Amex Fraud Phish

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 27 Nov 2024 16:45:20 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98 (FreeBSD))

(envelope-from )

id 1tGRhl-00000000GOe-0FUC

for dave@doctor.nl2k.ab.ca;

Wed, 27 Nov 2024 16:44:21 -0700

Resent-From: The Doctor

Resent-Date: Wed, 27 Nov 2024 16:44:21 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail.basa.school ([88.198.207.53]:36922 helo=elitzoo)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.98 (FreeBSD))

(envelope-from )

id 1tGRHU-000000001MF-2AgA

for doctor@nk.ca;

Wed, 27 Nov 2024 16:17:17 -0700

Received: from techno_group_usr by elitzoo with local (Exim 4.96)

(envelope-from )

id 1tGRFd-004bLq-0S

for doctor@nk.ca;

Thu, 28 Nov 2024 01:15:17 +0200

To: doctor@nk.ca

Subject: Action Needed: Verify Your Account to Restore Access

X-PHP-Originating-Script: 1009:ez.php

From: Amex Fraud Detection Team

Reply-To: support@techno-group.com.ua

MIME-Version: 1.0

Content-Type: text/html; charset=UTF-8

Message-Id:

Date: Thu, 28 Nov 2024 01:15:17 +0200

X-Spam_score: 10.9

X-Spam_score_int: 109

X-Spam_bar: ++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Account Security Notification Account Security Alert



Content analysis details: (10.9 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[88.198.207.53 listed in dnsbl.ahbl.org]

[88.198.207.53 listed in dnsbl.ahbl.org]

[88.198.207.53 listed in dnsbl.ahbl.org]

[88.198.207.53 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[88.198.207.53 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[88.198.207.53 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[88.198.207.53 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[88.198.207.53 listed in dnsbl.ahbl.org]

0.0 T_SPF_TEMPERROR SPF: test of record failed (temperror)

0.0 FSL_HELO_NON_FQDN_1 No description available.

1.5 TVD_PH_SEC BODY: Message includes a phrase commonly used in phishing

mails

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.5 TVD_PH_BODY_ACCOUNTS_PRE The body matches phrases such as "accounts

suspended", "account credited", "account

verification"

0.5 HELO_NO_DOMAIN Relay reports its domain incorrectly

0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS

0.9 URI_PHISH Phishing using web form

1.0 ACCT_PHISHING Possible phishing for account information

Subject: {SPAM?} Action Needed: Verify Your Account to Restore Access













Account Security Notification















Burnt out at work spam from Google Gmail

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 27 Nov 2024 16:46:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98 (FreeBSD))

(envelope-from )

id 1tGQJ8-00000000KAC-0MZz

for dave@doctor.nl2k.ab.ca;

Wed, 27 Nov 2024 15:14:50 -0700

Resent-From: The Doctor

Resent-Date: Wed, 27 Nov 2024 15:14:50 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-qt1-f178.google.com ([209.85.160.178]:48422)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.98 (FreeBSD))

(envelope-from )

id 1tGMOA-000000002RX-0Fqg

for root@nk.ca;

Wed, 27 Nov 2024 11:03:50 -0700

Received: by mail-qt1-f178.google.com with SMTP id d75a77b69052e-4668e48963eso241261cf.1

for ; Wed, 27 Nov 2024 10:01:51 -0800 (PST)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=themodernzen-co.20230601.gappssmtp.com; s=20230601; t=1732730505; x=1733335305; darn=nk.ca;

h=mime-version:date:subject:to:from:message-id:from:to:cc:subject

:date:message-id:reply-to;

bh=Z4YS4hNCsU3U90U9fWiG+ptJyNgKwAtJOJy5t00Vae4=;

