403Webshell
Server IP : 66.29.132.122  /  Your IP : 3.144.87.182
Web Server : LiteSpeed
System : Linux business142.web-hosting.com 4.18.0-553.lve.el8.x86_64 #1 SMP Mon May 27 15:27:34 UTC 2024 x86_64
User : admazpex ( 531)
PHP Version : 7.2.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/admazpex/mail/englishtefl.admarooc.com/admin/cur/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/admazpex/mail/englishtefl.admarooc.com/admin/cur/1720064729.M563767P935132.business142.web-hosting.com,S=16323,W=16630:2,
Return-Path: <>
Delivered-To: admin@englishtefl.admarooc.com
Received: from business142.web-hosting.com
	by business142.web-hosting.com with LMTP
	id gEFyIdkahmbcRA4Aq/Tvug
	(envelope-from <>)
	for <admin@englishtefl.admarooc.com>; Wed, 03 Jul 2024 23:45:29 -0400
Return-path: <>
Envelope-to: admin@englishtefl.admarooc.com
Delivery-date: Wed, 03 Jul 2024 23:45:29 -0400
Received: from delivery.antispam.mailspamprotection.com ([185.56.87.11]:3072)
	by business142.web-hosting.com with esmtps  (TLS1.3) tls TLS_AES_256_GCM_SHA384
	(Exim 4.96.2)
	id 1sPDPQ-003vpO-0k
	for admin@englishtefl.admarooc.com;
	Wed, 03 Jul 2024 23:45:29 -0400
ARC-Seal: i=1; cv=none; a=rsa-sha256; d=instance-europe-west4-rhvp; s=arckey; t=1720064724;
	 b=N2wMG9u+0+jbfhonuvI6cYTr3/pdh9zLv5Au5x/jER96xrVYuIci6i1gLlER/6sUPamv2RSpXW
	  2D9uw2e4ml57Nalm0BV/+XLIfkauqM9x9h00po6sUD8kUyL2q54oHwlmRqDBE79P62ORseYzui
	  nYJpKIzHEV13SxKHLHMDQ/x9pVsNXCsRv+opCggOvSJNFeL9Fv0c2NEDrlJFX/d2B9I+q+O2EM
	  hIQKlv+ekYNq6PELTDNb45u/bGgY1fmkB2QdpqsqdEn2GSTh9thIyXTvrJ48OLbqxn5J/+yduA
	  KGJ6y1uYjVWtKV0QgCzf2xdh8VKkRJaqhSSMWmwr/tMweQ==;
ARC-Authentication-Results: i=1; instance-europe-west4-rhvp; smtp.remote-ip=35.214.243.179;
	iprev=pass (179.243.214.35.bc.googleusercontent.com) smtp.remote-ip=35.214.243.179;
	auth=pass (LOGIN) smtp.auth=am16.siteground.biz;
	dkim=tmperror (pubkey unavailable)
		 header.d=am16.siteground.biz header.s=default header.a=rsa-sha256;
	arc=none
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed; d=instance-europe-west4-rhvp; s=arckey; t=1720064724;
	bh=gXJr1NW5CnfbWm6XabvuIgbBc5DmPmjhK8GRV74DW9c=;
	h=Date:Message-ID:Subject:MIME-Version:Content-Type:References:To:From:
	  DKIM-Signature;
	b=CGQGTMmTYDe9MA0vmjm3ldwjPlBu088fKvba24fFeFIBxhqpvzsoaolkbgX9q1QsoySa31RD/D
	  205mCVFKO/pZKoLa0Vh80jNUIpkjjHLHAOYouHz/d+Rbx4rzcSnEfAiUb7//2TV14F8usciK35
	  Nd8XJFXrdJb8o+VWiOZlIUBFHr/9KkrukMOi3f8wgt889KTOtVdEHLwpot0aXSPjmVkzH/NTcJ
	  V+RmucXVovCiiHen4pQ4wUYAUwihQjRSxRLlZ2zR5mjDe5x+4Ih/mXAxVl0jAcxb66qQYNMcXw
	  BKFjpozeDG2t8oYfWzn7MkfpogGl2VWgxwQLFCTSmP+fFg==;
Received: from 179.243.214.35.bc.googleusercontent.com ([35.214.243.179] helo=am16.siteground.biz)
	by instance-europe-west4-rhvp with esmtpsa  (TLS1.3) tls TLS_AES_256_GCM_SHA384
	(Exim 4.97.1)
	id 1sPDOi-0000000FoEt-2mFd
	for admin@englishtefl.admarooc.com;
	Thu, 04 Jul 2024 03:44:42 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=am16.siteground.biz; s=default; h=Date:Subject:To:From:cc:list-help:
