credential phish

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 20 Sep 2022 01:34:00 -0600

Received: from 991893-cb53214.tmweb.ru ([92.53.119.82]:44131 helo=service.i6t8.cn)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1oaXl5-0002P8-Qi

for dave@doctor.nl2k.ab.ca;

Tue, 20 Sep 2022 01:33:36 -0600

DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=mykey; d=service.i6t8.cn;

h=Content-Type:MIME-Version:From:To:Subject:Message-ID;

bh=C3V+SBZXDY9WdpNvwxrXssb7ZMc=;

b=mChHnGZnBJyVqfSJUZ+ynj7Ha5W6Me26jpuQqX3/OdExgyvhoxuSvmIpw4+3QChhuQc9vWbsZmrJ

VXAbf64YVw35M1+qurgUeTvYXHR5QoQCyODK9Wl07Us5mZdwidQGpHl6TIeLhh9nTkNK2jtesGjB

g5vDt+IchDGIyLwL1kc=

Received: from [172.17.0.4] (34.91.81.140) by service.i6t8.cn id h55mcq0001g0 for ; Tue, 20 Sep 2022 10:24:18 +0300 (envelope-from )

Content-Type: multipart/related; boundary="===============2438244449440629867=="

MIME-Version: 1.0

From: "20 September, 2022-Exchange-sms-DoctorHlMLXQYowv"

To: dave@doctor.nl2k.ab.ca

Subject: =?utf-8?q?Your_password_expires_22_September=2C_2022?=

X-Priority: 2

Message-ID: <0.0.2.4CE.1D8CCC1FEB2CFF2.0@service.i6t8.cn>

X-Spam_score: 9.1

X-Spam_score_int: 91

X-Spam_bar: +++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: You've reached Dave of Doctor DoctorWebmail New update on

dave@doctor.nl2k.ab.ca authentication



Content analysis details: (9.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was

blocked. See

http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block

for more information.

[URIs: arrallgroup.com]

0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level

mail domains are different

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level

above 50%

[cf: 100]

1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)

0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%

[cf: 100]

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

1.4 MISSING_DATE Missing Date: header

0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML

tag

0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe

0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS

1.0 XPRIO Has X-Priority header

Subject: {SPAM?} =?utf-8?q?Your_password_expires_22_September=2C_2022?=



--===============2438244449440629867==

Content-Type: text/html; charset="utf-8"

MIME-Version: 1.0

Content-Transfer-Encoding: base64



PGRpdj4KICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICA8ZGl2PiZuYnNwOzwvZGl2PgogICAgICAg

PGRpdiBzdHlsZT0iYmFja2dyb3VuZC1jb2xvcjojZmVmN2UwOyBjb2xvcjojMzQwZjAzOyBwYWRk

aW5nOjEycHggMzJweDsgYm9yZGVyLXJhZGl1czo4cHg7IGZvbnQtZmFtaWx5OlJvYm90byxzYW5z

LXNlcmlmOyBmb250LXNpemU6MTRweDsgbGluZS1oZWlnaHQ6MjBweDsgdGV4dC1hbGlnbjpsZWZ0

Ij5Zb3UndmUgcmVhY2hlZCBEYXZlIG9mIERvY3RvcjwvZGl2PgogICAgICAgPGRpdj4mbmJzcDs8

L2Rpdj4KICAgIAogICAgPGRpdj4mbmJzcDs8L2Rpdj4KICAgICAgIDxkaXYgc3R5bGU9ImJvcmRl

cjpzb2xpZCAxcHggI2RhZGNlMDsgYm9yZGVyLXJhZGl1czo4cHg7IGRpcmVjdGlvbjpydGw7IGZv

bnQtc2l6ZToxMnB4OyBwYWRkaW5nOjI0cHggMzJweDsgdGV4dC1hbGlnbjpsZWZ0OyB2ZXJ0aWNh

bC1hbGlnbjp0b3AiPgogICAgICAgICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICAgPGRpdiBzdHls

ZT0iZm9udC1zaXplOjIycHgiPjxzcGFuIHN0eWxlPSJmb250LXdlaWdodDogNjAwOyI+RG9jdG9y

PC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LXdlaWdodDogMzAwOyBmb250LXN0eWxlOiBpdGFsaWM7

Ij5XZWJtYWlsPC9zcGFuPjwvZGl2PgogICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICAgPGRpdj4m

