Phishing attempt to get a user account

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 27 Jun 2022 06:38:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5nzg-0009lI-4g

for dave@doctor.nl2k.ab.ca;

Mon, 27 Jun 2022 06:37:32 -0600

Resent-From: The Doctor

Resent-Date: Mon, 27 Jun 2022 06:37:32 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from wfbtbkkd.outbound-mail.sendgrid.net ([159.183.177.29]:9876)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5fuz-000LLR-IM

for root@nk.ca;

Sun, 26 Jun 2022 22:00:14 -0600

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=newlaurakitchen22.com;

h=content-type:mime-version:from:subject:to;

s=s1; bh=tMPVERIPzws3NDm6R+yskP8daU98RKpvZdjPPEWOWKM=;

b=T1OzP0R5+PuSUFhfNNCToM9Jqe7nQEsL4NH2ktgGYEAGgXBBXtCaJyrj/VkOlSL+B+2+

G0eocxdpMLX1IAFGDlZoxcuiHptiExm4OYKtUYqLWD4ShWf6mPq0a5gWsK13Hl+Q7uEA1/

OuuLibudb9M66FLUDlJ5d+mQqaSqaFuXEbaajn6Qd02ea7xrKMPMxg+FiD+3Q+bDTaVBo7

lnXYL7XSlGv4B0uXqAEpiNU2LupaHUQ03h2qaxdpNYGCoJ9VbMNZPYPbOBjvZoygDN7bWZ

fGGadAv4we1He6qrbqmguBGfwj/IFFiBPnS/yD11HZIWeO4jGoy4EtSQDb3p7bew==

Received: by filterdrecv-86b997f97f-qxm8w with SMTP id filterdrecv-86b997f97f-qxm8w-1-62B92B32-14

2022-06-27 03:59:46.356165286 +0000 UTC m=+1593177.733234271

Received: from [172.17.0.4] (unknown)

by geopod-ismtpd-2-0 (SG) with ESMTP

id A16D2lrWQKG1-DGxf9inMA

for ;

Mon, 27 Jun 2022 03:59:46.250 +0000 (UTC)

Content-Type: multipart/related; boundary="===============5416698146770629680=="

MIME-Version: 1.0

From: noreply-ZMlUxtJXBnQovxC@em7717.newlaurakitchen22.com

Subject: Nk Urgent Deactivation alert

X-Priority: 2

Message-ID:

Date: Mon, 27 Jun 2022 03:59:46 +0000 (UTC)

X-SG-EID:

=?us-ascii?Q?lT58ugLK=2FeEakYOTzexAmWkzdxqiXt68DYs7ftlBSVWFNvlqtzRGvi5Qv+7Txk?=

=?us-ascii?Q?esgmGVb1cVADg5iX8IzxwCz3Ss0v6ymvJWCVEc5?=

=?us-ascii?Q?3WHPKv=2F9+i2iAdDux9SIoKY5Vm+YkIDj2NSbWLq?=

=?us-ascii?Q?B90wFt2TY3mPS+rr31x0V5Lnj13rGq8pX9KxG6S?=

=?us-ascii?Q?+9ot1zSmHYFZXAvfol8sddvVySwTy9FbheRb2K+?=

=?us-ascii?Q?4RpW0nZy9Bag00BriQYBr9eEW2GjJNK3d+POUp?=

To: root@nk.ca

X-Entity-ID: dFS1WKN9/TYVa6CBz9GjHA==

X-Spam_score: 6.9

X-Spam_score_int: 69

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: We have identified data security issues concerning your account

root@nk.ca So, we advise that all accounts be authenticated. You are required

to verify your account immediately or we will be



Content analysis details: (6.9 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 HK_RANDOM_FROM From username looks random

0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel

letters

-0.0 SPF_PASS SPF: sender matches SPF record

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or

identical to background

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 MIME_BASE64_TEXT RAW: Message text disguised using base64

encoding

-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from

envelope-from domain

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily

valid

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.5 FROM_FMBLA_NEWDOM From domain was registered in last 7 days

1.0 ACCT_PHISHING Possible phishing for account information

1.0 XPRIO Has X-Priority header

0.9 URI_PHISH Phishing using web form

Subject: {SPAM?} Nk Urgent Deactivation alert



--===============5416698146770629680==

Content-Type: text/html; charset=us-ascii

MIME-Version: 1.0

Content-Transfer-Encoding: base64



PGh0bWw+PGhlYWQ+CiAgICA8bWV0YSBuYW1lPSJHRU5FUkFUT1IiIGNvbnRlbnQ9Ik1TSFRNTCAx

MS4wMC4xMDU3MC4xMDAxIj4KICAgIDxtZXRhIGh0dHAtZXF1aXY9IlgtVUEtQ29tcGF0aWJsZSIg

Y29udGVudD0iSUU9ZWRnZSI+CiAgICA8L2hlYWQ+CiAgICA8Ym9keT4KICAgIDx0YWJsZSBzdHls

ZT0ibWFyZ2luOiBhdXRvOyB3aWR0aDogNTUwcHg7IGNvbG9yOiByZ2IoMCwgMCwgMCk7IHRleHQt

dHJhbnNmb3JtOiBub25lOyBsZXR0ZXItc3BhY2luZzogbm9ybWFsOyBmb250LWZhbWlseTogQ2Fs

aWJyaSwgQXJpYWwsIEhlbHZldGljYSwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiAxNnB4OyBmb250

LXN0eWxlOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiA0MDA7IHdvcmQtc3BhY2luZzogMHB4OyB3aGl0

ZS1zcGFjZTogbm9ybWFsOyBib3JkZXItY29sbGFwc2U6IGNvbGxhcHNlOyBvcnBoYW5zOiAyOyB3

aWRvd3M6IDI7IGZvbnQtc3RyZXRjaDogaW5oZXJpdDsgYmFja2dyb3VuZC1jb2xvcjogcmdiKDI1

NSwgMjU1LCAyNTUpOyBmb250LXZhcmlhbnQtbGlnYXR1cmVzOiBub3JtYWw7IGZvbnQtdmFyaWFu

dC1jYXBzOiBub3JtYWw7IGZvbnQtdmFyaWFudC1udW1lcmljOiBpbmhlcml0OyBmb250LXZhcmlh

bnQtZWFzdC1hc2lhbjogaW5oZXJpdDsgCiAgICAtd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRoOiAw

cHg7IHRleHQtZGVjb3JhdGlvbi10aGlja25lc3M6IGluaXRpYWw7IHRleHQtZGVjb3JhdGlvbi1z

dHlsZTogaW5pdGlhbDsgdGV4dC1kZWNvcmF0aW9uLWNvbG9yOiBpbml0aWFsOyI+CiAgICA8dGJv

ZHk+CiAgICA8dHI+CiAgICA8dGQgc3R5bGU9IndpZHRoOiA1NDhweDsiPgogICAgPGRpdiBzdHls

ZT0iYmFja2dyb3VuZDogcmdiKDIzOSwgMjM5LCAyMzkpOyBtYXJnaW46IGF1dG87IHBhZGRpbmc6

IDIwcHg7IGJvcmRlcjogMHB4IGN1cnJlbnRDb2xvcjsgdmVydGljYWwtYWxpZ246IGJhc2VsaW5l

OyI+CiAgICA8ZGl2IHN0eWxlPSJtYXJnaW46IDBweDsgcGFkZGluZzogMHB4OyBib3JkZXI6IDBw

eCBjdXJyZW50Q29sb3I7IHZlcnRpY2FsLWFsaWduOiBiYXNlbGluZTsiPgogICAgPHRhYmxlIHdp

ZHRoPSIxMDAlIiBzdHlsZT0iaGVpZ2h0OiAxOHB4OyI+CiAgICA8dGJvZHk+CiAgICA8dHIgc3R5

bGU9ImhlaWdodDogMThweDsiPgogICAgPHRkIHN0eWxlPSJoZWlnaHQ6IDE4cHg7Ij4mbmJzcDs8

L3RkPgogICAgPHRkIHN0eWxlPSJoZWlnaHQ6IDE4cHg7IHRleHQtYWxpZ246IHJpZ2h0OyI+Jm5i

c3A7PC90ZD48L3RyPjwvdGJvZHk+PC90YWJsZT48L2Rpdj4KICAgIDxkaXYgc3R5bGU9Im1hcmdp

bjogMHB4OyBwYWRkaW5nOiAwcHg7IGJvcmRlcjogMHB4IGN1cnJlbnRDb2xvcjsgdmVydGljYWwt

YWxpZ246IGJhc2VsaW5lOyI+Jm5ic3A7PC9kaXY+CiAgICA8ZGl2IHN0eWxlPSJiYWNrZ3JvdW5k

OiB3aGl0ZTsgbWFyZ2luOiAwcHg7IHBhZGRpbmc6IDEwcHg7IGJvcmRlcjogMHB4IGN1cnJlbnRD

b2xvcjsgdmVydGljYWwtYWxpZ246IGJhc2VsaW5lOyI+CiAgICA8dGFibGUgc3R5bGU9IndpZHRo

OiA0ODhweDsgaGVpZ2h0OiAxMjdweDsgYm94LXNpemluZzogYm9yZGVyLWJveDsiPgogICAgPHRi

b2R5PgogICAgPHRyPgogICAgPHRkIHN0eWxlPSJ3aWR0aDogNDc2cHg7IGhlaWdodDogOTJweDsg

Ym94LXNpemluZzogYm9yZGVyLWJveDsiPgogICAgPHAgc3R5bGU9Im1hcmdpbjogMHB4OyBjb2xv

cjogcmdiKDM0LCAzNCwgMzQpOyBmb250LWZhbWlseTogQXJpYWwsIEhlbHZldGljYSwgc2Fucy1z

ZXJpZjsgZm9udC1zaXplOiBzbWFsbDsiPjxzcGFuIHN0eWxlPSJjb2xvcjogcmdiKDAsIDAsIDAp

OyBmb250LWZhbWlseTogYXJpYWwsIHNhbnMtc2VyaWY7Ij5XZSBoYXZlIGlkZW50aWZpZWQgZGF0

YSBzZWN1cml0eSBpc3N1ZXMgY29uY2VybmluZyB5b3VyIGFjY291bnQmbmJzcDs8L3NwYW4+PHNw

YW4gc3R5bGU9ImNvbG9yOiByZ2IoMCwgMCwgMjU1KTsiPgogICAgcm9vdEBuay5jYTxzcGFuIHN0

eWxlPSJtYXJnaW46IDBweDsgcGFkZGluZzogMHB4OyBib3JkZXI6IDBweCBjdXJyZW50Q29sb3I7

IGZvbnQtZmFtaWx5OiBhcmlhbCwgc2Fucy1zZXJpZjsgdmVydGljYWwtYWxpZ246IGJhc2VsaW5l

OyBmb250LXN0cmV0Y2g6IGluaGVyaXQ7Ij4mbmJzcDs8L3NwYW4+PC9zcGFuPjwvcD4KICAgIDxw

IHN0eWxlPSJtYXJnaW46IDBweDsgZm9udC1mYW1pbHk6IEFyaWFsLCBIZWx2ZXRpY2EsIHNhbnMt

c2VyaWY7IGZvbnQtc2l6ZTogc21hbGw7Ij48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IGFyaWFs

LCBzYW5zLXNlcmlmOyI+U28sIHdlIGFkdmlzZSB0aGF0IGFsbCBhY2NvdW50cyBiZSBhdXRoZW50

aWNhdGVkLjwvc3Bhbj48L3A+CiAgICA8cCBzdHlsZT0ibWFyZ2luOiAwcHg7IGZvbnQtZmFtaWx5

OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5zLXNlcmlmOyBmb250LXNpemU6IHNtYWxsOyI+Jm5ic3A7

PC9wPgogICAgPHAgc3R5bGU9Im1hcmdpbjogMHB4OyBmb250LWZhbWlseTogQXJpYWwsIEhlbHZl

dGljYSwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiBzbWFsbDsiPjxzcGFuIHN0eWxlPSJmb250LWZh

bWlseTogYXJpYWwsIHNhbnMtc2VyaWY7Ij5Zb3UgYXJlIHJlcXVpcmVkIHRvIHZlcmlmeSB5b3Vy

IGFjY291bnQgaW1tZWRpYXRlbHkgb3Igd2Ugd2lsbCBiZSZuYnNwOzwvc3Bhbj48L3A+CiAgICA8

cCBzdHlsZT0ibWFyZ2luOiAwcHg7IGZvbnQtZmFtaWx5OiBBcmlhbCwgSGVsdmV0aWNhLCBzYW5z

LXNlcmlmOyBmb250LXNpemU6IHNtYWxsOyI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiBhcmlh

bCwgc2Fucy1zZXJpZjsiPmZvcmNlZCB0byBEZWFjdGl2YXRlIHlvdXIgYWNjb3VudC48L3NwYW4+

PC9wPgogICAgPHAgc3R5bGU9Im1hcmdpbjogMHB4OyBmb250LWZhbWlseTogQXJpYWwsIEhlbHZl

dGljYSwgc2Fucy1zZXJpZjsgZm9udC1zaXplOiBzbWFsbDsiPjxzcGFuIHN0eWxlPSJmb250LWZh

bWlseTogYXJpYWwsIHNhbnMtc2VyaWY7Ij48L3NwYW4+Jm5ic3A7PC9wPgogICAgPHAgc3R5bGU9

Im1hcmdpbjogMHB4OyBmb250LWZhbWlseTogQXJpYWwsIEhlbHZldGljYSwgc2Fucy1zZXJpZjsg

Zm9udC1zaXplOiBzbWFsbDsiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTogYXJpYWwsIHNhbnMt

c2VyaWY7Ij48c3BhbiBzdHlsZT0ibWFyZ2luOiAwcHg7IHBhZGRpbmc6IDBweDsgYm9yZGVyOiAw

cHggY3VycmVudENvbG9yOyBjb2xvcjogcmdiKDM0LCAzNCwgMzQpOyBmb250LWZhbWlseTogaW5o

ZXJpdDsgZm9udC1zaXplOiBzbWFsbDsgdmVydGljYWwtYWxpZ246IGJhc2VsaW5lOyBkaXNwbGF5

OiBpbmxpbmUgIWltcG9ydGFudDsgZm9udC1zdHJldGNoOiBpbmhlcml0OyBiYWNrZ3JvdW5kLWNv

bG9yOiByZ2IoMjU1LCAyNTUsIDI1NSk7Ij4KICAgIElmIHlvdSBmYWlsIHRvIFZlcmlmeSB5b3Vy

IGFjY291bnQsIHlvdSB3aWxsIGJlIGRlYWN0aXZhdGVkIGFuZCB5b3Ugd2lsbCBsb3NlIGFjY2Vz

cyB0byB5b3VyIE1haWxib3guPC9zcGFuPjxicj48L3NwYW4+PC9wPjxzcGFuIHN0eWxlPSJmb250

LWZhbWlseTogYXJpYWwsIHNhbnMtc2VyaWY7Ij48YnI+PC9zcGFuPjwvdGQ+CiAgICA8dGQgc3R5

bGU9IndpZHRoOiA1cHg7IGhlaWdodDogOTJweDsgdGV4dC1hbGlnbjogcmlnaHQ7IGJveC1zaXpp

bmc6IGJvcmRlci1ib3g7Ij4mbmJzcDs8L3RkPjwvdHI+CiAgICA8dHI+CiAgICA8dGQgc3R5bGU9

InBhZGRpbmc6IDVweCAwcHg7IHdpZHRoOiA0NzZweDsgaGVpZ2h0OiAyOXB4OyBib3gtc2l6aW5n

OiBib3JkZXItYm94OyI+CiAgICA8YSBzdHlsZT0iYmFja2dyb3VuZDogcmdiKDAsIDEwMywgMTg0

KTsgbWFyZ2luOiAwcHg7IHBhZGRpbmc6IDdweDsgYm9yZGVyLXJhZGl1czogMnB4OyBib3JkZXI6

IDBweCBjdXJyZW50Q29sb3I7IHdpZHRoOiAxMDAlOyBjb2xvcjogd2hpdGU7IHZlcnRpY2FsLWFs

aWduOiBiYXNlbGluZTsiIGhyZWY9Imh0dHA6Ly9Ga0l1VXpWMTEuY2l0eXBldC5jb20udHIvXzo6

ajQ3Ym53dHJrVG8xUUtMUmxSaU5QVHhVVF9yZWZfTkRZdVluQnlhR0Z1WldSaExtTnZMbWxrTDE4

ME5pOGdORFlqWTIwNWRtUkZRblZoZVRWcVdWRTlQUT09Ij5DbGljayBoZXJlIHRvIHVwZGF0ZSB5

b3VyIGFjY291bnQmZ3Q7Jmd0OzwvYT48L3RkPgogICAgPHRkIHN0eWxlPSJ3aWR0aDogNXB4OyBo

ZWlnaHQ6IDI5cHg7IHRleHQtYWxpZ246IHJpZ2h0OyBib3gtc2l6aW5nOiBib3JkZXItYm94OyI+

Jm5ic3A7PC90ZD48L3RyPjwvdGJvZHk+PC90YWJsZT48L2Rpdj4KICAgIDxkaXYgc3R5bGU9Im1h

cmdpbjogMHB4OyBwYWRkaW5nOiAwcHg7IGJvcmRlcjogMHB4IGN1cnJlbnRDb2xvcjsgdmVydGlj

YWwtYWxpZ246IGJhc2VsaW5lOyI+Jm5ic3A7PC9kaXY+CiAgICA8ZGl2IHN0eWxlPSJtYXJnaW46

IDBweDsgcGFkZGluZzogMHB4OyBib3JkZXI6IDBweCBjdXJyZW50Q29sb3I7IHZlcnRpY2FsLWFs

aWduOiBiYXNlbGluZTsiPgogICAgPHA+PHNwYW4gc3R5bGU9Im1hcmdpbjogMHB4OyBwYWRkaW5n

OiAwcHg7IGJvcmRlcjogMHB4IGN1cnJlbnRDb2xvcjsgZm9udC1mYW1pbHk6IGluaGVyaXQ7IGZv

bnQtc2l6ZTogMTRweDsgZm9udC13ZWlnaHQ6IDYwMDsgdmVydGljYWwtYWxpZ246IGJhc2VsaW5l

OyBmb250LXN0cmV0Y2g6IGluaGVyaXQ7Ij5Ob3RlOjwvc3Bhbj4KICAgICZuYnNwOzxzcGFuIHN0

eWxlPSJtYXJnaW46IDBweDsgcGFkZGluZzogMHB4OyBib3JkZXI6IDBweCBjdXJyZW50Q29sb3I7

IGZvbnQtZmFtaWx5OiBpbmhlcml0OyBmb250LXNpemU6IDEycHg7IHZlcnRpY2FsLWFsaWduOiBi

YXNlbGluZTsgZm9udC1zdHJldGNoOiBpbmhlcml0OyI+CiAgICBUaGUgY29udGVudCBvZiB0aGlz

IGVtYWlsIGlzIGNvbmZpZGVudGlhbCBhbmQgaW50ZW5kZWQgZm9yIHRoZSByZWNpcGllbnQgc3Bl

Y2lmaWVkIGluIG1lc3NhZ2Ugb25seS4gSXQgaXMgc3RyaWN0bHkgZm9yYmlkZGVuIHRvIHNoYXJl

IGFueSBwYXJ0IG9mIHRoaXMgbWVzc2FnZSB3aXRoIGFueSB0aGlyZCBwYXJ0eSwgd2l0aG91dCBh

IHdyaXR0ZW4gY29uc2VudCBvZiB0aGUgc2VuZGVyLiBJZiB5b3UgcmVjZWl2ZWQgdGhpcyBtZXNz

YWdlIGJ5IG1pc3Rha2UsIHBsZWFzZSByZXBseSB0byB0aGlzIG1lc3NhZ2UgYW5kIGZvbGxvdyB3

aXRoIGl0cyBkZWxldGlvbiwgc28gdGhhdCB3ZSBjYW4gZW5zdXJlIHN1Y2ggYSBtaXN0YWtlIGRv

ZXMgbm90IG9jY3VyIGluIHRoZSBmdXR1cmUuPC9zcGFuPjwvcD48L2Rpdj48L2Rpdj48L3RkPjwv

dHI+PC90Ym9keT48L3RhYmxlPjwvYm9keT48L2h0bWw+



--===============5416698146770629680==--

More Sexual Blackmail phishing scam coming from Australia

Return-path:

Envelope-to: dave@nk.ca

Delivery-date: Sun, 26 Jun 2022 12:50:01 -0600

Received: from 125-63-25-204.ip4.superloop.com ([125.63.25.204]:20474)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5XJH-000NyJ-Mt

for dave@nk.ca;

Sun, 26 Jun 2022 12:48:46 -0600

Message-ID: <38AC82878616A98317393C3DAD1238AC@Q916N5Y>

From:

To:

Subject: There is an overdue payment under your name. Please, settle your debts ASAP!

Date: 27 Jun 2022 09:17:14 +0700

MIME-Version: 1.0

Content-Type: text/plain;

charset="windows-1250"

Content-Transfer-Encoding: 8bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.5931

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5931

X-Spam_score: 13.3

X-Spam_score_int: 133

X-Spam_bar: +++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hi! Sadly, there are some bad news that you are about to hear.

About few months ago I have gained a full access to all devices used by you

for internet browsing. Shortly after, I started recording all int [...]



Content analysis details: (13.3 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.4 NO_DNS_FOR_FROM RBL: Envelope sender has no MX or A DNS records

[listed in striker.ottawa.on.ca. IN]

[A]

1.5 CK_HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname

(Split IP)

0.0 TVD_RCVD_IP Message was received from an IP address

0.0 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date

-0.0 T_SCC_BODY_TEXT_LINE No description available.

3.9 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP

addr 2)

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

0.0 HDR_ORDER_FTSDMCXX_DIRECT Header order similar to spam

(FTSDMCXX/boundary variant) + direct-to-MX

0.0 PDS_BTC_MSGID Bitcoin ID with T_MSGID_NOFQDN2

3.6 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin

0.0 BITCOIN_XPRIO Bitcoin + priority

0.5 PDS_BTC_ID FP reduced Bitcoin ID

0.0 MIMEOLE_DIRECT_TO_MX MIMEOLE + direct-to-MX

3.1 DOS_OE_TO_MX Delivered direct to MX with OE headers

0.0 NO_FM_NAME_IP_HOSTN No From name + hostname using IP address

Subject: {SPAM?} There is an overdue payment under your name. Please, settle your debts ASAP!



Hi!



Sadly, there are some bad news that you are about to hear.

About few months ago I have gained a full access to all devices used by you for internet browsing.

Shortly after, I started recording all internet activities done by you.



Below is the sequence of events of how that happened:

Earlier I purchased from hackers a unique access to diversified email accounts (at the moment, it is really easy to do using internet).

As you can see, I managed to log in to your email account without breaking a sweat: (dave@nk.ca).



Within one week afterwards, I installed a Trojan virus in your Operating Systems available on all devices that you utilize for logging in your email.

To be frank, it was somewhat a very easy task (since you were kind enough to open some of links provided in your inbox emails).

I know, you may be thinking now that I'm a genius.



With help of that useful software, I am now able to gain access to all the controllers located in your devices (e.g., video camera, keyboard, microphone and others).

As result, managed to download all your photos, personal data, history of web browsing and other info to my servers without any problems.

Moreover, I now have access to all accounts in your messengers, social networks, emails, contacts list, chat history - you name it.

My Trojan virus continues refreshing its signatures in a non-stop manner (because it is operated by driver),

hence it remains undetected by any antivirus software installed in your PC or device.



So, I guess now you finally understand the reason why I could never be caught until this very letter...



During the process of your personal info compilation, I could not help but notice that you are a huge admirer and regular guest of websites with adult content.

You endure a lot of pleasure while checking out porn websites, watching nasty porn movies and reaching breathtaking orgasms.

Let me be frank with you, it was really hard to resist from recording some of those naughty solo scenes with you in main role and compiling them in special videos

that expose your masturbation sessions, which end with you cumming.



In case if you still have doubts, all I need is to click my mouse and all those nasty videos with you will be shared to friends, colleagues, and relatives of yours.

Moreover, nothing stops me from uploading all that hot content online, so all public can watch it too.

I sincerely hope, you would really not prefer that to happen, keeping in mind all the dirty things you like to watch,

(you certainly know what I mean) it will completely ruin your reputation.



However, don't worry, there is still a way to resolve this:

You need to carry out a $1290 USD transfer to my wallet (equivalent amount in bitcoins depending on exchange rate at the moment of funds transfer),

hence upon receiving the transaction, I will proceed with deleting all the filthy videos with you in main role.

Afterwards, we can forget about this unpleasant accident. Furthermore, I guarantee that all the malicious software will also be erased from your devices and accounts.

Mark my words, I never lie.



That is a great bargain with a low price, I assure you, because I have spent a lot of effort while recording

and tracking down all your activities and dirty deeds during a long period of time.

In case if you have no idea how to buy and transfer bitcoins - feel free to check the related info on the internet.



Here is my bitcoin wallet for your reference: 1Mjt2xobFExdZBGfjTVDcgzJWQxRxoHBdA



>From now on, you have only 48 hours and countdown has started once you opened this very email (in other words, 2 days).



The following list contains things you should definitely abstain from doing or even attempting:

> Abstain from trying to reply this email (since the email is generated inside your inbox alongside with return address).

> Abstain from trying to call or report to police or any other security services. In addition, it's a bad idea if you want to share it with your friends,

hoping they would help. If I happen to find out (knowing my awesome skills, it can be done effortlessly,

because I have all your devices and accounts under my control and unceasing observation) - kinky videos of yours will be share to public the same day.

> Abstain from trying to look for me - that would not lead anywhere either. Cryptocurrency transactions are absolutely anonymous and cannot be tracked.

> Abstain from reinstalling your OS on devices or throwing them away. That would not solve the problem as well,

since all your personal videos are already uploaded and stored at remote servers.



Things you may be confused about:

> That your funds transfer won't be delivered to me.

Chill, I can track down any transactions right away, so upon funds transfer I will receive a notification as well,

since I still control your devices (my trojan virus has ability of controlling all processes remotely, just like TeamViewer).

> That I am going to share your dirty videos after receiving money transfer from you.

Here you need to trust me, because there is absolutely no point to still bother you after receiving money.

Moreover, if I really wanted all those videos would be available to public long time ago!



I believe we can still handle this situation on fair terms!



Here is my last advice to you... in future you better ensure you stay away from this kind of situations!

My advice - don't forget to regularly update your passwords to feel completely secure.



More home depot survey phish

Return-path: <>

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 26 Jun 2022 20:17:00 -0600

Received: from [167.172.45.58] (port=39950 helo=vignobles-jolivet.fr)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

id 1o5eIf-000AW8-HC

for dave@doctor.nl2k.ab.ca;

Sun, 26 Jun 2022 20:16:35 -0600

MIME-Version: 1.0

Message-Id:

From:=?UTF-8?B?WW91J3JlIFNlbGVjdGVk?=

Subject:=?UTF-8?B?Q29uZ3JhdHVsYXRpb25zISBDb21wbGV0ZSBUaGUgU2hvcnQgU3VydmV5Lg==?=

Reply-To: reply_oeqn1O46KYcvHZUgB.bounce9@inx1and1.de

To: dave@doctor.nl2k.ab.ca

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset=UTF-8

Date: Mon, 27 Jun 2022 04:15:59 +0200























































Nigerian Spam from Gmail in German

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 26 Jun 2022 19:48:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5dqD-0007zS-HF

for dave@doctor.nl2k.ab.ca;

Sun, 26 Jun 2022 19:47:05 -0600

Resent-From: The Doctor

Resent-Date: Sun, 26 Jun 2022 19:47:05 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-io1-f46.google.com ([209.85.166.46]:33569)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5cYY-0001AV-Tb

for doctor@doctor.nl2k.ab.ca;

Sun, 26 Jun 2022 18:24:51 -0600

Received: by mail-io1-f46.google.com with SMTP id m13so8117370ioj.0

for ; Sun, 26 Jun 2022 17:24:25 -0700 (PDT)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=gmail.com; s=20210112;

h=mime-version:from:date:message-id:subject:to;

bh=RDQ7E5VZ59L3KbjS73t+9Ymd+9lsWBM26OhY2mqeW70=;

b=YdiyqIy2aOKjQqwydd+b48IlZnFNVc/+aDOQ1tKDwZmXB7MyA9ewFYm7qYAXjEmEs8

cqR1wKprtwSCy5zV9CAhn10kfznryWjB+RjBiaXpn5iREJ6Y+nOOfQkDmtpaY1YIagMJ

1IV4O41gYGbxPX+mwwUu+s2rCfW1qJhpLrNo//QWqnA0TlAV6E+YobItmFtFJu/WWZ08

R1HxuLeulQeYxXQEI5cUPuNASTi/qISkj0nW66Cam1ZxAHfjOcBkcgE3yYODNsftIshW

LxMcuQAbvGGdOx/GJCH7tBX/grlhpFEA1mmjl4++jmzR/8ceTy2ipfF99KVwiBmcT6xZ

Gluw==

X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1e100.net; s=20210112;

h=x-gm-message-state:mime-version:from:date:message-id:subject:to;

bh=RDQ7E5VZ59L3KbjS73t+9Ymd+9lsWBM26OhY2mqeW70=;

b=YgM+x/DK0EW38FWR5QdYnrHmwztk5dSsCLRVEG/h8ePckq1pgpRGveCIsZvkADn1Ks

qKCNPbKKDDLtdOsO+ndj7ROrmzYHpzEjOZwyYx5JEMpfV+70bil/zwjtyZOu7lHhOYf9

7yN+xUo+wf30rLqZC+7fMfx25pEYq/VvMd9KFrMYEAJ7fcPSC7L9QX88UmtvOm6lpIky

WWu3ToCaz4UHT+V5CfjFuZUXRVYgY04Myvqa+yGgH8JbdfAo9EUaah9i4XFjYzqjJmkc

6CXhOwviTWWICXEKyG+GABy0S3Z1ujuNjxMQHu4dtUS3mXx2GxGjtKF1PdiARTMOsgpt

G3Dw==

X-Gm-Message-State: AJIora/OJArVcHanOUpIyvsI959CX52CvaLssMWAcRrez6E0evqGa5QZ

QiqfTGEUuwvzprMOYByMUvnyKBrr2WyNPSHtA/8=

X-Google-Smtp-Source: AGRyM1tka1ESWMYRdoZgHptyqpGvYrxKUPnLfWL5v34I3ENFbjm3ACtGrGqawvanq0qubdv6Q9Di+SAvfCSniTlb1c4=

X-Received: by 2002:a05:6602:258e:b0:675:4648:ad5f with SMTP id

p14-20020a056602258e00b006754648ad5fmr489496ioo.14.1656289460162; Sun, 26 Jun

2022 17:24:20 -0700 (PDT)

MIME-Version: 1.0

From: Sonia kouassi

Date: Mon, 27 Jun 2022 00:24:09 +0000

Message-ID:

Subject: =?UTF-8?B?R3LDvMOfZQ==?=

To: undisclosed-recipients:;

Content-Type: multipart/alternative; boundary="000000000000eb12de05e262f09c"

Bcc: doctor@doctor.nl2k.ab.ca



--000000000000eb12de05e262f09c

Content-Type: text/plain; charset="UTF-8"

Content-Transfer-Encoding: quoted-printable



Gr=C3=BC=C3=9Fe



Ich bin Frau Sonia Kouassi aus Abidjan Elfenbeink=C3=BCste (C=C3=B4te d'Ivo=

ire). Ich

bin ein 22-j=C3=A4hriges M=C3=A4dchen, ein Waisenkind, weil ich keine Elter=

n habe.

Meine Onkel drohen, mich wegen des Erbes zu t=C3=B6ten, das mein Vater f=C3=

=BCr mich

hinterlassen hat US-Dollar) zehn Millionen f=C3=BCnfhunderttausend US-Dolla=

r,

die ich von meinem verstorbenen Vater geerbt habe, aber er hat das Geld auf

ein Fest-/Streukonto bei einer der besten Banken hier in Abidjan eingezahlt=

,

In =C3=9Cbereinstimmung mit der Bank, den Fonds auf ein ausl=C3=A4ndisches =

Bankkonto

f=C3=BCr Investitionen im Ausland zu =C3=BCberweisen, aber er starb, ohne d=

en Fonds

zu =C3=BCberweisen, verwendete mein Vater meinen Namen als ihre einzige Toc=

hter

f=C3=BCr die n=C3=A4chsten Angeh=C3=B6rigen, als er den Fonds einzahlte, un=

d der Fonds

kann nur auf ein ausl=C3=A4ndisches Bankkonto =C3=BCberwiesen werden, alles=

, was ich

brauche, ist Ihre Ehrlichkeit als meine ausl=C3=A4ndische Anleitung, und um=

mir

zu helfen, den Fonds zu investieren, und mir auch zu helfen, meine

Ausbildung in Ihrem Land fortzusetzen

Bitte, wenn Sie voll und ganz damit einverstanden sind, mir zu diesem Zweck

zu helfen, geben Sie bitte Ihr Interesse an, indem Sie mir zur=C3=BCckschre=

iben,

dann werde ich Ihnen die notwendigen Informationen zum weiteren Vorgehen

geben, ich werde Ihnen danach 20 % des Gesamtbetrags f=C3=BCr Ihre Hilfe ge=

ben

die =C3=9Cbertragung, danke f=C3=BCr Ihre Sorge

Deine

Sonja Kuassi



--000000000000eb12de05e262f09c

Content-Type: text/html; charset="UTF-8"

Content-Transfer-Encoding: quoted-printable



Gr=C3=BC=C3=9Fe

Ich bin Frau Sonia Kouassi aus Abid=

jan Elfenbeink=C3=BCste (C=C3=B4te d'Ivoire). Ich bin ein 22-j=C3=A4hri=

ges M=C3=A4dchen, ein Waisenkind, weil ich keine Eltern habe. Meine Onkel d=

rohen, mich wegen des Erbes zu t=C3=B6ten, das mein Vater f=C3=BCr mich hin=

terlassen hat US-Dollar) zehn Millionen f=C3=BCnfhunderttausend US-Dollar, =

die ich von meinem verstorbenen Vater geerbt habe, aber er hat das Geld auf=

ein Fest-/Streukonto bei einer der besten Banken hier in Abidjan eingezahl=

t,
In =C3=9Cbereinstimmung mit der Bank, den Fonds auf ein ausl=C3=A4ndi=

sches Bankkonto f=C3=BCr Investitionen im Ausland zu =C3=BCberweisen, aber =

er starb, ohne den Fonds zu =C3=BCberweisen, verwendete mein Vater meinen N=

amen als ihre einzige Tochter f=C3=BCr die n=C3=A4chsten Angeh=C3=B6rigen, =

als er den Fonds einzahlte, und der Fonds kann nur auf ein ausl=C3=A4ndisch=

es Bankkonto =C3=BCberwiesen werden, alles, was ich brauche, ist Ihre Ehrli=

chkeit als meine ausl=C3=A4ndische Anleitung, und um mir zu helfen, den Fon=

ds zu investieren, und mir auch zu helfen, meine Ausbildung in Ihrem Land f=

ortzusetzen
Bitte, wenn Sie voll und ganz damit einverstanden sind, mir =

zu diesem Zweck zu helfen, geben Sie bitte Ihr Interesse an, indem Sie mir =

zur=C3=BCckschreiben, dann werde ich Ihnen die notwendigen Informationen zu=

m weiteren Vorgehen geben, ich werde Ihnen danach 20 % des Gesamtbetrags f=

=C3=BCr Ihre Hilfe geben die =C3=9Cbertragung, danke f=C3=BCr Ihre Sorge
>Deine
Sonja Kuassi




--000000000000eb12de05e262f09c--

More SEO Spam from Microsoft

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 26 Jun 2022 16:02:02 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5aJg-000E0V-Cu

for dave@doctor.nl2k.ab.ca;

Sun, 26 Jun 2022 16:01:16 -0600

Resent-From: The Doctor

Resent-Date: Sun, 26 Jun 2022 16:01:16 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-sgaapc01olkn2080.outbound.protection.outlook.com ([40.92.53.80]:34017 helo=APC01-SG2-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5XCq-000NN8-NW

for root@nk.ca;

Sun, 26 Jun 2022 12:42:08 -0600

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=RspiK+50dWF6nV/VqgylZXIC9Cc7Jr531WTg+lPBDuzRx3NzF2F3Xo0SVB0241zYaGLkqxl2tJtO+dby1eOki1iswOkTVe8GQsVmtpyPDEawB5P3vhBqa2xhI7bFW7YW5E0vZt5oOOMVG8O+h7AF934lzBChhRfYO2xmv3IXiNIEFwoD5QDPlrG+7yywtUjVBtnnkWKEJruNRT2f6OKGESBBzrY3BG2Erd62z/kF7r8AyoFGoEIUEFhSeLgpzqjsIDqiVwwoe2ylab/IDJn8YQdDKBobZX09aSV46RPd7pPYyZXDqp2jZmYGvmatgMr1ILXSqf7FcyrXShm5iehjkg==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=Br22593OHvH/p9a4h8zzsvHE+8BMpY9axGwaQsiDcIs=;

b=iR8F9KrR/sdKIHo/r5wHeVhIULciiFJD8vo5dXax+7jq3Gu+2QtC98KvC5GxBeEwpzOpXY9rXlADsKsKRXZJ2V+AfOogLWmOKIoM0Q8rIFr8VrhTnStgrO7ZD5Tyx7mQcnSgkTM1VBQ4r24sATrf2iDvpwJbHiczHvQoTgTS0nPhiY2DDBAFjLnc+XGVojJLpGMHkHEXEhLpIULxJXl8Fz07gTWIhLxrC2tR5fa0ggBQWA4in4OKBvBQKULv2vPsb6kfKym11hNWNlC8U0diVu4HFB/a56eGv5hYsAXLhTEyprNpM43BMaVcwEZZRTqkCxuptaujUmzoxP2UgN+Heg==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none;

dkim=none; arc=none

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com;

s=selector1;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=Br22593OHvH/p9a4h8zzsvHE+8BMpY9axGwaQsiDcIs=;

b=Y/kEmOf+u12u3wW7RigiBFj8Wc9kg0Lwjv+dP3r3frTNKpSkF9nP/7l35kSd2gL5dlGWVZX2jdkLv3e1iueihGHlCLdthZioJCLWzQHiblHWQpas36g8W3L3HXHj5FHlG9LiWVvWDVRtZOkwIr2HbMNmU5MJs/wVxB9EwQUdc3b6lTsWJnBM6LPln4R+nZJX0aBsOcwgL9y2YMVSc7B2qpLbbJ13/51deNS4CFuDk61aMQm9wDk+LtpLt/uG1XvcyG0RTaAtw0ndfVaLSUCsnkscnJWxhOORRKusrZWAfF9hBGmA7VCoxtHzgDA1n/U+KAipTRAwkK6eseINhcMnXg==

Received: from KL1PR0401MB5130.apcprd04.prod.outlook.com

(2603:1096:820:91::14) by SG2PR04MB2617.apcprd04.prod.outlook.com

(2603:1096:4:5d::9) with Microsoft SMTP Server (version=TLS1_2,

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5373.18; Sun, 26 Jun

2022 18:40:07 +0000

Received: from KL1PR0401MB5130.apcprd04.prod.outlook.com

([fe80::e477:52fb:e851:341c]) by KL1PR0401MB5130.apcprd04.prod.outlook.com

([fe80::e477:52fb:e851:341c%5]) with mapi id 15.20.5373.018; Sun, 26 Jun 2022

18:40:07 +0000

From: Ankush singh

Subject: Online Marketing Consultant

Thread-Topic: Online Marketing Consultant

Thread-Index: AQHYiYwoqA/PxkL/YEKe1UBzQoJcYA==

Date: Sun, 26 Jun 2022 18:40:06 +0000

Message-ID:



Accept-Language: en-US

Content-Language: en-US

X-MS-Has-Attach:

X-MS-TNEF-Correlator:

msip_labels:

x-tmn: [AUYu8sV+YQHuwKfJNDrGYNKu9zFeNnp9]

x-ms-publictraffictype: Email

x-ms-office365-filtering-correlation-id: a81404d9-921f-4fc3-d765-08da57a34a99

x-ms-exchange-slblob-mailprops:

aZx04qTD+Wi3SIWDkaZwG76tdrFlXMkVoFLwYRQvxipKlQFpDKppBUqlAHIq1IQLVjPBDR4zJ6SqBiSBKBNUW2tLVpwEXO6OVl1+X8dm0se6MRMfoemCJ58pof/A2y18MNXMUiakdFBnavowqv1nPqq0F5OYlbibfJwpRCDd0Dgc5wEnCfTFWrokAeaGZN2cmLpl3TqChcBBmgG+mq/OvIoXZG/w2W6F+sO0p7SdSAHFpyls+HXl90QFbIipBmGW6SWKrB9o17Su0gx4xUD8ioSmJ7wiHqqm1PEAin/DVW6nVg4U9rBAboqm5/nYeBwKRiKLGoAt3QdLJ8ukU4tx7wjXvoq1pd0fkYhDVKlPbcPMn+2+O/0XjSmDpBsgobk37QykoHc/qcCkKv6IuMhFF23VbgTfkJM1AeIcOg4EswZKBwvYy3JPX1BR3xeqnKMvAAKF+VnOh2TogJks+o6E5H52PtSq8iYlOqIEb2CsJNbdRzzYdZPDVlvTBZxwl2/aL5DIro5/SbnboUhMILfngPukk5zOGnAxHWr4LE8reBvIOlt64otGh6YLuTaf8l+I43ZMXErEHpIoN87htV3dZKsOUDuw8MvNSSlfPMAi2TqeM24AUapuWo44QyrKSMMdtDTd9yNZmr0=

x-ms-traffictypediagnostic: SG2PR04MB2617:EE_

x-microsoft-antispam: BCL:0;

x-microsoft-antispam-message-info:

3CL7QFHcpUVbtqUWnjdTN2o8+ecSA8kRoIEvW/aqjuhTkf29wq8d1ssNjJJ9c+DmbJaO21kYg3m2PvmFTdWNbg2zjcAZTthNdZu0vCCWU+GOYupt0kre3HJZ7BpxIQkOoUxlR1e5j+ec0xasX/v4o6bQEj+Ba4PZfXggxTPruA/lAPsPlXmJaRSmQFCAFCesAl+jqmlEX+m82JOZNCmqh30Ilsy4G+8BmOZX7tKhEjWqp6YY1Z4XUKzDVWWG2f2x/cLcedpoHDoZSmQ8ja7QJjKmVBZ6xX/snP4uoHOZ71s9h03F4vtozcGYoVV+SflceFJtMoc3c+WMoG5cHoZJbDX1DkaZBHcnbcKlXpH6KDlRPBzcgh3I2/Lr1ZlAfzirDtiJMhHKPfQY43yaeoidpN4feQudzUal6/3AGN/5gW90NTvvXKnRrIqYwj/ZRY5HfuuiRMiu3T1YUxCzevHwGkpFwZuwJCoDT/4eKqRhBBhawPHIo4we2j5H7uurMunO6V+IVut3bOapdYuuakpRvKZRPtgwhI5nWK/ZN0YuLiX9oqxqkaPSZ/Zd/cPjuv93ZYKOsOT1i2T2Fo7cw7jn7Zx3y1drrJ+etRvvvGAGV8xp8z3bo02Jp1sJGGbTyaIZ

x-ms-exchange-antispam-messagedata-chunkcount: 1

x-ms-exchange-antispam-messagedata-0:

=?Windows-1252?Q?lHKCscuJtnrBpF88pR3k+AAw83507q6QBVQi7zQP44gOkYhiEJl5inKB?=

=?Windows-1252?Q?4UKRdvtafak/RA8RDlZXZEjScvrdTCGBb/WUxhpcCarlOOsCWRR8dj2Q?=

=?Windows-1252?Q?NiqBMFgv8oSs181GZzqvcugIrTesswAdF/hFzca8EXemBfRFtPFwpuAF?=

=?Windows-1252?Q?pLpI5ZHpGWm0sgISxfeiglTlHBRCdvbtqfpJPfhSlt9DKaA5ItaoevE4?=

=?Windows-1252?Q?KcUFm0iz8AH3gqE8Qc8Q/QtSg5qOXMqv8aUGYPywuOZE/mL+b6ZIQp1t?=

=?Windows-1252?Q?T6FlTR/pPRTF1lxTsQXAA1QeYNbMvqwLPxuYg5zZTUWyAEIAJH++xyu4?=

=?Windows-1252?Q?jfehwyj5v7sjdS1lWB5RGAsCaL2jreS3PDdvPC4xB/kWQpVcvqAPOcuK?=

=?Windows-1252?Q?BOQ9IO0pfkaWmVjM0sfnBekYPN/ZuU8OyNSB9PlewjpDkwY4DLxEYyWN?=

=?Windows-1252?Q?eHQkN8PKgakD1eNQ5rHcMr0WgGZeVgYP2ffSua/0meysD+eacCtDGDyo?=

=?Windows-1252?Q?W6731O+oOtu/dwYx5IWrOg//3omMumxZCL9/aMNyfNTiGml03/k4E+BC?=

=?Windows-1252?Q?81+VgQqy9LQHfRYNV6N58Po5TEm/6R6m1qwihExgSqMWivU4vvhhijOx?=

=?Windows-1252?Q?4QSeNsU6y8xGWoOMJWy84KAd/3ieIy1lKbGxC6Fqf+o/CYxSAL4Ve4oQ?=

=?Windows-1252?Q?sEYjpOfPPtBFzKHvU8MyDMcM8cuAGvPEuNRdVbd8EBc7yScwMMia+N3t?=

=?Windows-1252?Q?VVoyNWqQNFw6czJHfUTYaYO8BE7/eEahOQ5O5SL53IOWzjj9DPCGoPsK?=

=?Windows-1252?Q?pKXafIURc911NYqMhrdxVlos7Sy8ycm76YS3m1kajZ9kl3ozOva1w+2D?=

=?Windows-1252?Q?uKSrUhHiE5UOPYucDWu04D+97Fu7Mk6wkkin80uEvEzsWEC7Sebs5/T3?=

=?Windows-1252?Q?8LDv1B6scSIlcK6qEPf0Jl3vhxZp5fcJpD2xG+jz5IGBjnoNHjKBHClj?=

=?Windows-1252?Q?WhyYcUkez/78vToGKb2wr0I07htkwCZ1QuM0UDxeBi+Myae5RK5RJXOt?=

=?Windows-1252?Q?AZlYMboRWbwYBkKvyF+AyParaxRQpfQ3fAy1KrKNvDj9Ov6t8dKgGbJv?=

=?Windows-1252?Q?Dk+zu4ErbRxqi0j1nMeWMjCnkWPpsIZWCquW9wxN+SZ6iSaF9PP960yE?=

=?Windows-1252?Q?vXzaXhoaOvEnlGfOVAwIUbQZvrL2U8Sc+MsFkHAvRraTwF6grKgxcI1q?=

=?Windows-1252?Q?929yr45f3XgVR3SorI71plATuIKxsGLWOXNgmcr3x+f0smu5sk2xCAGs?=

=?Windows-1252?Q?CNSK4RGlCug130RTK1Ojc1my/D34ZR+/0Wkn4wjf2GC2IOwScuJHJfjn?=

=?Windows-1252?Q?xbSsGM1rVJUa2g=3D=3D?=

Content-Type: multipart/alternative;

boundary="_000_KL1PR0401MB5130245AC3E165A77929637BBBB69KL1PR0401MB5130_"

MIME-Version: 1.0

X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-6ea25.templateTenant

X-MS-Exchange-CrossTenant-AuthAs: Internal

X-MS-Exchange-CrossTenant-AuthSource: KL1PR0401MB5130.apcprd04.prod.outlook.com

X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000

X-MS-Exchange-CrossTenant-Network-Message-Id: a81404d9-921f-4fc3-d765-08da57a34a99

X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jun 2022 18:40:06.8759

(UTC)

X-MS-Exchange-CrossTenant-fromentityheader: Hosted

X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa

X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000

X-MS-Exchange-Transport-CrossTenantHeadersStamped: SG2PR04MB2617



--_000_KL1PR0401MB5130245AC3E165A77929637BBBB69KL1PR0401MB5130_

Content-Type: text/plain; charset="Windows-1252"

Content-Transfer-Encoding: quoted-printable



Morning



I hope you're well.



I am Ankush, and I was doing some research on some of your competitors when=

I came across your site;



Looks like you have a solid brand and a well-established company. I ran an =

analysis on your site using one of our software and I have found some areas=

and simple coding issues that are harming your search rankings.



Would you be interested in free initial analysis report and keywords sugges=

tion list with Google page 1 projection? I am more than happy to send it to=

you all I want is the opportunity to discuss how I could help improve the =

profitability and search traffic to your site?



Do let us know. If you are interested to know more about our client=92s tes=

timonials, service methodology and pricing details.



Kind Regards,



Ankush

Business Development Manager





--_000_KL1PR0401MB5130245AC3E165A77929637BBBB69KL1PR0401MB5130_

Content-Type: text/html; charset="Windows-1252"

Content-Transfer-Encoding: quoted-printable








252">








: 12pt; color: rgb(0, 0, 0);" class=3D"elementToProof">


4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

Morning




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

 




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

I hope you're well.
>




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

 




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

I am
, 34, 34)">Ankush
an>
, and I was doing some research on some of your competitors when I c=

ame across your site;




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

 




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

Looks like you have a solid b=

rand and a well-established company. I ran an analysis on your site using o=

ne of our software and I have found some areas and simple coding issues tha=

t are harming your search rankings.




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

 




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

Would you be interested in fr=

ee initial analysis report and keywords suggestion list with Google page 1 =

projection? I am more than happy to send it to you all I want is the opport=

unity to discuss how I could help improve

the profitability and search traffic to your site?




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

 




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

Do let us know. If you are in=

terested to know more about our client=92s testimonials, service methodolog=

y and pricing details.




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

 




4);background-color:rgb(255, 255, 255);line-height:12.65pt;font-size:12pt;f=

ont-family:"Times New Roman", "serif"">

Kind Regards,




r:rgb(34, 34, 34);background-color:rgb(255, 255, 255);font-size:12pt;font-f=

amily:"Times New Roman", "serif"">

Ankush




4);background-color:rgb(255, 255, 255);font-size:12pt;font-family:"Tim=

es New Roman", "serif"">

Business Development Manager<=

/span>














--_000_KL1PR0401MB5130245AC3E165A77929637BBBB69KL1PR0401MB5130_--

More Sexual Blackmail phishing scam coming from Brazil

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 26 Jun 2022 16:02:02 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5aJX-000DzU-PM

for dave@doctor.nl2k.ab.ca;

Sun, 26 Jun 2022 16:01:07 -0600

Resent-From: The Doctor

Resent-Date: Sun, 26 Jun 2022 16:01:07 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from ip-191-5-85-103.isp.valenet.com.br ([191.5.85.103]:31323)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5XI8-000Nrl-ER

for doctor@netknow.ca;

Sun, 26 Jun 2022 12:47:34 -0600

Message-ID:

From:

To:

Subject: There is an overdue payment under your name. Please, settle your debts ASAP!

Date: 26 Jun 2022 11:18:55 -0400

MIME-Version: 1.0

Content-Type: text/plain;

charset="windows-1250"

Content-Transfer-Encoding: 8bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.2565

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2565

X-Spam_score: 17.4

X-Spam_score_int: 174

X-Spam_bar: +++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hi! Sadly, there are some bad news that you are about to hear.

About few months ago I have gained a full access to all devices used by you

for internet browsing. Shortly after, I started recording all int [...]



Content analysis details: (17.4 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in

bl.spamcop.net

[Blocked - see ]

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[191.5.85.103 listed in bb.barracudacentral.org]

2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL

[191.5.85.103 listed in psbl.surriel.com]

1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

0.0 HDR_ORDER_FTSDMCXX_DIRECT Header order similar to spam

(FTSDMCXX/boundary variant) + direct-to-MX

0.0 PDS_BTC_MSGID Bitcoin ID with T_MSGID_NOFQDN2

3.6 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin

0.0 BITCOIN_XPRIO Bitcoin + priority

0.5 PDS_BTC_ID FP reduced Bitcoin ID

3.2 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP

addr 1)

0.0 MIMEOLE_DIRECT_TO_MX MIMEOLE + direct-to-MX

3.1 DOS_OE_TO_MX Delivered direct to MX with OE headers

0.0 NO_FM_NAME_IP_HOSTN No From name + hostname using IP address

Subject: {SPAM?} There is an overdue payment under your name. Please, settle your debts ASAP!



Hi!



Sadly, there are some bad news that you are about to hear.

About few months ago I have gained a full access to all devices used by you for internet browsing.

Shortly after, I started recording all internet activities done by you.



Below is the sequence of events of how that happened:

Earlier I purchased from hackers a unique access to diversified email accounts (at the moment, it is really easy to do using internet).

As you can see, I managed to log in to your email account without breaking a sweat: (doctor@netknow.ca).



Within one week afterwards, I installed a Trojan virus in your Operating Systems available on all devices that you utilize for logging in your email.

To be frank, it was somewhat a very easy task (since you were kind enough to open some of links provided in your inbox emails).

I know, you may be thinking now that I'm a genius.



With help of that useful software, I am now able to gain access to all the controllers located in your devices (e.g., video camera, keyboard, microphone and others).

As result, managed to download all your photos, personal data, history of web browsing and other info to my servers without any problems.

Moreover, I now have access to all accounts in your messengers, social networks, emails, contacts list, chat history - you name it.

My Trojan virus continues refreshing its signatures in a non-stop manner (because it is operated by driver),

hence it remains undetected by any antivirus software installed in your PC or device.



So, I guess now you finally understand the reason why I could never be caught until this very letter...



During the process of your personal info compilation, I could not help but notice that you are a huge admirer and regular guest of websites with adult content.

You endure a lot of pleasure while checking out porn websites, watching nasty porn movies and reaching breathtaking orgasms.

Let me be frank with you, it was really hard to resist from recording some of those naughty solo scenes with you in main role and compiling them in special videos

that expose your masturbation sessions, which end with you cumming.



In case if you still have doubts, all I need is to click my mouse and all those nasty videos with you will be shared to friends, colleagues, and relatives of yours.

Moreover, nothing stops me from uploading all that hot content online, so all public can watch it too.

I sincerely hope, you would really not prefer that to happen, keeping in mind all the dirty things you like to watch,

(you certainly know what I mean) it will completely ruin your reputation.



However, don't worry, there is still a way to resolve this:

You need to carry out a $1290 USD transfer to my wallet (equivalent amount in bitcoins depending on exchange rate at the moment of funds transfer),

hence upon receiving the transaction, I will proceed with deleting all the filthy videos with you in main role.

Afterwards, we can forget about this unpleasant accident. Furthermore, I guarantee that all the malicious software will also be erased from your devices and accounts.

Mark my words, I never lie.



That is a great bargain with a low price, I assure you, because I have spent a lot of effort while recording

and tracking down all your activities and dirty deeds during a long period of time.

In case if you have no idea how to buy and transfer bitcoins - feel free to check the related info on the internet.



Here is my bitcoin wallet for your reference: 1Mjt2xobFExdZBGfjTVDcgzJWQxRxoHBdA



>From now on, you have only 48 hours and countdown has started once you opened this very email (in other words, 2 days).



The following list contains things you should definitely abstain from doing or even attempting:

> Abstain from trying to reply this email (since the email is generated inside your inbox alongside with return address).

