Phishing for nk.ca credentials from 149.50.209.96 - datacamp.co.uk

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 11 Jan 2024 15:57:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rO3xw-000000001ds-3wVR

for dave@doctor.nl2k.ab.ca;

Thu, 11 Jan 2024 15:56:00 -0700

Resent-From: The Doctor

Resent-Date: Thu, 11 Jan 2024 15:56:00 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from bernsoft1.ultasrv.net ([149.50.209.96]:39960 helo=mail.tazama.tv)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rO1y3-00000000LMe-21Lt

for root@nk.ca;

Thu, 11 Jan 2024 13:48:03 -0700

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=digitalduka.com;

s=default; t=1705004676;

bh=O36adjSlsGT9IV2xQtp17fw5WEult2dPaSvxF5GW1vU=;

h=From:To:Subject:Date:From;

b=UKyXeXftBNfudO+T7xgLDZ0eEcfYyc0D6/IXbVzooFkwwszhAcV5mopO65pngSggY

fsLrvPF5FoFrNFWbP36ssDGI8Pijkw8glTtcVKqEgz+enO3xDDPF90H2coxEKL0I7M

WmO8leM0KbxR25Ekf8VV1YHqg8ARB7rbroI8d02tRcsyMHIfdtMBdGXxZBdEKSMReJ

GXk6H0wmpZ9lcwjZvZ3Wpjm4sP8b8b1/mzzCfUo0if2KSr0mPZEiOCByai4PT1v13P

WbY6UFLaf9VtjtOIN5DENG7C5FkoDKHtuiY8pdpLftiAeW88QpZ2j80qj29JaWmAVn

TGnPJQmuWJmBg==

Received: from static.116.24.108.65.clients.your-server.de (static.116.24.108.65.clients.your-server.de [65.108.24.116])

(Authenticated sender: admin@digitalduka.com)

by mail.tazama.tv (Postfix) with ESMTPSA id 4AACAB5C35

for ; Thu, 11 Jan 2024 20:24:36 +0000 (UTC)

From: nk.ca

To: root@nk.ca

Subject: PASSWORD EXPIRY NOTICE FOR root@nk.ca

Date: 11 Jan 2024 12:24:35 -0800

Message-ID: <20240111122435.D6A7945F34AF9192@digitalduka.com>

MIME-Version: 1.0

Content-Type: text/html;

charset="utf-8"

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 13.0

X-Spam_score_int: 130

X-Spam_bar: +++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Password Expiry Notice Dear root@nk.ca, Your email account

access is set expire in 3 days from today.



Content analysis details: (13.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist

[URI: digitalduka.com]

1.6 RCVD_IN_MSPIKE_L3 RBL: Low reputation (-3)

[149.50.209.96 listed in bl.mailspike.net]

-0.0 SPF_PASS SPF: sender matches SPF record

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

0.1 DKIM_INVALID DKIM or DK signature exists, but is not valid

0.0 RCVD_IN_MSPIKE_BL Mailspike blacklisted

0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

0.7 TO_NO_BRKTS_FROM_MSSP Multiple formatting errors

0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable

1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)

2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level

above 50%

[cf: 100]

0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%

[cf: 100]

1.6 FSL_BULK_SIG Bulk signature with no Unsubscribe

Subject: {SPAM?} PASSWORD EXPIRY NOTICE FOR root@nk.ca


















-office-part-9-shadow-style/256/Email-alert.png" alt=3D"root" height=3D"150=

">





Password Expiry Notice




Dear root@nk.ca,





Your email account access is set expire in
ck; font-weight: bold; text-decoration: underline;">3 days
from toda=

y.





You are required to take immediate action to retain access and to
=

prevent access limitation on your=20

email and other essential services.








Note: nk.ca will not b=

e responsible for your negligence.






Regards,
nk.ca - Team.














