🗂️ ShadowGate
Path:
home
/
newsgini
/
newsgini.one
/
✏️ Editing: mail.tar
newsgini.in/info/.Drafts/dovecot.index.log 0000640 00000000050 15060264272 0014477 0 ustar 00 ( B��h B��h newsgini.in/info/.Drafts/dovecot-uidlist 0000640 00000000063 15060264272 0014270 0 ustar 00 3 V1754855747 N1 G6cf9bf2d42f99868e7402c008491050f newsgini.in/info/.Junk/dovecot.index.log 0000640 00000000050 15060264272 0014163 0 ustar 00 ( B��h B��h newsgini.in/info/.Junk/dovecot-uidlist 0000640 00000000063 15060264272 0013754 0 ustar 00 3 V1754855748 N1 G6df9bf2d42f99868e7402c008491050f newsgini.in/info/.Sent/dovecot.index.log 0000640 00000000050 15060264272 0014165 0 ustar 00 ( B��h B��h newsgini.in/info/.Sent/dovecot-uidlist 0000640 00000000063 15060264272 0013756 0 ustar 00 3 V1754855749 N1 G6ef9bf2d42f99868e7402c008491050f newsgini.in/info/.Trash/dovecot.index.log 0000640 00000000050 15060264272 0014335 0 ustar 00 ( B��h B��h newsgini.in/info/.Trash/dovecot-uidlist 0000640 00000000063 15060264272 0014126 0 ustar 00 3 V1754855750 N1 G6ff9bf2d42f99868e7402c008491050f newsgini.in/info/cur/1757389527.M453290P4012064.server56.py-server.com,S=12194,W=12378:2, 0000640 00000027642 15060264272 0021550 0 ustar 00 Return-Path: <takedown-response+74962791@netcraft.com> Delivered-To: info@newsgini.in Received: from server56.py-server.com by server56.py-server.com with LMTP id WKphGdeiv2ggOD0AhJEFDw (envelope-from <takedown-response+74962791@netcraft.com>) for <info@newsgini.in>; Tue, 09 Sep 2025 09:15:27 +0530 Return-path: <takedown-response+74962791@netcraft.com> Envelope-to: info@newsgini.in Delivery-date: Tue, 09 Sep 2025 09:15:27 +0530 Received: from mail-1c.netcraft.com ([52.31.138.216]:45789) by server56.py-server.com with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from <takedown-response+74962791@netcraft.com>) id 1uvpIN-0000000Grst-09fj for info@newsgini.in; Tue, 09 Sep 2025 09:15:27 +0530 Received: from walleye.netcraft.com (unknown [10.9.0.81]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail-1c.netcraft.com (Postfix) with ESMTPS id 344445DA for <info@newsgini.in>; Tue, 9 Sep 2025 03:44:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=netcraft.com; s=default202405-yu9bqteb95aqcfpg; t=1757389480; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=CRAi6M11bY7H1fPDI1DWJPnGMGYEMW+vEEPz957hsqg=; b=u/2DRvstpYtMAt46D0FaiDtgThu1IuCEYdmLTaZaoGGaxJIVNkdIN11tp+Ecd3poIgJ6lC 5xvMymkG4I2B/bSzCQpOl3gvmEFjDLqaEBd2Y0B2j3xUXewGCOtXiX2T4Qq2bWzns4n0pq VcTune8iWcyebRScpsQkwKRXO6EYu+KJhIMNVrIFK3ziwjmdMIaKxaPJ/AEttbswytC3k0 jUQI4G57k/X3eJscyB5VUtSdy59Z7Mgb+P+agsHNjMdtzEfMZ0atQYjvy/vjzlVL3xQ8Dd MASQdk1rZQhDmjb9RqY8zKVicLE7KVMLwv8WYvzxibUHIpjlx6Jzj0xSRaIJig== Received: by walleye.netcraft.com (Postfix, from userid 507) id 311B61D01; Tue, 9 Sep 2025 03:44:40 +0000 (UTC) Content-Transfer-Encoding: 8bit Content-Type: multipart/report; boundary="_----------=_17573894802178630493"; report-type="feedback-report" MIME-Version: 1.0 Date: Tue, 9 Sep 2025 03:44:40 +0000 From: Netcraft Takedown Service <takedown-response+74962791@netcraft.com> Subject: Issue 74962791: Phishing attack at hxxps://www[.]gamesame.online.newsgini[.]in/wp-includes/IXR/irnknt/redirect To: info@newsgini.in Message-Id: <80d056163ff43a31c8f670160151dda3@takedown.netcraft.com> X-Mailer: MIME::Lite 3.030 (F2.85; T2.17; A2.20; B3.15; Q3.13) X-Spam-Status: No, score=-0.2 X-Spam-Score: -1 X-Spam-Bar: / X-Ham-Report: Spam detection software, running on the system "server56.py-server.com", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: आप वर्तमान में हमारे ग्राहक Inland Revenue NZ के खिलाफ फिशिंग हुम्ला होस्ट कर रहे हैं: Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [52.31.138.216 listed in bl.score.senderscore.com] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [52.31.138.216 listed in sa-accredit.habeas.com] 0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [52.31.138.216 listed in sa-trusted.bondedsender.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain X-Spam-Flag: NO This is a multi-part message in MIME format. --_----------=_17573894802178630493 Content-Disposition: inline Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="UTF-8" आप वर्तमान में हमारे ग्राहक Inland Revenue NZ के खिलाफ फिशिंग हुम्ला होस्ट कर रहे हैं: hxxps://www[.]gamesame.online.newsgini[.]in/wp-includes/IXR/irnknt/redirect आपको इस हमले के बारे में कोई जानकारी नहीं होगी, यद्यपि, आप फिर भी इसे दूर करने के लिए जिम्मेदार हैं. कृपया करके इस वेबसाइट को जल्द से जल्द बंध कर दिज्ये. हमारा मानना है कि इस हमले को प्रतिबंधित किया जा रहा है इसलिए यह केवल कुछ देशों से ही दिखाई देता है। यह तय करने से पहले कि हमले को सुलझा लिया गया है, कृपया पुष्टि करें कि इसे निम्नलिखित देशों से नहीं देखा जा सकता है: न्यूज़ीलैंड हम समझते हैं कि यह साइट केवल सौम्य सामग्री दिखाने वाले पृष्ठ पर रीडायरेक्ट है, हालांकि यह कपटपूर्ण सामग्री पर रीडायरेक्ट करती थी। रीडायरेक्ट को धोखेबाज द्वारा नियंत्रित किया जाता है, इसलिए भविष्य के हमलों के लिए इसका पुन: उपयोग किया जा सकता है, जिससे इसे हटाना और भी महत्वपूर्ण हो जाता है। इसके अतिरिक्त, कृपया करके इस साईट के विषय-सूचि को जालसाज़ सुरक्षित द्वारा नियंत्रित रखे, जिससे हमारे ग्राहक और कानून प्रवर्तन एजेंसियों इस घटना पर जाँच कर सके जब यह साईट ऑफलाइन हो जाये. आदर, Netcraft फ़ोन: +44(0)1225 447500 फैक्स: +44(0)1225 448600 नेटक्राफ्ट इश्यू नंबर: 74966840 इस हमले के बारे में अपडेट के बारे में हमसे संपर्क करने के लिए, कृपया इस ईमेल का जवाब दें। कृपया ध्यान दें: इस पते के उत्तरों को लॉग किया जाएगा, लेकिन हमेशा पढ़ा नहीं जाता है। यदि आपको लगता है कि आपको यह ईमेल गलती से प्राप्त हुआ है, या आपको और सहायता की आवश्यकता है, तो कृपया संपर्क करें: support@netcraft.com। इस मेल को x-arf टूल से पार्स किया जा सकता है। x-arf के बारे में अधिक जानकारी के लिए http://www.xarf.org/ पर जाएं। ------------------- Hello, We have discovered a phishing attack on your network. hxxps://www[.]gamesame.online.newsgini[.]in/wp-includes/IXR/irnknt/redirect [173.208.153.186] We believe that this attack is being restricted so it is only visible from certain countries. Before deciding that the attack has been resolved please confirm it cannot be viewed from the following countries: New Zealand We understand that this site is simply a redirect to a page showing benign content, however it used to redirect to fraudulent content. The redirect is controlled by a fraudster so can be reused for future attacks, making its removal all the more important. You may not have been aware of this attack, however, you are still responsible for removing it. This attack was targeting our customer, Inland Revenue NZ, website URL