Nigerian spam from China

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 17 Sep 2023 05:24:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qhppz-0008Vi-1b

for dave@doctor.nl2k.ab.ca;

Sun, 17 Sep 2023 05:21:15 -0600

Resent-From: The Doctor

Resent-Date: Sun, 17 Sep 2023 05:21:15 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from 59-126-158-195.hinet-ip.hinet.net ([59.126.158.195]:49184 helo=localhost)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.96 (FreeBSD))

id 1qhhic-00008T-0W

for cyrus@nl2k.ab.ca;

Sat, 16 Sep 2023 20:41:09 -0600

Received: from User (unknown [79.110.62.154])

by localhost (Postfix) with ESMTPA id A4CE348621C9;

Sun, 17 Sep 2023 09:58:04 +0800 (CST)

Reply-To:

From: "Mrs. Diana Barbara. Nilsson"<<>>

Subject: Congratulation!!! From World Bank Compensation Fund Program.

Date: Sat, 16 Sep 2023 18:58:16 -0700

MIME-Version: 1.0

Content-Type: text/plain;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

X-Spam_score: 41.6

X-Spam_score_int: 416

X-Spam_bar: +++++++++++++++++++++++++++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Attn: E-mail Owner / Beneficiary. OFFICIAL NOTICE: This is

to inform you that you've been selected by the WORLD BANK COMPENSATION FUND

PROGRAM COMMITTE to receive a compensation funds valued US $6,500,000.00

(Six Million Five Hundred [...]



Content analysis details: (41.6 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.1 MISSING_MID Missing Message-Id: header

0.6 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server

[59.126.158.195 listed in dnsbl.sorbs.net]

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[59.126.158.195 listed in bb.barracudacentral.org]

2.6 FROM_NO_USER From: has no local-part before @ sign

0.0 NSL_RCVD_FROM_USER Received from User

0.0 TVD_RCVD_IP Message was received from an IP address

0.0 FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam

3.6 HELO_LOCALHOST No description available.

0.0 FSL_HELO_NON_FQDN_1 No description available.

0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit

[largemoney01(at)gmail.com]

1.2 MISSING_HEADERS Missing To: header

2.6 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL

[79.110.62.154 listed in zen.spamhaus.org]

3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS

[79.110.62.154 listed in zen.spamhaus.org]

2.5 MILLION_USD BODY: Talks about millions of dollars

1.5 HK_SCAM_N8 BODY: No description available.

2.5 US_DOLLARS_3 BODY: Mentions millions of $ ($NN,NNN,NNN.NN)

0.0 MILLION_HUNDRED BODY: Million "One to Nine" Hundred

0.0 AXB_XMAILER_MIMEOLE_OL_024C2 Yet another X header trait

0.0 LOTS_OF_MONEY Huge... sums of money

0.0 MONEY_NOHTML Lots of money in plain text

0.0 MONEY_FROM_MISSP Lots of money and misspaced From

0.0 FROM_MISSP_XPRIO Misspaced FROM + X-Priority

0.7 HK_SCAM No description available.

1.9 REPLYTO_WITHOUT_TO_CC No description available.

0.0 HK_NAME_MR_MRS No description available.

2.4 MONEY_FREEMAIL_REPTO Lots of money from someone using free email?

0.0 FROM_MISSPACED From: missing whitespace

0.6 FSL_NEW_HELO_USER Spam's using Helo and User

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

0.0 LOTTO_DEPT Claims Department

2.5 TO_NO_BRKTS_MSFT To: misformatted and supposed Microsoft tool

2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook

0.0 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS

2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From

2.0 ADVANCE_FEE_2_NEW_MONEY Advance Fee fraud and lots of money

3.1 MONEY_FRAUD_3 Lots of money and several fraud phrases

Subject: {SPAM?} Congratulation!!! From World Bank Compensation Fund Program.



Attn: E-mail Owner / Beneficiary.



OFFICIAL NOTICE: This is to inform you that you've been selected by the WORLD BANK COMPENSATION FUND PROGRAM COMMITTE to receive a compensation funds valued US $6,500,000.00 (Six Million Five Hundred Thousand United States Dollars) Only. You are among the 100 lucky e-mail owner that was selected for this year World Bank Compensation Fund Program. This selection process usually come up every year and luckily for you, your e-mail address is among the 100 e-mail addresses that was selected for the year 2023.



Your compensation funds valued US$6,500,000.00 (Six Million Five Hundred Thousand United States Dollars) Only from the WORLD BANK COMPENSATION FUND PROGRAM has been signed for immediate pay out to you, but you will have to contact our financial legal officer for further information on how to claim your World Bank Compensation Fund.



Contact details below



Name: Mr. Woodruff Clark. Edmond (Esq).

E-mail: largemoney01@gmail.com



The purpose of this program is to sustain economic growth, and reduce poverty around the world. We have several humanitarian aid programs worldwide, and as we give humanitarian aid to the vulnerable in American's, Africa, Asian and European Countries, we also derive at the conclusion of giving a financial aid to an individual business owner to promote creation of jobs and opportunities worldwide. Note, with this program, we have been able to support a lot of individual to become a Business Owner worldwide.



Kindly contact our financial legal officer on the email address above for your approved World Bank Compensation Fund valued US$6,500,000.00 (Six Million Five Hundred Thousand United States Dollars) Only.



Congratulations to you.



Yours Faithfully.

Mrs. Diana Barbara. Nilsson

World Bank Compensation Fund Committee.

hinet phish involving payment

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 05 Sep 2023 14:15:04 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qdc76-000Lqy-2F

for dave@doctor.nl2k.ab.ca;

Tue, 05 Sep 2023 13:53:28 -0600

Resent-From: The Doctor

Resent-Date: Tue, 5 Sep 2023 13:53:28 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from 60-249-148-149.hinet-ip.hinet.net ([60.249.148.149]:56598 helo=secure.net)

by doctor.nl2k.ab.ca with esmtp (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qdbWG-000MST-0B

for root@mail.nl2k.ab.ca;

Tue, 05 Sep 2023 13:15:31 -0600

From: Adobe_Share_Payment_Doc

To: root@mail.nl2k.ab.ca

Subject: ** VIRUS ***Merchant/Payroll (Invoice) Payment Document Via Adobe share

Date: 06 Sep 2023 03:13:00 +0800

Message-ID: <20230906031300.B1C1D83ABCA4E797@secure.net>

MIME-Version: 1.0

Content-Type: multipart/mixed;

boundary="----=_NextPart_000_0012_E2123A9E.CAC34C29"

X-Spam_score: 5.5

X-Spam_score_int: 55

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: You’re all done. Attached is the final agreement for your

reference. You're required to sign EFT Invoice #7801 Payment Approved- Agreement

Attached is the final agreement for your approved EFT Invoice. The document

is encrypted and attached to your email for your safety.



Content analysis details: (5.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[60.249.148.149 listed in bb.barracudacentral.org]

1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist

[URI: cdn.glitch.me]

0.0 TVD_RCVD_IP Message was received from an IP address

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to

background

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_HTML_ATTACH HTML attachment to bypass scanning?

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

0.0 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS

0.0 FILL_THIS_FORM Fill in a form with personal information

0.0 T_FILL_THIS_FORM_FRAUD_PHISH Answer suspicious question(s)

0.4 FILL_THIS_FORM_FRAUD_PHISH Answer suspicious question(s)

Subject: **
VIRUS ***{SPAM?} Merchant/Payroll (Invoice) Payment Document Via Adobe share

X-Antivirus: AVG (VPS 230905-4, 9/5/2023), Inbound message

X-Antivirus-Status: Infected

X-Attachment: Adobe_Approved_(Invoice)_Payment.html#1246483431 Virus: HTML:Phishing-CJK [Phish] Moved to chest



This is a multi-part message in MIME format.



------=_NextPart_000_0012_E2123A9E.CAC34C29

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable




=3DUTF-8"/>

ss=3D"_xWdq isFirstCard jCu2s" style=3D"PADDING-BOTTOM: 12px; PADDING-TOP: =

0px; PADDING-LEFT: 12px; MARGIN-LEFT: 8px; PADDING-RIGHT: 12px; MARGIN-RIGH=

T: 20px">




dex=3D0 aria-label=3D"Opens Profile Card for Pella Austin" class=3D"undefin=

ed lpc-hoverTarget" data-is-focusable=3D"true" data-lpc-hover-target-id=3D"=

react-target-v2-500">


coin-374">



&=

nbsp;
=




z8y1T GNqVo yxtKT allowTextSelection">














OR: #f0f0f0" cellSpacing=3D16 cellPadding=3D0 border=3D0>












cellSpacing=3D0 cellPadding=3D0 align=3Dcenter border=3D0>





=





















  3D"Adobe
images/emailNextGen/email-adobe-sign-logo.3@2x.png" width=3D165 data-imaget=

ype=3D"External">

R: #ffffff; LINE-HEIGHT: 18px" vAlign=3Dtop width=3D39 align=3Dright>
tyle=3D"DISPLAY: inline-block; BACKGROUND-COLOR: #ff0000" border=3D0 alt=3D=

Adobe src=3D"https://na4.documents.adobe.com/images/emailNextGen/email-adob=

e-tag-classic@2x.png" width=3D39 height=3D64 data-imagetype=3D"External"> <=

/TD>

 











IN-LEFT: auto; DISPLAY: block; MARGIN-RIGHT: auto" alt=3D"" src=3D"https://=

na4.documents.adobe.com/images/emailNextGen/checkmarkCircle@2x.png" data-im=

agetype=3D"External">



f; DISPLAY: none !important; LINE-HEIGHT: 1px; MAX-HEIGHT: 0px; VISIBILITY:=

hidden; opacity: 0">You’re all done. Attached is the final agreement=

for your reference.




GN: center; MARGIN: 0px">You're required to sign

=3Dtrue>EFT Invoice #7801 Payment Approved-  Agreement
>


GN: center; MARGIN: 0px"> 




GN: center; MARGIN: 0px"> 


















 




Attached is the final agreement for your appro=

ved EFT Invoice. The document is encrypted and attached to your email for y=

our safety.



ue>























3D"Powered
4.documents.adobe.com/images/emailNextGen/email-powered-by-adobe-sign-logo.=

3@2x.png" width=3D136 data-imagetype=3D"External">
 


To ensure that you continue receiving our =

emails, please add adobesign@adobesign.com to your address book or safe lis=

t.



© 2022 Adobe. All rights reserved.
>
; BORDER-RIGHT: 0px; BORDER-BOTTOM: 0px; COLOR: #ffffff; BORDER-LEFT: 0px; =

MAX-HEIGHT: 0px; VISIBILITY: hidden; opacity: 0" alt=3D"" src=3D"https://na=

4.documents.adobe.com/track/CBFCIBAA3AAABLblqZhCB1uUYUR8CgHBqPOmnOcTNtFnF9P=

nnh0GOzyn6YBCl8w0p22qLUNcqV0QwA3HxsYg*/blank.gif" data-imagetype=3D"Externa=

l">


V>




 


------=_NextPart_000_0012_E2123A9E.CAC34C29--