Social Media Phishing from mail.achetefollowers.fr Strasbourg, Grand Est, France

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 15 Jan 2024 09:03:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rPPPr-00000000AsS-2Xeo

for dave@doctor.nl2k.ab.ca;

Mon, 15 Jan 2024 09:02:23 -0700

Resent-From: The Doctor

Resent-Date: Mon, 15 Jan 2024 09:02:23 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [78.138.98.138] (port=35338 helo=mail.likeglow.com)

by doctor.nl2k.ab.ca with esmtp (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rPP57-000000007UI-0GeV

for sales@nk.ca;

Mon, 15 Jan 2024 08:41:00 -0700

Received: from [127.0.0.1] (localhost [127.0.0.1])

by mail.likeglow.com (Postfix) with ESMTP id 56D55170BA9

for ; Mon, 15 Jan 2024 09:59:25 -0500 (EST)

DKIM-Filter: OpenDKIM Filter v2.11.0 mail.likeglow.com 56D55170BA9

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=boostsocial.ca;

s=default; t=1705330765;

bh=AxoAfDhTWT1OZo4+UAJY/6fKqP0tFCeSMrkpN8tybhc=;

h=From:To:Subject:Date:From;

b=ESyVpU4Aljd80o2r6AJtsOTcUWzK6mLJ3fmM10JQ6U38KSLfbisnPG4vV9lcFL8FU

FsQgksFZVSUI3oXh393r5m2+biC0DB5cfq4IYEh4izzfu/gFrKaZ0MT7ZmPWbHGP06

UfwQLrfe7naRNROrIHotoHLkCvcRWk7psdr2sbMg=

From: Emma Bains

To: sales@nk.ca

Subject: Good morning

Message-ID: <8d4dc9c43bddc5b509861ca82c6e6a19@boostsocial.ca>

MIME-Version: 1.0

Date: Mon, 15 Jan 2024 16:59:25 +0200

Content-Type: text/html; charset=utf-8

Content-Transfer-Encoding: quoted-printable

X-Antivirus: AVG (VPS 240115-4, 1/15/2024), Inbound message

X-Antivirus-Status: Clean










>



<=

meta name=3D"viewport" content=3D"width=3Ddevice-width, initial-scale=3D1.0=

">








UXMd">Hello,



My name is Olivia and I am =

part of the team at boostsocial.ca. I have reviewed your website

=

and I believe we can help you increase your visibility on social networks. =

We offer likes, followers, and much

more for Facebook, Instagram,=

and TikTok.



We are leaders in Canada in =

increasing online presence and offer the best prices,

having comp=

leted more than 9000 orders.



We use Apple=

Pay, Google Pay, Stripe, and PayPal as our payment processors.



<=

p class=3D"Y7WjlwHwqs">Wishing you a good day,




CKVO">Olivia Chalk



www.boostsocial.ca

=









ICANN PHish from mail.wconnectt.com Amsterdam, North Holland, Netherlands

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 14 Jan 2024 21:23:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rPEUc-00000000D2M-3g5J

for dave@doctor.nl2k.ab.ca;

Sun, 14 Jan 2024 21:22:34 -0700

Resent-From: The Doctor

Resent-Date: Sun, 14 Jan 2024 21:22:34 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail.wconnectt.com ([185.113.8.159]:36446)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rPD4N-000000008bL-0z45

for sales@nk.ca;

Sun, 14 Jan 2024 19:51:27 -0700

Received: from 42.74.234.35.bc.googleusercontent.com (42.74.234.35.bc.googleusercontent.com [35.234.74.42])

(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))

(No client certificate requested)

by mail.wconnectt.com (Postfix) with ESMTPSA id 6C04021E08

for ; Mon, 15 Jan 2024 04:49:21 +0200 (EET)

DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed;

d=wconnectt.com; s=default; h=Reply-To:From:To:Subject:

MIME-Version:Content-Type:Content-Transfer-Encoding; bh=NrZEi5h/

2Lvsb8OiIi4V32jI43o=; b=P9IXPEsAJcqnC9ZkFOvsvv4VdSPKBtzoEtc4s5+f

WusMf/znYJmZHZDHXML1K1fyLS4IDqsolyUTEqMmpXQgxTggD5waIpDPH0C6XIGd

RbDtVDUZq0AXb5DhiUdnSW6qysQZvrthbzKU857Zg0BNvRQniJl6E87ihHaLeJtp

AJyXttdNaPP4KZT53dalPYyJUizbSPpDj8yJOvc/Y+xBeV7WMm+EHhbX5m0qMj7W

oivwalCNvQl64xsszvnB57PizBVXP3+SYN+qN77yNszHUELAPXWmP+US23SK9Lbv

I5qiLkrVsqcdvI3uisdIcbS7WgYoi8Iiti9rOnVUasD7ZQ==

Reply-To: ICANN Domain Validation

From: ICANN Domain Validation

To: sales@nk.ca

Subject: ICAAN Verification for nk.ca user(s)

Date: 14 Jan 2024 18:49:17 -0800

Message-ID: <20240114184917.0B6992FC254D5E15@wconnectt.com>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Antivirus: AVG (VPS 240114-4, 1/14/2024), Inbound message

X-Antivirus-Status: Clean
















0px; letter-spacing: normal; font-family: "Helvetica Neue",Helvetica,Arial=

,sans-serif; font-size: 11px; font-style: normal; font-weight: 400; word-sp=

acing: 0px; white-space: normal; orphans: 2; widows: 2; background-color: r=

gb(255, 255, 255);'>


03669868v1yiv9364790116bodyTable" style=3D"margin: 0px; padding: 0px; width=

: 718px; border-collapse: collapse; min-height: 100%;" bgcolor=3D"#efeeea" =

border=3D"0" cellspacing=3D"0" cellpadding=3D"0">












align=3D"top" style=3D"margin: 0px; padding: 10px; width: 698px; min-height=

: 100%;">


rder-collapse: collapse; max-width: 640px;" border=3D"0" cellspacing=3D"0" =

cellpadding=3D"0">




















rgb(255, 255, 255);" bgcolor=3D"#ffffff" border=3D"0" cellspacing=3D"0" ce=

llpadding=3D"0">












px; padding-left: 20px;">


rder=3D"0" cellspacing=3D"0" cellpadding=3D"0">




















, 21); line-height: 36px; letter-spacing: normal; font-family: Georgia,Time=

s,"Times New Roman",serif; font-size: 28px; font-style: normal; font-weight=

: 400; display: block;'>DNS Security Threat Mitigation Program.


>




dding-top: 0px; font-family: "Helvetica Neue",Helvetica,Arial,Verdana,sans-=

serif; font-size: 16px; font-weight: 400; margin-top: 0px;'>Dear Re=

gistrant
,
The

Internet Corporation for Assigned Names and Numbers (ICANN) has

mandated that all ICANN accredited registrars begin verifying all email

addresses registered for each domain name.





The following Email: (sales@nk.ca) is associated

with the Domain: (nk.ca) and

requires verification.




dding-top: 0px; font-family: "Helvetica Neue",Helvetica,Arial,Verdana,sans-=

serif; font-size: 16px; font-weight: 400; margin-top: 0px;'>

Follow the prompt below to verify your email address and

explicitly consent to the terms of our Registration Agreement.

 =

;            &n=

bsp;            =

;       
ne;" href=3D"https://t.ly/1hTow#c2FsZXNAbmsuY2E=3D">


74)); padding: 3px 4px; border: 0px solid rgb(240, 255, 240); border-image:=

none; text-align: center; color: rgb(255, 255, 255); line-height: 2em; let=

ter-spacing: 2px; font-size: 24px; font-weight: bold; position: relative; c=

ursor: pointer; text-shadow: 1px 1px 1px rgba(32,32,32,0.7); -webkit-touch-=

callout: none; -webkit-user-select: none; -khtml-user-select: none; -moz-us=

er-select: none; user-select: none;">

Verify Email Address












lspacing=3D"0" cellpadding=3D"0">












r; color: rgb(106, 101, 95); line-height: 24px; padding-top: 40px; padding-=

bottom: 40px; font-family: "Helvetica Neue",Helvetica,Arial,Verdana,sans-se=

rif; font-size: 12px; font-weight: 400;'>


-height: 24px; padding-top: 0px; font-family: "Helvetica Neue",Helvetica,Ar=

ial,Verdana,sans-serif; font-size: 12px; font-weight: 400;'>©

2024 nk.ca  ® All Rights

Reserved
























Dewalt phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 14 Jan 2024 21:23:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rPEUH-00000000D0r-2T42

for dave@doctor.nl2k.ab.ca;

Sun, 14 Jan 2024 21:22:13 -0700

Resent-From: The Doctor

Resent-Date: Sun, 14 Jan 2024 21:22:13 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-db3eur04on2135.outbound.protection.outlook.com ([40.107.6.135]:39758 helo=EUR04-DB3-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rPCSA-000000007PW-3CRZ

for root@nk.ca;

Sun, 14 Jan 2024 19:11:58 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=HHYbucdBMgD9VVXmeYYfwVgHIcVsMcViovl7jGw2Bhuj2TTyLxvXh+6U3Z5xeX0bI2F3fVC5ytS9Qkjb2rwMvYL0ucYmuP6zm/8LguuzWCcoVQars2FnAD0XtF9hUy8ufuDKjdci+bSOFX19gAmzbYpJrBWKnAZMWJM9gB08M3vE0Xc0xAdbNq/yqDnbKsZR06XtF+F398eIXUzv1X5n2ddTv6sb75Hf9+V7UzSunQ+VGh64U4+RrQVYpW/fHIfFPIzRf9RycCIFpUyuSeEWFKU2TjnkuIcMCJ0Z/iZnIX618fCAVlqNGOaeT9mzddIw8UTrQz0dSIawi7x6ZjgfNg==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=vqBmgRkmveRYNWNW5tl+DBkQy13+Z2FB7/mzRmdCsGM=;

b=cQXV5SnC42p/LHwBJCV476PyBwFKy13nEtdMnoV6xsJ0iEmUit+z/ekKgZbBGIcSwXDQxye2escoC56eRL31T7GkySYDan+yZ5SE2KKau9PjXx4xmCHx4IqphjrpDOq0QlPwzVs1hFE74VCDPvl5ymAxD8BvDj/W8YlWjMUrMCphkiWyqyqaK9OTcKlrGpvbBCemA37gank6wBZVOFAAyGCG2N+Yo+K7syylbnFWdG+F1CIg5HMyHYMqE4a1xeWPpdTY2uPEWQ5GFNNbf3ayfi3XBhRLGlRFPNaAD9DyZpYJdlSjpdK/abdQ23MD9e6kt7l/Eprgpgz6dSh+8S5CEg==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

45.79.73.202) smtp.rcpttodomain=nk.ca smtp.mailfrom=t03ms.onmicrosoft.com;

dmarc=none action=none header.from=t03ms.onmicrosoft.com; dkim=none (message

not signed); arc=none (0)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=T03MS.onmicrosoft.com;

s=selector1-T03MS-onmicrosoft-com;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=vqBmgRkmveRYNWNW5tl+DBkQy13+Z2FB7/mzRmdCsGM=;

b=Ud02TcKJ4h2Z/jg0QEKbPvkCiF/P4L77ie6z6k1s0Bhnn+GD/VKi/Tvu2I9uIlM2MW9SiG4b2lWfyVxDflt+Jj2M5id7lwtK7uCYI9MktbAvPS6As+esx6Oqc3qzX/t7qrR4bKBBK1XcK+tH/saWkDjMZUP9onMUg6sEaG4ZgHvhLZA9FtD7LlX1jgSh3whvedyu2FzZU6gSetN83F7npdhsHXHpMqO70eSAkKle/fk17ofrdlwnwnhSL7o24v8nqoWHBSWrougJaBF/Td/CyenrhniMysEc7orpx7VxV+wcaxVlIcFQMBXCtLBnYNi3us9fbulGIqjVnpddHbc8PQ==

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 45.79.73.202)

smtp.mailfrom=T03MS.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=T03MS.onmicrosoft.com;

Content-Transfer-Encoding: 7bit

MIME-Version: 1.0

From: Deals

In-Reply-To:

To: root@nk.ca

Subject: Your Name Came Up For a Dewalt Power Station Reward

Content-Type: text/html; charset="UTF-8"

Importance: high

CC: root@nk.ca

Date: Mon, 15 Jan 2024 03:01:21 +0100

Message-ID:

<4934eba0-67e5-4156-b5d8-ced683fad6f1@AM3PEPF0000A794.eurprd04.prod.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: AM3PEPF0000A794:EE_|AM9PR07MB7122:EE_

X-MS-Office365-Filtering-Correlation-Id: 092bd862-a423-42a5-cde5-08dc156f094e

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

ot8YYG/4DADoyzfbwFX6XTHZuuKWgxKmj0+ezEGyelHRfDI1yUxFtZR5uOTgh9V4ynEVZccg1G/TnPCPg5TOLKJEZFaQG+F50JWXNkg9NkVhu4XIgEkBBCuYvZvTgtu0DcgKtSLUydfn0Jyf1ga+If+f1gTgArY2joVvp9690uT261xd7/t2xqzhnW0cVh7YrF3h8YWu4J0Hr9MzGYrewiPhD1L0txPs21nHWU5RLvcm4k/vt9/peO13EnuZliwkJ0BiSa/IdA5r7L1uJg+O2/IjKrWjyDNlClKAqhVcXf1CAZMkz4UmsdCBAspZLbW4fCzlwwM6hZnZXgc3o7iJbMEiFiDBiDWh+UOU+/VhS1IYTJYPVVkVGAriU6ytsWSXG8FPCTjYlIVXHfhrf6YhuF7i5BTcEeCtaCm5cFo+LZsb1kE5X2Of35AyeVkn43LhsyzK/f8SdUi0thQl7VFXaCkBfOIUZE7roKrdGHgQCmbHiSRg1Nmq4daEnVES5nx2O1zPHb6mwRi9AogS/+Tinw==

X-Forefront-Antispam-Report:

CIP:45.79.73.202;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.schinner.com;PTR:45-79-73-202.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(39860400002)(376002)(346002)(396003)(136003)(230922051799003)(61400799012)(64100799003)(186009)(82310400011)(1690799017)(7200799017)(451199024)(36840700001)(46966006)(40470700004)(8400799017)(40480700001)(40460700003)(41300700001)(70586007)(558084003)(81166007)(166002)(41320700001)(86362001)(31696002)(70206006)(34070700002)(36860700001)(47076005)(82740400003)(336012)(26005)(9686003)(2906002)(478600001)(8936002)(786003)(42186006)(6916009)(316002)(4326008)(5660300002)(8676002)(67280400001);DIR:OUT;SFP:1102;

X-OriginatorOrg: T03MS.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 15 Jan 2024 02:09:41.8199

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 092bd862-a423-42a5-cde5-08dc156f094e

X-MS-Exchange-CrossTenant-Id: 797ffa7c-6432-40c5-8603-f3a97de60bb8

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=797ffa7c-6432-40c5-8603-f3a97de60bb8;Ip=[45.79.73.202];Helo=[mail.schinner.com]

X-MS-Exchange-CrossTenant-AuthSource:

AM3PEPF0000A794.eurprd04.prod.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM9PR07MB7122

X-Antivirus: AVG (VPS 240114-4, 1/14/2024), Inbound message

X-Antivirus-Status: Clean









(1) Notifications