https://www.ird.govt.nz/. Please remove this fraudulent content, and any other associated fraudulent content, as soon as possible. Additionally, please keep the fraudulent content safe so that our customer and law enforcement agencies can investigate this incident further once the site is offline. More information about the detected issue is provided at https://incident.netcraft.com/915051ebcc99/ NEW: A beta version of our next generation incident reports is available at https://beta.incident.netcraft.com/reports/5gk2hydei7jfldc7i23mew See https://beta.incident.netcraft.com/about for more details including API support. Please contact incident-feedback@netcraft.com with any feedback or for more information. Kind regards, Netcraft Phone: +44(0)1225 447500 Fax: +44(0)1225 448600 Netcraft Issue Number: 74966840 To contact us about updates regarding this attack, please respond to this email. Please note: replies to this address will be logged, but aren't always read. If you believe you have received this email in error, or you require further support, please contact: support@netcraft.com. This mail can be parsed with x-arf tools. Visit http://www.xarf.org/ for more information about x-arf. --_----------=_17573894802178630493 Content-Disposition: inline Content-Transfer-Encoding: 7bit Content-Type: message/feedback-report MIME-Version: 1.0 X-Mailer: MIME::Lite 3.030 (F2.85; T2.17; A2.20; B3.15; Q3.13) Date: Tue, 9 Sep 2025 03:44:40 +0000 Feedback-Type: xarf User-Agent: Netcraft Version: 1 --_----------=_17573894802178630493 Content-Disposition: attachment; filename="xarf.json" Content-Transfer-Encoding: base64 Content-Type: application/json; charset=utf-8; name="xarf.json" MIME-Version: 1.0 X-Mailer: MIME::Lite 3.030 (F2.85; T2.17; A2.20; B3.15; Q3.13) Date: Tue, 9 Sep 2025 03:44:40 +0000 eyJPbkJlaGFsZk9mIjp7IkNvbXBsYWluYW50T3JnRG9tYWluIjoid3d3LmlyZC5nb3Z0Lm56Iiwi Q29tcGxhaW5hbnRPcmdFbWFpbCI6InRha2Vkb3duLXJlc3BvbnNlKzc0OTYyNzkxQG5ldGNyYWZ0 LmNvbSIsIkNvbXBsYWluYW50T3JnIjoiSW5sYW5kIFJldmVudWUgTloifSwiUmVwb3J0Ijp7IlJl cG9ydGVyTm90ZXMiOiJTZWUgaHR0cHM6Ly9pbmNpZGVudC5uZXRjcmFmdC5jb20vOTE1MDUxZWJj Yzk5LyBmb3IgbW9yZSBpbmZvcm1hdGlvbiIsIlNvdXJjZVVybCI6Imh0dHBzOi8vd3d3LmdhbWVz YW1lLm9ubGluZS5uZXdzZ2luaS5pbi93cC1pbmNsdWRlcy9JWFIvaXJua250L3JlZGlyZWN0Iiwi UmVwb3J0Q2xhc3MiOiJDb250ZW50IiwiUmVwb3J0ZXJDYXNlSUQiOiI3NDk2Njg0MCIsIlJlcG9y dFR5cGUiOiJQaGlzaGluZyIsIlNvdXJjZUlwIjoiMTczLjIwOC4xNTMuMTg2IiwiRGF0ZSI6IjIw MjUtMDktMDlUMDM6NDQ6MDNaIn0sIlJlcG9ydGVySW5mbyI6eyJSZXBvcnRlck9yZyI6Ik5ldGNy YWZ0IiwiUmVwb3J0ZXJPcmdEb21haW4iOiJuZXRjcmFmdC5jb20iLCJSZXBvcnRlck9yZ0VtYWls IjoidGFrZWRvd24tcmVzcG9uc2UrNzQ5NjI3OTFAbmV0Y3JhZnQuY29tIn0sIlZlcnNpb24iOiIx IiwiRGlzY2xvc3VyZSI6dHJ1ZX0= --_----------=_17573894802178630493-- newsgini.in/info/maildirsize 0000600 00000000033 15060264272 0012156 0 ustar 00 1073741824S,0C 0 0 12378 1 newsgini.in/info/.spam/maildirfolder 0000640 00000000000 15060264272 0013473 0 ustar 00 newsgini.in/info/.spam/dovecot.index.log 0000640 00000000050 15060264272 0014214 0 ustar 00 ( B��h B��h newsgini.in/info/.spam/dovecot-uidlist 0000640 00000000063 15060264272 0014005 0 ustar 00 3 V1754855751 N1 G70f9bf2d42f99868e7402c008491050f newsgini.in/info/dovecot.list.index.log 0000640 00000001350 15060264272 0014154 0 ustar 00 ( B��h B��h ���� <