Harbor Freight phish from Micosoft Outlook
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 02 Jan 2024 10:30:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rKiZg-00000000KiY-1LK5
for dave@doctor.nl2k.ab.ca;
Tue, 02 Jan 2024 10:29:08 -0700
Resent-From: The Doctor
Resent-Date: Tue, 2 Jan 2024 10:29:08 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-bn1nam02on2080.outbound.protection.outlook.com ([40.107.212.80]:42626 helo=NAM02-BN1-obe.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.97 (FreeBSD))
(envelope-from
id 1rKhWu-00000000ChL-3ECd
for root@nk.ca;
Tue, 02 Jan 2024 09:22:16 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=k2pMrfgkevuIUc/vYKjTJaBM642r8u67vICWVvWvqSDFU42vgmg4hUBEkCsUET9qcb3mLCujxm045IX9FPPzadforL9yhhFd3tNmNETULesl1mLU52opWebkd8fLSCnm0EC6fC4drQR8+bDQbUqJxX7PUa0F7+KDwKBqrFAgiXgP4VWONvK5LMjsn+515vJJogpcX2vWU99YllHdACmEilfypCeFI/59EErUcnOCNahtNRcg3+uHdyMJd3/j959kwWKMOHyypQqW5ds87K479Yz2hxYYpINGlNAPAwScYoT0DDaQiSK2+UZ2jRa5TiDqJstRWhxo9hf8eVn/OfDG9w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=kxajbDdO+q5DNjRQgpRAOpOQ1PIcBAn3M6NWhLe01YU=;
b=TxyyAGPzeClcWAH4u9fEYPjXviABMX7hk9PV2NC9SFtxyNlmVwOztyGfQdFfv74LIyu8OTGGfR78PQHaG9jgrlYXDx2cPvcSCtxKYviXjKa7gA/bjx2MpsfCM46FJejKA649UYY/8BPWK4JDAbqMddKX34p2XK/w1XEek9khIWhc6q4ZXA1DTJgdjFD5jNQczjWNZ+DiwjTf65jVEsA04eZnKd/3vqmHBwwN5iVSsFSogarDQ2IO7o48sj+QcEocl39sSl3tVFgZkssjL5CpflJDvAWz1RvaopiWK2Ps+GsnxiQtnlZaQUPrx/84aXsJxQ69uYTTlrpkW1IHYHj6Rw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is
78.46.149.17) smtp.rcpttodomain=nk.ca smtp.mailfrom=fw74778.onmicrosoft.com;
dmarc=none action=none header.from=fw74778.onmicrosoft.com; dkim=none
(message not signed); arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=fw74778.onmicrosoft.com; s=selector1-fw74778-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=kxajbDdO+q5DNjRQgpRAOpOQ1PIcBAn3M6NWhLe01YU=;
b=nnhCCtnwtDNgJL47wCw+80dFhVM8yI81bqh4y/HVtXArjFZEVonxMXjnJSEm9K0NcrXGFL6EVJqdKlvT3NBnnae1P1t3R926XeOjp8x41FOqudqlR/PiGr7xALKnNpc5FkVeAdPcVTfawnC/LrYAArheTEPlNiH72HsFce9yR3sTRamT1UQi2IczAZha6U66S4H3+jTr9lInBCt+XjJEJAZgOW7PcqIkJRWWSGvtHyKKmeRc86BShpaEAsyDjF859SqeUPZYQJ5aHePnh+1LVUEWKPAUtBLSv4gZ53pbAhUtjFMgwgvuBRnv3K/MArFlmXw8+uxjH03A/lBZQjGStQ==
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 78.46.149.17)
smtp.mailfrom=fw74778.onmicrosoft.com; dkim=none (message not signed)
header.d=none;dmarc=none action=none header.from=fw74778.onmicrosoft.com;
Date: Tue, 02 Jan 2024 17:15:48 +0100
Subject: =?UTF-8?B?WW91IGhhdmUgd29uIGFuIFBpdHRzYnVyZ2ggTWVjaGFuaWMgVG9vbCBTZXQ=?=
Content-Type: text/html; charset="UTF-8"
MIME-Version: 1.0
From: =?UTF-8?B?SGFyYm9yIEZyZWlnaHQ=?=
Importance: high
Content-Transfer-Encoding: 7bit
In-Reply-To: <2VDkuretc0Ber3UmZTLTUCZcQD6Wms@mLPuMdrxkA.fw74778.onmicrosoft.com>
CC: root@nk.ca
X-TOI-MSGID: <1063958650.74A810259C49D.1704212148848@goldner.net>
To: root@nk.ca
Message-ID:
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: CY4PEPF0000E9CD:EE_|CY8PR07MB9428:EE_
X-MS-Office365-Filtering-Correlation-Id: c5224b62-7a1a-49d7-9d20-08dc0baec427
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
iOc0+RrmnrXq8M73herKKL2vHoUoExRp1nTOBhjoi/+/dRF6is/ylK8iZN2QqckFBVM/91WKETSH3N49bOptZC93+iD6pSFXgyVABn21zeq99o7cLjsq8Nij8i9YuBbYlr6jqY/A8ijRQ0AtNNIcdaGvEUU5Uky/NQqAIPcbQsSHf4ovR4d5ycmY1Bu8FlCIgdsUHLMQEmuvVEuqb2DXyTh4V2di5Tqedba+jQr+lpgSgNaFAAY8XT74yYhuRM1fOEfivQdgBXdRiY+xoNtiNoUlGTRdib1XWVTpk6cKgJ9G+9b/xnJ269Rd48bFuiZJnMjBouq7zFhSknR8SPdMmyHqhOeiKUMupLMLOg6sNfxmCPn1po7Za1+Ibit5vYdMmXfNI9oN7lf8S4NbCCW8dIm5QhpgoRiAyUr8q6thJUZzklTsmTdLS552KV687NhzIhwq+h9arktRB4E6OwHEmshocROoktQ+lUmJWro9NlB3uBXMozGkBM615EYTgpdcCaksMP1XLuti7M83EkWF8XMUVkQus8Tg77PXbXUdCAg=
X-Forefront-Antispam-Report:
CIP:78.46.149.17;CTRY:DE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.goldner.net;PTR:static.17.149.46.78.clients.your-server.de;CAT:NONE;SFS:(13230031)(376002)(136003)(396003)(39860400002)(346002)(230922051799003)(82310400011)(451199024)(186009)(7200799017)(1690799017)(64100799003)(61400799012)(36840700001)(46966006)(40470700004)(558084003)(19625305002)(2906002)(8936002)(8676002)(4326008)(316002)(6916009)(42186006)(8400799017)(786003)(67280400001)(86362001)(5660300002)(478600001)(31696002)(40460700003)(40480700001)(41300700001)(9686003)(26005)(336012)(166002)(47076005)(70206006)(70586007)(81166007)(82740400003)(41320700001)(36860700001)(18963002)(15913002);DIR:OUT;SFP:1101;
X-OriginatorOrg: fw74778.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Jan 2024 16:20:41.9788
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: c5224b62-7a1a-49d7-9d20-08dc0baec427
X-MS-Exchange-CrossTenant-Id: cf8e0fc4-379f-4956-955b-8d3e8197e989
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=cf8e0fc4-379f-4956-955b-8d3e8197e989;Ip=[78.46.149.17];Helo=[mail.goldner.net]
X-MS-Exchange-CrossTenant-AuthSource:
CY4PEPF0000E9CD.namprd03.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY8PR07MB9428
X-Antivirus: AVG (VPS 240102-4, 1/2/2024), Inbound message
X-Antivirus-Status: Clean