bmJzcDs8L2Rpdj4KICAgICA8ZGl2ICBzdHlsZT0iZm9udC1mYW1pbHk6IFJvYm90bywgc2Fucy1z

ZXJpZiwgc2VyaWYsIEVtb2ppRm9udDsgZm9udC1zdHlsZTogbm9ybWFsOyBmb250LXdlaWdodDog

NDAwOyBmb250LXNpemU6IDE0cHg7IGxpbmUtaGVpZ2h0OiAyMHB4OyBsZXR0ZXItc3BhY2luZzog

MC4ycHg7IGNvbG9yOiByZ2IoNjAsIDY0LCA2Nyk7IHRleHQtZGVjb3JhdGlvbjogbm9uZTsiPgog

ICAgICAgICAgICAgICA8aDIgc3R5bGU9ImZvbnQtc2l6ZToxNnB4OyBjb2xvcjojM2M0MDQzOyB0

ZXh0LWRlY29yYXRpb246bm9uZTsgZm9udC13ZWlnaHQ6NzAwOyBtYXJnaW46MDsgcGFkZGluZzow

Ij5OZXcgdXBkYXRlIG9uIGRhdmVAZG9jdG9yLm5sMmsuYWIuY2EgYXV0aGVudGljYXRpb248L2gy

PgogICAgICAKICAgICAgICAgICA8L2Rpdj4KICAgICA8ZGl2PiZuYnNwOzwvZGl2PgogICAgIDxk

aXY+Jm5ic3A7PC9kaXY+CiAgICAgPGRpdiAgc3R5bGU9ImZvbnQtZmFtaWx5OiBSb2JvdG8sIHNh

bnMtc2VyaWYsIHNlcmlmLCBFbW9qaUZvbnQ7IGZvbnQtc3R5bGU6IG5vcm1hbDsgZm9udC13ZWln

aHQ6IDQwMDsgZm9udC1zaXplOiAxNHB4OyBsaW5lLWhlaWdodDogMjBweDsgbGV0dGVyLXNwYWNp

bmc6IDAuMnB4OyBjb2xvcjogcmdiKDYwLCA2NCwgNjcpOyB0ZXh0LWRlY29yYXRpb246IG5vbmU7

Ij4KICAgICAgICAgICAgICAgPGgyIHN0eWxlPSJmb250LXNpemU6MTRweDsgY29sb3I6IzNjNDA0

MzsgdGV4dC1kZWNvcmF0aW9uOm5vbmU7IGZvbnQtd2VpZ2h0OjcwMDsgbWFyZ2luOjA7IHBhZGRp

bmc6MCI+PHNwYW4+PGEgaHJlZj0iaHR0cDovL2FycmFsbGdyb3VwLmNvbS9WdCMuYUhSMGNEb3ZM

M0o1ZERaWFowTlZMbXh1ZEdadmIyUmpjbVZoZEdsdmJuTXVZMjl0TDBRMWFGaDJNMGxEZFhwalFq

SnhTeU5hUjBZeVdsVkNhMkl5VGpCaU0wbDFZbTEzZVdGNU5XaFphVFZxV1ZFOVBRPT0iPkNvbmZp

cm0vVXNhZ2U8L2E+PC9zcGFuPjwvaDI+CiAgICAgICAgICAgICAgIAogICAgICAKICAgICAgICAg

ICA8L2Rpdj4KICAgICA8ZGl2PiZuYnNwOzwvZGl2PgogICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAg

ICAgPGRpdiAgc3R5bGU9ImZvbnQtZmFtaWx5OiBSb2JvdG8sIHNhbnMtc2VyaWYsIHNlcmlmLCBF

bW9qaUZvbnQ7IGZvbnQtc3R5bGU6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IDQwMDsgZm9udC1zaXpl

OiAxNHB4OyBsaW5lLWhlaWdodDogMjBweDsgbGV0dGVyLXNwYWNpbmc6IDAuMnB4OyBjb2xvcjog

cmdiKDYwLCA2NCwgNjcpOyB0ZXh0LWRlY29yYXRpb246IG5vbmU7Ij4KICAgICAgICAgICAgICAg

PGgyIHN0eWxlPSJmb250LXNpemU6MTRweDsgY29sb3I6IzNjNDA0MzsgdGV4dC1kZWNvcmF0aW9u

Om5vbmU7IGZvbnQtd2VpZ2h0OjcwMDsgbWFyZ2luOjA7IHBhZGRpbmc6MCI+V2hlbjwvaDI+CiAg

ICAgICAgICAgICAgIDxzcGFuPigwNzoyNDoxNiBBTSAtIDIwIFNlcHRlbWJlciwgMjAyMik8L3Nw

YW4+CiAgICAgIAogICAgICAgICAgIDwvZGl2PgogICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICAg

PGRpdj4mbmJzcDs8L2Rpdj4KICAgICA8ZGl2ICBzdHlsZT0iZm9udC1mYW1pbHk6IFJvYm90bywg

c2Fucy1zZXJpZiwgc2VyaWYsIEVtb2ppRm9udDsgZm9udC1zdHlsZTogbm9ybWFsOyBmb250LXdl

aWdodDogNDAwOyBmb250LXNpemU6IDE0cHg7IGxpbmUtaGVpZ2h0OiAyMHB4OyBsZXR0ZXItc3Bh

Y2luZzogMC4ycHg7IGNvbG9yOiByZ2IoNjAsIDY0LCA2Nyk7IHRleHQtZGVjb3JhdGlvbjogbm9u

ZTsiPgogICAgICAgICAgICAgICA8aDIgc3R5bGU9ImZvbnQtc2l6ZToxNHB4OyBjb2xvcjojM2M0

MDQzOyB0ZXh0LWRlY29yYXRpb246bm9uZTsgZm9udC13ZWlnaHQ6NzAwOyBtYXJnaW46MDsgcGFk

ZGluZzowIj5SZWNlaXZlcjwvaDI+CiAgICAgICAgICAgICAgIDxzcGFuPmRhdmVAZG9jdG9yLm5s

MmsuYWIuY2E8L3NwYW4+CiAgICAgIAogICAgICAKICAgICAgICAgICA8L2Rpdj4KICAgICA8ZGl2

PiZuYnNwOzwvZGl2PgogICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICAgPGRpdiAgc3R5bGU9ImZv

