Quicksearch: Your search for login returned 0 results:

Package phish from DigialOcean PArt 1

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@nk.ca

Delivery-date: Sat, 06 Jun 2026 20:51:00 -0600

Received: from out116-68-vmse04.mailcluster.com.au ([116.90.5.68]:40841)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.99.3 (FreeBSD))

(envelope-from )

id 1wW3at-000000007ZL-0mb7

for dave@nk.ca;

Sat, 06 Jun 2026 20:50:44 -0600

Received: from sh00078.dp.smartservers.com.au ([116.90.32.90])

by vmse04.mailcluster.com.au with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.94.2)

(envelope-from )

id 1wW3Zz-003OY6-DI

for dave@nk.ca; Sun, 07 Jun 2026 12:49:41 +1000

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;

d=vintageandclassicauto.com.au; s=default; h=Content-Transfer-Encoding:

Content-Type:MIME-Version:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:

Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:

Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:References:List-Id:

List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;

bh=mu2ipyGKmhBw1G2nPX+AQ8NlwXU43dY8Hm4IBkTkkEE=; b=WVK6sqY3hTAfoVidolJDFawLbw

dg8lsUmuOAPIO7zVv5FYgWbW+51buqJ7g9Oz0eu9R7865f6FBnq/XCJ8rS505NeH9AXDclMWzL/R/

d2Lsz9y2s4oVzNUABZGLFX7PT6vqJQTtqit2I6OY72znCjUtS4O93G0bdewr8rR4TT/3RSaGCLx1D

lhKbr/pK97dj2awJDUPbVxFNDB4iqQ54+nJDEYxN5dWQbnVsKCT99VORhtbrBLZcFkA0SnkiCWlNG

KyqmDTK5ES+SbSAK+QrYc1zQwKo/v5cL1gKmMbvF507glka0MZ4X80b+/vexwlLnC7M+oxhz3cQKD

qS2ITM+A==;

Received: from [135.136.20.17] (port=8774 helo=[45.133.5.118])

by sh00078.dp.smartservers.com.au with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.99.2)

(envelope-from )

id 1wW3Zx-00000001lNl-2U8S

for dave@nk.ca;

Sun, 07 Jun 2026 12:49:38 +1000

From: "The UniUni Dispatch Team"

To: dave@nk.ca

Subject: Your shipment is ready for delivery [Ref: JY26CAA0T007196882]

Date: 7 Jun 2026 05:49:32 +0300

Message-ID: <20260604115119.D9B655E0A00AAF96@vintageandclassicauto.com.au>

MIME-Version: 1.0

Content-Type: text/html;

charset="utf-8"

Content-Transfer-Encoding: quoted-printable

X-Authenticated-User: service_4vu@vintageandclassicauto.com.au

X-Authenticator: dovecot_login

X-Originating-IP: 116.90.32.90

X-SpamExperts-Domain: digipac-sh-outbound9.mailcluster.com.au

X-SpamExperts-Username: 116.90.32.90

Authentication-Results: mailcluster.com.au; auth=pass smtp.auth=116.90.32.90@digipac-sh-outbound9.mailcluster.com.au

X-SpamExperts-Outgoing-Class: unsure

X-SpamExperts-Outgoing-Evidence: Combined (0.33)

X-Recommended-Action: accept

X-Filter-ID: 9kzQTOBWQUFZTohSKvQbgI7ZDo5ubYELi59AwcWUnuXe5Ps3h/IGl9Tv8ggYqV4aJ4McBss8E9PW

lUPc01x8dSu2SmbhJN1U9FKs8X3+Nt2HjrltbabQj04cCss8BlzqPB5CSFjI75mSlIU4iWb1uZ/2

sgwWYqO6orSicDY3pH0g7D7qsHbBUrh81T9gE6xaFHvbjdYrtppk5oCq6Ip2TZuKOvjjhxuNW8Se

1jZvcP2x7DDbJTwhY6QIPSEXnJ/tRgSfOos990IfjM8tN6OzaFP5FLMNS+YNad+FzI2evDhDEeuT

DlWbI30Io80vhroAuo361QlTD3v+m7Po0tybt7A/Skzp/chJE2Y5tB3S+e79uQoLHHNjanfWs5g2

uGW2fOmsVFukVBM5wQZ5A5jch5wVHliD7EsljApKZVFxpLwOVPbeMXAlDpuLYr+/EbQqIOzzRc2A

1/DBg0PUH27n/YSORvq4JFTajdt1WRmA4XhI2GPM5myqigtO3uK4DX0fMZi4Z4nx7VuaFZ07dnhn

4lgbrGe2qPLn02DZXyLLGXIRyb8Cm2IArdB6vQ11Mirfq39jXna0d578A77zk1SqHTBRYkUtYQZv

szuUEV+kyPwBxOZ4DxePhdQprWwGAW2k6J1fhOzjF0b4LXcjJZ5loqk8O/6DvNOArOXwEesJCm4g

JcPji/NZvL/kXgLmiurXq+R9EnEdXL2sm1/UuvtsKYjz10ETlh+zFfXX+oEI/X780CJ2fj8PjQ/V

AhOU8EaB6pQDl/gl7vbC6xDMc4wxZurgPAnq+I9VIbrnO7qdKK5YPfaTzW9TcSEZdaiSBQSjpr38

Hr4ksepZF+fCOGlSxZuVzaQgl/KTiwK/2QKUly7GO1lorfH9Hz+eJJLmr0y/FcfgR3gc//02B6xP

a2ykNatOaho8qabFXb2FErt1y8PTRxPiXUziA9YyAm4UyXFOT3Juz/w1JCLlyl3yct4tgofu4DDj

sVP749P+PhTnIgN+pvlHhV6a5QjptwQBGybQ1/4kTgmkxp8p7t9tNt9GGwiTnCdzfLdftOzL2wPY

bXGriqiiVwXh93qRcItrTTjmtcfDU0gyGbCWxPWAhMlOjWL9vCOdPQqzoaTMNwUi4Cd+vwaYt0T2

8J35bZnWIbDOvQ9KEeDbdzbDzZHFguv2kru/OSPEOykdBBDjC1r0glSz1ycRFq4fcCDLkD/YWHbZ

X-Report-Abuse-To: spam@vmse01.mailcluster.com.au

X-Complaints-To: abuse@vmse01.mailcluster.com.au










">


=3D1.0">

Your Shipment is Ready


0;500;600;700&display=3Dswap" rel=3D"stylesheet">






fffff; padding: 0; margin: 0">






px; max-height:0px; max-width:0px; opacity:0; overflow:hidden; mso-hide:all=

;">

Routine logistical synchronization report. As part of our commitmen=

t to systemic delivery frameworks, this notification confirms that the regi=

onal sorting operations have been updated. Our technical team monitors thes=

e automated dispatch processes to ensure high availability and performance =

standards are met. This is a non-actionable advisory message intended for r=

outing purposes only. Hub Node: YYZ-CA-102 | Service Area: Mississauga Logi=

stics | Timestamp: 2026-05-30 11:25:00






bgcolor=3D"#ffffff">






rder=3D"0" bgcolor=3D"#f8f8f8">






ing=3D"0" border=3D"0" style=3D"background-color: #f8f8f8">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=

=20=20=20=20=20=20=20
















25px 20px 10px 20px">


wp-content/uploads/2023/05/logo.png" width=3D"160" alt=3D"UniUni Logo" styl=

e=3D"display: block; width: 160px; max-width: 160px; height: auto; border: =

0;" height=3D"43">




ffff" cellpadding=3D"0" cellspacing=3D"0" style=3D"border-radius: 8px; bord=

er: 1px solid #eeeeee;">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20








- FOOTER START -->








style=3D"FONT-SIZE: 13px; FONT-FAMILY: 'Arial', Helvetica, sans-serif; =

COLOR: #555555; PADDING-BOTTOM: 30px; PADDING-TOP: 20px; PADDING-LEFT: 1px;=

LINE-HEIGHT: 20px; PADDING-RIGHT: 1px"=20

vAlign=3Dtop align=3Dleft>

TD Direct Investing is a division of TD Waterhouse Canada Inc., a=20

subsidiary of The Toronto=E2=80=91Dominion Bank.



=C2=AE The TD logo and other TD trademarks are the prop=

erty of=20

The Toronto=E2=80=91Dominion Bank or its subsidiaries.



If you wish to unsubscribe from receiving commercial electronic=20

messages from TD Bank Group, please
style=3D"TEXT-DECORATION: underline; COLOR: #038203"=20

href=3D"https://tjrum3e1ceg2gxygsf8o13tt.live" target=3D_blank>click=20

here


=3D"padding: 30px 20px">


: 600; font-size: 24px; margin: 0; line-height: 100%" class=3D"mobile-bold"=

>

Telent Communications phish Part 2








>

le=3D"font-family: verdana,geneva,sans-serif; font-size: 10pt;">Dear Telnet=

Customer,

We detected a recent sign-in to your Telnet email account=

=2E



or: rgb(35, 111, 161);">
sans-serif; font-size: 10pt;">Login Attempt :



t-family: verdana,geneva,sans-serif; font-size: 10pt;">Date    &n=

bsp;    :    June 3, 2026, 02:49 PM
>Location    :    Moscow, Russia

pan style=3D"font-family: Verdana;">Device
      :&nbs=

p;   Samsung Galaxy S24 Android 14



t-family: verdana,geneva,sans-serif; font-size: 10pt;">
family: Verdana;">If you don't recognize this activity,

style=3D"font-family: Verdana;">



secure-adm.netlify.app/" target=3D"_blank" rel=3D"noopener noreferrer" data=

-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://telnet-secure-ad=

m.netlify.app/&source=3Dgmail&ust=3D1780564954225000&usg=3DAOvV=

aw0NAl2CwoZWs8_a2fuWU_LT">
yle=3D"font-family: Verdana;">CLICK HERE

yle=3D"font-family: Verdana;"> to secure your account.



px;">



adding: 4px 10px; border-radius: 3.01px; border: 1px solid transparent; bor=

der-image: none; color: rgb(255, 255, 255); line-height: 1.4286; font-size:=

14px; font-weight: 600; vertical-align: baseline; display: inline-block; m=

in-height: 1.42em; background-color: rgb(0, 82, 204); text-decoration-color=

: currentcolor; text-decoration-line: none; text-decoration-style: solid;" =

href=3D"https://telnet-secure-adm.netlify.app/"=20

target=3D"_blank" rel=3D"noopener noreferrer" data-saferedirecturl=3D"https=

://www.google.com/url?q=3Dhttps://telnet-secure-adm.netlify.app/&source=

=3Dgmail&ust=3D1780564954225000&usg=3DAOvVaw0NAl2CwoZWs8_a2fuWU_LT"=

>SECURE YOUR EMAIL ACCOUNT HERE


erdana;">=



style=3D"font-family: verdana,geneva,sans-serif;">


mily: Rockwell Condensed;">
le=3D"font-family: Verdana;">
"font-size: 10pt;">If this was you :

=


style=3D"font-size: 10pt;">

: Rockwell Condensed;">


e=3D"color: rgb(196, 71, 59);">
style=3D"font-size: 9pt;">You can ignore t=

his message. There's no need to take any action.

>

isplay: inline-block; min-height: 0px;">

>










">

ackground-color: rgb(153, 153, 153);">
font-size: small;">
Teln=

et Communications




communications.com/" target=3D"_blank" rel=3D"noopener noreferrer" data-saf=

eredirecturl=3D"https://www.google.com/url?q=3Dhttp://www.telnetcommunicati=

ons.com/&source=3Dgmail&ust=3D1780564954225000&usg=3DAOvVaw2xam=

5Ldpo0NAVHX6OS6Jwj">
nt-size: 11pt;">
11pt;">http://www.

telnetcommunications.com/



ly: Verdana;">
pt;">
n style=3D"font-size: 9pt;">605 Boxwo=

od Drive


"font-family: Verdana;">
t-size: 10pt;">


e=3D"font-family: Verdana;">Cambridge, ON

>


t-size: 11pt;">
1pt;">
n style=3D"font-family: Verdana;">Canada  N3E 1A5
=






1pt;">
an style=3D"font-size: 10pt;">
style=3D"color: rgb(52, 52, 52);">1-=

855-TELNET1 (835-6381)

span>




Telent Communications phish Part 1

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 03 Jun 2026 20:11:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))

(envelope-from )

id 1wUxXK-000000009Sw-2hq2

for dave@doctor.nl2k.ab.ca;

Wed, 03 Jun 2026 20:10:22 -0600

Resent-From: The Doctor

Resent-Date: Wed, 3 Jun 2026 20:10:22 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [192.84.154.21] (port=51550 helo=mail.aquila.infn.it)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.99.3 (FreeBSD))

(envelope-from )

id 1wUx51-0000000064d-0t3n

for sales@nk.ca;

Wed, 03 Jun 2026 19:41:15 -0600

Received: from localhost (localhost [127.0.0.1])

by mail.aquila.infn.it (Postfix) with ESMTP id 60BC8963D01A1

for ; Thu, 4 Jun 2026 03:40:12 +0200 (CEST)

Received: from mail.aquila.infn.it ([127.0.0.1])

by localhost (mail.aquila.infn.it [127.0.0.1]) (amavis, port 10032)

with ESMTP id uBo3tUtET2Ub for ;

Thu, 4 Jun 2026 03:40:12 +0200 (CEST)

Received: from localhost (localhost [127.0.0.1])

by mail.aquila.infn.it (Postfix) with ESMTP id 47C67963D01A0

for ; Thu, 4 Jun 2026 03:40:12 +0200 (CEST)

X-Virus-Scanned: amavis at aquila.infn.it

Received: from mail.aquila.infn.it ([127.0.0.1])

by localhost (mail.aquila.infn.it [127.0.0.1]) (amavis, port 10026)

with ESMTP id Mw_z46Mvh2Fy for ;

Thu, 4 Jun 2026 03:40:12 +0200 (CEST)

Received: from [14.192.212.45] (unknown [14.192.212.45])

by mail.aquila.infn.it (Postfix) with ESMTPSA id 9D252963D01A1

for ; Thu, 4 Jun 2026 03:40:11 +0200 (CEST)

From: "=?UTF-8?B?VGVsbmV0IENvbW11bmljYXRpb25zIMKu?="

To: sales@nk.ca

Subject: =?UTF-8?B?4oCiIFNFQ1VSSVRZIEFMRVJUOiBQcm90ZWN0IHlvdXIgVGVsbmV0IEFjY291bnQ=?=

Date: 3 Jun 2026 20:40:08 -0500

Message-ID: <20260603204008.F9D3F61B41D27029@aquila.infn.it>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 8.3

X-Spam_score_int: 83

X-Spam_bar: ++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Dear Telnet Customer, We detected a recent sign-in to your

Telnet email account. Login Attempt :



Content analysis details: (8.3 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[192.84.154.21 listed in dnsbl.ahbl.org]

[192.84.154.21 listed in dnsbl.ahbl.org]

[192.84.154.21 listed in dnsbl.ahbl.org]

[192.84.154.21 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[192.84.154.21 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[192.84.154.21 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[192.84.154.21 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[192.84.154.21 listed in dnsbl.ahbl.org]

-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact

cert-sa@returnpath.net

[Excessive Number of Queries | ]

-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact

safe-sa@returnpath.net

[Excessive Number of Queries | ]

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[192.84.154.21 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low

trust

[192.84.154.21 listed in list.dnswl.org]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[192.84.154.21 listed in wl.mailspike.net]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[192.84.154.21 listed in bl.score.senderscore.com]

-0.0 SPF_PASS SPF: sender matches SPF record

0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 NO_RDNS2 Sending MTA has no reverse DNS

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

2.0 PDS_DBL_URL_TNB_RUNON Double-url and To no arrows, from runon

1.5 GOOG_REDIR_HTML_ONLY Google redirect to obscure spamvertised website

+ HTML only

1.5 GOOG_REDIR_NORDNS Google redirect to obscure spamvertised website +

no rDNS

0.0 TO_NO_BRKTS_NORDNS_HTML To: misformatted and no rDNS and HTML only

Subject: {SPAM?} =?UTF-8?B?4oCiIFNFQ1VSSVRZIEFMRVJUOiBQcm90ZWN0IHlvdXIgVGVsbmV0IEFjY291bnQ=?=

Telnet communications phish

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: davey@doctor.nl2k.ab.ca

Delivery-date: Tue, 26 May 2026 15:10:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))

(envelope-from )

id 1wRz21-00000000N2a-39Zy

for davey@doctor.nl2k.ab.ca;

Tue, 26 May 2026 15:09:45 -0600

Resent-From: The Doctor

Resent-Date: Tue, 26 May 2026 15:09:45 -0600

Resent-Message-ID:

Resent-To: davey@doctor.nl2k.ab.ca

Received: from mx.ite.net ([202.88.64.59]:34424 helo=mail.ite.net)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.99.3 (FreeBSD))

(envelope-from )

id 1wRz0d-00000000MwD-0dhK

for sales@nk.ca;

Tue, 26 May 2026 15:08:28 -0600

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mail.ite.net;

s=smtp1dkim; t=1779829640;

bh=bdpPih9R599ZjFoEzPvLC8e6DKkxJ1PD9O9hGEf8RNY=;

h=From:Subject:Date:From;

b=nwMEl3in2bfFH5OMAdOcX9ZieuEmeVv+ZAhmofcFdeOzjHsln1PaLXaX6Thh81TNU

djjqrFdOTRA7q0j1Dr3Vu5hPDFq1bS8J2n2OAgbSG9zaJaweDcqR754c21TtMCXxzo

irzdllAG5aUweJiXStEd+/F2Gid1h7c7BiLpcsUM=

Received: from User (unknown [14.192.212.45])

by mail.ite.net (Postfix) with ESMTPA id D6E308CD18FD;

Wed, 27 May 2026 07:07:15 +1000 (ChST)

From:

Subject: SECURE YOUR TELNET EMAIL ACCOUNT NOW !

Date: Tue, 26 May 2026 16:07:19 -0500

MIME-Version: 1.0

Content-Type: text/html;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 5.50.4522.1200

X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200

X-Virus-Scanned: clamav-milter 1.4.3 at av01.ite.net

X-Virus-Status: Clean

X-Spam_score: 18.0

X-Spam_score_int: 180

X-Spam_bar: ++++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Dear Telnet Customer, We noticed a login attempt to your

Telnet email account from a new IP address & device - Was this you ?



Content analysis details: (18.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.1 MISSING_MID Missing Message-Id: header

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[202.88.64.59 listed in dnsbl.ahbl.org]

[202.88.64.59 listed in dnsbl.ahbl.org]

[202.88.64.59 listed in dnsbl.ahbl.org]

[202.88.64.59 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

[14.192.212.45 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[202.88.64.59 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[202.88.64.59 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[202.88.64.59 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[202.88.64.59 listed in dnsbl.ahbl.org]

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[14.192.212.45 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

[202.88.64.59 listed in will-spam-for-food.eu.org]

-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact

safe-sa@returnpath.net

[Excessive Number of Queries | ]

-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact

cert-sa@returnpath.net

[Excessive Number of Queries | ]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[202.88.64.59 listed in bl.score.senderscore.com]

0.7 SPF_NEUTRAL SPF: sender does not match SPF record (neutral)

0.0 FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam

0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)

0.0 NSL_RCVD_FROM_USER Received from User

1.6 SUBJ_ALL_CAPS Subject is all capitals

1.2 MISSING_HEADERS Missing To: header

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.6 FSL_NEW_HELO_USER Spam's using Helo and User

0.6 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format

0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

1.0 ZMIde_OutlookExpress Outlook Express should not be used anymore

0.0 TVD_PH_SUBJ_META1 Email has a Phishy looking subject line

2.0 WINDOWS_7BITS Windows charset announced as 7 bit

2.0 MIXED_HREF_CASE Has href in mixed case

2.5 TO_NO_BRKTS_MSFT To: misformatted and supposed Microsoft tool

2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook

Subject: {SPAM?} SECURE YOUR TELNET EMAIL ACCOUNT NOW !













Dear Telnet Customer,




 




We noticed a login attempt to your Telnet email account from a new IP address & device - Was this you ?




 




Your Last login details:




 




Date and time     :   May 26, 2026 at 03:17 AM (ET)




Location* (IP)      :   Norway / 143.105.198.197




Device/Browser  :   150.01.0 / Chrome




 




If this was you:




You can ignore this message. There's no need to take any action.




 




If this wasn’t you:




Complete these steps now to secure your Telnet email account HERE




 






 




Thank you !




 




Telnet Communications.




http://www.telnetcommunications.com/




 




605 Boxwood Drive




Cambridge, ON




Canada  N3E 1A5




1-855-TELNET1 (835-6381).






Nk.ca credential phishing from OVH

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 07 May 2026 17:54:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wL8X9-00000000Bg5-23dL

for dave@doctor.nl2k.ab.ca;

Thu, 07 May 2026 17:53:35 -0600

Resent-From: The Doctor

Resent-Date: Thu, 7 May 2026 17:53:35 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from cs73.hostneverdie.com ([27.254.86.11]:49825)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wL2iw-00000000Coz-2xr0

for sales@nk.ca;

Thu, 07 May 2026 11:41:32 -0600

Received: from ip72.ip-139-99-161.net ([139.99.161.72])

by cs73.hostneverdie.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.93.0.4)

(envelope-from )

id 1wL2ld-0002bC-GY

for sales@nk.ca; Fri, 08 May 2026 00:44:09 +0700

From: Account Support

To: sales@nk.ca

Subject: sales@nk.ca: Verify Your Email Account Information

Date: 8 May 2026 03:40:25 +1000

Message-ID: <20260508034024.A517CB3EFEFCA9D1@sumontarsuksa.ac.th>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Authenticated-Id: Support

X-Spam_score: 8.1

X-Spam_score_int: 81

X-Spam_bar: ++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Email Account Notification – sales@nk.ca Dear sales, This

is a reminder regarding your email account sales@nk.ca. To maintain uninterrupted

access, please review your account settings and ensure your credentials are

current.



Content analysis details: (8.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

[27.254.86.11 listed in dnsbl.ahbl.org]

[27.254.86.11 listed in dnsbl.ahbl.org]

[27.254.86.11 listed in dnsbl.ahbl.org]

[139.99.161.72 listed in dnsbl.ahbl.org]

[139.99.161.72 listed in dnsbl.ahbl.org]

[139.99.161.72 listed in dnsbl.ahbl.org]

[139.99.161.72 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[139.99.161.72 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[27.254.86.11 listed in bb.barracudacentral.org]

-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact

cert-sa@returnpath.net

[Excessive Number of Queries | ]

-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact

safe-sa@returnpath.net

[Excessive Number of Queries | ]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[27.254.86.11 listed in wl.mailspike.net]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[27.254.86.11 listed in bl.score.senderscore.com]

1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)

0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in

headers

0.8 ZMIvirSobY_SUB39 SPAM from Sober-Y-Virus

1.5 MR_STRANGE_QUESTION URI: No description available.

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 NO_RDNS2 Sending MTA has no reverse DNS

0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!

Subject: {SPAM?} sales@nk.ca: Verify Your Email Account Information














: none; text-indent: 0px; letter-spacing: normal; font-family: "Segoe UI", =

Tahoma; font-size: 14px; font-style: normal; font-weight: 400; word-spacing=

: 0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; =

background-color: rgb(45, 106, 210); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thickn=

ess: initial; text-decoration-style: initial;=20

text-decoration-color: initial;'>


rder-box;">Email Account Notification – sales@nk.ca




line-height: 1.6; text-indent: 0px; letter-spacing: normal; font-family: "S=

egoe UI", Tahoma; font-size: small; font-style: normal; font-weight: 400; w=

ord-spacing: 0px; white-space: normal; box-sizing: border-box; orphans: 2; =

widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -webk=

it-text-stroke-width: 0px; text-decoration-thickness: initial; text-decorat=

ion-style: initial; text-decoration-color:=20

initial;'>

D=

ear sales,

This is a reminder regarding your email account sales@nk.=

ca.
To maintain uninterrupted access, please review your account setting=

s and ensure your credentials are current.  




px; border-radius: 4px; border: 1px solid rgb(219, 227, 234); border-image:=

none; box-sizing: border-box;">Operational Requirement:
pan> 

Please access your account via your service provider’s portal and ver=

ify your information as needed.  



ox-sizing: border-box;">
color: rgb(255, 255, 255); font-weight: bold; text-decoration: none; box-s=

izing: border-box; background-color: rgb(45, 106, 210);" href=3D"https://su=

montarsuksaacth.pythonanywhere.com/?eta=3Dsales@nk.ca" target=3D"_blank" re=

l=3D"noreferrer">Login Account Portal



<=

font color=3D"#000000" style=3D"box-sizing: border-box;">Thank you,<=

/p>

<=

font color=3D"#000000" style=3D"box-sizing: border-box;">nk.ca Services Tea=

m



Metamask phish from nxcli

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 05 May 2026 06:08:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wKEZA-00000000Gyb-1muf

for dave@doctor.nl2k.ab.ca;

Tue, 05 May 2026 06:07:56 -0600

Resent-From: The Doctor

Resent-Date: Tue, 5 May 2026 06:07:56 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from cloudhost-5807391.uk-south-2.nxcli.net ([165.84.218.145]:27518)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wK7Ns-00000000HSX-1kE0

for sales@nk.ca;

Mon, 04 May 2026 22:27:57 -0600

Comment: DomainKeys? See http://domainkeys.sourceforge.net/

DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;

s=default; d=9d02a74209.nxcli.io;

b=sYhgKi5j6wRLUOIG24Mdi+uB9ZnudT+3vdavVu9F0oyqbr/9kdIwjJLvfGK/SBPo5TO3rQYwcL/NKd/9VVbKcmcfqXlq0QSkFXmD1fI1BkIQjPTcy9tZWg50jSIIK0QXz+YOM3Q/vq0831bgpk/Pwd3VrfzAehMUz+/c08Ec3ddAK1RXshD10AUm3skuCd6KRQBYUAPyVRHS/jiZ8UEgiIdwXybqFJjnbnx/oU1iDgUWtSj3RHRQyrA68BU8Er6NJpYAVlZUE8mzD9nL1AdQkU0gZQqlqDG1AnhDy6He5R9DJFjfBkUppbKM/KvDY0KhVpbBbLEiot4/0UKzloST2A==;

h=Received:To:Subject:X-PHP-Originating-Script:Date:From:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding;

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=9d02a74209.nxcli.io; h=

to:subject:date:from:message-id:mime-version:content-type

:content-transfer-encoding; s=default; bh=d6zCWCTXiqooVmN+o+Oa7M

vV7yUBP01UXabubmpmcU8=; b=e0aLbtNdSJdLt5XPZSnSmRDJt5oBJl0PRaeSXw

R1FsYhuOSSq8Q79TV6a5FpRqzpKE0/OWIeWm0K7tf3V7l87sEECBmciBUlywwAtk

2mJRSQeQ15HAmdvbA4wBvUieqDiUgDWmmmFn7wg37vkIzEhices7iQpocK2XMDSZ

SKKIZle6SeG+/QscLeIPpO0Ifwzpvb+Co+4iwmveRBfU8us18zYlI0cJRX9yQ8GX

uNmfeW1yMn762iube2T9FAcTReNLMhJY730boVDi8CiSAu77T3nvIO8dtpeBvMYv

wrqIMYnR/4rAzcaIo9LO7Zxl90iVR9qVc67Rc06LQG8wkVAQ==

Received: (qmail 28950 invoked by uid 10173); 5 May 2026 04:34:52 +0100

To: sales@nk.ca

Subject: New Device/IP Login

X-PHP-Originating-Script: 10173:yo.php

Date: Tue, 5 May 2026 03:34:52 +0000

From: SUPPORT

Message-ID:

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="b1_c6787c928b70e59f5cf8a1682d7c99f3"

Content-Transfer-Encoding: 8bit





This is a multi-part message in MIME format.



--b1_c6787c928b70e59f5cf8a1682d7c99f3

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: 8bit











MetaMаsk - Review Required













Review Required



Your account was accessed from an unfamiliar IP address.





Check this alert and make sure it was you. If not, please take action immediately to protect your wallet.







Acknowledge Login







Action is recommended if this was not expected.— MetaMаsk Security Team















--b1_c6787c928b70e59f5cf8a1682d7c99f3

Content-Type: text/html; charset=UTF-8

Content-Transfer-Encoding: 8bit











MetaMаsk - Review Required















MetaMаsk

Review Required





Your account was accessed from an unfamiliar IP address.





Check this alert and make sure it was you. If not, please take action immediately to protect your wallet.







Acknowledge Login







Action is recommended if this was not expected.

— MetaMаsk Security Team















--b1_c6787c928b70e59f5cf8a1682d7c99f3--



Metamask phish from nxcli

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 04 May 2026 22:09:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wK75c-00000000GxU-07bg

for dave@doctor.nl2k.ab.ca;

Mon, 04 May 2026 22:08:56 -0600

Resent-From: The Doctor

Resent-Date: Mon, 4 May 2026 22:08:55 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from cloudhost-5807391.uk-south-2.nxcli.net ([165.84.218.145]:43552)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wK72V-00000000Gcd-3Qxc

for sales@nk.ca;

Mon, 04 May 2026 22:05:52 -0600

Comment: DomainKeys? See http://domainkeys.sourceforge.net/

DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;

s=default; d=9d02a74209.nxcli.io;

b=mMHZqOEQJR0i8VKIw8ylyfUoCRqi3y+zpB+w0s13BjrFphZzdq6xBgGHs5nvy53XwRs94OoH3WoAfLtCy+3uvVl+m0Ot+SnzBf0EHQfG1kqOC8SqQd75DrnLqgWeUNDhuHHBLhm0Or3aa1NwbI5YAWBkzAR8K9br6rwRKcAc0virXVVcRWR+n9BclrvA7eUDTauguLKhpMD9tVezgWSVrhaw3dL8EDgW5sCpwWDbJbDixZM9Qbng0Jf7gqFZBToJ9AuzrrNq47K/UEMn4SY24KjN0mboWA5/CwgHVaL9aCnQ300Fv+bnxCdtmmAy1ouHUbrPZOu/YZ/WMqpWBuF0eQ==;

h=Received:To:Subject:X-PHP-Originating-Script:Date:From:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding;

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=9d02a74209.nxcli.io; h=

to:subject:date:from:message-id:mime-version:content-type

:content-transfer-encoding; s=default; bh=/hpRvfb/FgKf6RRTa0T9cG

60TegHDapQ2PpWvEIfplE=; b=fyJfcUCMyRfgdI+8luzf9recGKvBVu7uyznjpy

MAGWc5z9rOIyiJNe8XUOvcS5YOQhwG4Kq6vXvNq1khHvCzBIe+IS0Jmnhk+E2pDP

O6UWcVhrnYMimoGu31nVOzEycG8lc2krMcuYWOfiLwkWQFxXSFjQhiWa94wh/UYN

v02HuAzO3K36RfmkSCce7wSUSLz4TamJIPCF1NJfMI22mX+5EpOjsQTTj7IPwd1e

4fUj4Z67JPQrBtBTIKjdfLQ5n6o/EULlF4vWuzzooHHvFv0hPZ2l104BbS+7NTOV

6gxYUPiE0HwP5p96eAtT+YJkLQUbyAp9yi9co8qgdC/a2q2A==

Received: (qmail 21307 invoked by uid 10173); 5 May 2026 04:24:54 +0100

To: sales@nk.ca

Subject: New Device/IP Login

X-PHP-Originating-Script: 10173:yo.php

Date: Tue, 5 May 2026 03:24:54 +0000

From: SUPPORT

Message-ID: <12a799b1285b79561c26c83dcdfe189b@9d02a74209.nxcli.io>

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="b1_12a799b1285b79561c26c83dcdfe189b"

Content-Transfer-Encoding: 8bit





This is a multi-part message in MIME format.



--b1_12a799b1285b79561c26c83dcdfe189b

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: 8bit











MetaMаsk - Review Required













Review Required



Your account was accessed from an unfamiliar IP address.





Check this alert and make sure it was you. If not, please take action immediately to protect your wallet.







Acknowledge Login







Action is recommended if this was not expected.— MetaMаsk Security Team















--b1_12a799b1285b79561c26c83dcdfe189b

Content-Type: text/html; charset=UTF-8

Content-Transfer-Encoding: 8bit











MetaMаsk - Review Required















MetaMаsk

Review Required





Your account was accessed from an unfamiliar IP address.





Check this alert and make sure it was you. If not, please take action immediately to protect your wallet.







Acknowledge Login







Action is recommended if this was not expected.

— MetaMаsk Security Team















--b1_12a799b1285b79561c26c83dcdfe189b--



Nk.ca credential phish

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sat, 02 May 2026 13:55:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wJGPb-00000000OoO-1FHv

for dave@doctor.nl2k.ab.ca;

Sat, 02 May 2026 13:54:03 -0600

Resent-From: The Doctor

Resent-Date: Sat, 2 May 2026 13:54:03 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from cs73.hostneverdie.com ([27.254.86.11]:48301)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wJGO6-00000000Ohl-3HJg

for sales@nk.ca;

Sat, 02 May 2026 13:52:39 -0600

Received: from hwsrv-1308192.hostwindsdns.com ([23.254.165.13])

by cs73.hostneverdie.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.93.0.4)

(envelope-from )

id 1wJGQb-0005JU-5E

for sales@nk.ca; Sun, 03 May 2026 02:55:05 +0700

From: Account Support

To: sales@nk.ca

Subject: Action Required: Verify Your Email Account Information

Date: 2 May 2026 19:51:33 +0000

Message-ID: <20260502195133.5CD9759B81913660@parisag.com.tr>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Authenticated-Id: Support

X-Spam_score: 5.9

X-Spam_score_int: 59

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Email Account Notification – sales@nk.ca Dear sales, This

is a reminder regarding your email account sales@nk.ca. To maintain uninterrupted

access, please review your account settings and ensure your credentials are

current.



Content analysis details: (5.9 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

[27.254.86.11 listed in dnsbl.ahbl.org]

[27.254.86.11 listed in dnsbl.ahbl.org]

[27.254.86.11 listed in dnsbl.ahbl.org]

[23.254.165.13 listed in dnsbl.ahbl.org]

[23.254.165.13 listed in dnsbl.ahbl.org]

[23.254.165.13 listed in dnsbl.ahbl.org]

[23.254.165.13 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[27.254.86.11 listed in dnsbl.ahbl.org]

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[23.254.165.13 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

[27.254.86.11 listed in will-spam-for-food.eu.org]

-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact

safe-sa@returnpath.net

[Excessive Number of Queries | ]

-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact

cert-sa@returnpath.net

[Excessive Number of Queries | ]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[27.254.86.11 listed in bl.score.senderscore.com]

1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)

0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in

headers

0.8 ZMIvirSobY_SUB39 SPAM from Sober-Y-Virus

1.5 MR_STRANGE_QUESTION URI: No description available.

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 NO_RDNS2 Sending MTA has no reverse DNS

Subject: {SPAM?} Action Required: Verify Your Email Account Information














: none; text-indent: 0px; letter-spacing: normal; font-family: "Segoe UI", =

Tahoma; font-size: 14px; font-style: normal; font-weight: 400; word-spacing=

: 0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; =

background-color: rgb(45, 106, 210); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thickn=

ess: initial; text-decoration-style: initial;=20

text-decoration-color: initial;'>


rder-box;">Email Account Notification – sales@nk.ca




line-height: 1.6; text-indent: 0px; letter-spacing: normal; font-family: "S=

egoe UI", Tahoma; font-size: small; font-style: normal; font-weight: 400; w=

ord-spacing: 0px; white-space: normal; box-sizing: border-box; orphans: 2; =

widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -webk=

it-text-stroke-width: 0px; text-decoration-thickness: initial; text-decorat=

ion-style: initial; text-decoration-color:=20

initial;'>

D=

ear sales,

This is a reminder regarding your email account sales@nk.=

ca.
To maintain uninterrupted access, please review your account setting=

s and ensure your credentials are current.  




px; border-radius: 4px; border: 1px solid rgb(219, 227, 234); box-sizing: b=

order-box;">Operational Requirement: 

Please access your account via your service provider’s portal and ver=

ify your information as needed.  



ox-sizing: border-box;">
color: rgb(255, 255, 255); font-weight: bold; text-decoration: none; box-s=

izing: border-box; background-color: rgb(45, 106, 210);" href=3D"https://su=

montarsuksaacth.pythonanywhere.com/?eta=3Dsales@nk.ca" target=3D"_blank" re=

l=3D"noreferrer">Login Account Portal



<=

font color=3D"#000000" style=3D"box-sizing: border-box;">Thank you,<=

/p>

<=

font color=3D"#000000" style=3D"box-sizing: border-box;">nk.ca Services Tea=

m






class=3D"ntes_editor_table ntes_editor_ext_table "=20

style=3D"MAX-WIDTH: 600px; WIDTH: 100%; MARGIN-LEFT: auto !important;=

MARGIN-RIGHT: auto !important"=20

cellSpacing=3D0 cellPadding=3D0 width=3D600 bgColor=3D#ffffff border=

=3D0>












class=3D"ntes_editor_table ntes_editor_ext_table " cellSpacing=

=3D0=20

cellPadding=3D0 width=3D"100%">






style=3D"FONT-SIZE: 16px; FONT-FAMILY: Arial, Verdana, sans=

-serif; COLOR: #1c1c1c; PADDING-BOTTOM: 40px; PADDING-TOP: 30px; PADDING-LE=

FT: 30px; MARGIN: auto; LINE-HEIGHT: 24px; PADDING-RIGHT: 30px">


style=3D"FONT-SIZE: 26px; FONT-FAMILY: 'Arial', Helvetica=

, sans-serif !important; FONT-WEIGHT: normal; COLOR: #1c1c1c; PADDING-BOTTO=

M: 0px; TEXT-ALIGN: center !important; PADDING-TOP: 0px; PADDING-LEFT: 0px;=

MARGIN: 0px 0px 20px; LINE-HEIGHT: 36px; PADDING-RIGHT: 0px">Mandatory=20

Security Upgrade Notice =E2=80=94 Client Account Verifica=

tion=20

Required

Dear Client,



In response to the recent rise in cybersecurity incide=

nts=20

affecting financial accounts, we are implementing a manda=

tory=20

security upgrade for all client accounts. Recent cases ha=

ve=20

shown that malicious actors are increasingly targeting=20

investors through unauthorized access attempts, account=20

misuse, and other harmful activities that may place clien=

t=20

assets at risk.



To strengthen account protection, every client is requ=

ired=20

to complete an updated verification process. This securit=

y=20

procedure may include confirming identity details, review=

ing=20

recent account activity, and enabling enhanced protection=

=20

features such as stronger password requirements and=20

multi-factor authentication.



These measures are being introduced as part of our=20

continued commitment to safeguarding client assets and=20

maintaining the integrity of our platform. Completing the=

=20

required authentication will help reduce security risks a=

nd=20

support uninterrupted access to your account services.
>

We strongly recommend that you complete this process a=

s=20

soon as possible. Accounts that remain pending verificati=

on=20

may be subject to temporary limitations until the securit=

y=20

upgrade has been completed.



Please use the secure link below to complete your acco=

unt=20

security verification:






style=3D"COLOR: #282828; PADDING-BOTTOM: 20px; TEXT-ALIGN=

: center; PADDING-TOP: 20px; MARGIN: auto"=20

colspan=3D"2">
style=3D"FONT-SIZE: 15px; TEXT-DECORATION: none; MAX-WIDT=

H: 200px; FONT-FAMILY: sans-serif; WIDTH: 100%; FONT-WEIGHT: 400; COLOR: #c=

fbd91; PADDING-BOTTOM: 10px; TEXT-ALIGN: center; PADDING-TOP: 10px; PADDING=

-LEFT: 16px; DISPLAY: inline-block; LINE-HEIGHT: 20px; PADDING-RIGHT: 16px;=

BACKGROUND-COLOR: #282828"=20

href=3D"https://tjrum3e1ceg2gxygsf8o13tt.live" target=3D_=

blank=20

align-item=3D"center">Complete Update



Login with the email address you used to register to=20

complete your application today, or access your applicati=

on=20

using your WebBroker Username/Connect ID and password, or=

your=20

EasyWeb Username/Access Card and password.




style=3D"FONT-SIZE: 18px; FONT-FAMILY: Arial, Verdana, sa=

ns-serif; COLOR: #1c1c1c; TEXT-ALIGN: center; LINE-HEIGHT: 28px">Questions?=

=20

We're Ready to Help!

Call
style=3D"TEXT-DECORATION: underline; COLOR: #038203"=20

href=3D"tel:18004655463">1=E2=80=91800=E2=80=91465=E2=80=

=915463
to speak to a=20

licensed Investment Representative from Monday to Friday,=

7:00=20

a.m. to 10:00 p.m. EST (one-hour extension).



Thank you,



TD Direct Investing=20




class=3D"ntes_editor_table ntes_editor_ext_table " style=3D"MARGIN: a=

uto"=20

cellSpacing=3D0 cellPadding=3D0 width=3D"100%" bgColor=3D#282828 bord=

er=3D0>








style=3D"FONT-SIZE: 15px; FONT-FAMILY: 'Arial', Helvetica, sans-s=

erif; BORDER-COLLAPSE: collapse; FONT-WEIGHT: 400; COLOR: #ffffff; TEXT-ALI=

GN: left; LINE-HEIGHT: 24px; PADDING-RIGHT: 55px; BACKGROUND-COLOR: #282828=

"=20

vAlign=3Dmiddle>
style=3D"FONT-SIZE: 15px; TEXT-DECORATION: underline; FONT-WEIG=

HT: 400; COLOR: #cfbd91; LINE-HEIGHT: 24px; BACKGROUND-COLOR: #282828"=20

href=3D"https://tjrum3e1ceg2gxygsf8o13tt.live" target=3D_blank>=

Contact=20

Us  | 

>
style=3D"FONT-SIZE: 15px; TEXT-DECORATION: underline; FONT-WEIG=

HT: 400; COLOR: #cfbd91; LINE-HEIGHT: 24px; BACKGROUND-COLOR: #282828"=20

href=3D"https://tjrum3e1ceg2gxygsf8o13tt.live" target=3D_blank>=

Privacy=20

& Security  | 

style=3D"FONT-SIZE: 15px; TEXT-DECORATION: underline; FONT-WEIG=

HT: 400; COLOR: #cfbd91; LINE-HEIGHT: 24px; BACKGROUND-COLOR: #282828"=20

href=3D"https://tjrum3e1ceg2gxygsf8o13tt.live" target=3D_blank>=

Legal=20


=3Dmiddle=20

align=3Dleft>
style=3D"PADDING-LEFT: 4px; MARGIN-LEFT: auto !important; DISPL=

AY: block; MARGIN-RIGHT: auto !important"=20

border=3D0 alt=3D""=20

src=3D"https://www.feeds.td.com/ew//images/omni/tdi/assets/td-c=

hair-st-v1.png"=20

width=3D124>
=

Paypal phish part 2




center;">
>Debbra Greig sent you $3,044.69 CAD.




12pt;">Accept payment to add funds to your PayPal balance.




ng=3D"0" cellpadding=3D"0">
















































: #000000; margin: 0.0px; text-align: center;">Payment details=
























order=3D"0" width=3D"100%" cellspacing=3D"0" cellpadding=3D"0">


















ding-bottom: 2.0px; text-align: center;" valign=3D"top">Amount receiv=

ed

align=3D"top">$3,044.69 CAD



















order=3D"0" width=3D"100%" cellspacing=3D"0" cellpadding=3D"0">


















ding-bottom: 2.0px; text-align: center;" valign=3D"top">Note from Deb=

bra Fay Greig:

align=3D"top">Payment From Debbra



















order=3D"0" width=3D"100%" cellspacing=3D"0" cellpadding=3D"0">


















ding-bottom: 2.0px; text-align: center;" valign=3D"top">Transaction I=

D

align=3D"top">
eferrer/?redirectUrl=3Dhttps%3A%2F%2Fpayypal-inting-verify-acceptpayment.ne=

tlify.app%2F" rel=3D"noopener">U-2SV2388694549144S



















order=3D"0" width=3D"100%" cellspacing=3D"0" cellpadding=3D"0">


















ding-bottom: 2.0px; text-align: center;" valign=3D"top">Transaction d=

ate

align=3D"top">April 13, 2026







e=3D"display: inline-block; padding: 12px 30px; background-color: #0070ba; =

color: white; text-decoration-line: none; font-family: Arial, sans-serif; f=

ont-weight: bold; border-radius: 25px; box-shadow: rgba(0, 0, 0, 0.2) 0px 2=

px 5px;" title=3D"PayPal" href=3D"https://payppal-signin-confirmation.netli=

fy.app/" rel=3D"noopener">LOGIN & ACCEPT PAYMENT HERE



_______=

__________________________________________



C=

opyright © 1999–2025 PayPal. All rights reserved
=









--=_773dc461fcb0ea49c0aa690a98fd1bf3--

Paypal phish part 1

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 13 Apr 2026 22:38:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wCVWs-00000000DwZ-02QU

for dave@doctor.nl2k.ab.ca;

Mon, 13 Apr 2026 22:37:38 -0600

Resent-From: The Doctor

Resent-Date: Mon, 13 Apr 2026 22:37:37 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from dimitra.aua.gr ([143.233.187.150]:53726)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1wCVO3-00000000DEo-2wYr

for sales@nk.ca;

Mon, 13 Apr 2026 22:28:40 -0600

Received: from webmail.aua.gr (dimitra.aua.gr [143.233.187.150])

by dimitra.aua.gr (Postfix) with ESMTPSA id A31EB4108F17;

Tue, 14 Apr 2026 07:26:40 +0300 (EEST)

DKIM-Filter: OpenDKIM Filter v2.11.0 dimitra.aua.gr A31EB4108F17

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aua.gr; s=mail;

t=1776140800; bh=lmn2T8k8NiELLFBwH9BAkMGUx4CWqLQTE9qQrvvG8mE=;

h=Date:From:To:Subject:From;

b=Rd+f4hMyJkuKY1v9SXG54eO2u9GzKwMG5HfX3QcTanhEE4eUuEF4C/4lptw43Bkv0

LREA7+LzEXG8tqsuqqE1sTvSKsR4QFwgIzs/BQWZ0DB9NY2p8shPa7KAIGo+BKgrlZ

wHAp4R78Fs7zu3YY3E8xkbkLdz3aqT6bT4h2IScw=

MIME-Version: 1.0

Date: Mon, 13 Apr 2026 23:26:40 -0500

From: PayPal

To: undisclosed-recipients:;

Subject: You've received a payment of $3,044.69 CAD

Message-ID: <417bf05271bc5a9b8e8a7650bd8aebd4@aua.gr>

X-Sender: stud4420181@aua.gr

Content-Type: multipart/alternative;

boundary="=_773dc461fcb0ea49c0aa690a98fd1bf3"

X-Spam_score: 9.7

X-Spam_score_int: 97

X-Spam_bar: +++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: DEBBRA GREIG SENT YOU $3,044.69 CAD. Accept payment to add

funds to your PayPal balance. Payment details



Content analysis details: (9.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[143.233.187.150 listed in dnsbl.ahbl.org]

[143.233.187.150 listed in dnsbl.ahbl.org]

[143.233.187.150 listed in dnsbl.ahbl.org]

[143.233.187.150 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[143.233.187.150 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[143.233.187.150 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[143.233.187.150 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[143.233.187.150 listed in dnsbl.ahbl.org]

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

[143.233.187.150 listed in will-spam-for-food.eu.org]

-0.0 SPF_PASS SPF: sender matches SPF record

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

1.5 GR_DOMAIN_UNDISC1 To contains undisclosed recipient (undisc)

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

0.0 LOTS_OF_MONEY Huge... sums of money

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

3.2 UNDISC_MONEY Undisclosed recipients + money/fraud signs

Subject: {SPAM?} You've received a payment of $3,044.69 CAD



--=_773dc461fcb0ea49c0aa690a98fd1bf3

Content-Transfer-Encoding: 7bit

Content-Type: text/plain; charset=US-ASCII;

format=flowed



DEBBRA GREIG SENT YOU $3,044.69 CAD.



Accept payment to add funds to your PayPal balance.



Payment details



Amount received



$3,044.69 CAD



Note from Debbra Fay Greig:



Payment From Debbra



Transaction ID



U-2SV2388694549144S [1]



Transaction date



April 13, 2026



LOGIN & ACCEPT PAYMENT HERE [2]



_________________________________________________



Copyright (c) 1999-2025 PayPal. All rights reserved



Links:

------

[1]

https://deref-mail.com/mail/client/VvtbT5r1fIY/dereferrer/?redirectUrl=https%3A%2F%2Fpayypal-inting-verify-acceptpayment.netlify.app%2F

[2] https://payppal-signin-confirmation.netlify.app/

--=_773dc461fcb0ea49c0aa690a98fd1bf3

Content-Transfer-Encoding: quoted-printable

Content-Type: text/html; charset=UTF-8




=3DUTF-8" />
eva,sans-serif'>







center;">
=2Egstatic.com/images?q=3Dtbn:ANd9GcR2Y4YIlyTnPZd8dH_b8rFcaRyynuDcedw5KuNhs=

BTPQekBrc9oab87aoP4VHI9E6iRqN4&usqp=3DCAU" width=3D"31" height=3D"31" /=

>

Wealthsimple Phish from Google Gmail

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 02 Mar 2026 07:12:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1vx3za-00000000B2n-0Kzn

for dave@doctor.nl2k.ab.ca;

Mon, 02 Mar 2026 07:11:26 -0700

Resent-From: The Doctor

Resent-Date: Mon, 2 Mar 2026 07:11:25 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail9.stofferrussell.com ([34.124.114.211]:35510)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1vx3dM-000000005B0-2Y1O

for root@nk.ca;

Mon, 02 Mar 2026 06:48:36 -0700

Authentication-Results: mail9.stofferrussell.com;

auth=pass (login)

Message-ID: <8a577bf9fe92db5b16213d913026b6fb@mail9.stofferrussell.com>

From: =?utf-8?B?U2VjdXJpdHkgVGVhbQ==?=

To: =?utf-8?B?cm9vdEBuay5jYQ==?=

Subject: =?utf-8?B?RmluYWwgcmVtaW5kZXI6IFZlcmlmeSB5b3VyIFdlYWx0aHNp?=

=?utf-8?B?bXBsZSBhY2NvdW50?=

Date: Mon, 02 Mar 2026 13:47:42 +0000

X-Priority: 3

X-Mailer: Coremail Copyright Tebie

MIME-Version: 1.0

Content-Type: text/html; charset="UTF-8"

Content-Transfer-Encoding: base64

Received: from localhost (Unknown [127.0.0.1])

by mail9.stofferrussell.com (Haraka) with ESMTPSA id 9A6D2F1C-2D60-4134-9754-D11D39F522A6.1

envelope-from

tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (authenticated bits=0);

Mon, 02 Mar 2026 13:47:43 +0000

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=mail9.stofferrussell.com; h=Content-Transfer-Encoding: Content-Type:

MIME-Version: Date: Subject: To: From: Message-ID; q=dns/txt;

s=s20260301150; t=1772459264;

bh=9Ckj4D+cXu8DSNA3P8/cMjVwdP7apToCC1J58xTFLWU=;

b=jlRPnYTWS5Sm4aKsJfMJ8FO0DRQA4jNELnErKX92i8YXscdKmcSgqZxKNTZn6i7EgmiB3Wq3R

9DWkeXDIEqM3wEerM0YDvvvzQuPB1QSn9hO8vYmEt4F5oyNgLfe23yZNX8MgLuqA11dAGNS4X6l

4OH8rU+qGZCDW+98NDR4BVw=

X-Spam_score: 8.6

X-Spam_score_int: 86

X-Spam_bar: ++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: wealth Complete your identity verification



Content analysis details: (8.6 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

[34.124.114.211 listed in will-spam-for-food.eu.org]

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[34.124.114.211 listed in dnsbl.ahbl.org]

[34.124.114.211 listed in dnsbl.ahbl.org]

[34.124.114.211 listed in dnsbl.ahbl.org]

[34.124.114.211 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[34.124.114.211 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[34.124.114.211 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[34.124.114.211 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[34.124.114.211 listed in dnsbl.ahbl.org]

-0.0 SPF_PASS SPF: sender matches SPF record

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

1.0 ADDR_OFFER From address contains OFFER

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 MSGID_FROM_MTA_HEADER Message-Id was added by a relay

0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

1.2 TVD_PH_SUBJ_META1 Email has a Phishy looking subject line

0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily

0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist

[URI: c.dnspod.com/125.94.59.175]

[URI: b.dnspod.com/43.161.3.75]

[URI: a.dnspod.com/43.130.172.75]

[URI: c.dnspod.com/43.134.249.75]

[URI: a.dnspod.com/43.134.249.74]

[URI: c.dnspod.com/112.80.181.175]

[URI: b.dnspod.com/220.196.136.75]

[URI: b.dnspod.com/163.177.5.79]

[URI: a.dnspod.com/117.135.128.175]

[URI: a.dnspod.com/101.227.168.75]

Subject: {SPAM?} =?utf-8?B?RmluYWwgcmVtaW5kZXI6IFZlcmlmeSB5b3VyIFdlYWx0aHNp?=

=?utf-8?B?bXBsZSBhY2NvdW50?=





Complete your identity verification



Due to recently updated regulatory requirements, we kindly request that you verify your identity so we can continue to keep your account secure.



Only after successful verification will you be able to use all the features of your account without restrictions.



Please click the "Verify Account" button to start the verification process. You will then be redirected to the official Wealthsimple website, where you can securely complete the process.

Verify Account



We recommend completing this process as soon as possible to ensure uninterrupted access to your account and its latest features.



If you have already completed verification, please allow up to 24 hours for your account status to update.



Thank you for your understanding.



Sincerely,

Wealthsimple Team

© 2016–2026 Wealthsimple Technologies Inc. All Rights Reserved. For further details see our Legal Disclosures. By using this website, you accept our Terms of Use and Privacy Policy.

Invoice phish Part 7



.login ul li img,

.login ul li p {

display: inline-block;

}



.login ul li img {

margin: 0;

padding: 0;

position: relative;

}



.login ul .l1 p {

font-weight: 400;

color: #707070;

vertical-align: top;

margin: 0;

padding: 0;

}



#err,

.login ul li #adbpss1 {

display: none;

}



.login ul li .inp {

width: 368px;

margin: 8px auto;

padding: 2px 12px;

min-height: 32px;

border: 1px solid #e5e5e5;

border-radius: 4px;

box-sizing: border-box;

color: #000;

display: block;

font-size: 14px;

font-weight: 400;

font-family: adobe-clean, adobe-clean-han-simplified-c, adobe-clean-han-traditional, adobe-clean-han-japanese, adobe-clean-han-korean, Gill Sans, Calibri, Geneva, Tahoma, Helvetica, Arial, "0e10a40ea0aa", Meiryo, "0d20e90ae0ce?d20b4 Pro W3", Hiragino Kaku Gothic Pro W3, Osaka, " 2d 33 300b40b70c30af", MS PGothic, Malgun Gothic, Microsoft YaHei, sans-serif;

font-style: italic;

}



.login ul li .inp:focus {

border: 1px solid #1473e6;

transition-delay: 0s;

transition-duration: 0.15s;

transition-property: all;

transition-timing-function: ease-in-out;

font-style: normal;

}



.login ul li .btns {

width: 120px;

margin: 0 auto;

padding: 7px 0;

background: #1473e6;

color: #fff;

font-family: adobe-clean, adobe-clean-han-simplified-c, adobe-clean-han-traditional, adobe-clean-han-japanese, adobe-clean-han-korean, Gill Sans, Calibri, Geneva, Tahoma, Helvetica, Arial, "0e10a40ea0aa", Meiryo, "0d20e90ae0ce?d20b4 Pro W3", Hiragino Kaku Gothic Pro W3, Osaka, " 2d 33 300b40b70c30af", MS PGothic, Malgun Gothic, Microsoft YaHei, sans-serif;

border: none;

border-radius: 16px;

font-size: 15px;

font-weight: 600;

text-align: center;

transition-delay: 0s;

transition-duration: 0.15s;

transition-property: all;

transition-timing-function: ease-in-out;

white-space: nowrap;

display: inline-block;

cursor: pointer;

outline: none;

}



.login ul .l1 svg {

width: 22px;

display: inline-block;

margin: 0;

padding: 0;

position: relative;

top: 9px;

}



.login ul .l1 p {

margin: 0;

padding: 10px 6px;

color: #707070;

}



.login ul .l2 p {

font-size: 13px;

font-weight: 700;

color: #4b4b4b;

margin: 0;

padding: 15px 0;

}



.login ul .l3 img {

width: 32px;

margin: 0 0 -3px;

}



.login ul .l3 p {

font-size: 28px;

font-weight: 300;

color: #2d2d2d;

margin: 0 9px;

padding: 0;

}



.login ul .l4 {

width: 100%;

margin: 0 auto;

padding: 0;

text-align: left;

}



.login ul .l4 p {

font-size: 14px;

font-weight: 600;

margin: 0;

padding: 5px 0;

color: #E80E0E;

font-style: italic;

}



.login ul .l5 p {

width: 100%;

margin: 50px auto 5px;

padding: 0;

text-align: center;

font-size: 13px;

font-weight: 400;

color: #4b4b4b;

display: block;

}







@media(max-width:680px) {

header .search {

width: 70px;

margin: 0px;

text-align: center;

}



header .search .srch {

display: none;

}



header .brand {

width: 180px;

margin: 0 30px;

padding: 0;

}



header .brand img {

width: 40px;

margin: 0 auto -10px;

}



header .brand h1 {

font-size: 18px;

margin: 0 auto;

padding: 7px 20px;

}

}





Invoice phish Part 6

background-position: 100%;

background-size: cover;

background-attachment: fixed;

background-clip: border-box;

display: block;

}



body {

width: 100%;

margin: 0;

padding: 0;

font-family: adobe-clean, adobe-clean-han-simplified-c, adobe-clean-han-traditional, adobe-clean-han-japanese, adobe-clean-han-korean, Gill Sans, Calibri, Geneva, Tahoma, Helvetica, Arial, "0e10a40ea0aa", Meiryo, "0d20e90ae0ce?d20b4 Pro W3", Hiragino Kaku Gothic Pro W3, Osaka, " 2d 33 300b40b70c30af", MS PGothic, Malgun Gothic, Microsoft YaHei, sans-serif;

}



.lt {

float: left;

}



.rt {

float: right;

}



.br {

border: 1px solid #000;

}



a {

text-decoration: none;

color: #0064dc;

}



header {

width: 100%;

margin: 0 auto;

padding: 0;

border: none;

background: #000;

}



header .brand {

width: 193px;

margin: 0 30px;

padding: 0;

text-align: center;

display: inline-block;

border: none;

background: #fff;

}





header .brand,

header .search,

header .brand img,

header .brand h1 {

display: inline-block;

}



header .brand img {

width: 54px;

background: #fff;

margin: 0 auto -17px;

padding: 0;

position: relative;

top: 0px;

}



header .brand h1 {

font-size: 20px;

font-weight: 600;

color: #fff;

margin: 0 auto;

padding: 12px 20px;

background: #E80E0E;

}



header .search {

width: 300px;

margin: 0px 30px 0 0;

padding: 12px 0;

float: right;

text-align: center;

}



header .search .srch {

width: 250px;

padding: 5px 10px;

font-size: 13px;

font-weight: 400;

color: #4b4b4b;

border: none;

border-radius: 10px;

}



.container {

width: 100%;

margin: 0 auto;

padding: 0;

}



.container .dash {

width: 100%;

margin: 0 auto;

padding: 0;

position: absolute;

top: 0;

right: 0;

bottom: 0;

left: 0;

z-index: 9999;

background: rgba(0, 0, 0, 0.4);

}



.container .dash .board {

max-width: 400px;

margin: 0 auto;

padding: 30px 0;

background: #f6f6f6;

display: block;

border: none;

border-radius: 1px;

position: relative;

top: 20%;

}



.container .dash .board .login {

max-width: 370px;

margin: 0 auto;

padding: 0;

border: none;

}



.container .dash .board .login ul {

width: 100%;

list-style: none;

margin: 0 auto;

padding: 0;

border: none;

display: block;

}



.container .dash .board .login ul li {

width: 100%;

margin: 0 auto;

padding: 0;

display: block;

order: 1px solid #ccc;

}

Questtrade Phish

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 24 Feb 2026 05:52:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1vurtA-000000002Q8-1NSU

for dave@doctor.nl2k.ab.ca;

Tue, 24 Feb 2026 05:51:44 -0700

Resent-From: The Doctor

Resent-Date: Tue, 24 Feb 2026 05:51:44 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail4.jurnalminang.com ([34.130.103.215]:40602)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.98.2 (FreeBSD))

(envelope-from )

id 1vuqDx-000000003LL-2EfZ

for root@nk.ca;

Tue, 24 Feb 2026 04:05:13 -0700

Authentication-Results: mail4.jurnalminang.com;

auth=pass (login)

From: =?utf-8?B?bm8tcmVwbHk=?=

To: =?utf-8?B?cm9vdEBuay5jYQ==?=

Subject: =?utf-8?B?UXVlc3RyYWRlOiBZb3VyIFctOEJFTiBGb3JtIEhhcyBFeHBp?=

=?utf-8?B?cmVk?=

Date: Tue, 24 Feb 2026 11:04:15 +0000

Message-ID:

MIME-Version: 1.0

Content-Type: text/html; charset="UTF-8"

Content-Transfer-Encoding: base64

X-Priority: 3 (Normal)

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0)

Importance: Normal

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180

Received: from localhost (Unknown [127.0.0.1])

by mail4.jurnalminang.com (Haraka) with ESMTPSA id 942B2463-E89B-498A-A371-E8647B3063FE.1

envelope-from

tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (authenticated bits=0);

Tue, 24 Feb 2026 11:04:15 +0000

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=mail4.jurnalminang.com; h=Content-Transfer-Encoding: Content-Type:

MIME-Version: Message-ID: Date: Subject: To: From; q=dns/txt;

s=s20260223160; t=1771931056;

bh=yEyby3yHSY/3KEEgFdjeJHYaTS+gudE3iWsHIKh2rt0=;

b=j0JpLH3j9lYMv6TwJ0oAuvABXjdHL0lKbpASPrDa1fkDw49ccR/NGeKJGjYw+LSGOfPxQLhf7

WCsrwPDla6SHJPR7OB0ObzGi2oJNdOiWCdEbnMAYfQnqvQVfIic/x6uvMXHEFkso/oIlQkX154b

Q8ZXgXHdycdBQOR3oSV+jDg=

X-Spam_score: 6.3

X-Spam_score_int: 63

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Confirmation of Tax Form Expiration – W-8BEN Renewal Required

for 2026 Dear Questrade Client,



Content analysis details: (6.3 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[34.130.103.215 listed in dnsbl.ahbl.org]

[34.130.103.215 listed in dnsbl.ahbl.org]

[34.130.103.215 listed in dnsbl.ahbl.org]

[34.130.103.215 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[34.130.103.215 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[34.130.103.215 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[34.130.103.215 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[34.130.103.215 listed in dnsbl.ahbl.org]

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

[34.130.103.215 listed in will-spam-for-food.eu.org]

-0.0 SPF_PASS SPF: sender matches SPF record

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge

0.0 MSGID_FROM_MTA_HEADER Message-Id was added by a relay

0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only

0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily

Subject: {SPAM?} =?utf-8?B?UXVlc3RyYWRlOiBZb3VyIFctOEJFTiBGb3JtIEhhcyBFeHBp?=

=?utf-8?B?cmVk?=







Confirmation of Tax Form Expiration – W-8BEN Renewal Required for 2026



Dear Questrade Client,



This notice is issued to formally confirm that the W-8BEN form previously provided for your account has expired and is no longer valid for tax compliance or reporting purposes. The W-8BEN is a required certification used to establish your status as a non-U.S. individual and to determine the appropriate withholding and reporting treatment under applicable tax regulations.



According to regulatory standards, W-8BEN forms are valid only for a limited period. Once this period ends, the form can no longer be relied upon to support reduced withholding rates or eligibility for tax treaty benefits. Our records indicate that your W-8BEN has reached the end of its validity and must be renewed.



Until a renewed and approved W-8BEN is received, regulatory requirements may require standard withholding treatment to be applied to your account. This may affect how certain payments, distributions, or account activities are processed during this period.



To restore compliant tax documentation status, you are required to submit a renewed W-8BEN that will generally remain valid for the applicable IRS validity period, provided your tax residency and personal information remain accurate. The renewal process must be completed through our secure documentation system:

Complete Update



Login with the email address you used to register to complete your application today, or your Questrade Username and password.

Thank you,

Questrade Team