Temu phish from 144.217.195.210 - OVH
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 18 Dec 2023 05:42:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))
(envelope-from
id 1rFCwN-000000006w6-1E3Q
for dave@doctor.nl2k.ab.ca;
Mon, 18 Dec 2023 05:41:47 -0700
Resent-From: The Doctor
Resent-Date: Mon, 18 Dec 2023 05:41:47 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from infiniy-smtp17.lifetimeoretho.info ([144.217.195.210]:33405)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.97 (FreeBSD))
(envelope-from
id 1rFCjd-000000005iy-3BYP
for root@nl2k.ab.ca;
Mon, 18 Dec 2023 05:28:42 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; s=default; d=lifetimeoretho.info;
h=Subject:From:To:Sender:Reply-To:Date:List-Unsubscribe:Message-ID:MIME-Version:Content-Type; i=levis@lifetimeoretho.info;
bh=KnOC/D/ZEmi7Wthxc0vtQml93zI0oWvcIuYk8jWuvs8=;
b=Z+D9HonXbMNutibSHeMZf4e6UoxUN9ZbTtAe5L5ZqiU7LF4UTv0FKIYjdUeA7J7daYH6jgwGGiyT
RbH44G35sa2fn/OCv5tSCBog6dnDpDbcE1/Pdt0eXgvdTx/DeF6lJtmpE90q16IBoBXiGCiVTIwj
CfBAIRi4SA/wv606Gkc=
Subject: We would like to offer you an unique opportunity to receive a Temu Pallets.
From: "Customer Service"
To: root@nl2k.ab.ca
Sender: levis@lifetimeoretho.info
Reply-To: levis@lifetimeoretho.info
Date: 18 Dec 2023 11:38:45 -0000
List-Unsubscribe:
X-CampaignID: s4:69385-42b2cd5de54d01e2
Message-ID:
X-Mailer-Info: 8.hFjM5UDN.YTOzgTN.y92b0BkbsJzauEmYuMWY.xEjNyIDMzcDM.YTOzkDO
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="==04e1e3895d4d5fbf009250bc9f24c1d6"
X-Spam_score: 8.2
X-Spam_score_int: 82
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: TEMU Dear Temu shopper, root@nl2k.ab.ca,
Content analysis details: (8.2 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: lifetimeoretho.info]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: lifetimeoretho.info]
[URI: wwps-ad.lifetimeoretho.info]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or Formatted
Colors in HTML
0.0 HTML_MESSAGE BODY: HTML included in message
-0.0 T_SCC_BODY_TEXT_LINE No description available.
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
Subject: {SPAM?} We would like to offer you an unique opportunity to receive a Temu Pallets.
This is a multi-part message in MIME format.
--==04e1e3895d4d5fbf009250bc9f24c1d6
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
TEMU
Dear Temu shopper,
root@nl2k.ab.ca,
We would like to offer you an unique opportunity to receive a
Temu Pallets.
To claim, simply take this short survey about your experience
with Temu.
Your opinion is very valuable. Click CONTINUE to begin.
CONTINUE ( https://wwps-ad.lifetimeoretho.info/ga/click/2-116220370-12954-3=
5128-69398-40704-893c4fa928-349cf2eb9b )
Attention! This survey offer expires today,
May 3, 2023
Unsubscribe from this mailing list ( https://wwps-ad.lifetimeoretho.info/ga=
/unsubscribe/2-116220370-12954-35128-69398-452488969a185fe-349cf2eb9b )=
--==04e1e3895d4d5fbf009250bc9f24c1d6
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
ft-com:office:office" xmlns:v=3D"urn:schemas-microsoft-com:vml">
ground-color: #ff6600;">
dth: 600px; width: calc(29000% - 179200px); overflow-wrap: break-word; word=
-wrap: break-word; word-break: break-word; background-color: #ff6600;">
: calc(28000% - 167400px); background-color: #ffffff;">
padding-left: 0px;" align=3D"center">
#ff6600;">TEMU
dth: 600px; width: calc(29000% - 179200px); overflow-wrap: break-word; word=
-wrap: break-word; word-break: break-word; background-color: #ffffff;">
: calc(28000% - 167400px); background-color: #ffffff;">
ly: Arial, 'Helvetica Neue', Helvetica, sans-serif; text-align: left;" alig=
n=3D"left">
nter;">
ft;">Dear Temu shopper,
pan>
ly: Arial, 'Helvetica Neue', Helvetica, sans-serif; text-align: left;" alig=
n=3D"left">root@nl2k.ab.ca=
,
ly: Arial, 'Helvetica Neue', Helvetica, sans-serif; text-align: left;" alig=
n=3D"left"> =
div>
ly: Arial, 'Helvetica Neue', Helvetica, sans-serif; text-align: left;" alig=
n=3D"left">
=3D"font-size: 12pt;">We would like to offer you an unique opportunity to r=
eceive a Temu Pallets.
To claim, simply take this sh=
ort survey about your experience with Temu.
=3D"font-size: 12pt; color: #000000;">Your opinion is very valuable. Click =
CONTINUE to begin.
=3D"font-size: 12pt; color: #000000;">
: 10px 20px 10px 20px;" align=3D"left">
; max-width: 250px; width: auto; font-family: Arial, 'Helvetica Neue', Helv=
etica, sans-serif; border: 0px solid transparent; padding: 5px 30px;" align=
=3D"center">
xt-decoration: none;" href=3D"https://wwps-ad.lifetimeoretho.info/ga/click/=
2-116220370-12954-35128-69398-40704-893c4fa928-349cf2eb9b">CONTINUE
an>
y: arial, helvetica, sans-serif; font-size: 12pt;">
ly: Arial, 'Helvetica Neue', Helvetica, sans-serif; text-align: left;" alig=
n=3D"left">
color: #ff0000;">Attention! This survey offer expir=
es today, May 3, 2023
font-family: arial, helvetica, sans-serif;">
width: 600px; width: calc(29000% - 179200px); overflow-wrap: break-word; wo=
rd-wrap: break-word; word-break: break-word; background-color: transparent;=
text-align: center;">
width: 600px; width: calc(29000% - 179200px); overflow-wrap: break-word; wo=
rd-wrap: break-word; word-break: break-word; background-color: transparent;=
text-align: center;">
width: 600px; width: calc(29000% - 179200px); overflow-wrap: break-word; wo=
rd-wrap: break-word; word-break: break-word; background-color: transparent;=
text-align: center;">
yle=3D"color: #ffffff;" href=3D"https://wwps-ad.lifetimeoretho.info/ga/unsu=
bscribe/2-116220370-12954-35128-69398-452488969a185fe-349cf2eb9b">Unsubscri=
be from this mailing list
width: 600px; width: calc(29000% - 179200px); overflow-wrap: break-word; wo=
rd-wrap: break-word; word-break: break-word; background-color: transparent;=
text-align: center;">
font-family: arial, helvetica, sans-serif;">
rial, helvetica, sans-serif;">
, helvetica, sans-serif;">
5128-69398-349cf2eb9b" height=3D"2" width=3D"3" alt=3D"">
=
--==04e1e3895d4d5fbf009250bc9f24c1d6--