Return-Path: <microsoft-noreply@microsoft.com>
Delivered-To: behniwal+spam@server.rnv.kpw.mybluehostin.me
Received: from server.rnv.kpw.mybluehostin.me
	by server.rnv.kpw.mybluehostin.me with LMTP
	id 1zU4HAt/4mmAWAAAyTkJsw
	(envelope-from <microsoft-noreply@microsoft.com>)
	for <behniwal+spam@server.rnv.kpw.mybluehostin.me>; Fri, 17 Apr 2026 12:42:19 -0600
Return-path: <microsoft-noreply@microsoft.com>
Envelope-to: info@behniwalgroup.com
Delivery-date: Fri, 17 Apr 2026 12:42:19 -0600
Received: from [14.174.72.186] (port=41214 helo=static.vnpt.vn)
	by server.rnv.kpw.mybluehostin.me with esmtp (Exim 4.95)
	(envelope-from <microsoft-noreply@microsoft.com>)
	id 1wDo8v-0005s5-RE
	for info@behniwalgroup.com;
	Fri, 17 Apr 2026 12:42:19 -0600
Content-Type: multipart/alternative;
 boundary="--------------nqumkyu3xvihaetgy4xh0nt8"
Message-ID: <cb7c1afd-a8ae-4537-bfbd-a8f41abf4a87@microsoft.com>
Date: Sat, 18 Apr 2026 01:38:17 +0700
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: en-US
To: info@behniwalgroup.com
From: microsoft-noreply@microsoft.com
X-Spam-Status: Yes, score=15.7
X-Spam-Score: 157
X-Spam-Bar: +++++++++++++++
X-Spam-Report: Spam detection software, running on the system "server.rnv.kpw.mybluehostin.me",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  *Microsoft Support Alert* Dear Customer, As a result, your
    Windows license has been temporarily suspended to protect your personal files
    and financial information. 
 Content analysis details:   (15.7 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                             blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: windows.net]
  1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in
                             bl.spamcop.net
               [Blocked - see <https://www.spamcop.net/bl.shtml?14.174.72.186>]
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [14.174.72.186 listed in bl.score.senderscore.com]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                          [14.174.72.186 listed in sa-trusted.bondedsender.org]
  0.0 HTML_MESSAGE           BODY: HTML included in message
  2.0 PYZOR_CHECK            Listed in Pyzor
                             (https://pyzor.readthedocs.io/en/latest/)
  2.0 RDNS_NONE              Delivered to internal network by a host with no rDNS
  3.5 KAM_PHISH4             Another phishing attempt
  3.0 KAM_DMARC_REJECT       DKIM has Failed or SPF has failed on the
                             message and the domain has a DMARC reject
                             policy
  1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
                             anti-forgery methods
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  0.0 FSL_BULK_SIG           Bulk signature with no Unsubscribe
  3.0 VFY_ACCT_NORDNS        Verify your account to a poorly-configured MTA -
                              probable phishing
X-Spam-Flag: YES
Subject:    Urgent: Your Windows License is Expiring and System is Infected!

This is a multi-part message in MIME format.
----------------nqumkyu3xvihaetgy4xh0nt8
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

*Microsoft Support Alert*

Dear Customer,

As a result, your Windows license has been temporarily suspended to 
protect your personal files and financial information.

To restore your service and remove the detected malware, you must verify 
your identity and update your security settings immediately.

Please click the link below to run a free online system scan and 
reactivate your license. <https://nuvecifa.z20.web.core.windows.net/>

Failure to complete this step within 12 hours will lead to a permanent 
suspension of your Windows OS and potential loss of all local data.

Thank you,

Windows Security Team

1 Microsoft Way, Redmond, WA 98052, USA

----------------nqumkyu3xvihaetgy4xh0nt8
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<!DOCTYPE html>
<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <b>Microsoft Support Alert</b><br><br>
Dear Customer,<br>
As a result, your Windows license has been temporarily suspended to 
protect your personal files and financial information. <br>
To restore your service and remove the detected malware, you must verify 
your identity and update your security settings immediately.<br>
<a href="https://nuvecifa.z20.web.core.windows.net/">Please click the 
link below to run a free online system scan and reactivate your 
license.</a><br>
<br>
Failure to complete this step within 12 hours will lead to a permanent 
suspension of your Windows OS and potential loss of all local data.<br>
<br>
Thank you,<br>
Windows Security Team<br>
1 Microsoft Way, Redmond, WA 98052, USA<br>
  </body>
</html>

----------------nqumkyu3xvihaetgy4xh0nt8--


