Canada Post Phish from virginmediabusiness.co.uk
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 20 Dec 2023 15:28:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))
(envelope-from)
id 1rG4jZ-00000000Eej-2JkA
for dave@doctor.nl2k.ab.ca;
Wed, 20 Dec 2023 15:08:09 -0700
Resent-From: The Doctor
Resent-Date: Wed, 20 Dec 2023 15:08:09 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from 197.152-31-62.static.virginmediabusiness.co.uk ([62.31.152.197]:62205 helo=account.email.com)
by doctor.nl2k.ab.ca with esmtp (Exim 4.97 (FreeBSD))
(envelope-from)
id 1rG1lz-00000000Nbd-3yjc
for doctor@nl2k.ab.ca;
Wed, 20 Dec 2023 11:58:31 -0700
From: Canada Post
To: doctor@nl2k.ab.ca
Subject: Canada Post - Pending Delivery
Date: 20 Dec 2023 18:56:27 +0000
Message-ID: <20231220185627.88FBCD4B32E89CB7@account.email.com>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Spam_score: 8.4
X-Spam_score_int: 84
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Customer, The package sent to you has been delivered
to Canada Post Office and should be delivered withing 48h. Please confirm
the payment (1.99 CAD) on the link below within a maximum of 14 days before
it expi [...]
Content analysis details: (8.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,
https://senderscore.org/blocklistlookup/
[62.31.152.197 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[62.31.152.197 listed in bl.score.senderscore.com]
0.0 TVD_RCVD_IP Message was received from an IP address
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
-0.0 T_SCC_BODY_TEXT_LINE No description available.
0.3 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
Subject: {SPAM?} Canada Post - Pending Delivery
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 20 Dec 2023 15:28:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))
(envelope-from
id 1rG4jZ-00000000Eej-2JkA
for dave@doctor.nl2k.ab.ca;
Wed, 20 Dec 2023 15:08:09 -0700
Resent-From: The Doctor
Resent-Date: Wed, 20 Dec 2023 15:08:09 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from 197.152-31-62.static.virginmediabusiness.co.uk ([62.31.152.197]:62205 helo=account.email.com)
by doctor.nl2k.ab.ca with esmtp (Exim 4.97 (FreeBSD))
(envelope-from
id 1rG1lz-00000000Nbd-3yjc
for doctor@nl2k.ab.ca;
Wed, 20 Dec 2023 11:58:31 -0700
From: Canada Post
To: doctor@nl2k.ab.ca
Subject: Canada Post - Pending Delivery
Date: 20 Dec 2023 18:56:27 +0000
Message-ID: <20231220185627.88FBCD4B32E89CB7@account.email.com>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Spam_score: 8.4
X-Spam_score_int: 84
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Customer, The package sent to you has been delivered
to Canada Post Office and should be delivered withing 48h. Please confirm
the payment (1.99 CAD) on the link below within a maximum of 14 days before
it expi [...]
Content analysis details: (8.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,
https://senderscore.org/blocklistlookup/
[62.31.152.197 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[62.31.152.197 listed in bl.score.senderscore.com]
0.0 TVD_RCVD_IP Message was received from an IP address
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
-0.0 T_SCC_BODY_TEXT_LINE No description available.
0.3 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
Subject: {SPAM?} Canada Post - Pending Delivery