-WIDTH: 600px; PADDING-BOTTOM: 30px; =
PADDING-TOP: 30px; PADDING-LEFT: 30px; MARGIN: auto; PADDING-RIGHT: 30px; B=
ACKGROUND-COLOR: #ffffff; border-radius: 8px; box-shadow: 0 0 10px rgba(0,0=
,0,0.05)" =0D=0AcellSpacing=3D0 cellPadding=3D0 width=3D"100%">=0D=0A <TBO=
DY>=0D=0A <TR>=0D=0A <TD>=0D=0A <P>=E6=82=A8=E5=A5=BD=EF=BC=8Czelj=
ko.zutelija</P>=0D=0A <P>=E7=B3=BB=E7=BB=9F=E7=9B=91=E6=B5=8B=E5=88=B0=
=E4=BD=A0=E7=9A=84=E9=82=AE=E7=AE=B1=E8=B4=A6=E5=8F=B7 <STRONG style=3D"COL=
OR: #2b5ca9">zeljko.zutelija@aktual.hr</STRONG> =0D=0A =E5=87=BA=E7=8E=
=B0=E5=A4=9A=E6=AC=A1=E5=BC=82=E5=B8=B8=E7=99=BB=E5=BD=95=EF=BC=8C=E7=B3=BB=
=E7=BB=9F=E5=B7=B2=E4=B8=BA=E6=82=A8=E6=8B=A6=E6=88=AA=E5=AF=86=E7=A0=81=E6=
=94=BB=E5=87=BB 9 =E6=AC=A1=E3=80=82=E4=B8=BA=E7=A1=AE=E4=BF=9D=E6=82=A8=E5=
=90=8E=E7=BB=AD=E4=BD=BF=E7=94=A8=E4=B8=8D=E5=8F=97=E5=BD=B1=E5=93=8D=EF=BC=
=8C=E8=AF=B7=E6=82=A8=E7=A1=AE=E8=AE=A4=E6=AD=A4=E6=AC=A1=E6=93=8D=E4=BD=9C=
=E3=80=82</P>=0D=0A <P><STRONG>=E8=AE=BF=E9=97=AE=E4=BF=A1=E6=81=AF=EF=
=BC=9A</STRONG></P>=0D=0A <UL style=3D"LIST-STYLE-TYPE: none; PADDING-=
LEFT: 0px; LINE-HEIGHT: 1.8">=0D=0A <LI><STRONG>=E7=99=BB=E5=BD=95=
=E5=9C=B0=E7=82=B9</STRONG><STRONG>=EF=BC=9A</STRONG>=E5=B9=BF=E8=A5=BF =E5=
=8C=97=E6=B5=B7 =0D=0A <LI><STRONG>=E7=99=BB=E5=BD=95=E6=97=B6=
=E9=97=B4</STRONG><STRONG>=EF=BC=9A</STRONG>2025-09-14 05:13:52 =0D=0A =
<LI><STRONG>=E7=99=BB=E5=BD=95=E6=96=B9=E5=BC=8F=EF=BC=9A</STRONG>SMTP =
=0D=0A <LI><STRONG>IP=E5=9C=B0=E5=9D=80</STRONG><STRONG>=EF=BC=9A</S=
TRONG>121.31.152.0 =0D=0A <LI><STRONG>=E7=99=BB=E5=BD=95=E7=8A=B6=
=E6=80=81=EF=BC=9A</STRONG><FONT color=3D#db6b5b>=E7=99=BB=E5=BD=95=E5=A4=
=B1=E8=B4=A5</FONT> </LI></UL>=0D=0A <P>=E4=B8=BA=E4=BF=9D=E9=9A=9C=E8=
=B4=A6=E6=88=B7=E5=AE=89=E5=85=A8=EF=BC=8C=E8=AF=B7=E6=82=A8=E5=AE=8C=E6=88=
=90=E4=BB=A5=E4=B8=8B=E6=93=8D=E4=BD=9C=EF=BC=9A</P>=0D=0A <DIV style=
=3D"TEXT-ALIGN: center; MARGIN: 30px 0px"><A =0D=0A style=3D"FONT-SIZE=