b=rLe7LwBXdTDUALgCFA4A8ietw+5FLsAjJTP7XLPJMkA97qQXzAtMuEgkE2GNX4Iove

a7aqwvm6T3KCi2yTTEM25G7dNNqT5n+zLB4rQ/Mb43rUo0CFnWJ0DpUrq5Pl6PEYaYL/

E0A6ItlZOhlJbnAmXpm/9opFcruNrmbTS8aFBoRHEU7i1VzAPF0snqj0EwZvG8vX9lF+

dVroRshyiN45jNWxWtZrr3JlEL2e6L4WF34NwaFEMkqVpYngnW5AMNPQGZJrBQWRMAy4

Jd1QmfZlCVKmqyhXZMeaN+C4RWOHx84skRjXPZmZ9eCNqrdP4Ccr7D5e/k39JH5yTpqZ

x9YA==

X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1e100.net; s=20230601; t=1732730505; x=1733335305;

h=mime-version:date:subject:to:from:message-id:x-gm-message-state

:from:to:cc:subject:date:message-id:reply-to;

bh=Z4YS4hNCsU3U90U9fWiG+ptJyNgKwAtJOJy5t00Vae4=;

b=DltEdvLVsmoTGABDofEq5TnMlJ+Y4EVcYdL5bbSvdPzUDsjMzoG3L3YkAoG6LIagin

3g1U/jYjL3TbwVh+u6ezufZefFn4XMo1QuqdGB4kgQbZ6b7sLvxF3m3C4lC4NaYMrhF7

n2ctYksXOGkfoHAPk2xHqJb1BkdRXG8zzH2WupGByx5eXVGJY/c0R0h5KIC/IqGPZtx3

ghfyX9Sxe7si/1hm9YKNrVArlmCXKBmp6vN4h0tD25y1kOTT7h1z8UfmE6FYvziJdyrX

qQk3RGzGLO7f56KAu+0Zj4zKc4jPi5ZxJ4vDOC3v/8wTQX11fy/HHxbDm2ZRwoiyOpHN

vEVg==

X-Gm-Message-State: AOJu0YxP0TKnPrWMTQpCiZ65efGo7/WLHXQwAVrcANbkOVuLJ/qU+n20

w4ZtFPPrqfd/jAIp5iB7uZkciuIKW3B7kJmIRkfm7bvlmzwYoE5eSi6/H1rWylD9ug50fRXRKuZ

1

X-Gm-Gg: ASbGncszvA2Tc4FV449zESKlASfKaPpGhhwmFtODqrIng51oWhqeR7kGfer+6Gw98wx

vOA/kXsJate49EriYmnZjOuJSsIRfSlKsBn+WAzyVfM1z0cArV+UqTBkK/VlctVcHwuULOuy0b1

S3GqwvrtMFMrJrp/RLAWAagk10H99ChrkZuVG90iMRs0kXahDzg8JoY5h4FGW9UR5h2QGPIE6bl

eZN+Im6BIUhG7CyjlL7aZiqv+oK/i6QHi95yC4mz3fOgC6oy7p2V9KzUBK+MMIwyzAWfiFsPYkS

PV/KpBf2ToijVxNHloUYw9tPBbcRXT/ehss9djsxwTAxR/kkyRDGwHyT+0pMmp/XGaJ0X9v7jRI

=

X-Google-Smtp-Source: AGHT+IEmjUt9vfeAvJN9JcT8fDo/AtXGqcTgn/K4G+mzjvTKZnK7S2CVMcn9qUbkMOkIHDomRLj/tw==

X-Received: by 2002:ac8:59d0:0:b0:458:23fc:f345 with SMTP id d75a77b69052e-466b3610dfemr57602111cf.38.1732730504457;

Wed, 27 Nov 2024 10:01:44 -0800 (PST)

Received: from ccd082fa-5d1c-471b-a871-4e6552d133b5.local (ec2-44-200-210-140.compute-1.amazonaws.com. [44.200.210.140])

by smtp.gmail.com with ESMTPSA id d75a77b69052e-4669e6e86f5sm29678001cf.28.2024.11.27.10.01.43

for

(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);

Wed, 27 Nov 2024 10:01:43 -0800 (PST)

Content-Type: multipart/alternative;

boundary="--_NmP-4b0cf263674ffbbd-Part_1"

Message-ID:

From: Ajanta

To: root@nk.ca

Subject: Feeling Stuck at Work?

