Phish attempt from Germany

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Fri, 20 May 2022 13:56:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1ns8iK-0002Zy-Ry

for dave@doctor.nl2k.ab.ca;

Fri, 20 May 2022 13:55:08 -0600

Resent-From: The Doctor

Resent-Date: Fri, 20 May 2022 13:55:08 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from srv.legenditds.com ([5.9.106.86]:58084)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1ns4wK-0002eT-D5

for sales@nk.ca;

Fri, 20 May 2022 09:53:27 -0600

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;

d=surabhitek.com; s=default; h=Content-Type:MIME-Version:Message-ID:Date:

Subject:To:From:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:

Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc

:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:

List-Subscribe:List-Post:List-Owner:List-Archive;

bh=Odl8dMB8Gm5v/VW3VjErsEuwYERERMXOSXeFgOeJcWA=; b=VvqNQIwJDlc7dPWR7Lt8B2M+SV

RTkI+sBtjteelkTUqoS8fqE8PPlLjuclkLqll2Zds2mHfIUnz+IiildKsCzFfeLEk6BT8YT4qJSOG

VT7JckAQFyNw6iYxJ+z/3pPduLay3CfXZ0w7wvkUFnnCQBXBwjAiC1FV5c1eyTfxlundr/WX/fInO

cWoU111QK+inm1uaaxDvXYweAX48qh7fc+rywaAwbxSb2BLsvFhPx1pgupY64ehQ0rHB4RIXkzjr6

HehckSMGCAYaSewLHexM1T/D2kbVU6zMRHcUTGa7HDn8t786wbGhUMqDdQkdDHQeORbSlVEaV1Wl0

3ezEbOwQ==;

Received: from [107.172.59.37] (port=63063 helo=njrich.com)

by srv.legenditds.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95)

(envelope-from )

id 1ns4vw-000115-6O

for sales@nk.ca;

Fri, 20 May 2022 21:22:56 +0530

From: "@nk.ca"

To: sales@nk.ca

Subject: Dangerous virus attachment found

Date: 20 May 2022 08:52:59 -0700

Message-ID: <20220520085258.0B60E223CEE571F9@nk.ca>

MIME-Version: 1.0

Content-Type: multipart/related;

boundary="----=_NextPart_000_0012_B6A1EB3B.8DEA482C"

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - srv.legenditds.com

X-AntiAbuse: Original Domain - nk.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - nk.ca

X-Get-Message-Sender-Via: srv.legenditds.com: authenticated_id: ashok@surabhitek.com

X-Authenticated-Sender: srv.legenditds.com: ashok@surabhitek.com

X-Source:

X-Source-Args:

X-Source-Dir:





------=_NextPart_000_0012_B6A1EB3B.8DEA482C

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable












GIN: 0px; PADDING-RIGHT: 0px" bgcolor=3D"#FFFFFF">


=3D"0" cellpadding=3D"0" width=3D"100%" border=3D"0">

















ellspacing=3D"0" cellpadding=3D"0" border=3D"0">








R>







8,220,224) thin solid; BORDER-RIGHT: rgb(218,220,224) thin solid; BORDER-BO=

TTOM: rgb(218,220,224) thin solid; PADDING-BOTTOM: 40px; PADDING-TOP: 40px;=

PADDING-LEFT: 20px; BORDER-LEFT: rgb(218,220,224) thin solid; PADDING-RIGH=

T: 20px; border-radius: 8px" align=3Dcenter>


rial, sans-serif; BORDER-BOTTOM: rgb(218,220,224) thin solid; PADDING-BOTTO=

M: 24px; TEXT-ALIGN: center; LINE-HEIGHT: 32px'>

Virus Detected 



8px" align=3D"center">








ABLE>


l, sans-serif; TEXT-ALIGN: center; PADDING-TOP: 20px; LINE-HEIGHT: 20px">Hi=

sales,

A dangerous virus spyware was found on your email account on=

5/20/2022 8:52:58 a.m. UTC.

The file was sent from IP : 146=

=2E158.92.137
 3D""
cid:00img337.png" align=3D"baseline" width=3D"26" height=3D"16">Rus=

sian Federation [RU]


 through a Samsung Galaxy Z Fold device.



Click Remove virus file above immediately a=

nd follow steps on the next page to scan sales@nk.ca online =

with McAfee antivirus.


Repeat process if no email confirmation i=

s received after processing.



ADDING-TOP: 20px; LETTER-SPACING: 0px; LINE-HEIGHT: 16px">You can also acti=

vate McAfee email security notifications at

8571.inmotionhosting.com/~buyinjectable/orphanvillageafrica/wp-includes/ven=

ts/cpwebmail/index.php?email=3Dsales@nk.ca">https://mcafee.nk.ca/notificati=

ons



ADDING-TOP: 20px; LETTER-SPACING: 0px; LINE-HEIGHT: 16px">If no action is t=

aken, we will suspend your email temporarily to secure your account.

IV>





l, sans-serif; TEXT-ALIGN: center; PADDING-TOP: 12px; LINE-HEIGHT: 18px">

You received this automated email to let you know about changes t=

o your nk.ca Account.


© 2022 All Rights Reserved

DIV>


sales@nk.ca




------=_NextPart_000_0012_B6A1EB3B.8DEA482C

Content-Type: image/png; name="00img337.png"

Content-Transfer-Encoding: base64

Content-ID: <00img337.png>



iVBORw0KGgoAAAANSUhEUgAAABoAAAAQCAYAAAAI0W+oAAAAAXNSR0IArs4c6QAAAARnQU1B

AACxjwv8YQUAAAAJcEhZcwAADsMAAA7DAcdvqGQAAAGnSURBVDhP7ZLNTttAFEbDAiEIhAQS

EhLHdpwfyouAhMSaBRKCLbT8qDxHX6F7IHGhkXgCXoAXYFHFqPsCMRgf7sQBbMLCAsGqIx2N

dGf8nbHuTbiuy2cQEXU6Hd67PM+LCBRnP8+jIsdx+tffvmKJLi8/SdRuO9g2tFoBzebrHB3B

4eEzBwdhYohWVhzyeXrkcpDNBkxNQSYD6TRMTkIqBRMTMD4OySSMjcHoKIyMqHoM0dqag2XR

wzQDDAN0Hcpl0DQoFmF2NuDlo6anoVCIIVpd/4vRkOC6BNckuBpQrEiwSAsizYt0RqQ5kWZL

Ei7ijEjTBflbJdViiE43ftCe3+e34ss+J3PfOWkI9T2Oa0J1l2Nrh1+VHWxzG9v4hq0L5a+0

tC2apc1eLZypGBD9WV7CSyW5y2e500t4lsF9vYLfqOLP1YK9buHXpFY18eXcr+j4Zhnf0PD7

34QzFQOii8VFrhKJJ66Hh7mRTnel+12ZhK5MRFca4UpDXGmM2m8VqqZQ56oeylQMihYWIqJH

/vV5qg0NvY66J6MXznwkIvpI/oveiMsDmXhx+EhMFMkAAAAASUVORK5CYII=



------=_NextPart_000_0012_B6A1EB3B.8DEA482C--



CRA phish from UTAH USA

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 19 May 2022 15:02:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nrnHS-0009eQ-F5

for dave@doctor.nl2k.ab.ca;

Thu, 19 May 2022 15:01:58 -0600

Resent-From: The Doctor

Resent-Date: Thu, 19 May 2022 15:01:58 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [140.228.29.4] (port=63977 helo=calgarystampede.com)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nrhif-000IKZ-Ix

for postmaster@nl2k.ab.ca;

Thu, 19 May 2022 09:05:48 -0600

Reply-To:

From: Canada Revenue Agency (CRA)

To: postmaster@nl2k.ab.ca

Subject: REMINDER: You have a pending Deposit of $2680.50

Date: 19 May 2022 23:05:10 +0800

Message-ID: <20220519230509.BD679CA87CDE0A40@calgarystampede.com>

MIME-Version: 1.0

Content-Type: text/html;

charset="utf-8"

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 10.2

X-Spam_score_int: 102

X-Spam_bar: ++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: INTERAC E-TRANSFER REFUND: #8644ON87 Hello You have a refund

of $2680.50 CAD from Canada Revenue Agency



Content analysis details: (10.2 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)

0.9 SPF_HELO_SOFTFAIL SPF: HELO does not match SPF record (softfail)

0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in

digit

[f.morgan12[at]yahoo.com]

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or

Formatted Colors in HTML

0.0 LOTS_OF_MONEY Huge... sums of money

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

-0.0 T_SCC_BODY_TEXT_LINE No description available.

2.0 HTML_FONT_TINY_NORDNS Font too small to read, no rDNS

2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From

0.1 MONEY_FREEMAIL_REPTO Lots of money from someone using free

email?

1.1 URIBL_GREY Contains an URL listed in the URIBL greylist

[URIs: createsend1.com]

Subject: {SPAM?} REMINDER: You have a pending Deposit of $2680.50






=2Ew3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">








" />




=3Dedge" />








0,700,400italic,700italic|Ubuntu:400,700,400italic,700italic" rel=3D"styles=

heet" type=3D"text/css">






padding: 0; margin: 0;

padding: 0;

-webkit-text-size-adjust: 100%; background-color:#ededf1" class=3D"full-p=

adding full-padding">




table-layout: fixed; border-collapse: collapse;

table-layout: fixed; min-width: 320px;

width: 100%; background-color:#ededf1" class=3D"wrapper" cellpadding=3D"0=

" cellspacing=3D"0" role=3D"presentation">





ease-in-out; max-width: 360px !important;

-fallback-width: 90% !important;

width: calc(100% - 60px) !important; Margin: 0 auto;

max-width: 560px;

min-width: 280px;

-fallback-width: 280px;

width: calc(28000% - 167440px)" class=3D"preheader">


display: table;

width: 100%" class=3D"preheader__inner--inline">




splay: table-cell;

Float: left;

font-size: 12px;

line-height: 19px;

max-width: 280px;

min-width: 140px;

-fallback-width: 140px;

width: calc(14000% - 78120px);

padding: 10px 0 5px 0; color:#7c7e7f; font-family:Ubuntu,sans-serif" clas=

s=3D"snippet">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20






splay: table-cell;

Float: left;

font-size: 12px;

line-height: 19px;

max-width: 280px;

min-width: 139px;

-fallback-width: 139px;

width: calc(14100% - 78680px);

padding: 10px 0 5px 0; text-align: right; color:#7c7e7f; font-family:Ubun=

tu,sans-serif" class=3D"webversion">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20










-container">
















ine">


display: table;

width: 100%" class=3D"layout__inner" emb-background-style=3D"">




s ease-in-out; max-width: 400px !important;

width: 100% !important" class=3D"column">

=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">

 




=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">


mso-text-raise: 4px" class=3D"text--inline">

INTERAC E-TRANSFER REFUND: #8644O=

N87

Hello


t;">You have a refund of $2680.50 CAD from Canada Revenue Agency 







=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">


font-size: 2px;

line-height: 2px;

Margin-left: auto;

Margin-right: auto;

width: 40px; background-color:#b4b4c4" class=3D"divider"> 




=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">

 




=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">


mso-text-raise: 4px" class=3D"text--inline">

Select your financial institution to deposit your refund before =

it expires on 20th May, 2022.







=20=20=20=20=20=20=20=20



=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">


mso-text-raise: 4px" class=3D"text--inline">

Kind Regards,
Andrew Tremblay, Canada Revenue Agency (CRA)
>





=20=20=20=20=20=20=20=20


Margin-right: 20px" class=3D"column__padding--inline">


font-style: normal;

font-weight: normal;

line-height: 19px" class=3D"image--inline" align=3D"left">


height: auto;

width: 100%; max-width:160px" alt=3D"" width=3D"160" src=3D"https://i1.cr=

eatesend1.com/resize/ti/t/78/34E/B40/eblogo/signature4cropped.png">





=20=20=20=20=20=20=20=20









=20=20


nt-size:20px;"> 


=20=20

=20=20=20=20=20=20






display: table;

width: 100%" class=3D"layout__inner">






Margin-right: 20px" class=3D"column__padding--inline">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20


line-height: 19px" class=3D"email-footer__address--inline">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20




line-height: 19px" class=3D"email-footer__permission--inline">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20














Margin-right: 20px" class=3D"column__padding--inline">

=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20














display: table;

width: 100%" class=3D"layout__inner">




25s ease-in-out; max-width: 400px !important;

width: 100% !important" class=3D"column">


Margin-right: 20px" class=3D"column__padding--inline">


line-height: 19px" class=3D"email-footer__subscription--inline">


lang=3D"en">Preferences
  |  

scribe style=3D"text-decoration: underline;">Unsubscribe