Ninja Air fryer phish from Microsoft Outlook
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 09 Mar 2024 12:46:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))
(envelope-from)
id 1rj2dQ-00000000EIR-2w5T
for dave@doctor.nl2k.ab.ca;
Sat, 09 Mar 2024 12:45:32 -0700
Resent-From: The Doctor
Resent-Date: Sat, 9 Mar 2024 12:45:32 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-mw2nam12on2122.outbound.protection.outlook.com ([40.107.244.122]:13153 helo=NAM12-MW2-obe.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.97.1 (FreeBSD))
(envelope-from)
id 1rj0Rj-00000000MTf-1QBq
for root@nk.ca;
Sat, 09 Mar 2024 10:25:24 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=fHIPmhNtWv8kfRzusjrT7yQv0dDQ+AsrfS6u46cM7JqEDEDyGGe9V6+lCo4/qm4OfKF0LCDGCUffjib40b3FK3e4HNOq2kevkrGqjePygy/5KWsU/4DR2I8TYujaawWSj2kkIpnZfYk3mXaYZ9Qs/OTDg8629DygSIMLH9l9jDIT0zw8CEXuzUATlnRBxmGHvsoidCf4x2Uz1mX5/NwTRuMjTPotLPhoTDfOJzOO0IBD8zrwebY3I2bKC/ed1XCMvXUGUlA2zxATpDU4+x7nc0chwuFSVmPbpdyS0OR1pcBiLw8XP0Jr+u8VCVuG50bay7nOQXGGYsuaR3yfnqeQdA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=Hwgp5uVOoppmQNJojsSp4hkLG91Ls2AnIjf0k3616CA=;
b=i+sFXxuiqebMEcx4L9AR2Nf6tE/a5rGILYGiMVknz+XkpprmNfpKdH/rwEeP6SffDwMUac2v6ODwlZbILNuL3QIp+tL1BCwrj02S+EonOMvOUIeZr1/sbVq68DtDh0cbvEwE64B96PHtAi7Q6HqDgrbh0O2UPFaTGjNQe1gOUOX6ubs4ZvoLUHMMVXpI8yBeJMJMfcApVkhjZwsrkdfdz4n0sHekq/iOSN6mREyY0pjxN6YB30LOlvDr3Z4kCdkpZ8CON6MXapX0u1GtE0DuJV0ocauQ/2cFideQpEHWFsINIYgxH8pMc0hSm2f3/Xa7QHDgI9VWQOhiU6Y/s1/Wkg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is
45.33.102.68) smtp.rcpttodomain=nk.ca
smtp.mailfrom=ghhjgjtg45jk.onmicrosoft.com; dmarc=none action=none
header.from=ghhjgjtg45jk.onmicrosoft.com; dkim=none (message not signed);
arc=none (0)
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 45.33.102.68)
smtp.mailfrom=ghhjgjtg45jk.onmicrosoft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=ghhjgjtg45jk.onmicrosoft.com;
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="UTF-8"
CC: root@nk.ca
Date: 03-09-2024
Subject: Order Confirmation
MIME-Version: 1.0
From: "Ninja-Air-Fryer-Unlocked"
In-Reply-To:
To: root@nk.ca
Message-ID:
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DM6NAM12FT065:EE_|SJ0PR11MB5198:EE_
X-MS-Office365-Filtering-Correlation-Id: b21958cf-69f2-43dd-3515-08dc405d9ae6
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
ay8bJSpyV8x3WxLSNcikfqfhP+tzkt4T+lw3ceEfAq8VsDYcFAYlaWhMAcJT+Or8ReFi7wdcABpd3ufWdyLSym89ocJTu1GaMRjb2KFC4u9RfvJKYF4s1KFb83YlTciEt3yV80uwsbPtUTzFttyqBVW2+nV4iOWU1GqTRPl08StPM9J2/bfgxwLE3zuukLG4g3Rtui96wE9EVqLM6GPnSRecEYj57MBUcISnW+RslHToI4WW6tsqyEqvSvYDBjsgQX+QIUlUQ2EfVSwgqoggWgaVw4IuN6zECIs02NO9BrdOP3E05lmnRb9Dbeljh/jLiovHMnzXwHse0fjifLxeNsBL/7Ai/RfrIZUIwN+zlW5ReV6iHxkF5CGWRRI86Qus2hjepehUNTkT/1YWM879XzV29vMvctc10m5NO7nUdvR2fxKUmL2f2QeO5uOsZQwRSD5zedKNr+uAQBN35Hsu0dOhrabOpY7lbuKse0/x/A3wmbNx2A5mWB+Ah2ZBMfYQyOYBH33NkpCYQSSz8sE2iSBJF3x69/MbpY7bSWhWSLtP0pHxh7PbtKGkVRxmdiIqfp9xnjcfkTSSt4lxpFOrcD7Xhim8UobsdJzGKMbpdbyI/p+BP9jAJmRUb9tTxhnQakGCLS6O62XAMlOLI/byT4fBlXibLiE+11BhBTaU7QcPqKOE7OxRFStarsYTrKRa7SLNEEoPovGC4ty5fANMuKC1VfErOHliYflms2jTx3Q=
X-Forefront-Antispam-Report:
CIP:45.33.102.68;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:ghhjgjtg45jk.onmicrosoft.com;PTR:45-33-102-68.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(36860700004)(41320700004)(34070700005)(82310400014)(61400799018)(376005)(4523499018);DIR:OUT;SFP:1102;
X-OriginatorOrg: ghhjgjtg45jk.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Mar 2024 17:23:15.3744
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b21958cf-69f2-43dd-3515-08dc405d9ae6
X-MS-Exchange-CrossTenant-Id: b1d303d8-ea8d-4ff8-b122-f8eceb6888d5
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=b1d303d8-ea8d-4ff8-b122-f8eceb6888d5;Ip=[45.33.102.68];Helo=[ghhjgjtg45jk.onmicrosoft.com]
X-MS-Exchange-CrossTenant-AuthSource:
DM6NAM12FT065.eop-nam12.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR11MB5198
(1) Notifications
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 09 Mar 2024 12:46:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rj2dQ-00000000EIR-2w5T
for dave@doctor.nl2k.ab.ca;
Sat, 09 Mar 2024 12:45:32 -0700
Resent-From: The Doctor
Resent-Date: Sat, 9 Mar 2024 12:45:32 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-mw2nam12on2122.outbound.protection.outlook.com ([40.107.244.122]:13153 helo=NAM12-MW2-obe.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rj0Rj-00000000MTf-1QBq
for root@nk.ca;
Sat, 09 Mar 2024 10:25:24 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=fHIPmhNtWv8kfRzusjrT7yQv0dDQ+AsrfS6u46cM7JqEDEDyGGe9V6+lCo4/qm4OfKF0LCDGCUffjib40b3FK3e4HNOq2kevkrGqjePygy/5KWsU/4DR2I8TYujaawWSj2kkIpnZfYk3mXaYZ9Qs/OTDg8629DygSIMLH9l9jDIT0zw8CEXuzUATlnRBxmGHvsoidCf4x2Uz1mX5/NwTRuMjTPotLPhoTDfOJzOO0IBD8zrwebY3I2bKC/ed1XCMvXUGUlA2zxATpDU4+x7nc0chwuFSVmPbpdyS0OR1pcBiLw8XP0Jr+u8VCVuG50bay7nOQXGGYsuaR3yfnqeQdA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=Hwgp5uVOoppmQNJojsSp4hkLG91Ls2AnIjf0k3616CA=;
b=i+sFXxuiqebMEcx4L9AR2Nf6tE/a5rGILYGiMVknz+XkpprmNfpKdH/rwEeP6SffDwMUac2v6ODwlZbILNuL3QIp+tL1BCwrj02S+EonOMvOUIeZr1/sbVq68DtDh0cbvEwE64B96PHtAi7Q6HqDgrbh0O2UPFaTGjNQe1gOUOX6ubs4ZvoLUHMMVXpI8yBeJMJMfcApVkhjZwsrkdfdz4n0sHekq/iOSN6mREyY0pjxN6YB30LOlvDr3Z4kCdkpZ8CON6MXapX0u1GtE0DuJV0ocauQ/2cFideQpEHWFsINIYgxH8pMc0hSm2f3/Xa7QHDgI9VWQOhiU6Y/s1/Wkg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is
45.33.102.68) smtp.rcpttodomain=nk.ca
smtp.mailfrom=ghhjgjtg45jk.onmicrosoft.com; dmarc=none action=none
header.from=ghhjgjtg45jk.onmicrosoft.com; dkim=none (message not signed);
arc=none (0)
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 45.33.102.68)
smtp.mailfrom=ghhjgjtg45jk.onmicrosoft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none
header.from=ghhjgjtg45jk.onmicrosoft.com;
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="UTF-8"
CC: root@nk.ca
Date: 03-09-2024
Subject: Order Confirmation
MIME-Version: 1.0
From: "Ninja-Air-Fryer-Unlocked"
In-Reply-To:
To: root@nk.ca
Message-ID:
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DM6NAM12FT065:EE_|SJ0PR11MB5198:EE_
X-MS-Office365-Filtering-Correlation-Id: b21958cf-69f2-43dd-3515-08dc405d9ae6
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
ay8bJSpyV8x3WxLSNcikfqfhP+tzkt4T+lw3ceEfAq8VsDYcFAYlaWhMAcJT+Or8ReFi7wdcABpd3ufWdyLSym89ocJTu1GaMRjb2KFC4u9RfvJKYF4s1KFb83YlTciEt3yV80uwsbPtUTzFttyqBVW2+nV4iOWU1GqTRPl08StPM9J2/bfgxwLE3zuukLG4g3Rtui96wE9EVqLM6GPnSRecEYj57MBUcISnW+RslHToI4WW6tsqyEqvSvYDBjsgQX+QIUlUQ2EfVSwgqoggWgaVw4IuN6zECIs02NO9BrdOP3E05lmnRb9Dbeljh/jLiovHMnzXwHse0fjifLxeNsBL/7Ai/RfrIZUIwN+zlW5ReV6iHxkF5CGWRRI86Qus2hjepehUNTkT/1YWM879XzV29vMvctc10m5NO7nUdvR2fxKUmL2f2QeO5uOsZQwRSD5zedKNr+uAQBN35Hsu0dOhrabOpY7lbuKse0/x/A3wmbNx2A5mWB+Ah2ZBMfYQyOYBH33NkpCYQSSz8sE2iSBJF3x69/MbpY7bSWhWSLtP0pHxh7PbtKGkVRxmdiIqfp9xnjcfkTSSt4lxpFOrcD7Xhim8UobsdJzGKMbpdbyI/p+BP9jAJmRUb9tTxhnQakGCLS6O62XAMlOLI/byT4fBlXibLiE+11BhBTaU7QcPqKOE7OxRFStarsYTrKRa7SLNEEoPovGC4ty5fANMuKC1VfErOHliYflms2jTx3Q=
X-Forefront-Antispam-Report:
CIP:45.33.102.68;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:ghhjgjtg45jk.onmicrosoft.com;PTR:45-33-102-68.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(36860700004)(41320700004)(34070700005)(82310400014)(61400799018)(376005)(4523499018);DIR:OUT;SFP:1102;
X-OriginatorOrg: ghhjgjtg45jk.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Mar 2024 17:23:15.3744
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: b21958cf-69f2-43dd-3515-08dc405d9ae6
X-MS-Exchange-CrossTenant-Id: b1d303d8-ea8d-4ff8-b122-f8eceb6888d5
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=b1d303d8-ea8d-4ff8-b122-f8eceb6888d5;Ip=[45.33.102.68];Helo=[ghhjgjtg45jk.onmicrosoft.com]
X-MS-Exchange-CrossTenant-AuthSource:
DM6NAM12FT065.eop-nam12.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR11MB5198
Trackbacks
Trackback specific URI for this entryThis link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.
No Trackbacks
Comments
Display comments as Linear | ThreadedNo comments