Date: Wed, 27 Nov 2024 18:01:43 +0000

MIME-Version: 1.0

X-Spam_score: 8.8

X-Spam_score_int: 88

X-Spam_bar: ++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hi Dave, Are you feeling stuck, overwhelmed, or burnt out

at work? Stress and anxiety can significantly impact your career performance,

and it’s easy to lose control over your workload. I help corporate professionals

like you not only overcome burnout but also improve productivity by up to

80%.



Content analysis details: (8.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[44.200.210.140 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

[209.85.160.178 listed in will-spam-for-food.eu.org]

1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org

[209.85.160.178 listed in dnsbl.ahbl.org]

[209.85.160.178 listed in dnsbl.ahbl.org]

[209.85.160.178 listed in dnsbl.ahbl.org]

[209.85.160.178 listed in dnsbl.ahbl.org]

[44.200.210.140 listed in dnsbl.ahbl.org]

[44.200.210.140 listed in dnsbl.ahbl.org]

[44.200.210.140 listed in dnsbl.ahbl.org]

[44.200.210.140 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org

[209.85.160.178 listed in dnsbl.ahbl.org]

0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org

[209.85.160.178 listed in dnsbl.ahbl.org]

0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org

[209.85.160.178 listed in dnsbl.ahbl.org]

1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org

[209.85.160.178 listed in dnsbl.ahbl.org]

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[209.85.160.178 listed in list.dnswl.org]

-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)

[209.85.160.178 listed in wl.mailspike.net]

-0.0 SPF_PASS SPF: sender matches SPF record

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders

0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in

headers

0.0 HTML_MESSAGE BODY: HTML included in message

1.6 HTML_IMAGE_ONLY_12 BODY: HTML: images with 800-1200 bytes of words

2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars

Subject: {SPAM?} Feeling Stuck at Work?



----_NmP-4b0cf263674ffbbd-Part_1

Content-Type: text/plain; charset=utf-8

Content-Transfer-Encoding: quoted-printable



Hi Dave,



Are you feeling stuck, overwhelmed, or burnt out at work? Stress =

and anxiety can significantly impact your career performance, and =

it=E2=80=99s easy to lose control over your workload.=C2=A0



I help corporate professionals like you not only overcome burnout but also =

improve productivity by up to 80%.=C2=A0



Imagine being able to regain =

focus, reduce anxiety, and enjoy your work again. If that sounds like =

something you=E2=80=99re looking for, I=E2=80=99d love to offer you a free =

consultation to explore how we can make that happen.=C2=A0



Ajanta

Founder "The Modern Zen"

peaceful progress possible.



Don't want any more emails? https://proxvestralheard.=

com/unsub/1/2aa48120-fa3a-482d-8487-4f3f6c798daa















--

----_NmP-4b0cf263674ffbbd-Part_1

Content-Type: text/html; charset=utf-8

Content-Transfer-Encoding: quoted-printable



Hi Dave,

Are you feeling stuck, overwhelmed, or burnt out at =

work? Stress and anxiety can significantly impact your career performance, =

and it’s easy to lose control over your workload. 

I help=

corporate professionals like you not only overcome burnout but also =

improve productivity by up to 80%. 

Imagine being able to =

regain focus, reduce anxiety, and enjoy your work again. If that sounds =

like something you’re looking for, I’d love to offer you a free=

consultation to explore how we can make that happen.=

 

Ajanta
Founder "The Modern Zen"
peaceful =

progress possible.




<=

br>



33-70Dbndw5sxuw5g.png' alt=3D'line'>

----_NmP-4b0cf263674ffbbd-Part_1--