DHL Phish
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 12 Jan 2025 10:12:00 -0700
Received: from sd96.btc-net.bg ([212.39.90.96]:46436)
by doctor.nl2k.ab.ca with smtp (Exim 4.98 (FreeBSD))
(envelope-from
id 1tX1UV-000000009VT-2wA4
for dave@doctor.nl2k.ab.ca;
Sun, 12 Jan 2025 10:11:18 -0700
Received: (qmail 10774 invoked by uid 605); 12 Jan 2025 17:09:08 -0000
Received: from unknown (HELO ?135.125.27.212?) (62.176.104.184)
by 0 with SMTP; 12 Jan 2025 17:09:08 -0000
Content-Type: multipart/alternative; boundary="===============2055944867=="
MIME-Version: 1.0
Subject: Action Required
To: mh9155@mclink.it
From: Express Delivery
Date: Sun, 12 Jan 2025 09:07:51 -0800
X-Mailer: Mozilla 4.72 [en] (Windows NT 5.0; I)
X-Priority: 1 (High)
X-Spam_score: 17.5
X-Spam_score_int: 175
X-Spam_bar: +++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Action Required: Customs Duties Payment Dear Customer, We
are reaching out regarding your shipment with tracking number JR9382912-388319.
Before we can proceed with the delivery, payment of outstandi [...]
Content analysis details: (17.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.1 MISSING_MID Missing Message-Id: header
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[212.39.90.96 listed in dnsbl.ahbl.org]
[212.39.90.96 listed in dnsbl.ahbl.org]
[212.39.90.96 listed in dnsbl.ahbl.org]
[212.39.90.96 listed in dnsbl.ahbl.org]
[62.176.104.184 listed in dnsbl.ahbl.org]
[62.176.104.184 listed in dnsbl.ahbl.org]
[62.176.104.184 listed in dnsbl.ahbl.org]
[62.176.104.184 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[212.39.90.96 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[212.39.90.96 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[212.39.90.96 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[212.39.90.96 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[62.176.104.184 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
[212.39.90.96 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[62.176.104.184 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
0.9 SPF_FAIL SPF: sender does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=mh9155%40mclink.it;ip=212.39.90.96;r=doctor.nl2k.ab.ca]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_IMAGE_ONLY_32 BODY: HTML: images with 2800-3200 bytes of words
1.0 FROM_MISSP_SPF_FAIL No description available.
1.6 FORGED_MUA_MOZILLA Forged mail pretending to be from Mozilla
0.0 TO_EQ_FM_SPF_FAIL To == From and external SPF failed
0.0 TO_EQ_FM_DOM_SPF_FAIL To domain == From domain and external SPF
failed
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
1.3 FSL_BULK_SIG Bulk signature with no Unsubscribe
Subject: {SPAM?} Action Required
You will not see this in a MIME-aware mail reader.
--===============2055944867==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
=
Action Required: Customs Duties Payment
Dear Customer,
We are reaching out regarding your shipment with tracking number JR9382912=
-388319. Before we can proceed with the delivery, payment of outstanding cu=
stoms duties and taxes is required.
The total amount due is =20AC2.99, covering customs clearance fees in comp=
liance with local regulations.
To ensure timely delivery, please complete your payment using the secure l=
ink below:
Pay Now =
Alternatively, scan the QR code below to make the payment:
If you have any questions or require assistance, please don't hesitate to=
contact our customer support team.
Best regards,
John Pearson
Customer Service Representative
DHL Express
--===============2055944867==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
" />
=3D1.0" />
Action Required: Customs Duties Payment
Dear Customer,
We are reaching out regarding your shipment with tracking number
>JR9382912-388319. Before we can proceed with the delivery, paymen=
t of outstanding customs duties and taxes is required.
The total amount due is =E2=82=AC2.99, covering customs=
clearance fees in compliance with local regulations.
To ensure timely delivery, please complete your payment using the secure=
link below:
ndmore.nl/dhl2025/index.php" target=3D_blank>Pay Now
Alternatively, scan the QR code below to make the payment:
=3D"HEIGHT: 126px; WIDTH: 123px" alt=3D"QR Code for Payment" src=3D"https:/=
/api.qrserver.com/v1/create-qr-code/?size=3D200x200&data=3Dhttps://send=
andmore.nl/dhl2025/index.php" width=3D199 height=3D200>
If you have any questions or require assistance, please don't hesitate t=
o contact our customer support team.
TML>
--===============2055944867==--