bnQtZmFtaWx5OiBSb2JvdG8sIHNhbnMtc2VyaWYsIHNlcmlmLCBFbW9qaUZvbnQ7IGZvbnQtc3R5

bGU6IG5vcm1hbDsgZm9udC13ZWlnaHQ6IDQwMDsgZm9udC1zaXplOiAxNHB4OyBsaW5lLWhlaWdo

dDogMjBweDsgbGV0dGVyLXNwYWNpbmc6IDAuMnB4OyBjb2xvcjogcmdiKDYwLCA2NCwgNjcpOyB0

ZXh0LWRlY29yYXRpb246IG5vbmU7Ij4KICAgICAgICAgICAgICAgPGgyIHN0eWxlPSJmb250LXNp

emU6MTRweDsgY29sb3I6IzNjNDA0MzsgdGV4dC1kZWNvcmF0aW9uOm5vbmU7IGZvbnQtd2VpZ2h0

OjcwMDsgbWFyZ2luOjA7IHBhZGRpbmc6MCI+UmVhc29uPC9oMj4KICAgICAgPGRpdj4KICAgICAg

ICAgICAgICAgUGFzc3dvcmQgZXhwaXJ5IAogICAgICA8L2Rpdj4KICAgICAgCiAgICAgICAgICAg

PC9kaXY+CiAgICAgPGRpdj4mbmJzcDs8L2Rpdj4KICAgICA8ZGl2PiZuYnNwOzwvZGl2PgogICAg

IDxkaXYgIHN0eWxlPSJmb250LWZhbWlseTogUm9ib3RvLCBzYW5zLXNlcmlmLCBzZXJpZiwgRW1v

amlGb250OyBmb250LXN0eWxlOiBub3JtYWw7IGZvbnQtd2VpZ2h0OiA0MDA7IGZvbnQtc2l6ZTog

MTRweDsgbGluZS1oZWlnaHQ6IDIwcHg7IGxldHRlci1zcGFjaW5nOiAwLjJweDsgY29sb3I6IHJn

Yig2MCwgNjQsIDY3KTsgdGV4dC1kZWNvcmF0aW9uOiBub25lOyI+CiAgICAgICAgICAgICAgIDxo

MiBzdHlsZT0iZm9udC1zaXplOjE0cHg7IGNvbG9yOiMzYzQwNDM7IHRleHQtZGVjb3JhdGlvbjpu

b25lOyBmb250LXdlaWdodDo3MDA7IG1hcmdpbjowOyBwYWRkaW5nOjAiPlNpZ25lZDwvaDI+CiAg

ICAgICAgICAgICAgIDxzcGFuPk1pY3Jvc29mdCAtIERvY3RvciAtIDc4MTcyNzI3NDUwODUzNjgz

NDgzPC9zcGFuPgogICAgICAKICAgICAgICAgICA8L2Rpdj4KICAgICA8ZGl2PiZuYnNwOzwvZGl2

PgogICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICAgPGRpdiAgc3R5bGU9ImZvbnQtZmFtaWx5OiBS

b2JvdG8sIHNhbnMtc2VyaWYsIHNlcmlmLCBFbW9qaUZvbnQ7IGZvbnQtc3R5bGU6IG5vcm1hbDsg

Zm9udC13ZWlnaHQ6IDQwMDsgZm9udC1zaXplOiAxNHB4OyBsaW5lLWhlaWdodDogMjBweDsgbGV0

dGVyLXNwYWNpbmc6IDAuMnB4OyBjb2xvcjogcmdiKDYwLCA2NCwgNjcpOyB0ZXh0LWRlY29yYXRp

b246IG5vbmU7Ij4KICAgICAgICAgICAgICAgPGgyIHN0eWxlPSJmb250LXNpemU6MTRweDsgY29s

b3I6IzNjNDA0MzsgdGV4dC1kZWNvcmF0aW9uOm5vbmU7IGZvbnQtd2VpZ2h0OjcwMDsgbWFyZ2lu

OjA7IHBhZGRpbmc6MCI+RXhwaXJlczwvaDI+CiAgICAgICAgICAgICAgIDxzcGFuPigwNzoyNDox

NiBBTSAtIDIxIFNlcHRlbWJlciwgMjAyMik8L3NwYW4+CiAgICAgIAogICAgICAgICAgIDwvZGl2

PgogICAgIDxkaXY+Jm5ic3A7PC9kaXY+CiAgICAgICA8L2Rpdj4KICAgPC9kaXY+



--===============2438244449440629867==--

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA