password phish
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 06 May 2022 16:10:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))
(envelope-from)
id 1nn68H-0006Re-Ff
for dave@doctor.nl2k.ab.ca;
Fri, 06 May 2022 16:09:05 -0600
Resent-From: The Doctor
Resent-Date: Fri, 6 May 2022 16:09:05 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from marula.iwayafrica.co.zw ([41.190.32.8]:52008 helo=smtp11.utande.co.zw)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.95 (FreeBSD))
(envelope-from)
id 1nn3xA-000Lsm-OL
for root@nl2k.ab.ca;
Fri, 06 May 2022 13:49:33 -0600
Received: from [196.44.176.151] (port=39354 helo=pop3.utande.co.zw)
by smtp11.utande.co.zw with esmtp (Exim 4.94)
(envelope-from)
id 1nn3wo-0001Uk-2N
for root@nl2k.ab.ca; Fri, 06 May 2022 21:49:06 +0200
Received: from [192.168.1.101] (unknown [85.237.194.26])
by pop3.utande.co.zw (Postfix) with ESMTPSA id 082222005A5039
for; Fri, 6 May 2022 21:49:03 +0200 (CAT)
Content-Type: multipart/alternative; boundary="===============0977781784=="
MIME-Version: 1.0
Subject: Account Deactivation Request for root@nl2k.ab.ca
To: root@nl2k.ab.ca
From: "ITHELP DESK"
Date: Fri, 06 May 2022 12:48:58 -0700
Message-Id: ac449dabff3c898a2a93ba86b377fe48@smtp11.utande.co.zw
X-Spam_score: 8.1
X-Spam_score_int: 81
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear root@nl2k.ab.ca , Series of account deactivation requests
have been made from your Email Address root@nl2k.ab.ca . If you did not make
this request, stop the process by clicking Stop Deactivation and follow the
instruc [...]
Content analysis details: (8.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 HTML_MESSAGE BODY: HTML included in message
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
-0.0 T_SCC_BODY_TEXT_LINE No description available.
1.5 FSL_BULK_SIG Bulk signature with no Unsubscribe
1.2 INVALID_MSGID Message-Id is not valid, according to RFC 2822
0.0 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: 360autodisplayusa.com, cranstonfamilyclinic.com]
Subject: {SPAM?} Account Deactivation Request for root@nl2k.ab.ca
You will not see this in a MIME-aware mail reader.
--===============0977781784==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Dear root@nl2k.ab.ca ,
Series of account deactivation requests have been made from your Email Addr=
ess root@nl2k.ab.ca . If you did not make this request, stop the process b=
y clicking Stop Deactivation and follow the instruction.
You have 12 Hours after Notification or your account will be closed. =
Note:Move the email to your Inbox to stop the deactivation
=A9 Support Team- Support Team.
--===============0977781784==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
=3Dutf-8"/>
)">Dear
30)">root@nl2k.ab.ca
R: rgb(32,31,30)">,
COLOR: rgb(32,31,30)">
R: rgb(32,31,30)">Ser=
ies of account deactivation requests have been made from your Email Address=
root@nl2k.ab.ca . If you did not make this request, stop the process=
by clicking
x; BORDER-RIGHT-WIDTH: 0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: =
0px; COLOR: rgb(17,85,204); PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-=
LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-var=
iant-numeric: inherit; font-variant-east-asian: inherit; font-stretch: inhe=
rit" href=3D"https://cranstonfamilyclinic.com/zimbra/webner/" rel=3D"noopen=
er noreferrer" target=3D_blank data-saferedirecturl=3D"https://www.google.c=
om/url?q=3Dhttps://www.360autodisplayusa.com/SDCFVSD/97884/38840/&sourc=
e=3Dgmail&ust=3D1651946190854000&usg=3DAOvVaw34_KBx6BqJneO9I9txdpVD=
">Stop Deactivation
"> and follow the instruction.
ONT-SIZE: 15px; COLOR: rgb(32,31,30)">
SIZE: 15px; COLOR: rgb(32,31,30)">
b(32,31,30)">You have 12 Hours after Notification or your account will be c=
losed.
0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(32,31,3=
0); PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; =
PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-variant-numeric: inherit; f=
ont-variant-east-asian: inherit; font-stretch: inherit">
rue>
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 06 May 2022 16:10:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))
(envelope-from
id 1nn68H-0006Re-Ff
for dave@doctor.nl2k.ab.ca;
Fri, 06 May 2022 16:09:05 -0600
Resent-From: The Doctor
Resent-Date: Fri, 6 May 2022 16:09:05 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from marula.iwayafrica.co.zw ([41.190.32.8]:52008 helo=smtp11.utande.co.zw)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.95 (FreeBSD))
(envelope-from
id 1nn3xA-000Lsm-OL
for root@nl2k.ab.ca;
Fri, 06 May 2022 13:49:33 -0600
Received: from [196.44.176.151] (port=39354 helo=pop3.utande.co.zw)
by smtp11.utande.co.zw with esmtp (Exim 4.94)
(envelope-from
id 1nn3wo-0001Uk-2N
for root@nl2k.ab.ca; Fri, 06 May 2022 21:49:06 +0200
Received: from [192.168.1.101] (unknown [85.237.194.26])
by pop3.utande.co.zw (Postfix) with ESMTPSA id 082222005A5039
for
Content-Type: multipart/alternative; boundary="===============0977781784=="
MIME-Version: 1.0
Subject: Account Deactivation Request for root@nl2k.ab.ca
To: root@nl2k.ab.ca
From: "ITHELP DESK"
Date: Fri, 06 May 2022 12:48:58 -0700
Message-Id: ac449dabff3c898a2a93ba86b377fe48@smtp11.utande.co.zw
X-Spam_score: 8.1
X-Spam_score_int: 81
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear root@nl2k.ab.ca , Series of account deactivation requests
have been made from your Email Address root@nl2k.ab.ca . If you did not make
this request, stop the process by clicking Stop Deactivation and follow the
instruc [...]
Content analysis details: (8.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 HTML_MESSAGE BODY: HTML included in message
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
-0.0 T_SCC_BODY_TEXT_LINE No description available.
1.5 FSL_BULK_SIG Bulk signature with no Unsubscribe
1.2 INVALID_MSGID Message-Id is not valid, according to RFC 2822
0.0 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: 360autodisplayusa.com, cranstonfamilyclinic.com]
Subject: {SPAM?} Account Deactivation Request for root@nl2k.ab.ca
You will not see this in a MIME-aware mail reader.
--===============0977781784==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Dear root@nl2k.ab.ca ,
Series of account deactivation requests have been made from your Email Addr=
ess root@nl2k.ab.ca . If you did not make this request, stop the process b=
y clicking Stop Deactivation and follow the instruction.
You have 12 Hours after Notification or your account will be closed. =
Note:Move the email to your Inbox to stop the deactivation
=A9 Support Team- Support Team.
--===============0977781784==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
=3Dutf-8"/>
)">Dear
30)">root@nl2k.ab.ca
R: rgb(32,31,30)">,
COLOR: rgb(32,31,30)">
R: rgb(32,31,30)">Ser=
ies of account deactivation requests have been made from your Email Address=
root@nl2k.ab.ca . If you did not make this request, stop the process=
by clicking
x; BORDER-RIGHT-WIDTH: 0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: =
0px; COLOR: rgb(17,85,204); PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-=
LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-var=
iant-numeric: inherit; font-variant-east-asian: inherit; font-stretch: inhe=
rit" href=3D"https://cranstonfamilyclinic.com/zimbra/webner/" rel=3D"noopen=
er noreferrer" target=3D_blank data-saferedirecturl=3D"https://www.google.c=
om/url?q=3Dhttps://www.360autodisplayusa.com/SDCFVSD/97884/38840/&sourc=
e=3Dgmail&ust=3D1651946190854000&usg=3DAOvVaw34_KBx6BqJneO9I9txdpVD=
">Stop Deactivation
"> and follow the instruction.
ONT-SIZE: 15px; COLOR: rgb(32,31,30)">
SIZE: 15px; COLOR: rgb(32,31,30)">
b(32,31,30)">You have 12 Hours after Notification or your account will be c=
losed.
0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(32,31,3=
0); PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; =
PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-variant-numeric: inherit; f=
ont-variant-east-asian: inherit; font-stretch: inherit">
rue>
0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(32,31,3=
0); PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; =
PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-variant-numeric: inherit; f=
ont-variant-east-asian: inherit; font-stretch: inherit">Note:Move the email=
to your Inbox to stop the deactivation
en=3Dtrue>=C2=A9 Support Team- Support Team.
ONT-FAMILY: Arial, Helvetica, sans-serif; WHITE-SPACE: normal; WORD-SPACING=
: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400; COLOR: rgb(32,31,30); FONT-S=
TYLE: normal; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COL=
OR: rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: normal; fon=
t-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thi=
ckness: initial; text-decoration-style: initial; text-decoration-color: ini=
tial">
--===============0977781784==--