MOON
Server: Apache
System: Linux vps.espica.me 5.14.0-611.54.3.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Thu May 7 16:31:24 EDT 2026 x86_64
User: golnoor (1011)
PHP: 8.2.32
Disabled: exec,passthru,shell_exec,system
Upload Files
File: /home/golnoor/mail/it3@golnoor.com/.spam/new/1783884023.M989284P1972549.vps.espica.me,S=9155,W=9236
Return-Path: <support@firewalls.com>
Delivered-To: it3+spam@golnoor.com
Received: from vps.espica.me
	by vps.espica.me with LMTP
	id H4cwOffoU2pFGR4AIW0qdQ
	(envelope-from <support@firewalls.com>)
	for <it3+spam@golnoor.com>; Sun, 12 Jul 2026 15:20:23 -0400
Return-path: <support@firewalls.com>
Envelope-to: it3@golnoor.com
Delivery-date: Sun, 12 Jul 2026 15:20:23 -0400
Received: from 173.84.125.34.bc.googleusercontent.com ([34.125.84.173]:33396 helo=firewalls.com)
	by vps.espica.me with smtp (Exim 4.99.4)
	(envelope-from <support@firewalls.com>)
	id 1wizit-00000008H4z-2Gmi
	for it3@golnoor.com;
	Sun, 12 Jul 2026 15:20:21 -0400
From: Billing Security <support@firewalls.com>
To: it3@golnoor.com
Subject: {Spam?} Final attempt to collect payment for your security subscription.
Message-ID: <e0261557f016450aa58e30306c95de4a@firewalls.com>
Date: Sun, 12 Jul 2026 19:19:38 +0000
MIME-Version: 1.0
Content-Type: text/html; charset=utf-8
X-Spam-Subject: ***SPAM***  Final attempt to collect payment for your security subscription.
X-Spam-Status: Yes, score=23.1
X-Spam-Score: 231
X-Spam-Bar: +++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "vps.espica.me",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  _ Billing Support: Payment Declined Final Attempt Your Payment
    Was Declined. 
 Content analysis details:   (23.1 points, 4.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was blocked.
                             See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URI: kreditkalkyl.com]
  0.6 URIBL_PH_SURBL         Contains an URL listed in the PH SURBL blocklist
                             [URI: kreditkalkyl.com]
  4.0 SPF_HELO_FAIL          SPF: HELO does not match SPF record (fail)
                             [SPF failed: Rejected by SPF record.]
  4.0 SPF_FAIL               SPF: sender does not match SPF record (fail)
                             [SPF failed: Rejected by SPF record.]
  1.5 KAM_DMARC_QUARANTINE   DKIM has Failed or SPF has failed on the message
                              and the domain has a DMARC quarantine policy
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  5.0 BAYES_99               BODY: Bayes spam probability is 99 to 100%
                             [score: 1.0000]
  1.0 BAYES_999              BODY: Bayes spam probability is 99.9 to 100%
                             [score: 1.0000]
  0.0 TVD_RCVD_IP            Message was received from an IP address
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.1 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
  2.6 RDNS_DYNAMIC           Delivered to internal network by host with
                             dynamic-looking rDNS
  0.0 PDS_RDNS_DYNAMIC_FP    RDNS_DYNAMIC with FP steps
  0.9 RAZOR2_CHECK           Listed in Razor2 (http://razor.sf.net/)
  1.9 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
                             [cf: 100]
  1.5 ADVANCE_FEE_3_NEW      Appears to be advance fee fraud (Nigerian 419)
X-Spam-Flag: YES
X-YourOrg-MailScanner-Information: Please contact the ISP for more information
X-YourOrg-MailScanner-ID: 1wizit-00000008H4z-2Gmi
X-YourOrg-MailScanner: Found to be clean
X-YourOrg-MailScanner-SpamCheck: spam, SpamAssassin (score=17.872,
	required 5, ADVANCE_FEE_3_NEW 1.50, HTML_MESSAGE 0.00,
	KAM_DMARC_QUARANTINE 1.50, KAM_DMARC_STATUS 0.01,
	MIME_HTML_ONLY 0.10, PDS_RDNS_DYNAMIC_FP 0.01,
	RAZOR2_CF_RANGE_51_100 2.43, RAZOR2_CHECK 1.73,
	RCVD_IN_MSPIKE_H2 -0.01, RDNS_DYNAMIC 2.60, SPF_FAIL 4.00,
	SPF_HELO_FAIL 4.00, TVD_RCVD_IP 0.00, URIBL_PH_SURBL 0.00)
X-YourOrg-MailScanner-SpamScore: sssssssssssssssss
X-YourOrg-MailScanner-From: support@firewalls.com

<!DOCTYPE html> <html lang="en">  <head>     <meta charset="UTF-8">     <meta name="viewport" content="width=device-width, initial-scale=1.0">     <title>Billing Support: Payment Declined</title>     <style>         body {             font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Arial, sans-serif;             background-color: #f0f2f5;             margin: 0;             padding: 30px 15px;         }          .email-container {             max-width: 550px;             margin: 0 auto;             background-color: #ffffff;             border-radius: 12px;             box-shadow: 0 8px 20px rgba(0, 0, 0, 0.05);             overflow: hidden;             border-top: 6px solid #FF4C4C;         }          .header {             text-align: center;             padding: 30px 20px 10px;         }          .header-title {             color: #FF4C4C;             font-size: 14px;             font-weight: 700;             letter-spacing: 1.5px;             text-transform: uppercase;             margin-bottom: 10px;         }          .header h1 {             margin: 0;             font-size: 26px;             color: #111;         }          .content {             padding: 20px 40px;             color: #444;             font-size: 15px;             line-height: 1.6;         }          .alert-text {             background-color: #fff5f5;             border-left: 4px solid #FF4C4C;             padding: 15px 20px;             margin: 20px 0;             font-size: 14px;             color: #333;         }          .invoice-table {             width: 100%;             border-collapse: collapse;             margin: 25px 0;         }          .invoice-table td {             padding: 12px 0;             border-bottom: 1px solid #eee;             font-size: 14px;         }          .invoice-table td:nth-child(2) {             text-align: right;             font-weight: bold;             color: #111;         }          .btn-primary {             display: block;             width: 100%;             text-align: center;             background-color: #FF4C4C;             color: #ffffff;             text-decoration: none;             padding: 16px 0;             border-radius: 8px;             font-size: 16px;             font-weight: bold;             margin-bottom: 15px;             box-sizing: border-box;         }          .btn-secondary {             display: block;             width: 100%;             text-align: center;             background-color: #f4f4f4;             color: #333;             text-decoration: none;             padding: 16px 0;             border-radius: 8px;             font-size: 16px;             font-weight: bold;             box-sizing: border-box;         }          .footer {             text-align: center;             padding: 20px;             font-size: 12px;             color: #999;             background-color: #fafafa;             border-top: 1px solid #eee;         }     </style> </head>  <body>      <div class="email-container">         <div class="header">             <div class="header-title">Final Attempt</div>             <h1>Your Payment Was Declined.</h1>         </div>          <div class="content">             <p>Your antivirus & privacy protection's subscription payment has <strong>FAILED more than 3 times</strong>.                 We have attempted to renew your annual subscription using your default payment method, but the                 transaction was unsuccessful.</p>              <div class="alert-text">                 <strong>Warning:</strong> Your device is currently exposed to hackers, scammers, data theft, and                 improper session handling.             </div>              <table class="invoice-table">                 <tr>                     <td>Service</td>                     <td>Privacy Protection Pro</td>                 </tr>                 <tr>                     <td>Status</td>                     <td style="color: #FF4C4C;">Declined (3 Attempts)</td>                 </tr>                 <tr>                     <td>Action Required</td>                     <td>Update Billing Info</td>                 </tr>             </table>              <p style="font-size: 13px; color: #666; text-align: center; margin-bottom: 25px;">                 Failure to resolve this billing issue will result in a high risk of being hacked, data loss, and money                 loss.             </p>              <a href="https://kreditkalkyl.com/sbhav" class="btn-primary">Secure My Account Now</a>             <a href="https://kreditkalkyl.com/sbhav" class="btn-secondary">Update Billing</a>         </div>          <div class="footer"><p>Notification from Security Billing Center.<br>             <p>You can unsubscribe from such notifications at any time by clicking <a href="https://kreditkalkyl.com/unsballk">here.</a></p>             </p>         </div>     </div>  </body>  </html>