Received: from [149.255.111.222] (HELO phone4profit.com)
by inbound.appriver.com (CommuniGate Pro SMTP 5.4.4)
with ESMTP id 115404443 for removed@oops.com; Wed, 30 Jul 2014
13:18:17 -0400
From: derek@phone4profit.com
To: removed@oops.com
Subject: --Critical problem with your account
Date: 30 Jul 2014 14:18:15 -0700
Message-ID: <20140730141814.2386798D6FAB9571@phone4profit.com>
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 8bit
X-Note-AR-ScanTimeLocal: 7/30/2014 1:18:18 PM
X-Policy: removed@oops.com
X-Primary: removed@oops.com
X-Note: This Email was scanned by AppRiver SecureTide
X-Virus-Scan: V-
X-Note-SnifferID: 57
X-GBUdb-Analysis: 0, 149.255.111.222, Ugly c=0 p=0 Source New
X-Signature-Violations:
57-6526004-694-718-m
57-6526004-1038-1062-m
57-6526004-0-1177-f
X-Note: StopOnFail for SIGNATURE
X-Warn: REVDNS No Reverse DNS record for 149.255.111.222
X-Warn: ARGDBL Failed URIBINARY Code: ZXp3YXkxMi5iaXo=
X-Warn: HELOBOGUS HELO command domain phone4profit.com is an NXdomain.
X-Warn: SIGNATURE Failed Signature
X-Warn: WEIGHT10
X-Warn: WEIGHT15
X-Warn: WEIGHT20
X-Warn: WEIGHT30
X-Note: Spam Tests Failed: REVDNS, ARGDBL, HELOBOGUS, SIGNATURE, WEIGHT10, WEIGHT15, WEIGHT20, WEIGHT30
X-Country-Path: UNITED KINGDOM->
X-Note-Sending-IP: 149.255.111.222
X-Note-Reverse-DNS:
X-Note-Return-Path: derek@phone4profit.com
X-Note: User Rule Hits:
X-Note: Global Rule Hits: G335 G336 G337 G338 G340 G345 G373 G385 G413 G435
G438 G445 G446 G447 G448 G487
X-Note: Encrypt Rule Hits:
X-Note: Mail Class: GETRICH

We have proactively blocked port 25 on the remaining servers. 

Also Read

NJ Port Scanning
We have blocked someone from your IP space for abuse. Reason: Port Scanning. Log lines are below....
California - 106 Notices of Claimed Infringements May 11
More Abusive DMCA reports from a single file.-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1...
NL Abuse Complaint: Abuse complaint: ***UNCHECKED*** RBL Listing Notification - AS16265 - LEASEWEB
** This is an automated e-mail to inform you of an abuse complaint **   ABUSE TYPE: ATTACK...
Dorkbot Malware Infection
Sir/Ma’am, US-CERT Received a report from a trusted third party of a possible malicious...
UK SPAM Static IP Server
X-Originalarrivaltime: 25 Jul 2014 15:11:43.0391 (UTC) FILETIME=[BE648AF0:01CFA81A] MIME-Version:...