HEX
Server: LiteSpeed
System: Linux cde2.duelhost.dk 4.18.0-553.34.1.lve.el8.x86_64 #1 SMP Thu Jan 9 16:30:32 UTC 2025 x86_64
User: dtptviut (1121)
PHP: 8.0.30
Disabled: exec,system,passthru,shell_exec,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Upload Files
File: /home/dtptviut/Maildir/.Junk/new/q1tdwpl-6538705400
From support@utech.advertisingindia.net Fri Jan 31 20:37:45 2025
Return-path: <support@utech.advertisingindia.net>
Envelope-to: mail@globen-flakket.dk
Delivery-date: Fri, 31 Jan 2025 20:37:45 +0100
Received: from server.kxo.bgz.mybluehostin.me ([162.240.163.222])
	by cde2.duelhost.dk with esmtps  (TLS1.2) tls TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
	(Exim 4.98)
	(envelope-from <support@utech.advertisingindia.net>)
	id 1tdwpl-0000000DPEJ-0aZJ
	for mail@globen-flakket.dk;
	Fri, 31 Jan 2025 20:37:45 +0100
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=utech.advertisingindia.net; s=default; h=Content-Transfer-Encoding:
	Content-Type:MIME-Version:Message-ID:From:Date:Subject:To:Sender:Reply-To:Cc:
	Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
	Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id:
	List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;
	bh=YuE+uRiyBW9dntBKb9inr8MyIsu6aKN6Gmz2AI99Xqs=; b=RJoCygi1sHUQe9VlpebgTXav0h
	we/jbXhotgMCDJ7iH6lZ7zDIXss/ZGrbG6a65bA3GfQtj+Bho+slorAyKGpLahymuaRg+KdCQxcYC
	pAFm+okSiBN0JITmwpWVEJjkKKPO3hHdESrFo7OLhLh8Dp63GcbvuOZQ0rSgf25EKO+BBhUUqEIi6
	IuiQKs0PoqmgMdACDMUj4/scGTZDCb+x4B9WFnlrnINsdwalyoubdfFmHe873cvY+f93anhLe6pWq
	plfW5i0i2NsdtSZL9GW9nMfohx5Z6R9wBfKIvMno2CU3BfgGlxnC0n7eoxD1OWZab+o8LKqoBxxkK
	vRfnECgA==;
Received: from advertisingindia by server.kxo.bgz.mybluehostin.me with local (Exim 4.96.2)
	(envelope-from <support@utech.advertisingindia.net>)
	id 1tdwph-0006Kr-2g
	for mail@globen-flakket.dk;
	Fri, 31 Jan 2025 12:37:42 -0700
To: mail@globen-flakket.dk
X-PHP-Script: utech.advertisingindia.net/wp-content/plugins/wp-mailer_nwuk/admin/wp-leaf.php for 105.71.135.166
X-PHP-Originating-Script: 1028:wp-leaf.php(6) : eval()'d code
Date: Fri, 31 Jan 2025 19:37:41 +0000
From: Punktum dk A/S <support@utech.advertisingindia.net>
Message-ID: <ca1ab92ce79540d6864bc55a1176f18a@utech.advertisingindia.net>
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="b1_ca1ab92ce79540d6864bc55a1176f18a"
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server.kxo.bgz.mybluehostin.me
X-AntiAbuse: Original Domain - globen-flakket.dk
X-AntiAbuse: Originator/Caller UID/GID - [1028 981] / [47 12]
X-AntiAbuse: Sender Address Domain - utech.advertisingindia.net
X-Get-Message-Sender-Via: server.kxo.bgz.mybluehostin.me: authenticated_id: advertisingindia/from_h
X-Authenticated-Sender: server.kxo.bgz.mybluehostin.me: support@utech.advertisingindia.net
X-Source: 
X-Source-Args: php-fpm: pool utech_advertisingindia_net                 
X-Source-Dir: advertisingindia.net:/public_html/utech.advertisingindia.net/wp-content/plugins/wp-mailer_nwuk/admin
Forward-Confirmed-ReverseDNS: Reverse and forward lookup success on 162.240.163.222, -10 Spam score
SPFCheck: Server passes SPF test, -30 Spam score
X-DKIM: signer='utech.advertisingindia.net' status='pass' reason=''
DKIMCheck: Server passes DKIM test, -20 Spam score
X-Spam-Score: 7.7 (+++++++)
X-Spam-Report: Spam detection software, running on the system "cde2.duelhost.dk",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 the administrator of that system for details.
 
