Hogyan lehet megoldani, hogy más e-mail címet írjon küldőnek, mint ami a valós volt?
no-reply@microsoft.com a feladó. Egy tájékoztató, hogy beléptek Moszkvából az outlook fiókomba. Hivatalosnak tűnik, főleg a cím miatt, de a rendszer levélszemétbe rakta, amit nem is értettem így (meg még sok dolgot nem értek). A benne levő linkek viszont mind egy kamu gmail címre mutatnak, tehát rendben van a levélszemét dolog. Miért lehet egyáltalán a feladó egy olyan cím, aki biztosan nem küldött ilyen üzenetet?
(belépni amúgy pedig nem is tudna csak úgy senki sem, mert rég be van kapcsolva a kétlépcsős azonosítás. Tehát egyértelmű volt, hogy kamu, csak nem értem azt, hogy hogyan adott meg egy hivatalos microsoft címet küldőként.)
Jaja, spoofing.
ha összegyűlik pár ilyen, akkor automatikusan fekete listára kerül a küldő mind a címzett, mind a küldő (gmail) levelező szerverén.
Megtaláltam a nyers levelet:
Melyik a küldő cím?
Received: from AM8P193MB1251.EURP193.PROD.OUTLOOK.COM (2603:10a6:20b:36a::12)
by VI1P193MB0605.EURP193.PROD.OUTLOOK.COM with HTTPS; Mon, 4 Apr 2022
01:08:15 +0000
Received: from SN4PR0501CA0078.namprd05.prod.outlook.com
(2603:10b6:803:22::16) by AM8P193MB1251.EURP193.PROD.OUTLOOK.COM
(2603:10a6:20b:36a::12) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5123.31; Mon, 4 Apr
2022 01:08:14 +0000
Received: from SN1NAM02FT0016.eop-nam02.prod.protection.outlook.com
(2603:10b6:803:22:cafe::db) by SN4PR0501CA0078.outlook.office365.com
(2603:10b6:803:22::16) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5144.18 via Frontend
Transport; Mon, 4 Apr 2022 01:08:13 +0000
Authentication-Results: spf=fail (sender IP is 31.192.232.163)
smtp.mailfrom=microsoft.com; dkim=none (message not signed)
header.d=none;dmarc=fail action=oreject
header.from=microsoft.com;compauth=fail reason=000
Received-SPF: Fail (protection.outlook.com: domain of microsoft.com does not
designate 31.192.232.163 as permitted sender)
receiver=protection.outlook.com; client-ip=31.192.232.163;
helo=wobrave35.com;
Received: from wobrave35.com (31.192.232.163) by
SN1NAM02FT0016.mail.protection.outlook.com (10.97.4.82) with Microsoft SMTP
Server id 15.20.5123.19 via Frontend Transport; Mon, 4 Apr 2022 01:08:13
+0000
X-IncomingTopHeaderMarker:
OriginalChecksum:A4D84B4CF22A014437CBDFF1B2DF611CA4AF79547E8A59A5CF6B89E46AB4511C;UpperCasedChecksum:46A4A1D0DA8B9ECF56E4027017F22553CE3961780E308CE1EE4326BD48044F40;SizeAsReceived:325;Count:10
From: Microsoft account team <no-reply@microsoft.com>
Subject: Microsoft account unusual sign-in activity
To: 😉😉😉😉@hotmail.com
Date: Mon, 4 Apr 2022 01:08:13 +0000
Reply-To: newsletter@figoshine.com
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: 8bit
X-IncomingHeaderCount: 10
Message-ID:
<ffa5389a-1f82-4b2b-af59-b83af9c7e5ef@SN1NAM02FT0016.eop-nam02.prod.protection.outlook.com>
Return-Path: no-reply@microsoft.com
X-MS-Exchange-Organization-ExpirationStartTime: 04 Apr 2022 01:08:13.7235
(UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id:
e22dc51a-5637-40ea-a2e5-08da15d797ea
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-Exchange-Organization-MessageDirectionality: Incoming
X-MS-PublicTrafficType: Email
X-MS-Exchange-Organization-AuthSource:
SN1NAM02FT0016.eop-nam02.prod.protection.outlook.com
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-UserLastLogonTime: 4/3/2022 8:01:07 PM
X-MS-Office365-Filtering-Correlation-Id: e22dc51a-5637-40ea-a2e5-08da15d797ea
X-MS-TrafficTypeDiagnostic: AM8P193MB1251:EE_
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 31.192.232.163
X-SID-PRA: NO-REPLY@MICROSOFT.COM
X-SID-Result: FAIL
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-SCL: 9
X-Microsoft-Antispam: BCL:0;
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Apr 2022 01:08:13.6610
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: e22dc51a-5637-40ea-a2e5-08da15d797ea
X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-AuthSource:
SN1NAM02FT0016.eop-nam02.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg:
00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM8P193MB1251
X-MS-Exchange-Transport-EndToEndLatency: 00:00:01.9117514
X-MS-Exchange-Processed-By-BccFoldering: 15.20.5123.031
X-Message-Flag: Flag
Importance: high
X-Priority: 1
X-Microsoft-Antispam-Mailbox-Delivery:
kl:0;iwl:0;dkl:0;rwl:0;ucf:0;jmr:0;ex:0;psp:0;auth:0;dest:J;OFR:SpamFilterAuthJ;ENG:(5062000285)(90000117)(90005022)(91005020)(91035115)(5061607266)(5061608174)(9050020)(9100338)(2008001134)(2008000189)(2008010094)(2008120399)(2008019284)(2008020189)(2008130190)(2008021020)(8390246)(8376100)(8377080)(8386120)(210498285)(210499095)(4810004)(4910013)(7110002)(9610025)(9525003)(10140023)(9320005)(9245025);RF:JunkEmail;
X-Message-Info:
qoGN4b5S4yo8NApp0VIRvAwL3oN4zh6R6by2cQPA17o/xfteRxZ2DDw0X+ub2JTa1XUbOPrl+XXYp6SfVEwq6Y1Vo3j8v90NtmTRxXfvyVXpFnq8nYN6Kr9W1IjIoapRoXvycA+YJZ+Pcz4PLnTUdwI+eCZUsf02x+KKFzsJkT8Y2/s0fmDMLBa/bqD+OU/iVRjmwWPm84Lylwsm9hUPGQ==
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtHRD0zO1NDTD02
X-Microsoft-Antispam-Message-Info:
=?utf-8?B?TFhWSTVqTGdiUUxtTVg1UnRzNmVYd0JXQXg0Ym1OcnNoeCtXU1VTbjZkN095?=
=?utf-8?B?ZFZvalJ2MWlXemFBOWE2Nmp0OFNQaVdFa01JVEhqNXhITndzcWRFSDlRSTFB?=
=?utf-8?B?Vm5WVEpkQytwU1h3TVVXU1p0RGQ4TlBNaDV5TlZrME9NRytNNGtYbDdhQXY5?=
=?utf-8?B?RE00bFlFZWNwSE5Wb1g4V3ZxOVV3L0Fyb3EzcnNZOU1JNytGK2l4REN0YTdF?=
=?utf-8?B?VDVUNTdGVTVOL2JkdFYwS1BVWFp0U3pNVEg5UnR6cW9ENVF0NFpORmpaMkRD?=
=?utf-8?B?NWJkVEs5QWxKS2t5OGpmTmtxcHFCLyttQ01DSkFicitOUjQzSWk2a3RSUFFN?=
=?utf-8?B?M2paVzFLalhaYXlFSDdrQUdTRUQ2UHY4YVpXQk5iaU0rb0YwRDA5WmYrTml5?=
=?utf-8?B?aXZQcTVtbUpmMG5rdGRrM055TVp4Nml4RWdCZnU0WVhjK1lEbjRkSU85Qisz?=
=?utf-8?B?b2N2N2ZpbmE5NWxzRVlITzEzd0tOdGp0b2xpVEl0REVYcDhEaloyQ1Y2YTFN?=
=?utf-8?B?dkpKK2RYcW1YaW5ud2JqMDAreUJKYmxQTVV2RWtScjFDWUdvczFSZlBtTExs?=
=?utf-8?B?VnR0Qy82dk5jeTBIOFRMNDZ3bG5PaHpRd1E1ZU9Hd2t1ZGJ4RVQ1M0kzZ1Zx?=
=?utf-8?B?MHl5TGVLbFRlYm81cGZXS3dJTGd6aGI0UHA0dEx0cDBrQ296azdEQWh0YzFk?=
=?utf-8?B?cktiWVROaUhkVHJMV1Foc3I3SHRtUjY5YWxyWjFIQ3lSZGJGTGpPdlY2UHFt?=
=?utf-8?B?TjVlSjRET2lkSTdVTFhPbWR0QUJYaVhwVDQ5LzdNV2tmMlE0UXo2S0tMQkUv?=
=?utf-8?B?bHl5Z21PdU5VQUZtM0xHNWtGazBmbXgyVHpxUk1pVllKR2JuWDJjNDBsaWFC?=
=?utf-8?B?T1A2OWRCSmx6Qk9jMHBWVC9XbUdESFhsSVpTd1NoMjlQM2Q3Z0FPb0htTVNM?=
=?utf-8?B?a3dQbXF2TW1UOU1xVEVCVjMvTmJJNFI2dnZvRzk1bzlYcndNOVV6eVNoQUJ3?=
=?utf-8?B?N0JBc0prdy9IVkRpTVE2bnRVWWxUSWV6M3pQQzUvZ0xXam45WlRRbjl2Z0l3?=
=?utf-8?B?WWR2cWNnZ3pUL0NPSnpIVTJUbmFOdWZveEhEa1F1YWtDTTBHbVc0MW52U0FQ?=
=?utf-8?B?dzl5UmVQWnMwc2IrcCtadmhiWkFVUkNpODUvNFdFamNFTG5ZT3kvZWFjMXc5?=
=?utf-8?B?V1RKSlBRQjJrWXZuUHFBZ3NxZUorQmo0eFU5NGQ1TW94VGUwNy80clZhQncr?=
=?utf-8?B?RXRncUExVUQrb1RpOXNlS3hFS05kcGVQRG9ub3pNZ2xycHY3eHlIbzJRZzgr?=
=?utf-8?B?T2JvODVrL2lzRHVHNURuYUVKUHFJaVlJeDYvaDFPYy8zNDJHcUxKTnlNRERs?=
=?utf-8?B?MUlBR0RVOXBOSTc5V3RUS1dGbnlRMzJlRXRHTklTVUpBa0ZVbmpQaVJaaktL?=
=?utf-8?B?QVJCZm5KMVV0alUySE5YcFc5NHErajhyaGFuaXhzUWIwWDBiM0NEWk1yeGpY?=
=?utf-8?B?cjc1VVIyVXJ2SU8yS01Nc0EzY01BbEtGeWRyWTZhMlVRRVlDVks0MUo3RjJN?=
=?utf-8?B?eGZFTGs0TENPdGI0L2FSalM1TmhDbUdHMjZSY2haVlI1K3lNdVZ5bHU1c0VQ?=
=?utf-8?B?bm9kU0tXZE9KNVNaZElYWXlmaXpjci9kL2JpRmptVVhnN3dsd1RpM2gvQVFU?=
=?utf-8?B?em9qRWEzRmdtL0RYNG9TN0VOUW9LWm1oNld3V2FuQ1kvY0hydTdQQmdPU0Rs?=
=?utf-8?B?T2ZDUUMyNlZibzNVRWM2eW8yM2w4c3hITnFTMzBEdDFIRXBFVi9YVFBIWm05?=
=?utf-8?B?b1RyQk1qbDdxUUlNSG9XQ3Fra1NsKzJ4NDFOZ2o5eTJ0VlJ6M1p4blE0WWtG?=
=?utf-8?B?VVltT3ZZaUZuTE9od091Y3ZqakI1cHh6elMvTklXZjE2clZiM29vRTlzeFZn?=
=?utf-8?B?bHd3dGhSV0JpeGg1cHMxTG45N2ZGblJ6aW82SFd0VmlPZ0J4azRzbXkzMnlr?=
=?utf-8?B?c1VENGw1RmJmTE9HZ0Ixd3M1ZE9jM1JCaTVxNFloOThnSlpHQ29ZVERmbnM1?=
=?utf-8?B?RlFiT05zVk9SRDl2Mmt1dzY3SHZ1LzltanVQRDFqTEcvcE5UallFSTFBS3cx?=
=?utf-8?B?eDNvc0FJUk5WcHJyZEYrN2JYOWxtWUVSdEZXV3FCSzlManBkYkZ5b1E1bUdF?=
=?utf-8?B?RkJxZjU3VkZSd3JHS2xKbDZsOEFGVnlrdWZ4OW80VHhnMnZKY3JWdEMvV1JY?=
=?utf-8?B?aE5PUXZzWDEvdU00YlhmMHkyUEJ6cTNEcjRQb0RzZldEREphaU0yMjFzN3Bu?=
=?utf-8?B?c1EvWGhsaVhnNHZJbVJTcmcxMlRIckdMdS9pR085d1BpQU4rZnkvQWJZTUxv?=
=?utf-8?B?cDcvcG01c1VoYUJidnZEZjc0eUp0N2pRdGJUbnNqZlV5VlhoYmU5UWQvTkhF?=
=?utf-8?B?bStNZWltNU1Gc1g4QkgrUFRja3RVM3JMZlRQTEcrZVVMa1FZNmV4eGpzSWIx?=
=?utf-8?B?RTVDT1dmaFYzWFpxOGRHWXA5WElLSmhtdHBqZkhQZzF1M2F5U3NDZlUwV1BP?=
=?utf-8?B?bzFLdGk5ZFRKVmxLcjhlNDZlcjNGQ0hDTU1FazJqM1B5blJXQ3Z4VDJSd05E?=
=?utf-8?B?NlNZV0N3MEFRaXNkYTd1MkVCMjBIM1Y0YW1FRWZPV0Y0WlpSbG9zZnVQcmhB?=
=?utf-8?B?eS9adlBFUDRGWWZOYVNRcXpydXZhQnYybFZjUVV1aWtyQlhsNlRZTlR1SVQr?=
=?utf-8?B?a0IwNk9PbmQveFRhbjZid1dYUlNjL1FDdFhEWlE0aGk4Q1YzSkJkLzZDcVJn?=
=?utf-8?B?SHdIVldmVlpkSDdLSW1ZRm5hL3QrNWRzUU5aNmFnMW45SjRza0cxOGJQa29Y?=
=?utf-8?B?NGIvTy9GdnN1R2dCQ29halREZlpQWlU0a1Y4c2JVeFhTYU9xMGg3Sm5GU2E2?=
=?utf-8?B?Y2RDa295YnBNcGpZWTZGdWZvK0Q3bkFlVCtySGVwbld1VG9SRlhqL2FmQzdu?=