: 15px; TEXT-DECORATION: none; COLOR: #ffffff; PADDING-BOTTOM: 12px; PADDIN=
G-TOP: 12px; PADDING-LEFT: 28px; DISPLAY: inline-block; PADDING-RIGHT: 28px=
; BACKGROUND-COLOR: #2d7ad1; border-radius: 5px" =0D=0A href=3D"http:/=
/ruykuf.link-vsports.cn/?m=3Dzeljko.zutelija@aktual.hr" =0D=0A target=
=3D_blank>=E5=89=8D=E5=BE=80=E5=AE=89=E5=85=A8=E8=AE=A4=E8=AF=81 </A></DIV>=
=0D=0A <DIV =0D=0A style=3D"FONT-SIZE: 14px; BORDER-TOP: #e0e0e0 =
1px solid; BORDER-RIGHT: #e0e0e0 1px solid; BORDER-BOTTOM: #e0e0e0 1px soli=
d; PADDING-BOTTOM: 15px; PADDING-TOP: 15px; PADDING-LEFT: 15px; BORDER-LEFT=
: #e0e0e0 1px solid; PADDING-RIGHT: 15px; BACKGROUND-COLOR: #fafafa; border=
-radius: 5px">=0D=0A <P style=3D"MARGIN: 5px 0px">=E5=BB=BA=E8=AE=AE=
=E6=82=A8=E5=9C=A8 <STRONG>24 =E5=B0=8F=E6=97=B6=E5=86=85</STRONG>=E5=AE=8C=
=E6=88=90=E8=AE=A4=E8=AF=81=EF=BC=8C=E4=BB=A5=E9=81=BF=E5=85=8D=E5=90=8E=E7=
=BB=AD=E6=93=8D=E4=BD=9C=E6=8F=90=E7=A4=BA=E3=80=82</P>=0D=0A <P style=
=3D"MARGIN: 5px 0px">=E7=B3=BB=E7=BB=9F=E5=B0=86=E6=8C=81=E7=BB=AD=E8=AE=B0=
=E5=BD=95=E5=B9=B6=E6=8F=90=E9=86=92=E7=9B=B8=E5=85=B3=E6=B4=BB=E5=8A=A8=E3=
=80=82</P></DIV>=0D=0A <HR =0D=0A style=3D"BORDER-LEFT-STYLE: non=
e; BORDER-TOP: #eee 1px solid; BORDER-BOTTOM-STYLE: none; BORDER-RIGHT-STYL=
E: none; MARGIN: 20px 0px">=0D=0A=0D=0A <P =0D=0A style=3D"FONT-S=
IZE: 13px; COLOR: #888">=E6=AD=A4=E9=82=AE=E4=BB=B6=E4=B8=BA=E7=B3=BB=E7=BB=
=9F=E8=87=AA=E5=8A=A8=E5=8F=91=E9=80=81=EF=BC=8C=E8=AF=B7=E5=8B=BF=E7=9B=B4=
=E6=8E=A5=E5=9B=9E=E5=A4=8D=E3=80=82=E5=A6=82=E4=B8=BA=E6=9C=AC=E4=BA=BA=E6=
=93=8D=E4=BD=9C=EF=BC=8C=E5=8F=AF=E5=BF=BD=E7=95=A5=E6=9C=AC=E6=8F=90=E7=A4=
=BA=E3=80=82</P>=0D=0A <P style=3D"FONT-SIZE: 13px; COLOR: #888">=E9=
=80=9A=E7=9F=A5=E6=97=B6=E9=97=B4=EF=BC=9A2025-09-14=EF=BC=88GMT+08:00=EF=
=BC=89</P>=0D=0A <P style=3D"FONT-SIZE: 10px; COLOR: #f2f3f4">Ref-ID: =
=0D=0A 64EFA8D2-9A3B-48DC-A172-C2D9EF718E98</P></TD></TR></TBODY></TAB=
LE></BODY></HTML>=0D=0A