 Content preview:  Faktura Påmindelse body { font-family: Arial, sans-serif;
    line-height: 1.6; color: #333; background-color: #f7f7f7; margin: 0; padding:
    0; } .email-container { max-width: 600px; margin: 20px auto; background:
   #ffffff; border: 1px solid #eaeaea; border-radius: 5px; box-shadow: 0 2px
   5px rgba(0, 0, 0, 0.1); } 
 
 Content analysis details:   (7.7 points, 5.0 required)
 
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                        [162.240.163.222 listed in sa-trusted.bondedsender.org]
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                           [162.240.163.222 listed in bl.score.senderscore.com]
  0.0 RCVD_IN_DNSWL_BLOCKED  RBL: ADMINISTRATOR NOTICE: The query to DNSWL
                             was blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#DnsBlocklists-dnsbl-block
                              for more information.
                             [162.240.163.222 listed in list.dnswl.org]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [162.240.163.222 listed in sa-accredit.habeas.com]
  1.2 URIBL_ABUSE_SURBL      Contains an URL listed in the ABUSE SURBL blocklist
                             [URI: pse-is.translate.goog]
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was blocked.
                             See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URI: translate.goog]
                             [URI: punktum.dk]
                             [URI: advertisingindia.net]
 -1.9 BAYES_00               BODY: Bayes spam probability is 0 to 1%
                             [score: 0.0000]
  0.0 HTML_MESSAGE           BODY: HTML included in message
  1.4 PYZOR_CHECK            Listed in Pyzor (https://pyzor.readthedocs.io/en/latest/)
  1.5 PDS_PHP_EVAL           PHP header shows eval'd code
  2.5 PHP_SCRIPT             Sent by PHP script
  3.0 PHP_ORIG_SCRIPT_EVAL   From suspicious PHP source
X-Old-Subject:Vi har tidligere sendt følgende faktura,
Subject:*****SPAM***** Vi har tidligere sendt følgende faktura,
X-Spam-Status: Yes, score=7.7, +20 total spam score
SpamTally: Final spam score: 37

This is a multi-part message in MIME format.

--b1_ca1ab92ce79540d6864bc55a1176f18a
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit




	
	
	Faktura Påmindelse
	body {
            font-family: Arial, sans-serif;
            line-height: 1.6;
            color: #333;
            background-color: #f7f7f7;
            margin: 0;
            padding: 0;
        }

        .email-container {
            max-width: 600px;
            margin: 20px auto;
            background: #ffffff;
            border: 1px solid #eaeaea;
            border-radius: 5px;
            box-shadow: 0 2px 5px rgba(0, 0, 0, 0.1);
        }

        .header {
            background-color: white;
            text-align: center;
            padding: 20px;
        }

        .header img {
            max-width: 200px;
        }

        .content {
            padding: 20px;
            font-size: 14px;
            /* Reduced font size for general text */
        }

        .highlight-box {
            background-color: #f1f8fb;
            border: 1px solid #d6e9f2;
            border-radius: 5px;
            padding: 15px;
            margin: 20px 0;
        }

        .highlight-box p {
            margin: 10px 0;
            font-size: 13px;
            /* Slightly smaller font size in the highlight box */
        }

        .footer {
            font-size: 12px;
            background-color: #f7f7f7;
            color: #666;
            text-align: center;
            padding: 15px;
            border-top: 1px solid #eaeaea;
        }

        .footer p {
            margin: 5px 0;
        }

        .footer a {
            color: #cc0000;
            text-decoration: none;
        }

        .footer a:hover {
            text-decoration: underline;
        }

        .red-line {
            border-top: 2px solid red;
            margin: 20px 0;
        }
	






Kære Kunde,

Vi har tidligere sendt følgende faktura, som vi ikke har modtaget betaling for. Drejer det sig om et årsgebyr, bliver domænenavnet/ene suspenderet, hvis fakturaen ikke betales.

Hvis du ikke ønsker at beholde registreringen af et eller flere domænenavne på fakturaen, skal det opsiges i vores .dk-selvbetjening, inden fakturaen betales.