=?utf-8?B?cU94eldmOHZ4NHBsNDI2ZFNZanFmQnBHbktLeDNMcEpnZjRoa0V1aHhwdktl?=
=?utf-8?B?ODJRd2hPdWtMWEdJZU5ZVGQ4QUlpUUx2T1M1SGpkWGpyaklPVjdmZ3VEMGZt?=
=?utf-8?B?TkxQWEo5a3FjZHA2eW13eTFDUmIxYWt1L1BBSkJPSGtVZGJYcTdnWjkreXJr?=
=?utf-8?B?WXpML3FhY2M2TTQ1WUhtYUZHNnpQdFZ0Zkd3SStjT1VUaG5RajNweUF6WmNR?=
=?utf-8?Q?bBIIzRbZybLaYE+SiCNidiA5ZA=3D?=
MIME-Version: 1.0
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"><table dir="ltr" style="height: 323px;">
<tbody>
<tr style="height: 22px;">
<td id="i1" style="padding: 0px; font-family: 'Segoe UI Semibold', 'Segoe UI Bold', 'Segoe UI', 'Helvetica Neue Medium', Arial, sans-serif; font-size: 17px; color: #707070; height: 22px; width: 696px;">Microsoft account</td>
</tr>
<tr style="height: 53px;">
<td id="i2" style="padding: 0px; font-family: 'Segoe UI Light', 'Segoe UI', 'Helvetica Neue Medium', Arial, sans-serif; font-size: 41px; color: #2672ec; height: 53px; width: 696px;">Unusual sign-in activity</td>
</tr>
<tr style="height: 18px;">
<td id="i3" style="padding: 25px 0px 0px; font-size: 14px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; color: #2a2a2a; height: 18px; width: 696px;">We detected something unusual about a recent sign-in to the Microsoft account <a id="iAccount" class="link" dir="ltr" style="color: #2672ec; text-decoration: none;" href="mailto:unrecognized.suspicious.chenged@googlemail.com?Subject=Report+The+User">😉😉😉😉@hotmail.com</a>.</td>
</tr>
<tr style="height: 18px;">
<td id="i4" style="padding: 25px 0px 0px; font-family: 'Segoe UI Bold', 'Segoe UI Semibold', 'Segoe UI', 'Helvetica Neue Medium', Arial, sans-serif; font-size: 14px; font-weight: bold; color: #2a2a2a; height: 18px; width: 696px;"><strong>Sign-in details</strong></td>
</tr>
<tr style="height: 18px;">
<td id="i5" style="padding: 6px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">Country/region: <strong>Russia/Moscow</strong></td>
</tr>
<tr style="height: 18px;">
<td id="i6" style="padding: 6px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">IP address: <strong>103.225.77.255</strong></td>
</tr>
<tr style="height: 18px;">
<td id="i7" style="padding: 6px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">Date: <strong>Mon, 04 Apr 2022 01:08:13 +0000</strong></td>
</tr>
<tr style="height: 18px;">
<td id="i8" style="padding: 6px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">Platform: <strong>Windows 10</strong></td>
</tr>
<tr style="height: 18px;">
<td id="i9" style="padding: 6px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">Browser: <strong>Firefox</strong></td>
</tr>
<tr style="height: 36px;">
<td id="i10" style="padding: 25px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 36px; width: 696px;">A user from <strong>Russia/Moscow</strong> just logged into your account from a new device, If this wasn't you, please report the user. If this was you, we'll trust similar activity in the future.</td>
