Sirius XM Phish from Amazon

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 26 Dec 2023 11:43:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rICOD-00000000KCL-1tgA

for dave@doctor.nl2k.ab.ca;

Tue, 26 Dec 2023 11:42:53 -0700

Resent-From: The Doctor

Resent-Date: Tue, 26 Dec 2023 11:42:53 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from a8-73.smtp-out.amazonses.com ([54.240.8.73]:33347)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

(Exim 4.97 (FreeBSD))

(envelope-from <0100018ca7610bff-8f8b3197-4c54-4983-b69a-4112adeeca20-000000@amazonses.com>)

id 1rICAb-00000000Ihh-2aQm

for root@nk.ca;

Tue, 26 Dec 2023 11:28:53 -0700

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;

s=iumxvzai7h3ln4d7i65v55tz7xp4hs74; d=foxlabs.in; t=1703615204;

h=Subject:From:Reply-To:To:Date:Message-ID:List-ID:List-Unsubscribe:List-Unsubscribe-Post:Content-Type;

bh=nURJbSYOjYkOR9fIDl90pipU2Va3RmVunNwhJeAFmPU=;

b=LwnxCosQjwQBGTlOa/4jm/D76IHU3+8i/G+39mxJKbs9ege4UmqFmW5lEKS8aXmY

wXK3ufw1ERGegIlz5xs56nzr4APYgQZbZ7fekwu8dSGS/g/PAqNzMdI7h9ehKT1aeir

gd4Vqecj4JJGUgI3tGLAjABDF1OHyEymzhg0fNLCyLNLc1fc/gQq4JC/sakhycfQK0o

grvmlwRhkTWOYu41gwbNagDONblTncXFRWhImfrKqFY3ZcUCdn0tN35ryTynNfpIY8Z

QGUjAB0w/tekNU7x7aOsRbLPYYO2clSqP9NLsDuBUtsxt8ZzjSfNt8wR1oTISdNzPrl

IdH0MqGQHA==

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;

s=224i4yxa5dv7c2xz3womw6peuasteono; d=amazonses.com; t=1703615204;

h=Subject:From:Reply-To:To:Date:Message-ID:Feedback-ID:List-ID:List-Unsubscribe:List-Unsubscribe-Post:Content-Type;

bh=nURJbSYOjYkOR9fIDl90pipU2Va3RmVunNwhJeAFmPU=;

b=FL1vllKf+gliauinZSqoyPlRfI55Qy5Jtf0+aZ6RoqDemJhsb1AeUMIzFnbwZc++

HsILAi6haCsbyQzoqNW2FolGhE7CBhWvVo3O/kCPVLsdGua8uF9meA+hA010qTCNRRo

xAzj1zfFFeQH+5pyw7SDP4MJduz4pSegy+a1E/e0=

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=macpacclub.co.nz;

s=k2; t=1702370545; x=1702631045; i=club@macpacclub.co.nz;

bh=MG33lH+CY79L0833Fn7WMiVOuPH1bWfCxhCKRsRyhGI=;

h=Subject:SPECIAL OFFER: Extend your membership for free

List-ID:List-Unsubscribe:List-Unsubscribe-Post:Content-Type:

MIME-Version:CC:Date:Tue, 26 Dec 2023 13:26:43 -0500

b=WgP1KUJeaUgrOkiymoZOvwBMLYFEY2v8RAr8j2IQ54ZwEEY68klLN38mqqFQ0Po7R

4lpTtv7jGI7oLtTwBQTFh1aOuHpA/mIxeOVnasPt3kQ5CeohPOn5q3lLnYZPeLCOHR

TmDYIm8juN9fgqzJ9Sc0LL37b1eSaq/p9rftmUlfLgGVCZx0fC3a2+MguUiyHr9Ov6

jVs0dxoY0x13SLlLAYqI9nPjUFcXlGqQ/lv6Hhl2Q+HNHSUTG4bP/GPGdlDvr3OybD

oxDTSGb7ri7v99U5IW3+jh8hvBZANBM7hJH5BNKQUWrv1Bpq4NgINQz0FeMOOJ6M0S

lSo9lNHMvJRxg==

Subject:SPECIAL OFFER: Extend your membership for free

From: SiriusXM_

Reply-To: root@nk.ca

To: root@nk.ca

Date: Tue, 26 Dec 2023 18:26:44 +0000

Message-ID: <0100018ca7610bff-8f8b3197-4c54-4983-b69a-4112adeeca20-000000@email.amazonses.com>

X-Mailer: Mailchimp Mailer - **CID7497ea0e6aed9fb56518**

X-Campaign: mailchimpe6a11f6e800e39b4814219c1e.7497ea0e6a

X-campaignid: mailchimpe6a11f6e800e39b4814219c1e.7497ea0e6a

X-Report-Abuse: Please report abuse for this campaign here: https://mailchimp.com/contact/abuse/?u=e6a11f6e800e39b4814219c1e&id=7497ea0e6a&e=ed9fb56518

X-MC-User: e6a11f6e800e39b4814219c1e

Feedback-ID: 1.us-east-1.4vz5eWi3mu8p3ejxSXq5bqW4hRrKTuBrAoonK+dzQNI=:AmazonSES

List-ID: e6a11f6e800e39b4814219c1emc list

X-Accounttype: pr

List-Unsubscribe: ,

List-Unsubscribe-Post: List-Unsubscribe=One-Click

Content-Type: multipart/alternative; boundary="_----------=_MCPart_1888620651"

X-SES-Outgoing: 2023.12.26-54.240.8.73

X-Spam_score: 5.8

X-Spam_score_int: 58

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: --

--




Content analysis details: (5.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[54.240.8.73 listed in list.dnswl.org]

-1.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5)

[54.240.8.73 listed in wl.mailspike.net]

-0.0 SPF_PASS SPF: sender matches SPF record

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from

envelope-from domain

-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's

domain

-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders

0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail

domains are different

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words

0.7 MPART_ALT_DIFF BODY: HTML and text parts are different

0.0 HTML_MESSAGE BODY: HTML included in message

0.8 HTML_IMAGE_RATIO_02 BODY: HTML has a low ratio of text to image area

2.0 MIME_HEADER_CTYPE_ONLY 'Content-Type' found without required MIME

headers

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image

2.5 HDRS_MISSP Misspaced headers

Subject: {SPAM?} SPECIAL OFFER: Extend your membership for free

X-Antivirus: AVG (VPS 231226-2, 12/26/2023), Inbound message

X-Antivirus-Status: Clean







--_----------=_MCPart_1888620651

Content-Type: text/plain; charset="utf-8"

Content-Transfer-Encoding: quoted-printable



--
49RaeSn32M>=0A--
Wc2t46TxJKJ2NqcxcvzGKOCN>=0A-
xkCw2konj>-=0A-
s3ZhdCewblfN9dgHUzgeCtQ>-=0A
J2Hcyci4>--=0A
2fUAbMJrCQEzjT6dWwPJPh>--
Nmlyn>=0A--
KU1RcJBDXr4GTuXexmE>=0A-
JFqf>-=0A-
iOw2NRuN4qSHfjgTxa>-=0A
OP0>--=0A
uH3B2fWDu8Xra2WVr>--
>=0A--
7UtuxtskT89aT6>



--_----------=_MCPart_1888620651

Content-Type: text/html; charset="utf-8"

Content-Transfer-Encoding: 8bit





"SPECIAL OFFER: Extend your membership for free"


--

--

--

--

--

--

--

--

--

--

--

--





--_----------=_MCPart_1888620651--

Nigerian PHish from Messagelabs

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 11:35:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHpn0-000000001u4-1Dv1

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 11:34:58 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 11:34:58 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail1.bemta34.messagelabs.com ([195.245.231.2]:40506)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHnsy-00000000HGm-2xOx

for doctor@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 09:33:03 -0700

X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrGKsWRWlGSWpSXmKPExsVibNLVrmu3rjP

VYOEZUYs7t5+xWsxuOcFu8ffubRaLDWt/Mlt8nLSWzaJ/9w5Wi8XXbjBbXG5YxGjx5dJTZiC3

n8Xi4cRXjBaHXylbXNnQzWJx/HQLs8XrQ++ZLO5OOMti8eTwMRaL6Ve2M1rcfB9n8fvVEzYHE

Y8VrSeZPPad/cDi8eIIkFjfvYPV42zHQyaPrtYlLB7fZ1xk8Zg6+ymjx71zU5g8GrpfsHp8bM

3y2LRxKaPHsSV9rB6T1j9i9ri76S+7x9Zj15kCRKJYM/OS8isSWDNO/P/EUvCQseLOjlbmBsY

djF2MXBxCAt8YJc68X8gE4RxklNj05j17FyMnB7OAnsSNqVPYQGxeAUGJkzOfsEDEtSWWLXzN

3MXIAWSrSXztKgEJCwsoScy9/J4JxBYRkJZYen4dmM0moCDRvGcl2EgWAVWJiW8fgdlCAioSS

2f0M0OM95Nov3aLESIuLrHq4T2WCYy8s5BcMQvJFbOQXDEL4YoFjCyrGE2LU4vKUot0zfSSij

LTM0pyEzNz9BKrdBP1Ukt1y1OLS3SN9BLLi/VSi4v1iitzk3NS9PJSSzYxAqM6pVj5wg7GJ98

b9A8xSnIwKYnyvv/ZkSrEl5SfUpmRWJwRX1Sak1p8iFGPg0PgwtmHnxgFrnz41MQkxZKXn5eq

JMFbsaYzVUiwKDU9tSItMweYhGAaJDh4lER4FZKA0rzFBYm5xZnpEKlTjMYc23fu38vM8fnQl

b3MQmCTpMR5r4BMEgApzSjNgxsES46XGGWlhHkZGRgYhHgKUotyM0tQ5V8xinMwKgnzfloNNI

UnM68Ebt8roFOYgE7596UD5JSSRISUVANTd5dusPBBpS0r1KYe3dp4/YKKPtOSUDvGX411O/a

78W34+rD5zyQbcVktBnaeg4GNNsun6D64dWbR7aB7zHe+HCtsY42xYow8VdHnu9tke+83t5R3

105Y9prv6E+9uScrtDD6fvkqzvf7rxhPbFp+wdGz01t23/lZbQzTw588/DbNpOjjusrADXbJ8

k3qs+LeMtvrqjTdurS1Vp/LNvGthnDHiVMfJY5+tdhjpXD+cbLt7Y2PshzuT+g51br8qVF2TK

c4+0qOfW0s3kfYMi9eLjw8xX+j9/8HoQw+m6JqjJ6Y3Ww7yb8t33H7ujrPy0p220SOOixcdOt

d4O6dc1zOtlnbeHBOil5yK0BOhD9PiaU4I9FQi7moOBEAkEPh7wkEAAA=

X-Env-Sender: PM@usa.com

X-Msg-Ref: server-6.tower-565.messagelabs.com!1703521851!87671!11

X-Originating-IP: [51.52.138.135]

X-SYMC-ESS-Client-Auth: outbound-route-from=fail

X-StarScan-Received:

X-StarScan-Version: 9.110.1; banners=-,-,-

X-VirusChecked: Checked

Received: (qmail 22291 invoked from network); 25 Dec 2023 16:30:54 -0000

Received: from unknown (HELO Corp-Exch-02.globalcoal.com) (51.52.138.135)

by server-6.tower-565.messagelabs.com with ECDHE-RSA-AES256-SHA384 encrypted SMTP; 25 Dec 2023 16:30:54 -0000

Received: from Colo-Exch-02.globalcoal.com (10.2.1.189) by

Corp-Exch-02.globalcoal.com (10.2.1.185) with Microsoft SMTP Server

(version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id

15.1.2176.14; Mon, 25 Dec 2023 16:28:28 +0000

Received: from [194.33.191.109] (194.33.191.109) by

Colo-Exch-02.globalcoal.com (10.2.1.189) with Microsoft SMTP Server id

15.1.2507.34 via Frontend Transport; Mon, 25 Dec 2023 16:28:27 +0000

Content-Type: text/plain; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body

Subject: COMPLIMENT OF THE SEASON.

To: Recipients

From: Precious Mpho

Date: Mon, 25 Dec 2023 18:28:58 -0800

Reply-To:

Message-ID:

X-Spam_score: 14.0

X-Spam_score_int: 140

X-Spam_bar: ++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hello, Write Mr. Grenville through this email (fredgrenville@aliyun.com)

and ask him for your draft of (3,750.000 USD) It is for your past effort.

