Return-Path: <microsoft-noreply@microsoft.com>
Delivered-To: behniwal+spam@server.rnv.kpw.mybluehostin.me
Received: from server.rnv.kpw.mybluehostin.me
	by server.rnv.kpw.mybluehostin.me with LMTP
	id UmMtF2H14GnCFQAAyTkJsw
	(envelope-from <microsoft-noreply@microsoft.com>)
	for <behniwal+spam@server.rnv.kpw.mybluehostin.me>; Thu, 16 Apr 2026 08:42:41 -0600
Return-path: <microsoft-noreply@microsoft.com>
Envelope-to: info@behniwalgroup.com
Delivery-date: Thu, 16 Apr 2026 08:42:41 -0600
Received: from [217.17.110.141] (port=54164 helo=141-110-17-217.static.stcable.net)
	by server.rnv.kpw.mybluehostin.me with esmtp (Exim 4.95)
	(envelope-from <microsoft-noreply@microsoft.com>)
	id 1wDNvU-0001R3-3l
	for info@behniwalgroup.com;
	Thu, 16 Apr 2026 08:42:41 -0600
Content-Type: multipart/alternative; boundary=Apple-Mail-B2257843-C211-4DA6-9562-F9A4F5B2C93E
Content-Transfer-Encoding: 7bit
From: microsoft-noreply@microsoft.com
Mime-Version: 1.0 (1.0)
Date: Thu, 16 Apr 2026 16:36:07 +0200
Message-Id: <0AC0B811-4BDB-48BB-931C-267E62444A14@microsoft.com>
To: info@behniwalgroup.com
X-Mailer: iPhone Mail (21G93)
X-Spam-Status: Yes, score=16.8
X-Spam-Score: 168
X-Spam-Bar: ++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "server.rnv.kpw.mybluehostin.me",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Microsoft Support Alert Dear Customer, As a result, your Windows
    license has been temporarily suspended to protect your personal files and
    financial information. To restore your service and remove the detected malware,
    you m [...] 
 Content analysis details:   (16.8 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                             blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: windows.net]
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                            [217.17.110.141 listed in bl.score.senderscore.com]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [217.17.110.141 listed in sa-accredit.habeas.com]
  0.0 HTML_MESSAGE           BODY: HTML included in message
  2.0 RDNS_NONE              Delivered to internal network by a host with no rDNS
  3.5 KAM_PHISH4             Another phishing attempt
  3.0 KAM_DMARC_REJECT       DKIM has Failed or SPF has failed on the
                             message and the domain has a DMARC reject
                             policy
  1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
                             anti-forgery methods
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  3.0 VFY_ACCT_NORDNS        Verify your account to a poorly-configured MTA -
                              probable phishing
  0.2 HELO_MISC_IP           Looking for more Dynamic IP Relays
  4.0 URI_PHISH              Phishing using web form
X-Spam-Flag: YES
Subject:    Urgent: Your Windows License is Expiring and System is Infected!


--Apple-Mail-B2257843-C211-4DA6-9562-F9A4F5B2C93E
Content-Type: text/plain;
	charset=us-ascii
Content-Transfer-Encoding: quoted-printable

Microsoft Support Alert

Dear Customer,
As a result, your Windows license has been temporarily suspended to protect y=
our personal files and financial information.
To restore your service and remove the detected malware, you must verify you=
r identity and update your security settings immediately.
Please click the link below to run a free online system scan and reactivate y=
our license. <https://lerudeba.z5.web.core.windows.net/>

Failure to complete this step within 12 hours will lead to a permanent suspe=
nsion of your Windows OS and potential loss of all local data.

Thank you,
Windows Security Team
1 Microsoft Way, Redmond, WA 98052, USA=

--Apple-Mail-B2257843-C211-4DA6-9562-F9A4F5B2C93E
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: 7bit

<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><b>Microsoft Support Alert</b><br><br>
Dear Customer,<br>
As a result, your Windows license has been temporarily suspended to protect your personal files and financial information. <br>
To restore your service and remove the detected malware, you must verify your identity and update your security settings immediately.<br>
<a href="https://lerudeba.z5.web.core.windows.net/">Please click the link below to run a free online system scan and reactivate your license.</a><br>
<br>
Failure to complete this step within 12 hours will lead to a permanent suspension of your Windows OS and potential loss of all local data.<br>
<br>
Thank you,<br>
Windows Security Team<br>
1 Microsoft Way, Redmond, WA 98052, USA<br></body></html>
--Apple-Mail-B2257843-C211-4DA6-9562-F9A4F5B2C93E--