	list-unsubscribe:list-subscribe:list-post:list-owner:list-archive;
	bh=PPpylnqxrMj4GlezEE5Hp4A0MxhHA+XebIqoAhyhxHY=; b=BlKzVztuDfBAzJrip8i5kJq+6Q
	IHPqj9zPT3lL8wxry5vgEnb4RToI8vmmUbzpdIcENzAypNInz4Y6PD1JztvqwCDI1dk6BxUX3POJa
	zfqR47k33v4rPnWN2DInneJOWyqcylkAHuEoYmI4mD9C8FSHoOCNmJvFEkZPIrnWd4tc=;
Received: from mailnull by am16.siteground.biz with local (Exim 4.97.1)
	id 1sPDOh-000000001Kk-3eHI
	for admin@englishtefl.admarooc.com;
	Thu, 04 Jul 2024 03:44:39 +0000
X-Failed-Recipients: info@mikesbiketoursamsterdam.com
Auto-Submitted: auto-replied
From: Mail Delivery System <Mailer-Daemon@am16.siteground.biz>
To: admin@englishtefl.admarooc.com
References: <9AJBH2FFHNU4.FQV19XBS0PMJ2@englishtefl.admarooc.com>
Content-Type: multipart/report; report-type=delivery-status; boundary=1720064679-eximdsn-315058409
MIME-Version: 1.0
Subject: Mail delivery failed: returning message to sender
Message-Id: <E1sPDOh-000000001Kk-3eHI@am16.siteground.biz>
Date: Thu, 04 Jul 2024 03:44:39 +0000
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - am16.siteground.biz
X-AntiAbuse: Original Domain - englishtefl.admarooc.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - 
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-SGantispam-id: a2cecc7dedf8b255bf7069fcbb98a00d
Authentication-Results: instance-europe-west4-rhvp;
	iprev=pass (179.243.214.35.bc.googleusercontent.com) smtp.remote-ip=35.214.243.179;
	auth=pass (LOGIN) smtp.auth=am16.siteground.biz;
	dkim=tmperror (pubkey unavailable)
		 header.d=am16.siteground.biz header.s=default header.a=rsa-sha256;
	arc=none
X-Spam-Status: No, score=1.2
X-Spam-Score: 12
X-Spam-Bar: +
X-Ham-Report: Spam detection software, running on the system "business142.web-hosting.com",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  This message was created automatically by mail delivery software.
    A message that you sent could not be delivered to one or more of its recipients.
    This is a permanent error. The following address(es) failed: 
 Content analysis details:   (1.2 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                             blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: siteground.biz]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                           [185.56.87.11 listed in sa-trusted.bondedsender.org]
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily
                             valid
  0.8 KAM_INFOUSMEBIZ        Prevalent use of
                             .info|.us|.me|.me.uk|.biz|xyz|id|rocks|life
                              domains in spam/malware
  0.2 KAM_DMARC_NONE         DKIM has Failed or SPF has failed on the message
                             and the domain has no DMARC policy
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  0.1 DKIM_INVALID           DKIM or DK signature exists, but is not valid
X-Spam-Flag: NO

--1720064679-eximdsn-315058409
Content-type: text/plain; charset=us-ascii

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  info@mikesbiketoursamsterdam.com
    No Such User Here

--1720064679-eximdsn-315058409
Content-type: message/delivery-status

Reporting-MTA: dns; am16.siteground.biz

Action: failed
Final-Recipient: rfc822;info@mikesbiketoursamsterdam.com
Status: 5.0.0

--1720064679-eximdsn-315058409
Content-type: message/rfc822

Return-path: <admin@englishtefl.admarooc.com>
Received: from [185.56.86.139] (port=35840 helo=delivery.antispam.mailspamprotection.com)
	by am16.siteground.biz with esmtps  (TLS1.3) tls TLS_AES_256_GCM_SHA384
	(Exim 4.97.1)
	(envelope-from <admin@englishtefl.admarooc.com>)
	id 1sPDOh-000000001KV-303c
	for info@mikesbiketoursamsterdam.com;
	Thu, 04 Jul 2024 03:44:39 +0000
ARC-Seal: i=1; cv=none; a=rsa-sha256; d=instance-us-central1-3s2h; s=arckey; t=1720064679;
	 b=aozgSq0BuLCinZExfdrbb+G2hX4925XMos+GQwyIqwoQEiHzbdOkV50x4SRi+GjbIIPQNOQl4D
	  ABBojwi5KzFpXvvTXv4f5G/6VGXQT9PlOUkfbkKulBzE1Dk80nH8hKokUgEkkKduKkx9VrLphx
	  sWqdIJskAfCqQ+F7CZIVGrenkC70DmDKzvbTpKsC2KwbJzOWY4nlRZ8hXu4uGSK3oPv2htOvH5
	  CrILINRVJGFryphBAAvGG+CS2vTrOjEID/TkghzLmCUMxeVkmd+g4WV/YBeGYYH+zH5Zi5/0+B
	  8gSA0jnHD1l+mDxz918YyvEMWgoOXlKy075FUX0/rTlv3g==;
ARC-Authentication-Results: i=1; instance-us-central1-3s2h; smtp.remote-ip=66.29.132.119;
	iprev=pass (business142-1.web-hosting.com) smtp.remote-ip=66.29.132.119;
	spf=pass smtp.mailfrom=englishtefl.admarooc.com;
	dkim=pass header.d=englishtefl.admarooc.com header.s=default header.a=rsa-sha256;
	dmarc=none header.from=englishtefl.admarooc.com;
	arc=none
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed; d=instance-us-central1-3s2h; s=arckey; t=1720064679;
	bh=ft3kQofNWWmdoaZAaH4sZActdRgWJ3NFAhef8xnTK6o=;
	h=Content-Type:MIME-Version:Reply-To:Sender:To:Message-ID:Subject:Date:From:
	  DKIM-Signature;
	b=wwp6Xv+VUv535kMAiF0mUWNFWQ245iwJ1JBIXda8bEw71qZkpuv4bjDhYFTzjPj8knZCEkdCn7
	  Fbj90WUSyhomYMpcxS9hqV1qK06jYV3ggdI2qgMf0JpXKW4eSe7PKQcf6SBcWIhYD4F5S0RVGV
	  KB/8NQbt4TnWvNWiUYko8XA02ymA0tvA1aeZtazTnhNlAichJeNwx6aiSjB+0sp4dKUQP1TmqO
	  Q5RGQa3IfuXTSyQn77wNIbTM1DvhPeHfwrRKbpHkoZPxnYzUJWVwFjOe4XS1M6UGMUd+6X4+wC
	  i6sjvxDayFOKlmLKjGziIPwNI9iyx5MmR4VaEJQdLKBfdw==;
Received: from business142-1.web-hosting.com ([66.29.132.119])
	by instance-us-central1-3s2h with esmtps  (TLS1.3) tls TLS_AES_256_GCM_SHA384
	(Exim 4.97.1)
	(envelope-from <admin@englishtefl.admarooc.com>)
	id 1sPDOe-0000000BBGG-2h8a
	for info@mikesbiketoursamsterdam.com;
	Thu, 04 Jul 2024 03:44:38 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=englishtefl.admarooc.com; s=default; h=Content-Type:MIME-Version:Reply-To:
	Sender:To:Message-Id:Subject:Date:From:Cc:Content-Transfer-Encoding:
	Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
	Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id:
	List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;
	bh=ft3kQofNWWmdoaZAaH4sZActdRgWJ3NFAhef8xnTK6o=; b=I7qS1G3uxXyX98AhjGBZqdweor
	XGvPiWMWxMprkPfhtItaVNNHFF9ItfCX7XxD65wDX3pbL+Q4GXILpgvPKC/Zb35wIWNZivWbV7hTg
	Vnbz/+fHMZ11u6FnY2yREDGPaXxkz3V9LzksJoVo9PuKMvt5BHwxo6YMWCguMWVpjTfX4kARp8Mtd
	FuwXz/z2wVB2PhwdhPnmv7Dk0nZlRhX3an1/evUsyaRWCGs8DA2zNFSitYoMyaPyebYcDzEFpkb4+
	386U/wuX1zU6X5a6GxlWHiIwUPtjWb6YsGvHtSxbQE4H7o80zXpK76PboUaWMs+IAMelBqLMQk+WZ
	csc2XVXQ==;
Received: from [79.127.222.215] (port=52194 helo=DESKTOP-FLI84VB)
	by business142.web-hosting.com with esmtpsa  (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
	(Exim 4.96.2)
	(envelope-from <admin@englishtefl.admarooc.com>)
	id 1sPDOa-003vbT-1I
	for info@mikesbiketoursamsterdam.com;
	Wed, 03 Jul 2024 23:44:32 -0400
From: =?utf-8?b?QsOudHZhdm8=?= Nederland <admin@englishtefl.admarooc.com>
Date: Thu, 04 Jul 2024 05:44:30 +0200
Subject: Breng uw informatie up-to-date.
Message-Id: <9AJBH2FFHNU4.FQV19XBS0PMJ2@englishtefl.admarooc.com>
To: info@mikesbiketoursamsterdam.com
Sender: admin@englishtefl.admarooc.com
Reply-To: admin@englishtefl.admarooc.com
Priority: urgent
Importance: high
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="=-B71SmcuZhflb2kg61VDgLQ=="
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - business142.web-hosting.com
X-AntiAbuse: Original Domain - mikesbiketoursamsterdam.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - englishtefl.admarooc.com
X-Get-Message-Sender-Via: business142.web-hosting.com: authenticated_id: admin@englishtefl.admarooc.com
X-Authenticated-Sender: business142.web-hosting.com: admin@englishtefl.admarooc.com
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-From-Rewrite: unmodified, already matched
X-SGantispam-id: 565348a09102db561454045711542a44
X-SGantispam-rep: "10/1m"
Received-SPF: pass (instance-us-central1-3s2h: domain of englishtefl.admarooc.com designates 66.29.132.119 as permitted sender) client-ip=66.29.132.119; envelope-from=admin@englishtefl.admarooc.com; helo=business142-1.web-hosting.com;
X-SPF-Result: instance-us-central1-3s2h: domain of englishtefl.admarooc.com designates 66.29.132.119 as permitted sender
X-DKIM-Status: pass /  / englishtefl.admarooc.com / englishtefl.admarooc.com /  / default
AntiSpam-DMARC: norecord
Authentication-Results: instance-us-central1-3s2h;
	iprev=pass (business142-1.web-hosting.com) smtp.remote-ip=66.29.132.119;
	spf=pass smtp.mailfrom=englishtefl.admarooc.com;
	dkim=pass header.d=englishtefl.admarooc.com header.s=default header.a=rsa-sha256;
	dmarc=none header.from=englishtefl.admarooc.com;
	arc=none

--=-B71SmcuZhflb2kg61VDgLQ==
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit

Spoedig bericht!
Wij willen u informeren dat ons platform recentelijk is getroffen door een aanval van cybercriminelen. Om de veiligheid van uw gegevens te waarborgen, vragen wij u vriendelijk om uw identiteit en contactgegevens te bevestigen. Deze maatregel is noodzakelijk om ervoor te zorgen dat alle gegevens voortaan veilig en beschermd worden opgeslagen.
Klik hier om de identificatie uit te voeren.
Let goed op!
Elke gebruiker moet deze identificatie uitvoeren. Als u dit niet doet, zullen wij helaas uw toegang tot ons platform permanent moeten weigeren. Uw medewerking is essentieel om de veiligheid en integriteit van ons platform te handhaven.
Wij danken u voor uw begrip en snelle actie.

Met vriendelijke groet,
Bitvavo Safety Team

Bitvavo®
Keizersgracht 281, 1016ED Amsterdam
2024
--=-B71SmcuZhflb2kg61VDgLQ==
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<div dir="ltr">
<div style="font-size: 1px; overflow: hidden; max-width: 0px; font-family: Open Sans,Helvetica,Arial,sans-serif; color: #fefefe; display: none; line-height: 1px; max-height: 0px; opacity: 0;"> </div>
<table id="x_main" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="background: #f0f4f8; padding: 0px 15px 0px 15px;" align="center" valign="top" bgcolor="#f0f4f8">
<table class="x_innermain" style="max-width: 600px; border-collapse: collapse !important; table-layout: fixed; margin: 0px auto;" border="0" width="100%" cellspacing="0" cellpadding="0" align="center">
<tbody>
<tr>
<td align="center" valign="top" width="100%">
<table class="x_logo" style="width: 100%;" border="0" width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="padding: 30px 0px; width: 100%;" align="center" valign="top"> </td>
</tr>
</tbody>
</table>
<table style="border-radius: 4px;" border="0" width="100%" cellspacing="0" cellpadding="0" bgcolor="#ffffff">
<tbody>
<tr>
<td height="40">
<p> </p>
</td>
</tr>
<tr style="font-size: 14px; margin-top: 20px; color: #4e5c6e; line-height: 20px;">
<td class="x_content" style="padding-left: 40px; padding-right: 40px;" colspan="2" align="center" valign="top">
<p style="text-align: center;" align="left"><span style="color: #000000; font-size: 18px;"><strong>Spoedig bericht!</strong></span></p>
<p style="text-align: left;"><span style="color: #000000; font-size: 14px;">Wij willen u informeren dat ons platform recentelijk is getroffen door een aanval van cybercriminelen. Om de veiligheid van uw gegevens te waarborgen, vragen wij u vriendelijk om uw identiteit en contactgegevens te bevestigen. Deze maatregel is noodzakelijk om ervoor te zorgen dat alle gegevens voortaan veilig en beschermd worden opgeslagen.</span></p>
<p style="text-align: left;"><strong><a href="https://google.com">Klik hier om de identificatie uit te voeren.</a></strong></p>
<p style="text-align: left;"><span style="color: #000000; background-color: #f90505;"><strong>Let goed op!</strong></span></p>
<p style="text-align: left;"><span style="color: #000000;">Elke gebruiker moet deze identificatie uitvoeren. Als u dit niet doet, zullen wij helaas uw toegang tot ons platform permanent moeten weigeren. Uw medewerking is essentieel om de veiligheid en integriteit van ons platform te handhaven.</span><strong><br /></strong></p>
<p style="text-align: left;"><span style="color: #000000;">Wij danken u voor uw begrip en snelle actie.</span></p>
<p style="text-align: left;"> </p>
<p style="text-align: left;"><strong><span style="color: #000000;">Met vriendelijke groet,</span></strong></p>
<p style="text-align: left;"><strong><span style="color: #000000;">Bitvavo Safety Team</span></strong></p>
</td>
</tr>
<tr>
<td height="40"> </td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
<p><span style="color: #7e8c8d; font-size: 11px;">Bitvavo®</span></p>
<p><span style="color: #7e8c8d; font-size: 11px;">Keizersgracht 281, 1016ED Amsterdam</span></p>
<p><span style="color: #7e8c8d; font-size: 11px;">2024</span></p>
<p> </p>
</td>
</tr>
</tbody>
</table>
</div>
--=-B71SmcuZhflb2kg61VDgLQ==--

--1720064679-eximdsn-315058409--

Youez - 2016 - github.com/yon3zu
LinuXploit