1. Gendan domænenavnet i .dk selvbetjening Her.

2. Her logger du ind med dit bruger-id eller e-mail, samt dit valgte password.

Betalingen genaktiverer automatisk domænenavnet.


 

Med venlig hilsen,

Punktum dk



Punktum dk A/S • CVR-nr. 24210375 • punktum.dk

Dette er en e-mail fra Punktum dk A/S. Denne meddelelse kan indeholde fortrolige oplysninger og er udelukkende beregnet til den tilsigtede modtager. Hvis du ikke er den tiltænkte modtager, bedes du straks underrette afsenderen og slette denne e-mail fra dit system. Du har ikke tilladelse til at videregive, distribuere eller kopiere oplysningerne i denne e-mail.





--b1_ca1ab92ce79540d6864bc55a1176f18a
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html lang="da">
<head>
	<meta charset="UTF-8" />
	<meta content="width=device-width, initial-scale=1.0" name="viewport" />
	<title>Faktura Påmindelse</title>
	<style type="text/css">body {
            font-family: Arial, sans-serif;
            line-height: 1.6;
            color: #333;
            background-color: #f7f7f7;
            margin: 0;
            padding: 0;
        }

        .email-container {
            max-width: 600px;
            margin: 20px auto;
            background: #ffffff;
            border: 1px solid #eaeaea;
            border-radius: 5px;
            box-shadow: 0 2px 5px rgba(0, 0, 0, 0.1);
        }

        .header {
            background-color: white;
            text-align: center;
            padding: 20px;
        }

        .header img {
            max-width: 200px;
        }

        .content {
            padding: 20px;
            font-size: 14px;
            /* Reduced font size for general text */
        }

        .highlight-box {
            background-color: #f1f8fb;
            border: 1px solid #d6e9f2;
            border-radius: 5px;
            padding: 15px;
            margin: 20px 0;
        }

        .highlight-box p {
            margin: 10px 0;
            font-size: 13px;
            /* Slightly smaller font size in the highlight box */
        }

        .footer {
            font-size: 12px;
            background-color: #f7f7f7;
            color: #666;
            text-align: center;
            padding: 15px;
            border-top: 1px solid #eaeaea;
        }

        .footer p {
            margin: 5px 0;
        }

        .footer a {
            color: #cc0000;
            text-decoration: none;
        }

        .footer a:hover {
            text-decoration: underline;
        }

        .red-line {
            border-top: 2px solid red;
            margin: 20px 0;
        }
	</style>
</head>
<body>
<div class="email-container">
<div class="header"><img alt="Punktum.dk Logo" src="https://self-service.punktum.dk/images/sb-logo_en.png" /></div>

<div class="content">
<p><strong>Kære Kunde,</strong></p>

<p>Vi har tidligere sendt følgende faktura, som vi ikke har modtaget betaling for. Drejer det sig om et årsgebyr, bliver domænenavnet/ene suspenderet, hvis fakturaen ikke betales.</p>

<p>Hvis du ikke ønsker at beholde registreringen af et eller flere domænenavne på fakturaen, skal det opsiges i vores .dk-selvbetjening, inden fakturaen betales.</p>

<div class="highlight-box">
<p><strong>1.</strong> Gendan domænenavnet i .dk selvbetjening <a href="https://pse-is.translate.goog/73b2cm?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=fr&_x_tr_pto=wapp" style="color:red;">Her</a>.</p>

<p><strong>2.</strong> Her logger du ind med dit bruger-id eller e-mail, samt dit valgte password.</p>

<p>Betalingen genaktiverer automatisk domænenavnet.</p>
</div>

<div class="red-line"> </div>

<p>Med venlig hilsen,</p>

<p>Punktum dk</p>
</div>

<div class="footer">
<p>Punktum dk A/S • CVR-nr. 24210375 • <a href="https://punktum.dk">punktum.dk</a></p>

<p>Dette er en e-mail fra Punktum dk A/S. Denne meddelelse kan indeholde fortrolige oplysninger og er udelukkende beregnet til den tilsigtede modtager. Hvis du ikke er den tiltænkte modtager, bedes du straks underrette afsenderen og slette denne e-mail fra dit system. Du har ikke tilladelse til at videregive, distribuere eller kopiere oplysningerne i denne e-mail.</p>
</div>
</div>
</body>
</html>



--b1_ca1ab92ce79540d6864bc55a1176f18a--