I am now out of USA for investment in Iceland



Content analysis details: (14.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.6 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server

[194.33.191.109 listed in dnsbl.sorbs.net]

2.6 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL

[194.33.191.109 listed in zen.spamhaus.org]

3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS

[194.33.191.109 listed in zen.spamhaus.org]

1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[195.245.231.2 listed in list.dnswl.org]

1.6 SUBJ_ALL_CAPS Subject is all capitals

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[pm(at)usa.com]

0.0 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[195.245.231.2 listed in wl.mailspike.net]

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 LOTS_OF_MONEY Huge... sums of money

1.4 MONEY_NOHTML Lots of money in plain text

1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different

freemails

1.4 MONEY_FREEMAIL_REPTO Lots of money from someone using free email?

1.0 SPOOFED_FREEM_REPTO_CHN Forged freemail sender with Chinese freemail

reply-to

0.0 SPOOFED_FREEM_REPTO Forged freemail sender with freemail reply-to

Subject: {SPAM?} COMPLIMENT OF THE SEASON.

X-Antivirus: AVG (VPS 231225-6, 12/25/2023), Inbound message

X-Antivirus-Status: Clean



Hello,



Write Mr. Grenville through this email (fredgrenville@aliyun.com) and ask h=

im for your draft of (3,750.000 USD)



It is for your past effort. I am now out of USA for investment in Iceland



Regards,

Mrs. Precious Mph

Fedex phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 20:38:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHyGB-00000000Nxy-3enS

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 20:37:39 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 20:37:39 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-mw2nam12rlnn2042.outbound.protection.outlook.com ([40.95.45.42]:56545 helo=NAM12-MW2-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

id 1rHwiz-00000000BTb-0f1i

for doctor@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 18:59:21 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=IyWd3qJE7rzPPPacy+hx4Dp71JnhZZlzhgB7ABikqcV7ByKkiYoO46u1m0SJTXu19A2C/pebK0zZj4VLctTGvPINgvOL0uBBdAdhuKgMVSsO5WOA7Uu7jQeVMFF49SuYpDKaHEWtYQWH3LI1aIBpiRu3vKAxNNx5yAo8aERMFnYqCp69BMjVyqbxeMgubhkx42jXXyPoFNapltduMIYyMLNklsyg+gDO61ghfmfa8vwCUhlpgVfD6Zy6fnAzwHIBRDsfa+UTTiLxjZve/60gBSktdrWr/2atMQpkVVSCc//A748V9hHaHS+w/hfwi6b74u6iGIxDOOgjx6acK6i5eQ==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=9pYJNLQbb2WSMdqZJGsZfIpL3UANBtAaMHK4fG4wyA8=;

b=ePMTTfHmd7oVMiVcQvbqOaHgyWJHk9mlC5eex5kE4bSJ+7OjFrQ7je3vggvifGzunmTZ/eYCIZg9niZMOIlgN3nh5X1KY+VoAn49wTxeN03FjL53CfH2cbNjyffmolfhHGCQsVa+YkIlmlyOgubjj5F9Z6zYM3pzvRMIxoTqhYTNsmUg1b+nbvgY+g3s32qIgjkIa429Gg9Yj9/VCSoTwhAl8ySSYhFlXtrd7qrJ77iqSRQzX5iau8tC5DlhQD4z9YaowFK7Im6feYktuQ5aJHGqvON999UeiH6RriKecHCvcRswZOfVC0lYZztsaKArr+KR3XYXVNb7glySRQ3elA==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none (sender ip is

78.46.149.17) smtp.rcpttodomain=doctor.nl2k.ab.ca smtp.helo=mail.goldner.net;

dmarc=none action=none header.from=fnh.q0a8bjy.com; dkim=none (message not

signed); arc=none (0)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1r78099.onmicrosoft.com; s=selector1-1r78099-onmicrosoft-com;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=9pYJNLQbb2WSMdqZJGsZfIpL3UANBtAaMHK4fG4wyA8=;

b=qZSmr4OavZVV/v1ieBbhnPz1ODWrHAunYFdYIPT5ACY0iMosPj54AYvEHt3CptZ75P0ldHSbhcMxkTNCIb80SfZnqOGTengcb6hn0+Onls6niuI+WatFmUAiQFkTouRV0GAZg55c6IwKscEnR/Sb1UPj+PMEW/Op8xLvD1EV8JD1FPwUeOQ4OyHT4cWttFBQvFir3aX/1ROVgGKK9ZQ5hMLft78+/3TkgM3s6cIPJ5rt422C0qcu9ThIpb3DoY2odsPb5I/Swwg7FkgYH6rKBIqw7zJU8AjdCavTpPzJnwVN6x7NlqU/g2Hh2wlpyQJfYTCYodlDAFaVt6wOWQFy2g==

X-MS-Exchange-Authentication-Results: spf=none (sender IP is 78.46.149.17)

smtp.helo=mail.goldner.net; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=fNh.q0A8bJy.com;

Subject: Your Delivery: Tracking Information and More

From: Fedex

MIME-Version: 1.0

Date: Tue, 26 Dec 2023 02:48:21 +0100

Importance: high

X-TOI-MSGID: <1200938992.4FED7243399A4.1703555301764@goldner.net>

To: doctor@doctor.nl2k.ab.ca

CC: doctor@doctor.nl2k.ab.ca

In-Reply-To:

Content-Type: text/html; charset="UTF-8"

Content-Transfer-Encoding: 7bit

Message-ID:

<9c441263-823d-4982-8569-5ae622d88834@CO1PEPF000044FA.namprd21.prod.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: CO1PEPF000044FA:EE_|LV3P222MB0937:EE_

X-MS-Office365-Filtering-Correlation-Id: 5ec87d09-5d6e-4808-1c89-08dc05b5f914

X-MS-Exchange-SenderADCheck: 2

X-MS-Exchange-AntiSpam-Relay: 1

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

XuV2lWGmfPej2RDBugowGrvRl6lhkTznynZIMX3fFCKDsUBMC+HzyS1Hw6CnMLCt91kQ9UYKz6lWgmxaNDwdZXw/BmZzTwRoGqhSsYr36/osbzlVt9TH8lxAcgfgvudSVUhWkT1dHtvQwn4hUV8O/PNDxiNX9e8s9oaIvLZMdhn//NslGgKHdfSmEfpWdv1gr3Y7qOR5OsmXL9FYEbV5l0qx1BDMOyDT+yf30+DY2waWNOjeNg84/87HKxvGUPHe/P+95cFJB9S7ed8EST52CrrCyTwwgveFDeEM6wLG46LW9YMtjQF3gw5I3my9FFZASUO5fdMcgUS4ijZJ3JN20KW/1PfZz+UfwCa9JGoXXe4GvXM0BvPNWeA2QL/wmhxP/wBoJZcFsDQBXr6SoTvbSntc1pMqsLsAWiLY3gPQKBWDwzaO1Hkzlb16dMX/LWfDTwJI8Ucs9J9pNgK3r0nz01Dx6FMUx2ciebOucO3AUUjVCr5rKB5qnJpSEmea+Mjug0FJIND4lXYdZHG1h3VjwdkzWzuTfGQwkRUvr/r1YSE=

X-Forefront-Antispam-Report:

CIP:78.46.149.17;CTRY:DE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.goldner.net;PTR:static.17.149.46.78.clients.your-server.de;CAT:NONE;SFS:(13230031)(346002)(136003)(396003)(376002)(39860400002)(230922051799003)(1690799017)(451199024)(7200799017)(64100799003)(82310400011)(61400799012)(48200799006)(46966006)(9686003)(336012)(26005)(42882007)(47076005)(35950700001)(67280400001)(4326008)(41300700001)(19625305002)(5660300002)(2906002)(10290500003)(8676002)(508600001)(42186006)(8936002)(6916009)(786003)(316002)(78352004)(70586007)(70206006)(41320700001)(558084003)(81166007)(82740400003)(166002)(31696002)(40480700001)(8400799017)(52070400007)(42472002)(38122002);DIR:OUT;SFP:1022;

X-OriginatorOrg: 1r78099.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Dec 2023 01:57:10.2394

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 5ec87d09-5d6e-4808-1c89-08dc05b5f914

X-MS-Exchange-CrossTenant-Id: d2ae39a8-0ef3-4185-90be-c73d99c9fb7f

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=d2ae39a8-0ef3-4185-90be-c73d99c9fb7f;Ip=[78.46.149.17];Helo=[mail.goldner.net]

X-MS-Exchange-CrossTenant-AuthSource:

CO1PEPF000044FA.namprd21.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: LV3P222MB0937

X-Spam_score: 7.6

X-Spam_score_int: 76

X-Spam_bar: +++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: (1) Notifications



Content analysis details: (7.6 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[40.95.45.42 listed in list.dnswl.org]

0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=NAM12-MW2-obe.outbound.protection.outlook.com;ip=40.95.45.42;r=doctor.nl2k.ab.ca]

0.8 DKIM_ADSP_NXDOMAIN No valid author signature and domain not in DNS

0.0 ARC_SIGNED Message has a ARC signature

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

0.0 ARC_VALID Message has a valid ARC signature

0.1 DKIM_INVALID DKIM or DK signature exists, but is not valid

1.0 HK_RANDOM_FROM From username looks random

0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

2.0 PDS_HELO_SPF_FAIL High profile HELO that fails SPF

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_REMOTE_IMAGE Message contains an external image

0.7 BODY_URI_ONLY Message body is only a URI in one line of text or for

an image

Subject: {SPAM?} Your Delivery: Tracking Information and More

X-Antivirus: AVG (VPS 231225-6, 12/25/2023), Inbound message

X-Antivirus-Status: Clean









(1) Notifications










































































































Fedex phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 20:38:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHyFm-00000000Nwn-3kii

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 20:37:14 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 20:37:14 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-bn7nam10hn2243.outbound.protection.outlook.com ([52.100.155.243]:41696 helo=NAM10-BN7-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHvnH-00000000A74-1vI9

for doctor@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 17:59:44 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=RXT20panvKKOPEqKq4/e+QLlEsiHpjCC+XDrsW5Kte/OHdVx1lItTj3Lv8A+WR1bbS4YUMjI8COxReV0TJkv/5o8q2oMLGM8WmGmIIQY/llsCWiHoQcoFZhjt2mNkciSOq0h6wJNyvDHDGb40aHTO819z5D7I97YOijsO49VXIWoGZhjfiLtE99T1uLq13vZWaWcfNCNoYFhBUmvU3IlrWJeG4XJPTV+6vH89HDCqu3wK4LGhNysvwZDrvfn8nNl9YAajcoyJz/uKduMnNcjmqNdz42XTqz9rkHBtRQCDgrj3i6zscbwH/VFsyQG/7G7ZtINBHDDxw1nlZLtruLG9w==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=ZoVq+EKvLQytwwGKE8t9PGBR4Gat2tzvKcS/KW4EiJU=;

b=MqbH/tsyoOJNwo/0SkJW4pGyU3tQQ30kkQ2+ZmtqSZhZPoci2p9x5/n7rnT32Vx/trBBPDEz+DT3u8AyL5SS9BLIYfhvOHbiJmxenXNnSUfw7PVkg1NStefQh3SWs+bMH0IpOEUEJ/6NIJxdE5LY6gqqUuJXl+iGkPNy3yJZp8IdrhyactZofkIcSro5Z9WOOjw3voG+Lbc+aw+H4xyz/E7DU7kHVOkCHcXkscACS2OuRVm4E0+Wo7v30vb8R/D32xGoLCwrvS2rRu+C4Zx766iHDVf47JirPdfuX8Rdz02m84voMAjExYahm/cuMfzQtW4/apO9VRAP5XXMJjGt1Q==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

116.203.114.137) smtp.rcpttodomain=doctor.nl2k.ab.ca

smtp.mailfrom=or01ms.onmicrosoft.com; dmarc=none action=none

header.from=or01ms.onmicrosoft.com; dkim=none (message not signed); arc=none

(0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 116.203.114.137)

smtp.mailfrom=OR01MS.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=OR01MS.onmicrosoft.com;

X-TOI-MSGID: <1332766177.895AF7183ECEA.1703551724065@beatty.com>

CC: doctor@doctor.nl2k.ab.ca

MIME-Version: 1.0

Date: Tue, 26 Dec 2023 01:48:44 +0100

From: Fedex Shipment

To: doctor@doctor.nl2k.ab.ca

Content-Type: multipart/alternative; charset="UTF-8";boundary="PART_FMVw.rgjstnwz"

In-Reply-To:

Importance: high

Subject: Important Shipment Update: Your Delivery Progress

Message-ID:

<7ab8ceb4-9c23-45ea-b999-bfd5c42a5404@BN8NAM12FT093.eop-nam12.prod.protection.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: BN8NAM12FT093:EE_|SN4PR18MB4933:EE_

X-MS-Office365-Filtering-Correlation-Id: b1e617fa-5fc0-4e65-eb6c-08dc05ada494

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

/1GpzC/7KadwGIZtf+WitiTscAXEuu6d8wadowcd9lSlmHcAtqI8zEvKc5PYIIybtgJNH3s+zcKxEeZKhj9I9jtJildn8c3lDEYtdtxCALkkOqbxdryan9avNite3MFlFz2B8Unkd7B956GOEkZQ3yn9h2rs4BBdRdmD5mBHTNsQDdNQnRVklBc4cPOs9prSFT25JnS2WHh5eszCfOcI7QscfHnswum1gwxX/ivPAoF52zEQkIxuwPalbwNu8xGyYzzzKBD6HzHrSafMxr4KLhbPDFT7J/lO1QhFLP5KN8WkDmt4fETQVRFjLAb+ByOUIu7VuABaVrWdmT5CNc3cqWM1LIHxg4tGrvY+5+5z/46FuYIGXwtW8k+ddQF4NrvcwZQpp7l2jrfmrHLya+AzFcFLSVa0Nfj+FPVL2iUcxLWycXXlOWg+Qnzfua25+RF6qlGnS5A9cpQ9z3znYW9AJEOv7GES8G1ES+VwCAL5SO9Y8igVtfDMX0L9SZJp1eeW+VjsjFO7DbTOq85Ktkzw6g==

X-Forefront-Antispam-Report:

CIP:116.203.114.137;CTRY:DE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.beatty.com;PTR:static.137.114.203.116.clients.your-server.de;CAT:NONE;SFS:(13230031)(136003)(396003)(346002)(376002)(39860400002)(230922051799003)(61400799012)(82310400011)(451199024)(7200799017)(1690799017)(64100799003)(186009)(40470700004)(46966006)(36840700001)(8400799017)(40480700001)(31686004)(26005)(336012)(40460700003)(32880700267)(31696002)(41320700001)(564344004)(82740400003)(81166007)(166002)(47076005)(8676002)(4326008)(5660300002)(19625305002)(9686003)(33964004)(36860700001)(34020700004)(786003)(478600001)(70206006)(42186006)(6916009)(70586007)(316002)(41300700001)(2906002)(10290500003)(8936002);DIR:OUT;SFP:1501;

X-OriginatorOrg: OR01MS.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Dec 2023 00:57:32.6284

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: b1e617fa-5fc0-4e65-eb6c-08dc05ada494

X-MS-Exchange-CrossTenant-Id: a01d98f8-0352-4b0b-8366-03de14849325

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a01d98f8-0352-4b0b-8366-03de14849325;Ip=[116.203.114.137];Helo=[mail.beatty.com]

X-MS-Exchange-CrossTenant-AuthSource:

BN8NAM12FT093.eop-nam12.prod.protection.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN4PR18MB4933

X-Antivirus: AVG (VPS 231225-6, 12/25/2023), Inbound message

X-Antivirus-Status: Clean



--PART_FMVw.rgjstnwz

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset="UTF-8"











(5844) Notifications For YOU










































































































--PART_FMVw.rgjstnwz--

Fedex phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 20:35:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHyDK-00000000JJu-3EeG

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 20:34:42 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 20:34:42 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-vi1eur02on2075.outbound.protection.outlook.com ([40.107.241.75]:3009 helo=EUR02-VI1-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHsZl-00000000F96-0glU

for doctor@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 14:33:33 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=koz6FP5+HvyFdSWKHlSpeVBREGkkNYlrKRd7GpLL2vGeJL5XRsxkU3sRNGHrVhyLatIzHYbo2+G5b7ZGXJ9YlYzxsEuQtuV7dsrUSnhJNSBQ03cU1iy86AaqgaFNG2DnEJxwPSyIgNIi6eHJnPkxb9aMrc8RwM8jazVB/Xdo+2xj07QVJ8T1K3dSYqWI+t7KhIf3XE5HQP5rv27+bFhNbg7TeKT+v9z6CdC6P4zjrbMAHH7JLKxV2rPNpecyUrmQ3LIMnD1Tzihtdu+dg8MB9jA+70OQi7fBmHCOkFnBR0h1TZJ26ObpYQ17ZDHsGqapJtbe/QGTJ2cu6dTYCnldug==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=x36O24XqDykl2r/X//DPlFF0FjBYKhJk5pntPLC8ck8=;

b=B3mMKNA6LXp4zXaRFJYvBDOW8yoNE//eyNpoE6iUEXRIRNygY9qaXPiMO/XtcugiBfK5BTgi8uDrJpfJxdScSek9wtYa12IAggHOUuwjVXGoOuz+QzfnmkdK7vj0vaxBUVCXZz/6QYjeUPjoAuFBtbGFHQ5yIHT48RFpyX3+rsg1hBv88Iuo0qQVPTf0Mac2amvcTm1czAwKjseHMOWJuyUmL05An/NmpGbNyivPUCLaHHyb4nS6UimuoNQmY5QvhgB7Mf0fK4QNzyj4wa8hoX1zMMT3yPKSgqJaR6dUqxCASu3fDNPhKLr4AdFySX4pGCQAsXIhbHVF0WhN3L2H1w==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

198.58.103.69) smtp.rcpttodomain=doctor.nl2k.ab.ca

smtp.mailfrom=exlzbuch.onmicrosoft.com; dmarc=none action=none

header.from=exlzbuch.onmicrosoft.com; dkim=none (message not signed);

arc=none (0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 198.58.103.69)

smtp.mailfrom=exlzbuch.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=exlzbuch.onmicrosoft.com;

Received-SPF: Fail (protection.outlook.com: domain of exlzbuch.onmicrosoft.com

does not designate 198.58.103.69 as permitted sender)

receiver=protection.outlook.com; client-ip=198.58.103.69;

helo=mail.legros.com;

Content-Type: multipart/alternative; charset="UTF-8";boundary="PART.VfTr.ztujdqpg"

Subject: Important for doctor

To: doctor@doctor.nl2k.ab.ca

MIME-Version: 1.0

X-TOI-MSGID: <109030220.E9CD72F3EA47C.1703536740944@legros.com>

In-Reply-To: <6sT1vIPeSejl32qTklOFUl4XcJ1mxcqcKECyIaSJ@gJBiM.exlzbuch.onmicrosoft.com>

Date: Mon, 25 Dec 2023 21:39:00 +0100

Importance: high

CC: doctor@doctor.nl2k.ab.ca

From: =?UTF-8?B?U2hpcHBpbmcgRGVwYXJ0bWVudA==?=

Message-ID:

<8afca768-eefb-49c5-b2af-14e20a8011d3@AM3PEPF0000A792.eurprd04.prod.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: AM3PEPF0000A792:EE_|AS4PR06MB8469:EE_

X-MS-Office365-Filtering-Correlation-Id: 6b21ded7-6c23-48ff-7b6d-08dc0590d6fb

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

lIkT8D8VuYP4HRtHv4g/HqRHU25wrYu8DsitfGVJVt1Zl/5D6Bg1Fwy5Q+lv+LFx3jukg8aMQQdwtVOmMO5SYtNIkc26I5pHe2CoG/SeI5DiJSMql98p74FBTvBIRnoIjRtZRzxb1zbuwWM5yiIsW+FobbvumSDXtV0o9X+TAeR6GHJ3LQ459fSh1Eaq/SpXebF86CErD9dj+S4VypJnnjylzX9YvprxokyucjICT8mkW01SkG6szEk9fo3Iod3rQ7N5IXwh2n9ifyGNzfodA/x2iynLnqdmiOntHEvPVyiZzSl1V7O+SuX4opaDdTOyfpkblhEvXuSfRZbPTVRwVmDr7O5mavM+qIMFsMWPlEaf5cVxOqJPwAYtzJHkCqYlkl5zAjW6gDmIOhQ3pZ99L2el59mr7GVNh/z1dwm6mZTdLv0Yucn3Z6emf4we0B7cETZbm3XT3J0BvACxFlPkfyHAW+Q8aB7xTLbJ3z77VzFUoFW9U+FI7eto8WBR+BM4IhhCivLU2hVCnun3lTsSwAoEtrWVT4O8awz1I4t/xzpPylfW4PIhrYhbb+Lszv7klpB9LdFS4lr9kG1BQ617dicA/ALGBMxPT/QxmKZFyZd9eH9G0C3uJQmQXJ7G120pPqY92ffowMQs8rWhJBMzouSivaEXH9emG/BQrHN+CZKzpWWgcMJ6NKXjJA3mwqWXz/HaoE3zIW61YR685ZX4n9V8VpFs598gaKP3e+ygMZz1g4XETS6AnJawaKWB6POkX7lZoaGVAdzxCjk6tmHR9qAF5c5PySrlC8cau+7/9em/bXChEb7P5zqbUlthp/w8

X-Forefront-Antispam-Report:

CIP:198.58.103.69;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.legros.com;PTR:198-58-103-69.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(396003)(39860400002)(136003)(346002)(376002)(230922051799003)(7200799017)(64100799003)(1800799012)(451199024)(1690799017)(82310400011)(186009)(40470700004)(46966006)(36840700001)(31696002)(41320700001)(9686003)(478600001)(33964004)(26005)(336012)(6916009)(2906002)(70586007)(70206006)(8676002)(8936002)(7116003)(4326008)(316002)(786003)(42186006)(19625305002)(5660300002)(66899024)(41300700001)(3480700007)(166002)(82740400003)(81166007)(83380400001)(36860700001)(47076005)(34020700004)(40480700001)(8400799017)(40460700003)(564344004)(1406899027)(83022004);DIR:OUT;SFP:1101;

X-OriginatorOrg: exlzbuch.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Dec 2023 21:31:21.7346

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 6b21ded7-6c23-48ff-7b6d-08dc0590d6fb

X-MS-Exchange-CrossTenant-Id: 0e191e3b-e3a2-4894-ab85-8072d33f32b2

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=0e191e3b-e3a2-4894-ab85-8072d33f32b2;Ip=[198.58.103.69];Helo=[mail.legros.com]

X-MS-Exchange-CrossTenant-AuthSource:

AM3PEPF0000A792.eurprd04.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4PR06MB8469

X-Spam_score: 5.9

X-Spam_score_int: 59

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: (4318) Notifications If you no longer wish to receive these

emails, you may unsubscribe by clicking here.



Content analysis details: (5.9 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist

[URI: boukaboslbkay.blob.core.windows.net]

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[40.107.241.75 listed in list.dnswl.org]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[40.107.241.75 listed in wl.mailspike.net]

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

-0.0 SPF_PASS SPF: sender matches SPF record

0.0 ARC_SIGNED Message has a ARC signature

0.0 ARC_VALID Message has a valid ARC signature

1.0 HK_RANDOM_FROM From username looks random

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[support_gqfvfidss(at)exlzbuch.onmicrosoft.com]

0.7 MPART_ALT_DIFF BODY: HTML and text parts are different

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts

0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily

Subject: {SPAM?} Important for doctor

X-Antivirus: AVG (VPS 231225-6, 12/25/2023), Inbound message

X-Antivirus-Status: Clean



--PART.VfTr.ztujdqpg

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset="UTF-8"











(4318) Notifications
































































If you no longer wish to receive these emails, you may unsubscribe by

clicking here.























--PART.VfTr.ztujdqpg--

X-rated Google Groups spam "Angela J. Ginsburg" <ngcobophilani9@gmail.com> from Google Gmail

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 11:33:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHpk8-000000001UQ-46K9

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 11:32:00 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 11:32:00 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-qt1-f189.google.com ([209.85.160.189]:47367)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHnsn-00000000HGA-1U35

for root@nl2k.ab.ca;

Mon, 25 Dec 2023 09:32:53 -0700

Received: by mail-qt1-f189.google.com with SMTP id d75a77b69052e-4279038f814sf76595611cf.3

for ; Mon, 25 Dec 2023 08:30:50 -0800 (PST)

ARC-Seal: i=2; a=rsa-sha256; t=1703521844; cv=pass;

d=google.com; s=arc-20160816;

b=UWz0xJPcKPna3KHfrc/0OKNU2nfjjYMsmYe3Pjr7i929U/PttQE5IxVsLxh0ixnO5s

R8D0ZpVT7u8UcK9idk+VqXMf/eWb7kr5Rloia16aoiKD+gZOfbXHaRIq2lnvSdQpAFNI

BbGEA7jQgGlGTGUhhRS64m46x5DEK9/IqaG2S9g4cAwkHnQkkJUnlPDHJ/h4Hs1mvU94

Ssl6E6og+PDzLmOrIBPRP2DKb4VRnw1SfGesEPjcr9ws59n4DC6tOxYVrGVaTwxOqiWf

7qOTYnSkQTaZPv63qMLwqFRufpz4dZmJ9+v8KSMB2onV0u9AMoJwewdIub3Bve4jsFvh

MKDw==

ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;

h=list-unsubscribe:list-archive:list-help:list-post:list-id

:mailing-list:precedence:to:subject:message-id:date:from

:mime-version:sender:dkim-signature:dkim-signature;

bh=p8W7zh/MPDgngd8sD6DdoJf11U1HmI7x/UwJTX5GSeg=;

fh=vCqRcHC98WpWqvdUf7zGW6Q9V1Ia0/5mOVn+iRYtj6U=;

b=xeq6uA5farRXlE9dyZP8TXVjYnk6pfDKhZTNEhFmiFt0jYt8Kc5Am6XawvgWSq1Tbz

bkegw6rJ2QXEWAwL8s+snJqw9qqIGrtG5X8P+Edn4KXpJQPN7bwKsPgQu/va9nOnhfoj

O1PWc01g7AZNG0LDvg0dxRlX1ydOycHynHpqI/4XCjE6utX/4YnOA5cQYhUm/mr7+HzC

9ufIdeKRBy5TFdqMJqAfUJRXFxWGANxPErQWDMhMx39cAXDll2JIYpETspuHAnbNTI67

JdFEV7rKyOFG7ivGcwAp+zjEvpa42/AxNx8USXErD57Y92H3KItSbqxqFjhAO3jhjS6b

m9Qg==

ARC-Authentication-Results: i=2; gmr-mx.google.com;

dkim=pass header.i=@gmail.com header.s=20230601 header.b=bJwAfXaD;

spf=pass (google.com: domain of ngcobophilani9@gmail.com designates 2607:f8b0:4864:20::832 as permitted sender) smtp.mailfrom=ngcobophilani9@gmail.com;

dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=googlegroups.com; s=20230601; t=1703521844; x=1704126644; darn=nl2k.ab.ca;

h=list-unsubscribe:list-archive:list-help:list-post:list-id

:mailing-list:precedence:x-original-authentication-results

:x-original-sender:to:subject:message-id:date:from:mime-version

:sender:from:to:cc:subject:date:message-id:reply-to;

bh=p8W7zh/MPDgngd8sD6DdoJf11U1HmI7x/UwJTX5GSeg=;

b=jJHwUG9qrCd8z9A+5P+V2p6LSyHfhZN1rFQwEinHsQ/ruTIuECHiOW7d+oIg5Jxxn+

+J7MfKK3Bh1Gfgb/Q5LyddYl6yC493IvkxEEGeY+bwXzIFE6l3jKEjMR6dQ/w55v3tRd

2GiQK3uPyAJNdVpyr8M9v+y1P0u8WugQVmbN60bsi3FWA+E97yk9h0rO6Ys0yIfHLZmz

j5ZJp5AlsyN2vVujXCoJLp2/P6ntEwmw2sNlm5ejhdKpUmcmKAAGo7e4RjvSqNNVAhYK

vFLz++h86i3RQMm6bQcqxHocHQQV7Q0fbWLhln+mnXrJY9+q0NBYcDllczyuC89Ze5x2

JToQ==

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=gmail.com; s=20230601; t=1703521844; x=1704126644; darn=nl2k.ab.ca;

h=list-unsubscribe:list-archive:list-help:list-post:list-id

:mailing-list:precedence:x-original-authentication-results

:x-original-sender:to:subject:message-id:date:from:mime-version:from

:to:cc:subject:date:message-id:reply-to;

bh=p8W7zh/MPDgngd8sD6DdoJf11U1HmI7x/UwJTX5GSeg=;

b=Vjy5DjlxztxjoqFBWGOjlgQy60ys97IioJn32HSaE0Jj/aTbQwNH04G51Qu4iF4uow

E9xCOmc649jeJkalxoOEPOswNHs50sN5B/r2F3/5r5WtD+yLqxr/DGECGqUCNcb9ER++

L1XJ4/KIml7y4zJ1OWN0ONJOshaA5+7VjBP5Sn7COJD0ngIhYdwlCTw9xAhARe24Sgvw

qwBBySH+BmFMXcUxpOcFEVf0RMMTvB7ahPICTnm9EqZUgxCprXsZRTWRzXqz5PBTSgNg

FRmtljVhBPjgRyTYjVPuipMeufMKbzRBN3FzZPsxZp/ZlMXCKTIterGflf4Q4N8qU3uD

kJoA==

X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1e100.net; s=20230601; t=1703521844; x=1704126644;

h=list-unsubscribe:list-archive:list-help:list-post

:x-spam-checked-in-group:list-id:mailing-list:precedence

:x-original-authentication-results:x-original-sender:to:subject

:message-id:date:from:mime-version:x-beenthere:x-gm-message-state

:sender:from:to:cc:subject:date:message-id:reply-to;

bh=p8W7zh/MPDgngd8sD6DdoJf11U1HmI7x/UwJTX5GSeg=;

b=PauUNjPOFkRmqNpe2JIngqegb+AIsqRIa5r+97OJkbm6ACc9o879k52uQDmdzHQAdC

7Z3R/1zp1wUn8cL58fBsGw9B4h66hs9M0afB64AW9bj/OBUzvuYns9vVX4kw1HyZdGkU

idIsfOa17mGZ0OSgDVchAlreDXf3bAaRmrmhQXH1AF+unSazOVRPGhMPIeND+/b7gkRn

r3iHbbIRx3rgYj76XCgDUzs8ursSdV4e3Ig4gI45rvW7f23fMBaJfPHDYEQqYNRlgkLl

TqzPFKRT5Tmj5kgvg2kogrNZrcl52oRJpbGSIEAFpyrYRyTDPiBj/qEz8rbBJoIFRQln

eaEw==

Sender: fresh_01_58528212485814@googlegroups.com

X-Gm-Message-State: AOJu0YzUuP3tF2YVFvzPLiCh8fcrWbHZ5+DC15gN2HQ1A/FjMNOS7riq

Rpz9maJXa+MK8uPhzCQxtAI=

X-Google-Smtp-Source: AGHT+IHRbbUU6ONv66Ye/ibKccs6n3CEuMh4KcNFQ5iPxBRkWP3OzDVBKP6RkjxELNPgEgktVn9HWg==

X-Received: by 2002:a05:6214:c27:b0:67a:a61e:f1fa with SMTP id a7-20020a0562140c2700b0067aa61ef1famr7218767qvd.52.1703518106346;

Mon, 25 Dec 2023 07:28:26 -0800 (PST)

X-BeenThere: fresh_01_58528212485814@googlegroups.com

Received: by 2002:ad4:5c6a:0:b0:67f:6bd0:4930 with SMTP id i10-20020ad45c6a000000b0067f6bd04930ls751963qvh.1.-pod-prod-02-us;

Mon, 25 Dec 2023 07:28:24 -0800 (PST)

X-Received: by 2002:a05:6214:20a1:b0:67f:3efb:a8e2 with SMTP id 1-20020a05621420a100b0067f3efba8e2mr8820594qvd.26.1703518104361;

Mon, 25 Dec 2023 07:28:24 -0800 (PST)

ARC-Seal: i=1; a=rsa-sha256; t=1703518104; cv=none;

d=google.com; s=arc-20160816;

b=RGt3vMs4/dP7E5xySZa4VVQY4a8Pf20MTnP28UaooQmGpLQyNSd6mKDyU/f2WosSPT

odj+7DGHXta4FKx71pClx9K3v9C12vXUNFB2RU8jjcWBc/OTIX54KA7l2+Zo3YRcyt+X

qpdKjRQldxF7APolNKzfjx07HBTmQuFy/NH57n2g8wduc9APm7e8O2AzDj8+TkZWBcYf

AlmgJw8XgPR3DDiJgyLDHKcO8jvC6TNrkDG/qz97PTeKhvYQNV1oEP8V6O8zhZFCytHh

r6Ja+wV3ow+S5Z6SLR33DuakEyoh3TSGc7tpuhRpsMwkF+vhlGDhp6IKGqAeL9Nv/fvk

yrqQ==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;

h=to:subject:message-id:date:from:mime-version:dkim-signature;

bh=Geg2/KM3FyuVawTbgZ3n0obOf+B22BUwctyzbd37cag=;

fh=vCqRcHC98WpWqvdUf7zGW6Q9V1Ia0/5mOVn+iRYtj6U=;

b=Sx1dFNV5dONAnefv2w5MTdaSSU+pOBNnODrnYQyTQOkzrnFeoqd+hS8lEmRja+mTNE

8uQe3nsAIVg3Xe15iZzuLbhxYRNauRUm1bxdn7xAiKP0GzY/hO5dMmKBgoj0R01ETRCl

ru+DHOiIUfHMf97g3w/Rpgn3RNg9fA5XOIR99jlgDzZYciRt3bPeNj10SEGoQmpAxjgg

vd3+LiY5K7inxGFD/6IX31uRbuMW7XqL6GgcXbrK1Gk+Wrn2cmkem4wcirHCcQ4YUDR6

157YC4iNLG0demX/fq9f/rtteVFRsnu/lSYM2+OMzbxVSM64R2RSyMMR1chzz/BTPTMF

2Ggg==

ARC-Authentication-Results: i=1; gmr-mx.google.com;

dkim=pass header.i=@gmail.com header.s=20230601 header.b=bJwAfXaD;

spf=pass (google.com: domain of ngcobophilani9@gmail.com designates 2607:f8b0:4864:20::832 as permitted sender) smtp.mailfrom=ngcobophilani9@gmail.com;

dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com

Received: from mail-qt1-x832.google.com (mail-qt1-x832.google.com. [2607:f8b0:4864:20::832])

by gmr-mx.google.com with ESMTPS id v12-20020ad4528c000000b0067f7f198909si765034qvr.7.2023.12.25.07.28.24

(version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128);

Mon, 25 Dec 2023 07:28:24 -0800 (PST)

Received-SPF: pass (google.com: domain of ngcobophilani9@gmail.com designates 2607:f8b0:4864:20::832 as permitted sender) client-ip=2607:f8b0:4864:20::832;

Received: by mail-qt1-x832.google.com with SMTP id d75a77b69052e-427ca22a66cso13442761cf.0;

Mon, 25 Dec 2023 07:28:24 -0800 (PST)

X-Received: by 2002:ac8:7d51:0:b0:427:a3ba:4f with SMTP id h17-20020ac87d51000000b00427a3ba004fmr9597194qtb.43.1703518103853;

Mon, 25 Dec 2023 07:28:23 -0800 (PST)

MIME-Version: 1.0

From: "Angela J. Ginsburg"

Date: Mon, 25 Dec 2023 21:28:12 +0600

Message-ID:

Subject: Free hookups tonight or tomorrow

To: fresh_01_585282124583698@googlegroups.com,

fresh_01_585282124589@googlegroups.com, fresh_01_585282@googlegroups.com,

fresh_01_5852821245961@googlegroups.com,

fresh_01_58528212485814@googlegroups.com,

fresh_01_5852821249@googlegroups.com, fresh_01_5852821254@googlegroups.com,

fresh_01_58528212589@googlegroups.com, fresh_01_58528212616@googlegroups.com,

fresh_01_585282126546@googlegroups.com

Content-Type: multipart/alternative; boundary="00000000000072e7aa060d5737c3"

X-Original-Sender: ngcobophilani9@gmail.com

X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass

header.i=@gmail.com header.s=20230601 header.b=bJwAfXaD; spf=pass

(google.com: domain of ngcobophilani9@gmail.com designates

2607:f8b0:4864:20::832 as permitted sender) smtp.mailfrom=ngcobophilani9@gmail.com;

dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com

Precedence: list

Mailing-list: list fresh_01_58528212485814@googlegroups.com; contact fresh_01_58528212485814+owners@googlegroups.com

List-ID:

X-Spam-Checked-In-Group: fresh_01_58528212485814@googlegroups.com

X-Google-Group-Id: 128202668634

List-Post: ,

List-Help: ,

List-Archive:
List-Unsubscribe: ,



X-Antivirus: AVG (VPS 231225-6, 12/25/2023), Inbound message

X-Antivirus-Status: Clean



--00000000000072e7aa060d5737c3

Content-Type: text/plain; charset="UTF-8"



Hey, I'm a very naughty, funny & open minded girl...! See my all nudes &

Contact information Before meet.

Go here> sites.google.com/view/nilly21



No Need Any CC













































------------------------//////////



--

You received this message because you are subscribed to the Google Groups "fresh_01_58528212485814" group.

To unsubscribe from this group and stop receiving emails from it, send an email to fresh_01_58528212485814+unsubscribe@googlegroups.com.

To view this discussion on the web, visit https://groups.google.com/d/msgid/fresh_01_58528212485814/CAEW1Ac9jfv0_97BSAMEsu1pwCeyvN5CgE6roiJkpADq011YEKA%40mail.gmail.com.



--00000000000072e7aa060d5737c3

Content-Type: text/html; charset="UTF-8"

Content-Transfer-Encoding: quoted-printable



Hey, I'm a very naughty, funny & open minded girl.=

..!=C2=A0 See my all nudes & Contact information Before meet.
Go her=

e> =C2=A0 =C2=A0 =C2=A0
>sites.google.com/view/nilly21


No Need Any CC




>

















--=

----------------------//////////








--


You received this message because you are subscribed to the Google Groups &=

quot;fresh_01_58528212485814" group.


To unsubscribe from this group and stop receiving emails from it, send an e=

mail to
com">fresh_01_58528212485814+unsubscribe@googlegroups.com
.


To view this discussion on the web, visit
com/d/msgid/fresh_01_58528212485814/CAEW1Ac9jfv0_97BSAMEsu1pwCeyvN5CgE6roiJ=

kpADq011YEKA%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https=

://groups.google.com/d/msgid/fresh_01_58528212485814/CAEW1Ac9jfv0_97BSAMEsu=

1pwCeyvN5CgE6roiJkpADq011YEKA%40mail.gmail.com
.




--00000000000072e7aa060d5737c3--

NEtflix Phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 11:32:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHpjo-000000001Sz-1uML

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 11:31:40 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 11:31:40 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-dm6nam12hn2221.outbound.protection.outlook.com ([52.100.166.221]:53344 helo=NAM12-DM6-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHmTQ-00000000ECc-2mWQ

for doctor@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 08:02:36 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=Hjpx8TvOL521j2/PSeRw1Xoppl5khpv761At6kWOeEcME47cXXDnGbC9nhemkyqiCTgecPZ38VAIf5Hkz2pyhVDjiz7OfHOydxJY7j1qS1or3F2Qh6vJwexUodzh9mUqDbytX4CIV8Ar7seB5FxIk9nTaxcx2z8BJXBEC6ljxhbwmE4Jj7xEwgTeoR1fdmFh/ijw0F8CAJmCHdoeC6TENPL118Sdt5PB7dRM2VLO1+aMt8aBEmZJQhnVUPJW+AMjaG2zO3K3mfPGx1LF+jlHLn3j6wulu0GJO+oNC5P1+sUDMdQNpmQmdO1xlPC4/1FC6COm3CIA55IlA0DXpshOng==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=Q5ePlfsNMmc8S+TBUsMC5kdp6gzkgfjF6IEkvwjGzhA=;

b=WRbh5f28MRr7Gwy+lSnKmcYxRTpLyv9a9tR4RJNlAES6rsph7tZNmM7ENbnWHF11V78VxYd0B3d3TnSp7SSYe/XVWB+8dCDDxlewL4KY5g8ZngdzAHPzsm/hV1hMDmwNm77TkvgV43XPvOFIvszLseWRVMKMb6O9xfIc4l8rIPNN1SRoyguZkeDioInwhdFQ5eNlceMTOorFnh9xVCV57zlBzxfvq6LJNOuKn7uqWhBxgjEAvBoILRhRdqMjOOURGT+UZfe3Yia+pfUIUuguL9ppC9wIN1j5jca3SG1HwLdmk1E8UZ/+ymhli7zMFNB91viBPGqeX0k5Iiqs47vi6g==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

116.203.114.137) smtp.rcpttodomain=doctor.nl2k.ab.ca

smtp.mailfrom=sumxaonb.onmicrosoft.com; dmarc=none action=none

header.from=sumxaonb.onmicrosoft.com; dkim=none (message not signed);

arc=none (0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 116.203.114.137)

smtp.mailfrom=sumxaonb.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=sumxaonb.onmicrosoft.com;

X-TOI-MSGID: <1201209180.044433D2AF6AB.1703515499164@beatty.com>

CC: doctor@doctor.nl2k.ab.ca

MIME-Version: 1.0

Date: Mon, 25 Dec 2023 15:44:59 +0100

From: Netflix Membership

To: doctor@doctor.nl2k.ab.ca

Content-Type: multipart/alternative; charset="UTF-8";boundary="PART_oAOy.ywrqzgxt"

In-Reply-To:

Importance: high

Subject: Notice for doctor, You Are Our December Winner_!!

Message-ID:

<7defd098-bbd2-4a80-8183-9004360da1a3@MW2NAM12FT102.eop-nam12.prod.protection.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: MW2NAM12FT102:EE_|SJ2P222MB1043:EE_

X-MS-Office365-Filtering-Correlation-Id: a11030fc-e35d-410a-826c-08dc055a3917

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

k1KH6VBDnV6OCKp2vY+N20EXYN4ctF80wC2m6LEk9wPzJ3X1fpNSJYlbSiZ4KvXn9732ck6PdVRzoAKyHD9UooIP6x4eOQI/B7Oszt5mqynnryAPi/yMQ5NWZkiNhgukhAD9W/6IVwFTvOklReRgSmPOxQneRVvjiAPgxpTwPer/LgFUQg5lICgjxDgBkFJ086GiGmetvJA1oweDgO2YgdzQ08kuanYwmWnvZpov1L5KX3bJrF7QKrUASGw9F6KsVtGT7NDwRIv499bBteI6QUvZOEPDYLwPxNIBg5Xy5PwtEea1+v4J7nphLeT14UAvNmH3UUKrZPShG4YV1m4u6x/iSykOUsB01JvN4hIzDNtCeNFrnMQfb74EKwViQCRtkqtcJmipxdzEkEv+Bqg4Vt3nL3LVO5bADFpQpW9yvfJXySsCMDoYhHWNZdBdsyuv1Ji6f9pOf5o6ZVIo5D9dy+wOCiCa1drXJEQYB2UFHu3bYMGStBjhyvd/R4VyUO9U2197dFVhcJURft1c32TqhvbLkycoT4CUv8TMuDVALFUIAOdcoOS18XA5y88g9a0DSW2DKQeJiLykrxqSganhkg==

X-Forefront-Antispam-Report:

CIP:116.203.114.137;CTRY:DE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.beatty.com;PTR:static.137.114.203.116.clients.your-server.de;CAT:NONE;SFS:(13230031)(376002)(346002)(136003)(396003)(39860400002)(230922051799003)(1690799017)(82310400011)(186009)(64100799003)(451199024)(7200799017)(61400799012)(46966006)(40470700004)(36840700001)(47076005)(82740400003)(316002)(786003)(70206006)(6916009)(70586007)(42186006)(8400799017)(31686004)(34020700004)(166002)(81166007)(33964004)(9686003)(40480700001)(336012)(26005)(8676002)(5660300002)(19625305002)(478600001)(31696002)(8936002)(4326008)(564344004)(2906002)(36860700001)(32880700267)(40460700003)(41300700001)(41320700001)(18023003)(38122002)(83022004);DIR:OUT;SFP:1501;

X-OriginatorOrg: sumxaonb.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Dec 2023 15:00:23.8899

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: a11030fc-e35d-410a-826c-08dc055a3917

X-MS-Exchange-CrossTenant-Id: ef88eda8-d614-4081-a99d-551fc0881e13

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=ef88eda8-d614-4081-a99d-551fc0881e13;Ip=[116.203.114.137];Helo=[mail.beatty.com]

X-MS-Exchange-CrossTenant-AuthSource:

MW2NAM12FT102.eop-nam12.prod.protection.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2P222MB1043

X-Spam_score: 6.3

X-Spam_score_int: 63

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: (1373) Notifications For YOU



Content analysis details: (6.3 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist

[URI: trimbo2.blob.core.windows.net]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[52.100.166.221 listed in wl.mailspike.net]

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[52.100.166.221 listed in list.dnswl.org]

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

-0.0 SPF_PASS SPF: sender matches SPF record

0.0 ARC_SIGNED Message has a ARC signature

0.0 ARC_VALID Message has a valid ARC signature

1.0 HK_RANDOM_FROM From username looks random

0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters

0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in

digit

[return_1373(at)sumxaonb.onmicrosoft.com]

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[app_uoyfvbwdlkb(at)sumxaonb.onmicrosoft.com]

0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words

0.7 MPART_ALT_DIFF BODY: HTML and text parts are different

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts

0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image

0.0 T_REMOTE_IMAGE Message contains an external image

Subject: {SPAM?} Notice for doctor, You Are Our December Winner_!!

X-Antivirus: AVG (VPS 231225-6, 12/25/2023), Inbound message

X-Antivirus-Status: Clean



--PART_oAOy.ywrqzgxt

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset="UTF-8"











(1373) Notifications For YOU










































































































--PART_oAOy.ywrqzgxt--

credential phishing for nk.ca user from wmailboxserv.net Balkány Hungary

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 06:55:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHlQ3-00000000ApC-3Fps

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 06:54:59 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 06:54:59 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail.wmailboxserv.net ([45.9.168.237]:54636)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHkpN-0000000086I-1p8q

for webmaster@nk.ca;

Mon, 25 Dec 2023 06:17:11 -0700

Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id BF1C2632F6

for ; Mon, 25 Dec 2023 13:14:56 +0000 (UTC)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wmailboxserv.net;

s=dkim; t=1703510099; h=from:subject:date:message-id:to:mime-version:content-type:

content-transfer-encoding; bh=/afPXldfXGlc6JjXhHgSFkW3hmKqjkvRFTaAGQxwBrg=;

b=ZVpa4ddW68B8PhFU3PRn3a8X1Q7CRqAz3FxMmjTbwH5e2egLzYSSmy0lhVFlKpuoKcqTlY

WFuUcq6//ASihSnmsKc/QzJpjLk1+TjNd25kOkEGsl8LJUhFYlzYInLZ+wGcVOa78mbleO

vhC08KC8Tm3Nw5/Ebb6XYhdd+pdpHz0zVbM59zRYC6WH4f93qRVwUb6Tuik+lnvn52VHpp

QlWFGD8nkPFOFFDSJ8rQJYCKlNGbGDe/4OkyndaPBu1Ks5OfAlNZA0romiUfpWMxIaXm44

EuuKVPBwF3JuFey6EGRVfH1bAgjPOWw4GZamDNLd0efVLCwpYtS+I//a1Gkhnw==

From: Mailbox on nk.ca

To: webmaster@nk.ca

Subject: =?UTF-8?B?4pqg77iPICBBY3Rpb24gUmVxdWlyZWQ6IEZvciBlbWFpbCBhY2NvdW50IA==?=webmaster@nk.ca

Date: 25 Dec 2023 05:14:56 -0800

Message-ID: <20231225051455.51B16BC54453E7E3@wmailboxserv.net>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Last-TLS-Session-Version: TLSv1.3

X-Rspamd-Fuzzy: 8313a110ed47221e8da9b9ec96fbc2e30d0978a73f59fdab753d17c86bd44bca83883be67c4cada1342174baedb7a902f21ab0c2ecc11bdf5d77cc8c8e9a56f6