Heater Phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 11 Jan 2024 12:55:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rO17v-000000008Q0-2Zv2

for dave@doctor.nl2k.ab.ca;

Thu, 11 Jan 2024 12:54:07 -0700

Resent-From: The Doctor

Resent-Date: Thu, 11 Jan 2024 12:54:07 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-westus2azhn15013027.outbound.protection.outlook.com ([52.102.136.27]:24600 helo=MW2PR02CU002.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

id 1rNzFB-00000000JHx-0YLL

for doctor@doctor.nl2k.ab.ca;

Thu, 11 Jan 2024 10:53:32 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=OA4BHrg5xxgAfj7atapWmpf8ZTThujnp+uS5BvkDcuItqMtT+YZgVU5YfT4UnXxf8v4T9DvbhAjkECRgi+4dK7Zu/afdWNJue41hrbDfezj3T8GQPN5RUAZOjkvhgleeQDC/dS6M1jK7SpGFwhMpErfNVkTtxYm5cB+K55rjWBasKspbiIRhC84OP0mWQpLUt3x30UNvMja8W/4w+m02I7YYdvhX9yZ42u5JijAmLCdtG+ldzeaZgPGSIGIMHS832H+n0b0ihnMisGgngeAYPvNg8D962tJmwocJWyA9Ir+m6971oL+MUVu+vIvJREVatXl02JDpj7sEuxlhpbfChw==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=4TLMn+dTvUHATV9NzigG8aBgvZnAfkIoOrk2iP/4kf4=;

b=CxOpohhvTszovRSCd774AWOLDLE4QJ4vrmmGt4U5QofhRjim1f/a7yCT/djOMe9aX50RlSfM7qnx9OiNwS0WhzN429ucxF7mKVKsQ4zpMJQocMa9mcFapQI2NQUAPj4YcFQeMk3kINNU+3/zf5gJHoM6Rclri3zIm+zAyy/CnzjVhr8AW66mGJf1PHtEpTScAb60xA0WjLLB5xkPZ13jxpHw2/1fbGypTJjzJd1YMPWraZ7GDVi4ypEiAnJc0XuQapeTSW1i3ZVJyxmMs1PzGtbF78ZxqRW5C7K4gfeVR4F5kK04k34aJTmmALq9hpsUziphMjzUl5fBCA/sVj7IXg==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none (sender ip is

45.91.171.107) smtp.rcpttodomain=doctor.nl2k.ab.ca smtp.helo=mail.beatty.com;

dmarc=none action=none header.from=43a4s5k.onmicrosoft.com; dkim=none

(message not signed); arc=none (0)

X-MS-Exchange-Authentication-Results: spf=none (sender IP is 45.91.171.107)

smtp.helo=mail.beatty.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=43a4s5k.onmicrosoft.com;

Date: Thu, 11 Jan 2024 18:47:52 +0100

MIME-Version: 1.0

Importance: high

Content-Transfer-Encoding: 7bit

From: Portable Heater

To: doctor@doctor.nl2k.ab.ca

Content-Type: text/html; charset="UTF-8"

In-Reply-To:

Subject: Elon's Innovation: The Ultimate Heating Solution!

CC: doctor@doctor.nl2k.ab.ca

X-TOI-MSGID: <736747251.F901F9397CDFB.1704995272576@beatty.com>

Message-ID:



X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: BL6PEPF0001AB74:EE_|SA1PR05MB8014:EE_