</tr>
<tr style="height: 32px;">
<td style="padding: 25px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 32px; width: 696px;">
<table border="0" cellspacing="0">
<tbody>
<tr>
<td style="background-color: #2672ec; min-width: 50px; padding: 5px 20px 5px 20px;" bgcolor="#2672ec"><a id="i11" style="font-family: 'Segoe UI Semibold', 'Segoe UI Bold', 'Segoe UI', 'Helvetica Neue Medium', Arial, sans-serif; font-size: 14px; text-align: center; text-decoration: none; font-weight: 600; letter-spacing: 0.02em; color: #fff;" href="mailto:unrecognized.suspicious.chenged@googlemail.com?subject=unusual sign-in activity&body=Report The User">Report The User</a></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr style="height: 18px;">
<td id="i12" style="padding: 25px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">To opt out or change where you receive security notifications, <a id="iLink5" class="link" style="color: #2672ec; text-decoration: none;" href="mailto:unrecognized.suspicious.chenged@googlemail.com?Subject=Unsubscribe+me">click here</a>.</td>
</tr>
<tr style="height: 18px;">
<td id="i13" style="padding: 25px 0px 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">Thanks,</td>
</tr>
<tr style="height: 18px;">
<td id="i14" style="padding: 0px; font-family: 'Segoe UI', Tahoma, Verdana, Arial, sans-serif; font-size: 14px; color: #2a2a2a; height: 18px; width: 696px;">The Microsoft account team</td>
</tr>
<img alt="" src="http://neversuit.com/track/o12505biSxa3996694YBGM10447870KVQ6239FnHx56" width="1px" height="1px" style="visibility:hidden">
</tbody>
</table>
31.192.232.163
dariusblevins3.pserver.ru
ISP PDK LLC
Usage Type Data Center/Web Hosting/Transit
Hostname(s) dariusblevins3.pserver.ru
Domain Name pserver.ru
Country United States of America
City Los Angeles, California
hostname "dariusblevins3.pserver.ru"
region "California"
country "US"
loc "34.0522,-118.2437"
org "AS44493 Chelyabinsk-Signal LLC"
postal "90009"
timezone "America/Los_Angeles"
- Azért van annyi incidens usában, mert törvényesítették a korrupciót. Ott a szolgáltatók törvényi kötelessége 0. Csak a pénzt kell keresniük. Ezért van a cégeknél 1000 könyvelő és 1 informatikus. Aztán "belűlről" széthekkelik őket, mert orosz hacker csoportok bérlik az usa ip címek java részét.
A törvényhozás meg arra szavaz aki többet fizet a pártnak "támogatás" jogcímen. Ha nem is szarabb rendszer mint a diktatúra, de majdnem. Ott a cégek diktatúrája van.
Köszönöm a segítséget! Nagyon hasznos válaszokat kaptam.
Szép napot!
Kapcsolódó kérdések:
Minden jog fenntartva © 2025, www.gyakorikerdesek.hu
GYIK | Szabályzat | Jogi nyilatkozat | Adatvédelem | Cookie beállítások | WebMinute Kft. | Facebook | Kapcsolat: info(kukac)gyakorikerdesek.hu
Ha kifogással szeretne élni valamely tartalommal kapcsolatban, kérjük jelezze e-mailes elérhetőségünkön!