X-Antivirus: AVG (VPS 231225-4, 12/25/2023), Inbound message

X-Antivirus-Status: Clean














e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">Dear webmaster,

border-box;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">
Th=

e following account(s) lost IMAP/POP3 coverage:

izing: border-box;">
⦿ 
nt color=3D"#e7182d" style=3D"box-sizing: border-box; background-color: inh=

erit;">webmaster@nk.ca





ne; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size=

: medium; font-style: normal; font-weight: 400; word-spacing: 0px; white-sp=

ace: normal; box-sizing: border-box; orphans: 2; widows: 2; background-colo=

r: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: n=

ormal; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; =

text-decoration-style: initial;=20

text-decoration-color: initial;">

-height: 23px; padding-right: 30px; padding-left: 30px; font-family: Helvet=

ica, Verdana, Arial, sans-serif; font-size: 19px; box-sizing: border-box;">=



nt-size: medium; box-sizing: border-box;">Kindly use the "Re-validate" butt=

on below to fix.

ox-sizing: border-box;">


=


30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-ser=

if; font-size: 19px; box-sizing: border-box;">
rial; font-size: medium; box-sizing: border-box;">
t: bolder; box-sizing: border-box;">
<=

/span>



x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">
older; box-sizing: border-box;">Note:
 Failure to carry out the&=

nbsp;below exercise would lead to mail delivery problems or terminatio=

n of account.


ox;">
der-box;">
border-box; background-color: rgb(244, 243, 248);">
ily: Arial; font-size: small; box-sizing: border-box;">

ing: border-box;">
<=

/div>


x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">

er-box;">



ne; text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-ser=

if; font-size: 14px; font-style: normal; font-weight: 400; word-spacing: 0p=

x; float: none; display: inline !important; white-space: normal; orphans: 2=

; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: =

normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-dec=

oration-thickness: initial; text-decoration-style:=20

initial; text-decoration-color: initial;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">




rgb(44, 54, 58); text-transform: none; letter-spacing: normal; font-family=

: Roboto, sans-serif; font-size: 14px; font-style: normal; font-weight: 400=

; word-spacing: 0px; white-space: normal; border-collapse: collapse; box-si=

zing: border-box; orphans: 2; widows: 2; background-color: rgb(43, 170, 223=

); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-=

stroke-width: 0px; text-decoration-thickness:=20

initial; text-decoration-style: initial; text-decoration-color: initial;" b=

order=3D"0" cellspacing=3D"0" cellpadding=3D"0">
border-box;">

lign=3D"middle" style=3D"margin: 0px; padding: 15px; font-family: Arial; bo=

x-sizing: border-box;">
ox;">


der-box; background-color: transparent;" href=3D"https://rb.gy/88c8in#webma=

ster@nk.ca" target=3D"_blank" rel=3D"noreferrer">
yle=3D"box-sizing: border-box;">RE-VALIDATE


ox-sizing: border-box;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">
e=3D"font-family: Arial; font-size: xx-small; box-sizing: border-box;">
n style=3D"color: rgb(130, 148, 159); box-sizing: border-box;">
=3D"font-size: 12pt; box-sizing: border-box;">

er-box;">

order-box;">The system generated this notice on 12/25/2023 5:14:55 a.m=

=2E Do not reply to this automated message.



"box-sizing: border-box;">
le=3D"box-sizing: border-box;">


"v1ydpf10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

f10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
sizing: border-box;">
"box-sizing: border-box;">



-sizing: border-box;">
=3D"box-sizing: border-box;">

8pt; box-sizing: border-box;">
n style=3D"box-sizing: border-box;">
>

x-sizing: border-box;">


ox;">

=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

border-box;">
font-size: 12pt; box-sizing: border-box;">
ox-sizing: border-box;">

Copyright © 2023 cPanel, L.L.C. All Rights Reserved.

>

an>



credential phishing for nk.ca user from wmailboxserv.net Balkány Hungary

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 05:38:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHkDI-000000002Tb-2Oas

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 05:37:44 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 05:37:44 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail.wmailboxserv.net ([45.9.168.237]:46686)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHjmO-000000000Wn-2AQ2

for root@nk.ca;

Mon, 25 Dec 2023 05:10:01 -0700

Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id 4774865B39

for ; Mon, 25 Dec 2023 12:07:50 +0000 (UTC)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wmailboxserv.net;

s=dkim; t=1703506073; h=from:subject:date:message-id:to:mime-version:content-type:

content-transfer-encoding; bh=qJLyZcyOJJIjkSpFqJM0qiukE6e8GgIx2LQYhHrL5i8=;

b=J4OBbt0036Vp3fUsfLxmpM7PhFgiSBdIuq5F4Zgj9qzKWnM34Qu1tv2cjqkGr3Nc1QD7Xh

fFUyf2qN760Aaw2IPkqFTcXlx4GDC0+RWrNPwNlHfETBYlbYZHBWMDeSjEEi68k81ql70E

ZDWYysdj+sVS6f2g5j+MgdGefXdtclrsuSige0ZG29NYqnmNwsW+TOSFFGkMzpH+7fdG2P

1WdtAjZBlex2vmcxy6lLU+1kZwrrM0hK9NXf9J7sbyDDwe/lUTkWWtXGW3mUhNH5D0o/pc

4Uz3T3Nu1t98dGbzb2/8Ijvo91ySaEpP1XPTlue+ezct8254B0OmpMAs3dGtCQ==

From: Mailbox on nk.ca

To: root@nk.ca

Subject: =?UTF-8?B?4pqg77iPICBBY3Rpb24gUmVxdWlyZWQ6IEZvciBlbWFpbCBhY2NvdW50IA==?=root@nk.ca

Date: 25 Dec 2023 04:07:50 -0800

Message-ID: <20231225040747.57E2B0443EB8E6E6@wmailboxserv.net>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Last-TLS-Session-Version: TLSv1.3

X-Rspamd-Fuzzy: 8313a110ed47221e8da9b9ec96fbc2e30d0978a73f59fdab753d17c86bd44bca83883be67c4cada1342174baedb7a902f21ab0c2ecc11bdf5d77cc8c8e9a56f6

X-Antivirus: AVG (VPS 231224-4, 12/24/2023), Inbound message

X-Antivirus-Status: Clean














e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">Dear root,

r-box;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">
Th=

e following account(s) lost IMAP/POP3 coverage:

izing: border-box;">
⦿ 
nt color=3D"#e7182d" style=3D"box-sizing: border-box; background-color: inh=

erit;">root@nk.ca





ne; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size=

: medium; font-style: normal; font-weight: 400; word-spacing: 0px; white-sp=

ace: normal; box-sizing: border-box; orphans: 2; widows: 2; background-colo=

r: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: n=

ormal; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; =

text-decoration-style: initial;=20

text-decoration-color: initial;">

-height: 23px; padding-right: 30px; padding-left: 30px; font-family: Helvet=

ica, Verdana, Arial, sans-serif; font-size: 19px; box-sizing: border-box;">=



nt-size: medium; box-sizing: border-box;">Kindly use the "Re-validate" butt=

on below to fix.

ox-sizing: border-box;">


=


30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-ser=

if; font-size: 19px; box-sizing: border-box;">
rial; font-size: medium; box-sizing: border-box;">
t: bolder; box-sizing: border-box;">
<=

/span>



x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">
older; box-sizing: border-box;">Note:
 Failure to carry out the&=

nbsp;below exercise would lead to mail delivery problems or terminatio=

n of account.


ox;">
der-box;">
border-box; background-color: rgb(244, 243, 248);">
ily: Arial; font-size: small; box-sizing: border-box;">

ing: border-box;">
<=

/div>


x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">

er-box;">



ne; text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-ser=

if; font-size: 14px; font-style: normal; font-weight: 400; word-spacing: 0p=

x; float: none; display: inline !important; white-space: normal; orphans: 2=

; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: =

normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-dec=

oration-thickness: initial; text-decoration-style:=20

initial; text-decoration-color: initial;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">




rgb(44, 54, 58); text-transform: none; letter-spacing: normal; font-family=

: Roboto, sans-serif; font-size: 14px; font-style: normal; font-weight: 400=

; word-spacing: 0px; white-space: normal; border-collapse: collapse; box-si=

zing: border-box; orphans: 2; widows: 2; background-color: rgb(43, 170, 223=

); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-=

stroke-width: 0px; text-decoration-thickness:=20

initial; text-decoration-style: initial; text-decoration-color: initial;" b=

order=3D"0" cellspacing=3D"0" cellpadding=3D"0">
border-box;">

lign=3D"middle" style=3D"margin: 0px; padding: 15px; font-family: Arial; bo=

x-sizing: border-box;">
ox;">


der-box; background-color: transparent;" href=3D"https://rb.gy/88c8in#root@=

nk.ca" target=3D"_blank" rel=3D"noreferrer">
=3D"box-sizing: border-box;">RE-VALIDATE


sizing: border-box;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">
e=3D"font-family: Arial; font-size: xx-small; box-sizing: border-box;">
n style=3D"color: rgb(130, 148, 159); box-sizing: border-box;">
=3D"font-size: 12pt; box-sizing: border-box;">

er-box;">

order-box;">The system generated this notice on 12/25/2023 4:07:47 a.m=

=2E Do not reply to this automated message.



"box-sizing: border-box;">
le=3D"box-sizing: border-box;">


"v1ydpf10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

f10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
sizing: border-box;">
"box-sizing: border-box;">



-sizing: border-box;">
=3D"box-sizing: border-box;">

8pt; box-sizing: border-box;">
n style=3D"box-sizing: border-box;">
>

x-sizing: border-box;">


ox;">

=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

border-box;">
font-size: 12pt; box-sizing: border-box;">
ox-sizing: border-box;">

Copyright © 2023 cPanel, L.L.C. All Rights Reserved.

>

an>



credential phishing for nk.ca user from wmailboxserv.net Balkány Hungary

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 05:38:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHkDI-000000002Tb-2Oas

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 05:37:44 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 05:37:44 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail.wmailboxserv.net ([45.9.168.237]:46686)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHjmO-000000000Wn-2AQ2

for root@nk.ca;

Mon, 25 Dec 2023 05:10:01 -0700

Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id 4774865B39

for ; Mon, 25 Dec 2023 12:07:50 +0000 (UTC)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wmailboxserv.net;

s=dkim; t=1703506073; h=from:subject:date:message-id:to:mime-version:content-type:

content-transfer-encoding; bh=qJLyZcyOJJIjkSpFqJM0qiukE6e8GgIx2LQYhHrL5i8=;

b=J4OBbt0036Vp3fUsfLxmpM7PhFgiSBdIuq5F4Zgj9qzKWnM34Qu1tv2cjqkGr3Nc1QD7Xh

fFUyf2qN760Aaw2IPkqFTcXlx4GDC0+RWrNPwNlHfETBYlbYZHBWMDeSjEEi68k81ql70E

ZDWYysdj+sVS6f2g5j+MgdGefXdtclrsuSige0ZG29NYqnmNwsW+TOSFFGkMzpH+7fdG2P

1WdtAjZBlex2vmcxy6lLU+1kZwrrM0hK9NXf9J7sbyDDwe/lUTkWWtXGW3mUhNH5D0o/pc

4Uz3T3Nu1t98dGbzb2/8Ijvo91ySaEpP1XPTlue+ezct8254B0OmpMAs3dGtCQ==

From: Mailbox on nk.ca

To: root@nk.ca

Subject: =?UTF-8?B?4pqg77iPICBBY3Rpb24gUmVxdWlyZWQ6IEZvciBlbWFpbCBhY2NvdW50IA==?=root@nk.ca

Date: 25 Dec 2023 04:07:50 -0800

Message-ID: <20231225040747.57E2B0443EB8E6E6@wmailboxserv.net>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Last-TLS-Session-Version: TLSv1.3

X-Rspamd-Fuzzy: 8313a110ed47221e8da9b9ec96fbc2e30d0978a73f59fdab753d17c86bd44bca83883be67c4cada1342174baedb7a902f21ab0c2ecc11bdf5d77cc8c8e9a56f6

X-Antivirus: AVG (VPS 231224-4, 12/24/2023), Inbound message

X-Antivirus-Status: Clean














e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">Dear root,

r-box;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">
Th=

e following account(s) lost IMAP/POP3 coverage:

izing: border-box;">
⦿ 
nt color=3D"#e7182d" style=3D"box-sizing: border-box; background-color: inh=

erit;">root@nk.ca





ne; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size=

: medium; font-style: normal; font-weight: 400; word-spacing: 0px; white-sp=

ace: normal; box-sizing: border-box; orphans: 2; widows: 2; background-colo=

r: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: n=

ormal; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; =

text-decoration-style: initial;=20

text-decoration-color: initial;">

-height: 23px; padding-right: 30px; padding-left: 30px; font-family: Helvet=

ica, Verdana, Arial, sans-serif; font-size: 19px; box-sizing: border-box;">=



nt-size: medium; box-sizing: border-box;">Kindly use the "Re-validate" butt=

on below to fix.

ox-sizing: border-box;">


=


30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-ser=

if; font-size: 19px; box-sizing: border-box;">
rial; font-size: medium; box-sizing: border-box;">
t: bolder; box-sizing: border-box;">
<=

/span>



x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">
older; box-sizing: border-box;">Note:
 Failure to carry out the&=

nbsp;below exercise would lead to mail delivery problems or terminatio=

n of account.


ox;">
der-box;">
border-box; background-color: rgb(244, 243, 248);">
ily: Arial; font-size: small; box-sizing: border-box;">

ing: border-box;">
<=

/div>


x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">

er-box;">



ne; text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-ser=

if; font-size: 14px; font-style: normal; font-weight: 400; word-spacing: 0p=

x; float: none; display: inline !important; white-space: normal; orphans: 2=

; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: =

normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-dec=

oration-thickness: initial; text-decoration-style:=20

initial; text-decoration-color: initial;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">




rgb(44, 54, 58); text-transform: none; letter-spacing: normal; font-family=

: Roboto, sans-serif; font-size: 14px; font-style: normal; font-weight: 400=

; word-spacing: 0px; white-space: normal; border-collapse: collapse; box-si=

zing: border-box; orphans: 2; widows: 2; background-color: rgb(43, 170, 223=

); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-=

stroke-width: 0px; text-decoration-thickness:=20

initial; text-decoration-style: initial; text-decoration-color: initial;" b=

order=3D"0" cellspacing=3D"0" cellpadding=3D"0">
border-box;">

lign=3D"middle" style=3D"margin: 0px; padding: 15px; font-family: Arial; bo=

x-sizing: border-box;">
ox;">


der-box; background-color: transparent;" href=3D"https://rb.gy/88c8in#root@=

nk.ca" target=3D"_blank" rel=3D"noreferrer">
=3D"box-sizing: border-box;">RE-VALIDATE


sizing: border-box;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">
e=3D"font-family: Arial; font-size: xx-small; box-sizing: border-box;">
n style=3D"color: rgb(130, 148, 159); box-sizing: border-box;">
=3D"font-size: 12pt; box-sizing: border-box;">

er-box;">

order-box;">The system generated this notice on 12/25/2023 4:07:47 a.m=

=2E Do not reply to this automated message.



"box-sizing: border-box;">
le=3D"box-sizing: border-box;">


"v1ydpf10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

f10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
sizing: border-box;">
"box-sizing: border-box;">



-sizing: border-box;">
=3D"box-sizing: border-box;">

8pt; box-sizing: border-box;">
n style=3D"box-sizing: border-box;">
>

x-sizing: border-box;">


ox;">

=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

border-box;">
font-size: 12pt; box-sizing: border-box;">
ox-sizing: border-box;">

Copyright © 2023 cPanel, L.L.C. All Rights Reserved.

>

an>



credential phishing for nk.ca user from wmailboxserv.net Balkány Hungary

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 25 Dec 2023 05:36:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHkBV-000000002Ld-0I9G

for dave@doctor.nl2k.ab.ca;

Mon, 25 Dec 2023 05:35:53 -0700

Resent-From: The Doctor

Resent-Date: Mon, 25 Dec 2023 05:35:52 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail.wmailboxserv.net ([45.9.168.237]:56188)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHi3R-00000000L84-1jY3

for info@nk.ca;

Mon, 25 Dec 2023 03:19:32 -0700

Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPSA id BE20C65723

for ; Mon, 25 Dec 2023 10:17:20 +0000 (UTC)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wmailboxserv.net;

s=dkim; t=1703499443; h=from:subject:date:message-id:to:mime-version:content-type:

content-transfer-encoding; bh=8+Mc73MNfvWT0Bz/cCjq9HV8Qd+XBUxfLPqr3XXcTdg=;

b=Ru5ME7Hio4onhVsXTa2D04gI0XMUa5cZX+6BOidAowYnIjdCd4gC1lchwgzTf9CLcB6OTg

dIFem4LhbyBk6LAmEpykldsSSihhnDm/eeccQoUz9YNjaSE+juo+M9EX+IqsYEZM87efKL

xFh6n++aNQXiVmp36bozM1OzK4BLEamBFptS2NEcmmPSMHtF46uFSiB0IvanKhBxsSlDOl

NFfNCPViemVj/5XgJE/2qoIVRuhNZV4CGnlXhkugXAZ/826zeVtIL1hdFn61HCgBasx0tw

cAAwf6reraSzTHGrlmSVeFh1khbbKclwQYRVLqn1W3GpztAncXtOJ3qyekaBSA==

From: Mailbox on nk.ca

To: info@nk.ca

Subject: =?UTF-8?B?4pqg77iPICBBY3Rpb24gUmVxdWlyZWQ6IEZvciBlbWFpbCBhY2NvdW50IA==?=info@nk.ca

Date: 25 Dec 2023 02:17:20 -0800

Message-ID: <20231225021719.11B6581DEF33105C@wmailboxserv.net>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Last-TLS-Session-Version: TLSv1.3

X-Antivirus: AVG (VPS 231224-4, 12/24/2023), Inbound message

X-Antivirus-Status: Clean














e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">Dear info,

r-box;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">
: medium; box-sizing: border-box;">
Th=

e following account(s) lost IMAP/POP3 coverage:

izing: border-box;">
⦿ 
nt color=3D"#e7182d" style=3D"box-sizing: border-box; background-color: inh=

erit;">info@nk.ca





ne; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size=

: medium; font-style: normal; font-weight: 400; word-spacing: 0px; white-sp=

ace: normal; box-sizing: border-box; orphans: 2; widows: 2; background-colo=

r: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: n=

ormal; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; =

text-decoration-style: initial;=20

text-decoration-color: initial;">

-height: 23px; padding-right: 30px; padding-left: 30px; font-family: Helvet=

ica, Verdana, Arial, sans-serif; font-size: 19px; box-sizing: border-box;">=



nt-size: medium; box-sizing: border-box;">Kindly use the "Re-validate" butt=

on below to fix.

ox-sizing: border-box;">


=


30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-ser=

if; font-size: 19px; box-sizing: border-box;">
rial; font-size: medium; box-sizing: border-box;">
t: bolder; box-sizing: border-box;">
<=

/span>



x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">
older; box-sizing: border-box;">Note:
 Failure to carry out the&=

nbsp;below exercise would lead to mail delivery problems or terminatio=

n of account.


ox;">
der-box;">
border-box; background-color: rgb(244, 243, 248);">
ily: Arial; font-size: small; box-sizing: border-box;">

ing: border-box;">
<=

/div>


x; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-serif; =

font-size: 19px; box-sizing: border-box;">
; font-size: medium; box-sizing: border-box;">

er-box;">



ne; text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-ser=

if; font-size: 14px; font-style: normal; font-weight: 400; word-spacing: 0p=

x; float: none; display: inline !important; white-space: normal; orphans: 2=

; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: =

normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-dec=

oration-thickness: initial; text-decoration-style:=20

initial; text-decoration-color: initial;">



e; line-height: 23px; text-indent: 0px; letter-spacing: normal; padding-rig=

ht: 30px; padding-left: 30px; font-family: Helvetica, Verdana, Arial, sans-=

serif; font-size: 19px; font-style: normal; font-weight: 400; word-spacing:=

0px; white-space: normal; box-sizing: border-box; orphans: 2; widows: 2; b=

ackground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-v=

ariant-caps: normal; -webkit-text-stroke-width:=20

0px; text-decoration-thickness: initial; text-decoration-style: initial; te=

xt-decoration-color: initial;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">




rgb(44, 54, 58); text-transform: none; letter-spacing: normal; font-family=

: Roboto, sans-serif; font-size: 14px; font-style: normal; font-weight: 400=

; word-spacing: 0px; white-space: normal; border-collapse: collapse; box-si=

zing: border-box; orphans: 2; widows: 2; background-color: rgb(43, 170, 223=

); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-=

stroke-width: 0px; text-decoration-thickness:=20

initial; text-decoration-style: initial; text-decoration-color: initial;" b=

order=3D"0" cellspacing=3D"0" cellpadding=3D"0">
border-box;">

lign=3D"middle" style=3D"margin: 0px; padding: 15px; font-family: Arial; bo=

x-sizing: border-box;">
ox;">


der-box; background-color: transparent;" href=3D"https://rb.gy/88c8in#info@=

nk.ca" target=3D"_blank" rel=3D"noreferrer">
=3D"box-sizing: border-box;">RE-VALIDATE


sizing: border-box;">



text-indent: 0px; letter-spacing: normal; font-family: Roboto, sans-serif;=

font-size: 14px; font-style: normal; font-weight: 400; margin-top: 0px; ma=

rgin-bottom: 1rem; word-spacing: 0px; white-space: normal; box-sizing: bord=

er-box; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial;=20

text-decoration-style: initial; text-decoration-color: initial;">
e=3D"font-family: Arial; font-size: xx-small; box-sizing: border-box;">
n style=3D"color: rgb(130, 148, 159); box-sizing: border-box;">
=3D"font-size: 12pt; box-sizing: border-box;">

er-box;">

order-box;">The system generated this notice on 12/25/2023 2:17:19 a.m=

=2E Do not reply to this automated message.



"box-sizing: border-box;">
le=3D"box-sizing: border-box;">


"v1ydpf10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

f10eb54dv1v1v1Object" style=3D"box-sizing: border-box;">
sizing: border-box;">
"box-sizing: border-box;">



-sizing: border-box;">
=3D"box-sizing: border-box;">

8pt; box-sizing: border-box;">
n style=3D"box-sizing: border-box;">
>

x-sizing: border-box;">


ox;">

=3D"box-sizing: border-box;">
style=3D"box-sizing: border-box;">

border-box;">
font-size: 12pt; box-sizing: border-box;">
ox-sizing: border-box;">

Copyright © 2023 cPanel, L.L.C. All Rights Reserved.

>

an>



Dewalt phish from Microsoft

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 24 Dec 2023 21:24:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHcV8-00000000AAc-1Bwj

for dave@doctor.nl2k.ab.ca;

Sun, 24 Dec 2023 21:23:38 -0700

Resent-From: The Doctor

Resent-Date: Sun, 24 Dec 2023 21:23:38 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-dm6nam11rlnn2052.outbound.protection.outlook.com ([40.95.38.52]:33319 helo=NAM11-DM6-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

id 1rHYxP-00000000J8g-0oUR

for doctor@doctor.nl2k.ab.ca;

Sun, 24 Dec 2023 17:36:38 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=KRIFp5fnp39UJ0qA21IrQSkew34CM4es1hodsi5SRoXckjsYdWnRgY16G9vdCnW0eo18Glz9Qty5CEVfmTq21Q4r4EnwMakDFjTbNMsF7bvyN7F5uor25QIAJwidxzZKkyMVvAj3IT06Q2hPuws1GWkTFrFIR/G1vlVxx0bFMs8X+YegVHfL2jNne5w5asKpboTcpOv//jDtFK7BawS36bxodDR9hwuDXL8kvEMI/CtZN4ZhcmMzjM13Lwg/FNbpQ0l9L7uoGv+legqsGTsA08YyD3CJCNpkANKetXAnfgf3pOfFFIOw9Ns/J20yJ88ze+jHC/3bue6DaYE5EGnJ9A==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=0l9+y8HwCdgwCyHWOgg3TZFGPmQfspQDEa6Ql67J46g=;

b=C8KjOgeA5FibsAN+A1S1fk+sO7tKgyiZju3OxZBxAKZppp/adcAgxyyB9xe7yJ0JGpHRLJvcDC9rzE5GyJ5QDVdkoAkkxIaCjRyoLexg8xoVSzgI4LlDpBQa8Gfs/i0gn9pNxVVLxoZBJoRXtu4D/gegO55gykpFQonyYdSwfzg7os8NdKGVnNovw9yF0oa7iMvt3+MXYbZHARqFAXhCdZF1Of27ihF2oW1AlX7KuAd4NOLbRyb7lTL5r1N2f0zWjMZYtvTjg8DHGVNOsO6V28anEx+jn/LvXVjcnRhL6Hv4wls15x44C1kKUE/yT1jtJVzVBVoGGgiBwQkaH32XuA==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none (sender ip is

78.46.149.17) smtp.rcpttodomain=doctor.nl2k.ab.ca smtp.helo=mail.goldner.net;

dmarc=none action=none header.from=blh.hqvot.com; dkim=none (message not

signed); arc=none (0)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=fw74778.onmicrosoft.com; s=selector1-fw74778-onmicrosoft-com;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=0l9+y8HwCdgwCyHWOgg3TZFGPmQfspQDEa6Ql67J46g=;

b=g4WqAYAMAKNDdTU5exDq7vfPReyHMu7w9oR2Af6bwXf+q+0VDD1qdT+2+rc67gUFalfLg0gb1sZ4oK2ijMdPTvkRFvHMhZp/dcpjgvafIppRYp/PciQV5nsWw/O5BQJ6YCKo/PlSb1hwT4Olz9pWnUQJveC4JJJ+cMJp9iwNKnU9ICLh2ozLpUNhwGITHF0otRKefAawMLixdtxE8fuGBDvDIkYmdyuO3iaa9860acjW9Kt8/pTS3bbgQbpJPUtkExxYGnrASkKV9o51qWuS1PY5wlTZ0jrGJrdwqLR4knihsSWM44sccNlgaAxax16JWg+U9qR7FS9i29f7iP7Emw==

X-MS-Exchange-Authentication-Results: spf=none (sender IP is 78.46.149.17)

smtp.helo=mail.goldner.net; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=blh.hQvot.com;

To: doctor@doctor.nl2k.ab.ca

MIME-Version: 1.0

In-Reply-To:

Content-Transfer-Encoding: 7bit

From: Limited

Content-Type: text/html; charset="UTF-8"

X-TOI-MSGID: <1340913344.0E1BC06400DB0.1703464358886@goldner.net>

Importance: high

Date: Mon, 25 Dec 2023 01:32:38 +0100

CC: doctor@doctor.nl2k.ab.ca

Subject: Order Verification - DEWALT 200 Piece Mechanics Tool Set

Message-ID:



X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: MWH0EPF000971E2:EE_|SJ0PR07MB7552:EE_

X-MS-Office365-Filtering-Correlation-Id: 6e4ec2b7-34c1-43f9-cf27-08dc04e13fff

X-MS-Exchange-SenderADCheck: 2

X-MS-Exchange-AntiSpam-Relay: 1

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

+TvTUdZzvqlo0o9YOw995Px7kJ9OD5dHbtVb0Zdq7lRE6G/5D1SeTWU2Zsr78U8C0TleSu04YKV4DZu3vedsgZ0AKpMh9ZSvTesYhf9qdejbpAYm0GwmuTTvUbR2Lzwt74JGVvBcmAIxiZBd/dMHUl59Vo+JUF99F7vL1ot/Eq23bw1V1tWW651q1pU4rZSTye/VgPe8hy236B811Ej5PYt+KnhDXe/jxaOELOMHEOxNj1LMEUYN8FBt6rM2ZTzuKWYAuM5vFjLCfpSDSE90EFgMY/io2CyjuSpawu359sUMTRk2Fn+9CJiYlFbv7EFE7cbWbuK0vlp6fKj/WcXDcfWWiE5VLKJs+9Wb6F+f5HoYsuSXy7+3+v0zWLJF4i0GGf0vynmsnipk5B6rdl1HGzOxwsR4gkkbHzg1XMN0KSqnUaC41tNYutLd8t7tqP/jp0ml545VpjQ74NCzo8FTQRHoqA16jrFsAlOkdhn5LB8=

X-Forefront-Antispam-Report:

CIP:78.46.149.17;CTRY:DE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.goldner.net;PTR:static.17.149.46.78.clients.your-server.de;CAT:NONE;SFS:(13230031)(39860400002)(346002)(396003)(376002)(136003)(230922051799003)(451199024)(64100799003)(48200799006)(7200799017)(1690799017)(61400799012)(82310400011)(46966006)(9686003)(41320700001)(31696002)(2906002)(498600001)(166002)(47076005)(35950700001)(41300700001)(81166007)(26005)(42882007)(82740400003)(336012)(78352004)(8400799017)(786003)(42186006)(4326008)(67280400001)(316002)(40480700001)(6916009)(70206006)(70586007)(8936002)(558084003)(8676002)(19625305002)(5660300002)(38122002);DIR:OUT;SFP:1022;

X-OriginatorOrg: fw74778.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Dec 2023 00:34:26.4212

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 6e4ec2b7-34c1-43f9-cf27-08dc04e13fff

X-MS-Exchange-CrossTenant-Id: cf8e0fc4-379f-4956-955b-8d3e8197e989

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=cf8e0fc4-379f-4956-955b-8d3e8197e989;Ip=[78.46.149.17];Helo=[mail.goldner.net]

X-MS-Exchange-CrossTenant-AuthSource:

MWH0EPF000971E2.namprd02.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR07MB7552

X-Spam_score: 6.5

X-Spam_score_int: 65

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: (1) Notifications



Content analysis details: (6.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[40.95.38.52 listed in wl.mailspike.net]

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[40.95.38.52 listed in list.dnswl.org]

0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=NAM11-DM6-obe.outbound.protection.outlook.com;ip=40.95.38.52;r=doctor.nl2k.ab.ca]

0.8 DKIM_ADSP_NXDOMAIN No valid author signature and domain not in DNS

0.0 ARC_SIGNED Message has a ARC signature

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

0.0 ARC_VALID Message has a valid ARC signature

1.0 HK_RANDOM_FROM From username looks random

0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words

2.0 PDS_HELO_SPF_FAIL High profile HELO that fails SPF

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_REMOTE_IMAGE Message contains an external image

Subject: {SPAM?} Order Verification - DEWALT 200 Piece Mechanics Tool Set

X-Antivirus: AVG (VPS 231224-4, 12/24/2023), Inbound message

X-Antivirus-Status: Clean









(1) Notifications










































































































Harbor Freight phish from Micosoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 24 Dec 2023 21:24:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHcUv-00000000AAU-1uBt

for dave@doctor.nl2k.ab.ca;

Sun, 24 Dec 2023 21:23:25 -0700

Resent-From: The Doctor

Resent-Date: Sun, 24 Dec 2023 21:23:25 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-vi1eur04on2125.outbound.protection.outlook.com ([40.107.8.125]:51632 helo=EUR04-VI1-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97 (FreeBSD))

(envelope-from )

id 1rHYou-00000000IbI-47Fl

for doctor@doctor.nl2k.ab.ca;

Sun, 24 Dec 2023 17:27:52 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=kKVM9/vg7R0tN0mBbzwHM581XwhU+yZ0ChatnpT9a4ot+ah2YMOFTTyXzxb2QpbSN835y99kpcSy+c6/LHBjTYoRiafnDJxhM9vJTcCk/2I0zjY2zqWZWsFA28Q9V8hGZRgMqAV7CM506Hg96J+erxyg3qHcd69kq9RCWiAzdHTseA13TnXn5WWT9aSS4NJFdruYn/ApZDISc29wo9ssWX6CkThEhLqdaiSBNkqe3IkPxIXNB/BXF35WLx7xC+KDbDpazSdUZfyszO5Lh6WEucsPzJR8A2xqqShXRviR/sLZ3FSLEloek7xKxzaWdfWA0gqmAhoVZfDkVCXxCMqGug==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=GKdbOx2mytdAFq1wHDjrsrbwg1rM3UwT4vhGi067lZI=;

b=KiV/xXe1QUl1B/kJbUSsoT75/nElUuYnjw97YzyojVm3peiVWXjvDOAv4DbCPgoJG36ECOgHUW+Iq8IE/s0fc8nmSK3tPAqRxQ3eaB42jBZ8C8eHw4xndzOSr3vzycrBZu+VzckSCbMsV6Xjxk/xQgKTeZdJUKVhO2LJYySpbF4WSqQ93mhiG8RJUY/+a0wwcVeMH7yLjS9Z8UIWIZYw/sRLDCzOSSyMbZvDD6QcPHJdW0h2++n/TwNCtJiuPn5QMLo9y0Bth0qLb1c/dTwTNsrHD8/DLoBeZEkKTyKcm6WManCnVhisyoNPkiWSS9nEi4Q5E1v4GjN4MUHrDcjfzg==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

139.144.212.20) smtp.rcpttodomain=doctor.nl2k.ab.ca

smtp.mailfrom=or08ms.onmicrosoft.com; dmarc=none action=none

header.from=or08ms.onmicrosoft.com; dkim=none (message not signed); arc=none

(0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 139.144.212.20)

smtp.mailfrom=OR08MS.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=OR08MS.onmicrosoft.com;

CC: doctor@doctor.nl2k.ab.ca

Content-Transfer-Encoding: 7bit

Importance: high

In-Reply-To:

From: =?UTF-8?B?SGFyYm9yIEZyZWlnaHQgQ3VzdG9tZXIgU3VwcG9ydA==?=

Date: Mon, 25 Dec 2023 01:22:30 +0100

Content-Type: text/html; charset="UTF-8"

To: doctor@doctor.nl2k.ab.ca

MIME-Version: 1.0

Subject: =?UTF-8?B?SnVtcHN0YXJ0IFlvdXIgRElZIFByb2plY3Qgd2l0aCBhIEZSRUUgUGl0dHNidXJnaCBUb29sIFNldCE=?=

X-TOI-MSGID: <1702963052.36E69A8195666.1703463750600@thompson.com>

Message-ID:



X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: AMS0EPF00000194:EE_|AM0PR10MB3281:EE_

X-MS-Office365-Filtering-Correlation-Id: 4fc5d112-7989-468a-9f13-08dc04e006be

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

UjCq2k1nzKjXPLetE8vNZKCkQdDz4YHlFPlUSuWF0K10MynVsB3/e7isAiw9B61y3yT0j5WfNeudzkHgKWclZp6DGkWtm/6V/OEpheWya3bn13IIfEnywUuGpZ8GIakMlfusiBe7TbAvm62vsBdl7AHVt9xGA2FGlPClUeLuRGmQfYpd+lGKtj7PJIb8goo5sAYtzjJWeq5CWSGuhPw2YxhqlEfjCcsP8p1WgkSyZIdfM3BD/7PZ9nRkYsrbkuoPEhA9t+/J6bYwtSoPQw0dxc5C23IzlFcSMBqNREpfRvscZbKNAEFwqo/7hgdUvMk3q8Fxc9tbgUC0JGYi7IVmZLshwE0t1SXkgwTagmUrqHWPakfY1e7VExc/tDEqNSqaOtaowdElaCLu2EFDIRo4034i9wgLC38tfr5peYswcJWQaxsycEmisBfvNo/5JhXX6TYcMY7hg4E7HoP7McJLMAfgOi0Creowoui97eG5t+6lE3PDogi01vOTcPnl0kdMEv37fbxER/IO4cKFasyLvQ==

X-Forefront-Antispam-Report:

CIP:139.144.212.20;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.thompson.com;PTR:139-144-212-20.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(396003)(136003)(39850400004)(376002)(346002)(230922051799003)(1690799017)(186009)(82310400011)(451199024)(64100799003)(61400799012)(40470700004)(46966006)(36840700001)(478600001)(2906002)(8676002)(8936002)(5660300002)(19625305002)(40480700001)(9686003)(6916009)(70206006)(4326008)(40460700003)(42186006)(316002)(786003)(70586007)(558084003)(336012)(86362001)(47076005)(26005)(41320700001)(36860700001)(41300700001)(34020700004)(31696002)(166002)(82740400003)(81166007)(146393003);DIR:OUT;SFP:1102;

X-OriginatorOrg: OR08MS.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Dec 2023 00:25:41.0234

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 4fc5d112-7989-468a-9f13-08dc04e006be

X-MS-Exchange-CrossTenant-Id: 0919be8b-ccb7-4282-8d6c-59bc2bf4ed75

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=0919be8b-ccb7-4282-8d6c-59bc2bf4ed75;Ip=[139.144.212.20];Helo=[mail.thompson.com]

X-MS-Exchange-CrossTenant-AuthSource:

AMS0EPF00000194.eurprd05.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR10MB3281

X-Antivirus: AVG (VPS 231224-4, 12/24/2023), Inbound message

X-Antivirus-Status: Clean









Harbor Freight