X-MS-Office365-Filtering-Correlation-Id: 16648a52-9c08-4c6b-b752-08dc12cdec77

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

O/FW/8OwsIoFfgZwJBWfSU45wGf9KBXuGHJqqwONfs5QcJhy0dCI+vlIDMTylYt7KWY7Eu3g71wZXVTrvWUBhVth6k2DaUhCzTOYxrPc9JbifBSI+djmPe7gTdrBgxvdTsUi9BeRlL09TAugmvbT2+0RO7yd+Ij/3STdANNOwjQtmGwvv5wqNeUCD6xEAkEzUdCDIxE0u4gmmOSaX0MuQO3zCDhr2AQ6tNCPU9OSzNTfNZ9k3sksBjUERbWxBuflAQGFgQ0pMNr7hrOsyl5CNV3r2d+lw1ZW/LJWvRFDiUmGTVkK5BokObRM0eeDRlUB7S7oB7EBunQX6mIDQBIiP5Ye6U9VE7KyzxjXFJcOWbkRTLJ/LHIjnuQ7F1bISJw2KXySfTIpZ9ZtWu6e+i5yW4H9fwlOCjEF7G9ffZ1JfOGR/tNmYA/cwmdCC0feE5MQxmL4whwe97jXxbb/rPV6TovaeLI4o8k/1A1bd1vUXwfjmuzR5t/svxZpLSU3MZ0hasfBdUWf3oP1eXgEc2s9jAwotANbvtPFmPWdVPV6K61BFbZ/UMvbfs+8isRx2aXUWSlApnojJfjPVLCgq/PNFGcq+nKEX0ovf4fWMwRySOA=

X-Forefront-Antispam-Report:

CIP:45.91.171.107;CTRY:SE;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.beatty.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230031)(39850400004)(136003)(376002)(346002)(396003)(230922051799003)(64100799003)(61400799012)(1690799017)(7200799017)(451199024)(82310400011)(46966006)(4326008)(6916009)(8676002)(316002)(82740400003)(5660300002)(8936002)(2906002)(786003)(9686003)(40480700001)(42186006)(8400799017)(26005)(70206006)(498600001)(78352004)(3082699006)(70586007)(67280400001)(336012)(42882007)(47076005)(17440700003)(35950700001)(41320700001)(166002)(81166007)(41300700001)(31696002)(558084003)(38122002);DIR:OUT;SFP:1501;

X-OriginatorOrg: 43a4s5k.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Jan 2024 17:51:22.1663

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 16648a52-9c08-4c6b-b752-08dc12cdec77

X-MS-Exchange-CrossTenant-Id: c4b06595-23ab-43c5-85e0-bb27a3ff5659

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=c4b06595-23ab-43c5-85e0-bb27a3ff5659;Ip=[45.91.171.107];Helo=[mail.beatty.com]

X-MS-Exchange-CrossTenant-AuthSource:

BL6PEPF0001AB74.namprd02.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR05MB8014









(1) Notifications










































































































I1.17KL0LD35.4KI2.16KwhoissourceRank10.8MPIN0Summary reportDiagnosisDensity00n/a

Fedex Phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 11 Jan 2024 12:53:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rO16f-000000008E9-47QE

for dave@doctor.nl2k.ab.ca;

Thu, 11 Jan 2024 12:52:49 -0700

Resent-From: The Doctor

Resent-Date: Thu, 11 Jan 2024 12:52:49 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-bn8nam12on2045.outbound.protection.outlook.com ([40.107.237.45]:65121 helo=NAM12-BN8-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rNyIu-00000000Fpc-3Bfx

for root@nk.ca;

Thu, 11 Jan 2024 09:53:20 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=NU7OIuPCKqB/tHSzElcLGA69rfVvKCcS5BFMYNOZy57pXGroBETdce+muwh+9vNGDZMg0Pm2dljPy5JuOIjMUovskUEc2VSFNZTpBnI7WTv8+L7qOaue/k8tRKhSjfDQwxX0rcc31iO3ykzwOYVAPaWSqWaMc3/8fAn29CHZvc8Pg6R1OvdYVf7V6eTg5OXzOEgI0k8a9L+ckYf/W1xiwvS6JAVraeWgrvXOvSGxKx9t52hP3Od93J6PMlyuNYrDksFiRgtF85n8r/BuDVM/oi2wO6cncF3rrnw1zzny6B5VK/jLukk7RT2VgeMxZozY2FoBNMF1p1AGs8DTRBWGyg==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=GyUqRocvtycVAF93CpoF0t9mZYqFy+oPeNqYynerq/c=;

b=Bq2ZNyqZOyDHnWrKonp+snvHbGgqzkZlk/vsqxQ0vr32XntL0jVKbgRQvCGVApA6ql/pRro1J/O2DCSgKld4LyNwprt9mk5j1QOOdenUyFf4UHjQ8hdCFTM0aC/E9qEjJ9EaH5It3asF2EOIB5GMEI1LZWcXbvuXAa+vH+9qvOyz9DNZH+/6SP9bA0a9QvkUZSF0e0KEflGP1vKSUJvaYfKNaWxfc0vnyn0ue9V7xUprWuNsMvJUaMaw7IF/EZEtBF3rZzVDxCgZSX96iigSfT5+SgX+TItzjyPMv75mWdFUe7+h3ZAyreF5L2FerkZO8hzPXiRRtIfJI6sTJAPecQ==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

172.105.148.13) smtp.rcpttodomain=nk.ca

smtp.mailfrom=v529s1yfe486.onmicrosoft.com; dmarc=none action=none

header.from=v529s1yfe486.onmicrosoft.com; dkim=none (message not signed);

arc=none (0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 172.105.148.13)

smtp.mailfrom=v529s1yfe486.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none

header.from=v529s1yfe486.onmicrosoft.com;

Content-Type: text/html; charset="UTF-8"

Date: Thu, 11 Jan 2024 17:48:29 +0100

Subject: Shipping Notice: Your Package is in Motion

MIME-Version: 1.0

From: MemberSurveyPanel

CC: root@nk.ca

To: root@nk.ca

In-Reply-To:

Content-Transfer-Encoding: 7bit

Importance: high

Message-ID:



X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: BN8NAM12FT018:EE_|MW4PR13MB5962:EE_

X-MS-Office365-Filtering-Correlation-Id: ac558680-95fe-445c-c7b0-08dc12c57f43

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

+dhQrrPc8G4VC2WwRBlcR4s5eY+MeBjPOzr5mr8iYKvoHiOGHcfMro01ZD/R8bjW9k1rWwNwX5YjYpMd/Yn13fN/FRXR9lDrg6+0xRFhRpWiH+1+KvfRpdkwvSKcSStk3jgcNMcS0Ctfzu94zEF8TW3IPEcRh7+THjnBS5KIpsqTVO39wOR0uedalnwoDH5k/aU4afaskF2YTHGV3YF5IhPsph6OB/R2r1bTMqLECk8jqWGL1btXgw4wccaVavlCaLMCMPPguSUn+EiIm1S2fkTEyMcX/gQVMKc5n6dLM4w7BI9Jmr8q+1SUT8iBovij5OAn/ypDMaXv3ddwsNW6zm6hTiruq6BAoEsy/oxN+1xOeUdxyy60VGkeucAhwI9UTU48zjiiGvGRM6ewEdW48FVYxHowx1NaQIC4XVs+NjjR8qpKKjfhcStARAX1zzEwY+d0xCj+RlnWP0JqM4EpTT0O732ONkBfmqkw6e2NEVjjxtfDe1nbfUOu9oPFL3MFgdWWwx64YZgS4gXb8p2znObHRaUI6M1jyDuRJt3iILkJ+3Yj3FVeyWa5sU//uZH2

X-Forefront-Antispam-Report:

CIP:172.105.148.13;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.thompson.com;PTR:172-105-148-13.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(376002)(39860400002)(396003)(136003)(346002)(230922051799003)(82310400011)(186009)(7200799017)(64100799003)(61400799012)(451199024)(1690799017)(36840700001)(40470700004)(46966006)(67280400001)(8676002)(4326008)(8936002)(478600001)(36860700001)(6916009)(70206006)(786003)(316002)(42186006)(26005)(46730400001)(70586007)(9686003)(336012)(47076005)(5660300002)(41300700001)(2906002)(558084003)(166002)(82740400003)(81166007)(34070700002)(66899024)(86362001)(31696002)(41320700001)(8400799017)(31686004)(40480700001)(40460700003);DIR:OUT;SFP:1101;

X-OriginatorOrg: v529s1yfe486.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Jan 2024 16:51:03.1523

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: ac558680-95fe-445c-c7b0-08dc12c57f43

X-MS-Exchange-CrossTenant-Id: a3a2ce3b-7d94-4495-b8c8-943d9c957f44

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=a3a2ce3b-7d94-4495-b8c8-943d9c957f44;Ip=[172.105.148.13];Helo=[mail.thompson.com]

X-MS-Exchange-CrossTenant-AuthSource:

BN8NAM12FT018.eop-nam12.prod.protection.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW4PR13MB5962









(1) Notifications












































































































I1.17KL0LD35.4KI2.16KwhoissourceRank10.8MPIN0Summary reportDiagnosisDensity00n/a

Fedex Phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 11 Jan 2024 12:52:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rO15A-0000000085v-3aOB

for dave@doctor.nl2k.ab.ca;

Thu, 11 Jan 2024 12:51:16 -0700

Resent-From: The Doctor

Resent-Date: Thu, 11 Jan 2024 12:51:16 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-bn7nam10on2091.outbound.protection.outlook.com ([40.107.92.91]:8672 helo=NAM10-BN7-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rNxlh-00000000DF8-0ipQ

for doctor@doctor.nl2k.ab.ca;

Thu, 11 Jan 2024 09:19:01 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=CKWLydNz0vv8DX48j+Bcvq9igMSkA3GhRNLenTd98EsQrvflnFLAF4u0i6JEO149x6DzkdGjlQT+av+oxKSGiTyE1hnjT8fTAfGmnwkFAijIsRo6qjDaCP0P40OaJtKtcVV0fhlSj395DSaMigT+GCxVvSkxiepVBIBVnCxHjltOn/YF4afEQPBTXSBe7+NEAXFTTwXYSGj8ARg5EqhQUbcVOQpO1lJygbJDAvIl9Evxl8T/fMVoBBKA2lGAKy6dxch51LuG6VbZPD24SB38mjdMnQPW+AcI+ex7mzl2/Fs3PZRcTD6ZuLmvZHMlj1jwn//GxfqzdQ9BfM3fcONIgg==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=CvUho8hZVrtYu9XM7HhFRP7jU0zCgPGbLft43QwrRmg=;

b=KIbO4j8MxmjThEfPudIsY1B5KuS49NxR57F3CW8Dhz7hVzmYYWaGUcpO4zH6Yg90fr2+x5Tycyh9oeRvmNzrm7ITW6b32BAOd9oNc+r18Ar6XM4trd2P7f9Y3ZAaDGhuLA7ld2WwHZWbsC84SfmU5Mn0XZ8IuNn6iLvYpH6HJwMUMc5xdZOwX0z/zjuB0GUJTaPhfDYNJ/K7oMoE+6eOxotftPvytp8dgzc5EUzraoOJmy+nE+3v5MDESBZsalcBljPhuJE8B5QAcNL4heTO+hzF9Ypzm9efr7n5RdzGIWUbFgyNa78dQzVLvVsuxZhvx1gA6hjHBHk7fgg1KoKwiw==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

172.105.148.250) smtp.rcpttodomain=doctor.nl2k.ab.ca

smtp.mailfrom=teuhcnsf54ov.onmicrosoft.com; dmarc=none action=none

header.from=teuhcnsf54ov.onmicrosoft.com; dkim=none (message not signed);

arc=none (0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 172.105.148.250)

smtp.mailfrom=teuhcnsf54ov.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none

header.from=teuhcnsf54ov.onmicrosoft.com;

CC: doctor@doctor.nl2k.ab.ca

Importance: high

To: doctor@doctor.nl2k.ab.ca

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset="UTF-8"

MIME-Version: 1.0

From: Fedex Shipment

In-Reply-To:

Date: Thu, 11 Jan 2024 17:09:01 +0100

Subject: Package in Transit: Stay Informed on Your Shipment

Message-ID:

<0579616c-efa9-4b14-be7b-b75710995126@DS1PEPF00017096.namprd05.prod.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: DS1PEPF00017096:EE_|MW4PR19MB6603:EE_

X-MS-Office365-Filtering-Correlation-Id: c929632d-aebb-4183-7170-08dc12c0b6f3

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

nX94CshPegJ9LM14d3pgjbBYLezCKnOckJMq4dnjJmSjm4bMSYZ+AvXO0yjIQ328kezZOPFdiSsQtQWvjFEjP5bjxTEgIfLQ7PAXM/daEswRxOfXI9W+AesXB9rj9zSi4cGu6ptVt1P9Qp73aOLrmD/bx37359y8ZqSi1WQzwe5vVQk9+ww5tT+KVf5iKqjcCDOu2Ysy+Gs7CkT2t8I76PJLQEKE7QWpN9Ss4H0y3lf06J3aMZtrF7Ouoax5Ife4To27TcQOFzeHw4b9LpokYiWJChuDVL1spNOD/kPZ9ljjbmpJgr1wSLmsRojr0FQIqTbZdBO2hMTHOQETgax6FAX5/lHWE4LsqLjOiGBNJvgNeShv2BD8O6aNQZBPuJGbVsW7sYePlY2XRM9N6ianUNlSnSP3V3enIwBL9QWATK5bsXrF0iSDS8A8rf9/GqCAC4PdhP0e0R3kK3KYW4FwBcZ/3kC2/JY/bpP/3EfYH1tIxVC7J7Ahh7IZ4DwCPlgP4Q5ryn6h+32xGqZqxlX0bg==

X-Forefront-Antispam-Report:

CIP:172.105.148.250;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.simonis.com;PTR:172-105-148-250.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(396003)(376002)(39860400002)(136003)(346002)(230922051799003)(451199024)(1690799017)(7200799017)(61400799012)(82310400011)(64100799003)(186009)(40470700004)(46966006)(36840700001)(478600001)(336012)(10290500003)(9686003)(5660300002)(42186006)(2906002)(41300700001)(4326008)(6916009)(8936002)(67280400001)(47076005)(8676002)(70586007)(316002)(786003)(70206006)(34070700002)(82740400003)(81166007)(558084003)(166002)(31696002)(86362001)(36860700001)(26005)(8400799017)(40480700001)(40460700003)(41320700001);DIR:OUT;SFP:1102;

X-OriginatorOrg: teuhcnsf54ov.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Jan 2024 16:16:49.1258

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: c929632d-aebb-4183-7170-08dc12c0b6f3

X-MS-Exchange-CrossTenant-Id: 7c267c28-5a13-4bd3-b9c5-c1866e238faa

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=7c267c28-5a13-4bd3-b9c5-c1866e238faa;Ip=[172.105.148.250];Helo=[mail.simonis.com]

X-MS-Exchange-CrossTenant-AuthSource:

DS1PEPF00017096.namprd05.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW4PR19MB6603

X-Spam_score: 5.1

X-Spam_score_int: 51

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: (1) Notifications



Content analysis details: (5.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[40.107.92.91 listed in list.dnswl.org]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[40.107.92.91 listed in wl.mailspike.net]

1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist

[URI: e7azgci4k4.storage.googleapis.com]

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

-0.0 SPF_PASS SPF: sender matches SPF record

0.0 ARC_SIGNED Message has a ARC signature

0.0 ARC_VALID Message has a valid ARC signature

1.0 HK_RANDOM_FROM From username looks random

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[donaropad_mnxtqadlmvp(at)teuhcnsf54ov.onmicrosoft.com]

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_REMOTE_IMAGE Message contains an external image

Subject: {SPAM?} Package in Transit: Stay Informed on Your Shipment









(1) Notifications












































































































I1.17KL0LD35.4KI2.16KwhoissourceRank10.8MPIN0Summary reportDiagnosisDensity00n/a

Ace Vacuum Phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 10 Jan 2024 19:47:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rNl5P-000000002cl-1JJA

for dave@doctor.nl2k.ab.ca;

Wed, 10 Jan 2024 19:46:27 -0700

Resent-From: The Doctor

Resent-Date: Wed, 10 Jan 2024 19:46:27 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-dm6nam11on2086.outbound.protection.outlook.com ([40.107.223.86]:36896 helo=NAM11-DM6-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rNjvi-00000000Oqt-1VZZ

for root@nk.ca;

Wed, 10 Jan 2024 18:32:26 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=aYej2KD3h6tD9Y3SQXbok6E9tR5RcDhLJR7wi+56WGZK8hGjSDT+iVhYg9Dbo0ia/K99IcTORgpDNl6ClhBr7nLqUng8P+6j24Yu6nYQo1PsT4UMlAv+BNGqzqadfd0vcT9mP3YFcEyU4ssx/IILASFPwZWdz3AAmJFkzvUgdElSEiwR+bEW7VTu1fkJdZNexUl3D4t+L6OdIdScOpiInqJYY4M8ZfeK+d+C4jE3yWXr8z0cxPpORion6B0ew/tCJ1tLYHeCAhWc/kepihy56+ypxjJnzYEeDphA8Cb+eSUigbmwTeYQPEV8hEszNFzJ2H3MMyEnyrCS2ouc34R/Vg==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=NoPTkDzZTgZrzJ25ssIzorqiV8q4HpFp5WxeT2VXxYA=;

b=VFscgvq7DdfA+Pg3AfDE7GgSQIxIcnoHrwcdNIsEwg0b6rcKmZobI8WXPlVFVRew60XY8cHLUKlD0MO4Dt6Kn2aZLgKBiz5JAaV2VuRkZutzmgeBCoOg0I2A2UGd2aphTN/u9yoE/7RdRPdTrMlD5EjjKpNiIpprCqF/X1UgvB22mdt6wkEj7j4v7RJK2c/jAoA5ZEaMqpMjXQDU9yLeqBdbdYRfXddWPYrEXZ+TWUoRtoSkEYgVXAHhJ1V7AjvBltPMdUpqQTxhmHq8ZyWfyyj5o9R6Q5a1pPEGhT53utUvC6P/QPciBmwTlZGe2a8MAtQPgUjrboap0OWk5Ua9tg==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

172.105.148.13) smtp.rcpttodomain=nk.ca

smtp.mailfrom=4pfvf63.onmicrosoft.com; dmarc=none action=none

header.from=4pfvf63.onmicrosoft.com; dkim=none (message not signed); arc=none

(0)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=4pfvf63.onmicrosoft.com; s=selector1-4pfvf63-onmicrosoft-com;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=NoPTkDzZTgZrzJ25ssIzorqiV8q4HpFp5WxeT2VXxYA=;

b=l+85mv3S+21uacWbnoShgKIYjFOnbPN74djQ0J0qEQ8YS8rkKppoatviE1ZdC5Sk2Y+/Tf+LxTnMfBdng67binOrmrvLnYHEL2amRv1UiBOMcS6TtMzjY1VcCC6fPh5w5CyMo9gLLoQwKG7zE/JnTyiI+vst8483X2oSghmimX76oe6tZGJxO2CYkxqzv8YVzObI1eV3pvhfw1h2M/03up5mf5RgCZJKnJqfQC8kGLipzkPAXSQTUjuvCrfYGql4ftqsWcBKF+lLT51BJ6hOehybITWfViKLF4v3GrWQh9905UIXa3i8jykjTcTVryeLBzXdZ50U1OK9RW/uL8XdoA==

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 172.105.148.13)

smtp.mailfrom=4pfvf63.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=4pfvf63.onmicrosoft.com;

Importance: high

From: Ace Hardware

MIME-Version: 1.0

Subject: Order Confirmation - Craftsman Wet/Dry Vacuum

Content-Transfer-Encoding: 7bit

In-Reply-To:

Content-Type: text/html; charset="UTF-8"

To: root@nk.ca

CC: root@nk.ca

Date: Thu, 11 Jan 2024 02:25:36 +0100

Message-ID:

<4948888c-640a-42c3-8004-f41f4ca77147@DS3PEPF000099D7.namprd04.prod.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: DS3PEPF000099D7:EE_|IA1PR10MB7165:EE_

X-MS-Office365-Filtering-Correlation-Id: f2f7be5d-b042-4051-01de-08dc1244df72

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

fJx9CBbx8UF/ZdNPrni1manx60tJDIHmvqUkt8Ic1rtvEmRhhNWubuc+FP3pftBILgnRDSPlin7/nw0BESNMFVsKplwRWiH378IdAwn9KRUFF6CSgxyPbagaDLc+zaXmfM1sAwwxONwFumtfEY8s9KvOP3qOaMnoLW7RUZRYZGiingfcDV2MRkXPv3Ecai9EPogxazOri1Ku+U2M5MuS3oNpCVwJYNkr7pqkWZVxVrGjOEbCn4C+zPRnXRmxpsVrQURbgRXK+qzERvGkisRPYoyqEcz/MdByl9bwl4NDeT9ZWG/vmY7KiVwnHpt9xNBmcaNGi9EmUgwwZ8y7SMjyeifZ7yXbjPV/4rL8O7d7psV9p/7oQitBNx57/K5Uqd/YzGFhFPlejcZfiuvxWRyqJfgBZH/d3PNl3CFFXjE0t/9oukr1t6xYqX/9Uhvj0xt4UHJ8WOOFHk2rjghMZRzM4hV2uwuk2vJmHU+SO52Q3D747jRYcnlwKicOGVcIqbonLbNtUqpt9sBQCbZJdvTNjg==

X-Forefront-Antispam-Report:

CIP:172.105.148.13;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.thompson.com;PTR:172-105-148-13.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(396003)(39860400002)(376002)(346002)(136003)(230922051799003)(1690799017)(186009)(82310400011)(64100799003)(61400799012)(451199024)(7200799017)(46966006)(36840700001)(40470700004)(2906002)(5660300002)(336012)(8676002)(9686003)(31696002)(26005)(558084003)(478600001)(70206006)(86362001)(67280400001)(8936002)(316002)(41320700001)(42186006)(786003)(6916009)(70586007)(36860700001)(81166007)(82740400003)(34070700002)(47076005)(4326008)(166002)(41300700001)(40460700003)(40480700001)(8400799017)(66899024);DIR:OUT;SFP:1101;

X-OriginatorOrg: 4pfvf63.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Jan 2024 01:30:19.4540

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: f2f7be5d-b042-4051-01de-08dc1244df72

X-MS-Exchange-CrossTenant-Id: 90903da3-5cf4-445f-8a84-a419febd4dd7

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=90903da3-5cf4-445f-8a84-a419febd4dd7;Ip=[172.105.148.13];Helo=[mail.thompson.com]

X-MS-Exchange-CrossTenant-AuthSource:

DS3PEPF000099D7.namprd04.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA1PR10MB7165









(1) Notifications












































































































I1.17KL0LD35.4KI2.16KwhoissourceRank10.8MPIN0Summary reportDiagnosisDensity00n/a