> Abstain from trying to call or report to police or any other security services. In addition, it's a bad idea if you want to share it with your friends,

hoping they would help. If I happen to find out (knowing my awesome skills, it can be done effortlessly,

because I have all your devices and accounts under my control and unceasing observation) - kinky videos of yours will be share to public the same day.

> Abstain from trying to look for me - that would not lead anywhere either. Cryptocurrency transactions are absolutely anonymous and cannot be tracked.

> Abstain from reinstalling your OS on devices or throwing them away. That would not solve the problem as well,

since all your personal videos are already uploaded and stored at remote servers.



Things you may be confused about:

> That your funds transfer won't be delivered to me.

Chill, I can track down any transactions right away, so upon funds transfer I will receive a notification as well,

since I still control your devices (my trojan virus has ability of controlling all processes remotely, just like TeamViewer).

> That I am going to share your dirty videos after receiving money transfer from you.

Here you need to trust me, because there is absolutely no point to still bother you after receiving money.

Moreover, if I really wanted all those videos would be available to public long time ago!



I believe we can still handle this situation on fair terms!



Here is my last advice to you... in future you better ensure you stay away from this kind of situations!

My advice - don't forget to regularly update your passwords to feel completely secure.



NetKnow still in the Netcraft's Top 850

All data is from Netcraft Toolbar . Looks as if there are major changes to the Netcraft algorithm!



NetKnow







Netknow now 804 from ranks 839 at Netcraft .




We are now redirecting all traffic to Secured general server which now 804 from ranks 839 and pfs compliant .



A slight increase! We must do
  1. security audits regularly
  2. check on illegitimate traffic hitting the web server
  3. a
  4. keep design current!




Some of our others domains and services ranks as follows:



NetKnow Secure Server

ranks >2000000 from >2000000 Netcraft and pfs compliant .

NetKnow's secondary server

ranks at >2000000 from >2000000 last week on Netcraft and Secured secondary server using the wildcard certificate is at 827 from 629 .

NetKnow's Anonynous FTP server

and non-anonymous must be set to client ports higher than 42000.

www.nl2k.ab.ca

ranks >2000000 from >2000000 on Netcraft.

internetedmonton.ca

ranks at >2000000 from >2000000.

edmontoninternetserviceprovider.ca

is at >2000000 from >2000000 .

edmontonab.ca

ranks > 2000000 from >2000000



How do we compare with other providers in

Edmonton
, Alberta, Canada?



Netknow again





We at Netknow are 804 from 774 since the middle of May 2022.



Rogers





Rogers Business Solutions

which rank 8060 from 8050 and are hosted in Europe.



Telus and reviews





Next we have Telus.com

ranked by Netcraft at 9596 from 9735 .

Sometimes their Web Hosting is done by
title="Internet Names for Business">Internet Names for Business


is ranked by Netcraft at >2000000 from >2000000 .



Is Telus's ADSL network susceptible to Code Red Attacks and Attackers?

Reviews of Telus are available :





Government of Alberta



The Government of Alberta Website

ranks 13150 from 12910 by Netcraft and seems to hosted on Cloudfare.



University of Alberta







The University of Alberta
ranks 34156 from 34294 hosted by Amazon Techonologies.



Juno and NetZero





We have Juno Internet ranked on top

at https://www.juno.com/ 37096 from 36916 who are the owners of

US Based Netzero
at Netcraft Rank 56989 from 55515 .



Shaw Cable





Next,

members.shaw.ca

ranks 778545 from 716391 and retired and

Shaw Cable

is next at Netcraft rank 48219 from 46404 . Hosted now by Akamei .

Their Network Hosting Arm,

Big Pipe is at

Netcraft rank 268976 from 263214 and hosted by Akamai in Europe .



Reviews of Shaw are available :





NAIT / Northern Alberta Institute of Technology



NAIT ranks 81907 from 87921 hosted by Microsoft .



City of Edmonton







The City of Edmonton
ranks 101708 from 101658 by Netcraft and hosted by Google.



Xplornet



xplornet

ranks 119952 from 120925 and are listed with

Stentor and are joining up with Shaw.

According to an article in the Sherwood Park Independent, they are also getting an Alberta Government subsidy.



TekSavvy



TekSavvy ranks 138979 from 136278 and are hosted by Microsoft



Primus



Primus

ranks 216488 from 203568 and now points to BLACKIRON_DataCentres ranked >2000000 from >2000000.



Grant MacEwen University





MacEwan

ranks 284998 from 291328 .



Internet Centre / CCINet



Internet Centre

rank 293548 from 280045 . Their partner Rack Nine ranks > 2000000.



Distributel / 3Web / CIA



Cybersurf

is ranked 415388 from 414952 and seems to be hosted in USA by Microsoft.



Radiant Communications / goco.ca





Radiant Communications

are ranked by Netcraft >2000000 from >2000000 and part of goco.ca

which ranks 1048520 from 1046744 .



Nucleus Internet Services





After that we have

Nucleus Information Services
which can be found at Netcraft Rank 1199446 from 1197195 .



MCSnet





MCSNET ranks 1329947 from 1321657 and are hosted by Microsoft .



Tera Byte Edmonton and reviews





Next is Tera-Byte

at Netcraft Rank >2000000 from >2000000 with

Tera-Byte.ca

ranking >2000000 from >2000000 and their wireless arm Tera-Byte Wireless

sold to Xplornet.

One of Tera-Byte's acquisitions

Edmonton Community Networks

ranks at >2000000 from >2000000 and

Go Edmonton ranks >2000000 from >2000000.

Alberta political blogger Daveberta ranks >2000000 from >2000000; interesting!!!

Reviews of Tera-byte is available at

here

and another here

and check Google for more reviews; just search tera byte.



4Web





4web ranks >2000000 from >2000000 .



Alentus / Wolfpaw





Alentus

rank by Netcraft >2000000 from >2000000 and I note they are hosted in the USA .

wolfpaw.net

which ranks at >2000000 from >2000000



Wiband Wireless





Wiband Wireless

is dead



Yellowpencil





Yellowpencil Ranks >2000000 from >2000000



WSI Corporation





Next is WSI - We Simply The Internet of Toronto

at Netcraft Position >2000000 from >2000000 and are being hosted on Amazon.







Uniserve / Interbaun





Next, Uniserve

ranks on Netcraft >2000000 from >2000000

One of their acquisitions

interbaun

ranks with Netcraft ?????? from ?????? due to merging of sites.

One customer just came over from this organization in Nov 2006.



Clearwave Broadband





Clearwave Broadband ranks

at >2000000 from >2000000



Emergence by Design





Emergence by Design

now ranks >2000000 from >2000000.



Platinum Communications





Platinum Communications Corp.

bought out by Xplornet .



Wild Rose Internet





Wild Rose Internet

ranks >2000000 from >2000000 and I wonder if this is another wireless branch of Tera-Byte and bought out by Xplornet





TIC Internet





TIC Internet

ranks >2000000 from >2000000 ( I do remember you).







Nisa Custom Internet Solutions





Nisa Custom Internet Solutions

ranks >2000000 from >2000000 by Netcraft



MediaShaker





Media Shakers of Edmonton

ranks >2000000 from >2000000





Koi Media





Koi Media

rank >2000000 from >2000000



WebFire





Webfire.ca

ranks >2000000 from >2000000 and seems to be connected with Shaw.



Core Network Solutions Inc.





Core Network Solutions Inc.

ranks at >2000000 from >2000000 .



The Network Centre





The Network Centre

ranks >2000000 from >2000000 and are linked with Telus high Speed.





Open Concept Internet, Inc.





Open Concept Internet, Inc.

rank > 2000000 from > 2000000





InterSpots





Interspots of Edmonton

rank > 2000000 from > 2000000 hosted by Stentor and acquired by Techalta ;



Yegtel





Yegtel rank > 2000000 .



Internet Crossroads





Internet Crossroads Ltd of North Edmonton

rank nothing from nothing by Netcraft and seems to merged with Tera-Byte/ecn.ab.ca .



If I remember anymore, I will add to this entry, before Netcraft changes our ranking. Please watch this space and please feel free to peruse

our services.