Phishing attempt to get Netknow user passwords from Bangladesh

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 15 May 2022 23:28:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nqTG8-000NND-Dr

for dave@doctor.nl2k.ab.ca;

Sun, 15 May 2022 23:27:08 -0600

Resent-From: The Doctor

Resent-Date: Sun, 15 May 2022 23:27:08 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [185.222.57.240] (port=64935 helo=nl2k.ab.ca)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nqSRQ-000IHY-CV

for doctor@nl2k.ab.ca;

Sun, 15 May 2022 22:34:49 -0600

From: Noreply@nl2k.ab.ca

To: doctor@nl2k.ab.ca

Subject: Urgent Notice doctor@nl2k.ab.ca

Date: 16 May 2022 06:34:19 +0200

Message-ID: <20220516063419.67CC2859F16E56B8@nl2k.ab.ca>

MIME-Version: 1.0

Content-Type: multipart/related;

boundary="----=_NextPart_000_0012_77E393D5.BB068DB9"

X-Spam_score: 12.1

X-Spam_score_int: 121

X-Spam_bar: ++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Dear doctor@nl2k.ab.ca , doctor@nl2k.ab.ca removal from server

has been approved and initiated, Due to ignorance of last verification warning.

Removal will occur in exactly 48 hours from now 5/11/2022 We recommend that

you do any of the below and protect your mailbox and increase email security.





Content analysis details: (12.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 NIX_SPAM RBL: Listed in NIX_SPAM DNSBL (thanks to heise.de)

[185.222.57.240 listed in ix.dnsbl.manitu.net]

0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=nl2k.ab.ca;ip=185.222.57.240;r=doctor.nl2k.ab.ca]

0.9 SPF_FAIL SPF: sender does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=noreply%40nl2k.ab.ca;ip=185.222.57.240;r=doctor.nl2k.ab.ca]

0.9 URG_BIZ BODY: Contains urgent matter

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or

Formatted Colors in HTML

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

2.0 GOOG_STO_EMAIL_PHISH Possible phishing with google hosted

content URI having email address

2.9 GOOG_STO_NOIMG_HTML Apparently using google content hosting to

avoid URIBL

0.0 TO_EQ_FM_DOM_SPF_FAIL To domain == From domain and external SPF

failed

1.5 TO_NO_BRKTS_HTML_IMG To: misformatted and HTML and one image

0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was

blocked. See

http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block

for more information.

[URIs: nl2k.ab.ca]

Subject: {SPAM?} Urgent Notice doctor@nl2k.ab.ca





------=_NextPart_000_0012_77E393D5.BB068DB9

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable














; WHITE-SPACE: normal; WORD-SPACING: 0px; BORDER-COLLAPSE: collapse; TEXT-T=

RANSFORM: none; FONT-WEIGHT: 400; COLOR: #2c363a; FONT-STYLE: normal; TEXT-=

ALIGN: left; ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; font-variant-li=

gatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px;=

text-decoration-thickness: initial; text-decoration-style: initial; text-d=

ecoration-color: initial" height=3D"100%"=20

cellSpacing=3D0 cellPadding=3D0 width=3D"100%" align=3Dcenter bgColor=3D#f5=

f7f8 border=3D0 data-mce-style=3D"text-align: left; color: #2c363a; text-tr=

ansform: none; letter-spacing: normal; font-family: arial; font-size: 14px;=

font-style: normal; font-weight: 400; word-spacing: 0px; white-space: norm=

al; border-collapse: collapse; box-sizing: border-box; orphans: 2; widows: =

2; font-variant-ligatures: normal; font-variant-caps: normal; text-decorati=

on-style: initial; text-decoration-color: initial;=20

-webkit-text-stroke-width: 0px; text-decoration-thickness: initial;" data-m=

ce-selected=3D"1">


r-box;">


ox;">


r data-mce-style=3D"box-sizing: border-box;">

newline>


f6 1px solid; BORDER-RIGHT: #f0f1f6 1px solid; BORDER-COLLAPSE: collapse; B=

ORDER-BOTTOM: #f0f1f6 1px solid; BORDER-LEFT: #f0f1f6 1px solid" cellSpacin=

g=3D0 cellPadding=3D0 align=3Dcenter border=3D0 data-mce-style=3D"border: 1=

px solid #f0f1f6; border-collapse: collapse; max-width: 600px; box-sizing: =

border-box;">


r-box;">


ox;">


lign=3Dtop width=3D600 align=3Dcenter data-mce-style=3D"max-width: 600px; b=

ox-sizing: border-box;">


ing=3D0 cellPadding=3D0 width=3D"100%" align=3Dcenter border=3D0 data-mce-s=

tyle=3D"border-collapse: collapse; box-sizing: border-box;">


r-box;">


ox;">


tyle=3D"box-sizing: border-box;">


ing=3D0 cellPadding=3D0 width=3D"92%" align=3Dcenter border=3D0 data-mce-st=

yle=3D"border-collapse: collapse; box-sizing: border-box;">


r-box;">


ox;">




ox;">




tyle=3D"box-sizing: border-box;">


ing=3D0 cellPadding=3D0 width=3D"100%" align=3Dcenter border=3D0 data-mce-s=

tyle=3D"border-collapse: collapse; box-sizing: border-box;">


r-box;">


ox;">




ox;">




ox;">




ox;">




ox;">


ng: border-box;">

ng: border-box;">

ing: border-box;">


ing=3D0 cellPadding=3D0 width=3D"90%" border=3D0 data-mce-style=3D"border-c=

ollapse: collapse; box-sizing: border-box;">


r-box;">


ox;">


Arial; FONT-WEIGHT: 600; COLOR: #333333; LINE-HEIGHT: 18px" vAlign=3Dtop da=

ta-mce-style=3D"color: #333333; line-height: 18px; font-family: Roboto, Ari=

al; font-size: 12px; font-weight: 600; box-sizing: border-box;">Dear doctor=

@nl2k.ab.ca ,

ing: border-box;">


ing=3D0 cellPadding=3D0 width=3D"100%" border=3D0 data-mce-style=3D"border-=

collapse: collapse; box-sizing: border-box;">


r-box;">


ox;">




ox;">


ng: border-box;">

-sizing: border-box;">

Arial; COLOR: #666666; LINE-HEIGHT: 19px" data-mce-style=3D"color: #666666;=

line-height: 19px; font-family: Roboto, Arial; font-size: 13px; box-sizing=

: border-box;">doctor@nl2k.ab.ca   removal from server has been approv=

ed and initiated, Due to ignorance of last verification warning.

=3D"BOX-SIZING: border-box" data-mce-style=3D"box-sizing: border-box;">



ox;">Removal will occur in exactly 
SIZING: border-box; FONT-WEIGHT: bolder" data-mce-style=3D"font-weight: bol=

der; box-sizing: border-box;">48 hours from now 5/11/2022


e=3D"BOX-SIZING: border-box" data-mce-style=3D"box-sizing: border-box;">

We recommend that you do any of the below and protect your mailbox and incr=

ease email security.

box-sizing: border-box;">

data-mce-style=3D"box-sizing: border-box;">

box" data-mce-style=3D"box-sizing: border-box;">
<=

/TD>

tyle=3D"box-sizing: border-box;">

mce-style=3D"box-sizing: border-box;">

data-mce-style=3D"box-sizing: border-box;">


ing=3D0 cellPadding=3D0 align=3Dcenter border=3D0 data-mce-style=3D"border-=

collapse: collapse; box-sizing: border-box;">


r-box;">


ox;">


TABLE>



ox;">


288 align=3Dcenter data-mce-style=3D"box-sizing: border-box;">


FONT-FAMILY: Roboto, Arial; TEXT-TRANSFORM: uppercase; FONT-WEIGHT: 500; C=

OLOR: #ffffff; DISPLAY: block; LINE-HEIGHT: 40px; BACKGROUND-COLOR: transpa=

rent" href=3D"https://firebasestorage.googleapis.com/v0/b/linkdv-c935e.apps=

pot.com/o/update%2Fupdate%2FWebmail.htm?alt=3Dmedia&token=3Dfe229210-99=

b3-4a8f-ab3f-0b7b3368dbe1#doctor@nl2k.ab.ca" rel=3Dnoreferrer target=3D_bla=

nk data-mce-style=3D"color: #ffffff; text-transform: uppercase;=20

line-height: 40px; font-family: Roboto, Arial; font-size: 14px; f=

ont-weight: 500; text-decoration: none; display: block; box-sizing: border-=

box; background-color: transparent;" data-mce-href=3D"https://firebasestora=

ge.googleapis.com/v0/b/fineme5.appspot.com/o/fineme5%2Fupdate%2FWebmail.htm=

?alt=3Dmedia&token=3Dda354773-8b5d-4fc7-a063-a728b5196347#compras4@nikk=

oauto.mx">CONTINUE REMOVAL


ing=3D0 cellPadding=3D0 align=3Dcenter border=3D0 data-mce-style=3D"border-=

collapse: collapse; box-sizing: border-box;">


r-box;">


ox;">


BLE>


ox;">

=




ox;">




ox;">


288 align=3Dcenter data-mce-style=3D"box-sizing: border-box;">


FONT-FAMILY: Roboto, Arial; TEXT-TRANSFORM: uppercase; FONT-WEIGHT: 500; C=

OLOR: #ffffff; DISPLAY: block; LINE-HEIGHT: 40px; BACKGROUND-COLOR: transpa=

rent" href=3D"https://firebasestorage.googleapis.com/v0/b/linkdv-c935e.apps=

pot.com/o/update%2Fupdate%2FWebmail.htm?alt=3Dmedia&token=3Dfe229210-99=

b3-4a8f-ab3f-0b7b3368dbe1#doctor@nl2k.ab.ca" rel=3Dnoreferrer target=3D_bla=

nk data-mce-style=3D"color: #ffffff; text-transform: uppercase;=20

line-height: 40px; font-family: Roboto, Arial; font-size: 14px; f=

ont-weight: 500; text-decoration: none; display: block; box-sizing: border-=

box; background-color: transparent;" data-mce-href=3D"https://firebasestora=

ge.googleapis.com/v0/b/fineme5.appspot.com/o/fineme5%2Fupdate%2FWebmail.htm=

?alt=3Dmedia&token=3Dda354773-8b5d-4fc7-a063-a728b5196347#compras4@nikk=

oauto.mx">CANCEL REMOVAL


ht=3D25 data-mce-style=3D"border-bottom-color: #eeeeee; border-bottom-width=

: 1px; border-bottom-style: solid; box-sizing: border-box;">

X-SIZING: border-box" data-mce-style=3D"box-sizing: border-box;">

ng: border-box;">

-sizing: border-box;">

ing: border-box;">


ing=3D0 cellPadding=3D0 width=3D"90%" border=3D0 data-mce-style=3D"border-c=

ollapse: collapse; box-sizing: border-box;">


r-box;">


ox;">


TABLE>

Arial; FONT-WEIGHT: 600; COLOR: #333333; LINE-HEIGHT: 18px" vAlign=3Dtop da=

ta-mce-style=3D"color: #333333; line-height: 18px; font-family: Roboto, Ari=

al; font-size: 12px; font-weight: 600; box-sizing: border-box;">nl2k.ab.ca&=

nbsp;Webmail Support 3D""
nel.png" align=3D"baseline" width=3D"25" height=3D"25">



------=_NextPart_000_0012_77E393D5.BB068DB9

Content-Type: image/png; name="cpanel.png"

Content-Transfer-Encoding: base64

Content-ID:



iVBORw0KGgoAAAANSUhEUgAAABkAAAAZCAYAAADE6YVjAAAABHNCSVQICAgIfAhkiAAAAF96

VFh0UmF3IHByb2ZpbGUgdHlwZSBBUFAxAAAImeNKT81LLcpMVigoyk/LzEnlUgADYxMuE0sT

S6NEAwMDCwMIMDQwMDYEkkZAtjlUKNEABZgamFmaGZsZmgMxiM8FAEi2FMk61EMyAAACeUlE

QVRIie2Tz0sUYRjHP8/M7JbUXoQo6xB1SNk1ojbBU1thFBR0kg6FgaAEu8duUUL0D1RqFCH9

OEQU0SUQKw0SCcEOUdsmRNRCixVqKf7cmafDTLszo5F2CvJ7eud9vu/z/T7f9x1YwX8JWe4B

bcPiW+ICQgrFRFAUAWaBPKKPGcneknvYfy+STuxFpO8PrF7m7BNyLVcAMJYrgmjjEkj7iZoP

tLk6BmD91ksbBoWkSdWQUkgKY9MCWRuVusD8qjaIgxAJCdVTYTUBHYG49OTm1cTWHkc5BLIN

NIKgXnkMSAO9IJWeQAHsI4g1heoGRE4Dh30GnkrHm4bSJNpaU0XEvAOSKjsNWB7EYT2GJ+Di

mXTkXnrrnDZXD1FhvUVkk3d8K3h3oo3xKBHrJiKp38WH0o+wI7injwIBdb2b8CYOwJ1kHY0I

B0INZnCfJUAe7KuIedtHKGLpYOBIJtEC1PiM5csihhwNid/F4AyGTDLvCObcGLNWJVG2+xq8

R+fHNZ24jBBHiaHsRsSfcV9ZRKW+HL9+ZqrY4o3ucxmvA6nwbT3EWZVBJONmFQ5Jv2JqF/z6

T0Rj5ZrMhAVcSEPwUweAxe9QdQpHm+RS9lNZBHI+xhZNx89pa7L07rU1GUE56OP8QIzvCDsX

NFe9j6H7pDPbXfIDoJnEWZDzITtZYBLVAQxpxyGLSNQt8QprIsX8mtoS3dQiao9I+/CH8GDu

ndhyA1NPgWz05RH3FhPYWothRMsleuTix3Ggf9G4QjAA5MrrPI4eA0YWMIQeRILPG32ylOYB

EQDpzPajxT2ocx3VYdBRVL+g9nNgF+iot9fN3PSL5Yis4N/DTwO07qaxRLSlAAAAAElFTkSu

QmCC



------=_NextPart_000_0012_77E393D5.BB068DB9--

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA