DHL Phish from Bulgaria

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sat, 26 Nov 2022 06:55:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1oyvdu-000AOE-Fe

for dave@doctor.nl2k.ab.ca;

Sat, 26 Nov 2022 06:54:55 -0700

Resent-From: The Doctor

Resent-Date: Sat, 26 Nov 2022 06:54:54 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from cska.bg ([79.98.107.6]:60504 helo=server.cska.bg)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1oyvFn-00075q-HQ

for doctor@nl2k.ab.ca;

Sat, 26 Nov 2022 06:30:08 -0700

Received: by server.cska.bg (Postfix, from userid 500)

id 6EFA13466267; Sat, 26 Nov 2022 15:26:59 +0200 (EET)

To: doctor@nl2k.ab.ca

Subject: Your package is waiting for delivery

X-PHP-Originating-Script: 500:m.php

Date: Sat, 26 Nov 2022 15:26:59 +0200

From: "Support [DHL]"

Message-ID: <6fc19dc570df01cf235a0a9cb3ce9d68@cska.bg>

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="b1_6fc19dc570df01cf235a0a9cb3ce9d68"

Content-Transfer-Encoding: 8bit

X-Spam_score: 9.1

X-Spam_score_int: 91

X-Spam_bar: +++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: DHL Dear Customer, The health medical today-marketpackage

health medical today-marketsent health medical today-marketto health medical

today-marketyou health medical today-markethas health medical today-m [...]





Content analysis details: (9.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[79.98.107.6 listed in bb.barracudacentral.org]

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

-0.0 SPF_PASS SPF: sender matches SPF record

2.4 HTML_OBFUSCATE_20_30 BODY: Message is 20% to 30% HTML

obfuscation

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or

identical to background

0.0 HTML_MESSAGE BODY: HTML included in message

3.0 URI_WP_DIRINDEX URI for compromised WordPress site, possible

malware

2.0 URI_WP_HACKED_2 URI for compromised WordPress site, possible

malware

Subject: {SPAM?} Your package is waiting for delivery



This is a multi-part message in MIME format.



--b1_6fc19dc570df01cf235a0a9cb3ce9d68

Content-Type: text/plain; charset=UTF-8

Content-Transfer-Encoding: quoted-printable







DHL





=20

=20

=20

=20

=20

=20

=20

=20

=20

=20

=20

=20

Dear Customer,

The health medical today-marketpackage health medical today-marketsent heal=

th medical today-marketto health medical today-marketyou health medical tod=

ay-markethas health medical today-marketbeen health medical today-marketdel=

ivered health medical today-marketto health medical today-marketDHL health =

medical today-marketOffice health medical today-marketand health medical to=

day-marketshould health medical today-marketbe health medical today-marketd=

elivered health medical today-marketwithing health medical today-market48h.=

health medical today-marketPlease health medical today-marketconfirm healt=

h medical today-marketthe health medical today-marketpayment

on health medical today-marketthe health medical today-marketlink health =

medical today-marketbelow health medical today-marketwithin health medical =

today-marketa health medical today-marketmaximum health medical today-marke=

tof health medical today-market14 health medical today-marketdays health me=

dical today-marketbefore health medical today-marketit health medical today=

-marketexpires:

Follow health medical today-marketmy health medical today-marketpackage



This health medical today-marketemail health medical today-marketis health =

medical today-marketprovided health medical today-marketfor health medical =

today-marketinformational health medical today-marketpurposes health medica=

l today-marketonly health medical today-marketand health medical today-mark=

etdoes health medical today-marketnot health medical today-marketguarantee =

health medical today-marketdelivery health medical today-marketof health me=

dical today-marketthe health medical today-marketshipment. health medical t=

oday-marketUnable health medical today-marketto health medical today-market=

reply health medical today-marketto health medical today-marketthis health =

medical today-marketemail. health medical today-marketYour health medical t=

oday-markete-mail health medical today-marketaddress health medical today-m=

arketwill health medical today-marketonly health medical today-marketbe hea=

lth medical today-marketused health medical today-marketfor health medical =

today-marketthe health medical today-marketannouncement health medical toda=

y-marketof health medical today-marketthe health medical today-marketparcel=

health medical today-marketof health medical today-marketthe health medica=

l today-marketabove health medical today-marketshipment health medical toda=

y-marketand health medical today-marketwill health medical today-marketnot =

health medical today-marketbe health medical today-marketsaved health medic=

al today-marketfor health medical today-marketadvertising health medical to=

day-marketpurposes. health medical today-marketIf health medical today-mark=

etyou health medical today-marketno health medical today-marketlonger healt=

h medical today-marketwish health medical today-marketto health medical tod=

ay-marketreceive health medical today-marketthe health medical today-market=

package health medical today-marketannouncement, health medical today-marke=

tplease health medical today-marketclick health medical today-markethere: D=

HL health medical today-marketNotification health medical today-marketServi=

ce=20







Website

Contact

Impressum

=C2=A9 2022 DHL ID00##09-{7}##







=20









--b1_6fc19dc570df01cf235a0a9cb3ce9d68

Content-Type: text/html; charset=UTF-8

Content-Transfer-Encoding: quoted-printable







DHL

















<=

td style=3D"width: 390.0px;">




td>
3D""
"http://www.dhl.de/content/dam/dhlde/external/dhl-header.gif">









">



Dear Customer,



The
0px">health medical today-market
package
">health medical today-market
sent heal=

th medical today-market
to health medic=

al today-market
you health medical toda=

y-market
has health medical today-marke=

t
been health medical today-market
n>delivered health medical today-market
>to health medical today-marketDHL
an style=3D"font-size:0px">health medical today-market
Office
tyle=3D"font-size:0px">health medical today-market
and
"font-size:0px">health medical today-market
should
t-size:0px">health medical today-market
be
px">health medical today-market
delivered
x">health medical today-market
withing =

health medical today-market
48h. health=

medical today-market
Please health med=

ical today-market
confirm health medica=

l today-market
the health medical today=

-market
payment

on health medical today-market
>the health medical today-marketlink <=

span style=3D"font-size:0px">health medical today-market
below
style=3D"font-size:0px">health medical today-market
within
e=3D"font-size:0px">health medical today-market
a
-size:0px">health medical today-market
maximum
ze:0px">health medical today-market
of =

health medical today-market
14 health m=

edical today-market
days health medical=

today-market
before health medical tod=

ay-market
it health medical today-marke=

t
expires:





ground:#d40511; padding: 6px 20px; border-radius: 2px;text-decoration:none"=

href=3D"https://soy-yummies.com/wp-includes/images/smilies/mydhl-id57577HG=

4N2/">Follow health medical today-market
n>my health medical today-marketpackag=

e






This health me=

dical today-market
email health medical=

today-market
is health medical today-m=

arket
provided health medical today-mar=

ket
for health medical today-market
an>informational health medical today-market<=

/span>purposes health medical today-market
pan>only health medical today-marketan=

d health medical today-marketdoes
n style=3D"font-size:0px">health medical today-market
not
=3D"font-size:0px">health medical today-market
guarantee
=3D"font-size:0px">health medical today-market
delivery
=3D"font-size:0px">health medical today-market
of
-size:0px">health medical today-market
the
px">health medical today-market
shipment.
x">health medical today-market
Unable h=

ealth medical today-market
to health me=

dical today-market
reply health medical=

today-market
to health medical today-m=

arket
this health medical today-market<=

/span>email. health medical today-market
n>Your health medical today-markete-ma=

il health medical today-marketaddress =

health medical today-marketwill
style=3D"font-size:0px">health medical today-market
only
=3D"font-size:0px">health medical today-market
be
-size:0px">health medical today-market
used
0px">health medical today-market
for he=

alth medical today-market
the health me=

dical today-market
announcement health =

medical today-market
of health medical =

today-market
the health medical today-m=

arket
parcel health medical today-marke=

t
of health medical today-market=

the health medical today-marketabove <=

span style=3D"font-size:0px">health medical today-market
shipment
an style=3D"font-size:0px">health medical today-market
and
e=3D"font-size:0px">health medical today-market
will
ont-size:0px">health medical today-market
not
e:0px">health medical today-market
be h=

ealth medical today-market
saved health=

medical today-market
for health medica=

l today-market
advertising health medic=

al today-market
purposes. health medica=

l today-market
If health medical today-=

market
you health medical today-market<=

/span>no health medical today-marketlo=

nger health medical today-marketwish <=

span style=3D"font-size:0px">health medical today-market
to
le=3D"font-size:0px">health medical today-market
receive
=3D"font-size:0px">health medical today-market
the
t-size:0px">health medical today-market
package
ize:0px">health medical today-market
announcement,
t-size:0px">health medical today-market
please
ze:0px">health medical today-market
click
x">health medical today-market
here:
phx.event.mailUrlClicked('https://nolb.dhl.de/nextt-online-business/gw/evs/=

SendEmail.action'); return true;" target=3D"_blank">DHL
-size:0px">health medical today-market
Notification
nt-size:0px">health medical today-market
Service

















tps://www.paket.de'); return true;" style=3D"font-size: 9.0px;font-family: =

Arial;" target=3D"_blank">Website

tion.href=3D'../../mail/compose/redirect;jsessionid=3DAF24F7D7CC7E7722158EA=

5B86E69A98F-n2.bs05b?editorAction=3DNEW&to=3Dpaket@dhl.de'; return false;" =

style=3D"font-size: 9.0px;font-family: Arial;" target=3D"_blank">Contact
>

target=3D"_blank">Impressum


0.0px;font-family: Arial;text-align: left;">=C2=A9 2022 DHL ID00##09-{7}=

##




0%">


colgroup>

3D""
/dam/dhlde/external/dhl-footer.gif">










--b1_6fc19dc570df01cf235a0a9cb3ce9d68--



Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA