Mcafee phish from sendgrid
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 28 Apr 2023 10:19:40 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))
(envelope-from)
id 1psQnD-0007tc-DR
for dave@doctor.nl2k.ab.ca;
Fri, 28 Apr 2023 10:17:55 -0600
Resent-From: The Doctor
Resent-Date: Fri, 28 Apr 2023 10:17:55 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from xtrwhxbr.outbound-mail.sendgrid.net ([167.89.10.181]:43298)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.95 (FreeBSD))
(envelope-from)
id 1psQVd-000O5s-OT
for doctor@nk.ca;
Fri, 28 Apr 2023 10:00:06 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=whatscamaleon.com;
h=from:subject:list-id:to:content-type:content-transfer-encoding:cc:
content-type:from:subject:to;
s=s1; bh=rhkuToRPInE/qBSNB+jDFWsBBjFU2as7PEQ49GQWgy4=;
b=KbJyswTt5KyhkfULCr7lDt7SdwAub1Wp1V/l2CP9W9fAxadfvFTwcWiIsqSlm66KN4WG
Ye8Rp9KDQ7NGzpeNgc7MKuisldmQUGyjNrsPKvpJ2eq0dvW/eBMXfRhczOeQCGA5uJEGzj
SQyhSheQSDPzWRjmSsNERA+bOcdRa6ZLXD+NH7ta6nkswPIrt+2OhuiVq6Mhhod2Npef65
3vmOJgMhXDKz5LhIkqq7IE8fDBKlTM0xWPnGJslrm1EnXULzdvFOZdUTyYyu+t9j+j+Ek9
ylj73CU6nAk72fi1CepvJquEu2HYUpoDp9W3hjSqKE5esIfrdCiiATyKKi2sFkig==
Received: by filterdrecv-849fc8479d-z5m2l with SMTP id filterdrecv-849fc8479d-z5m2l-1-644BECF3-C2
2023-04-28 15:57:40.002690233 +0000 UTC m=+5675009.439933933
Received: from 8227f904-2ae7-4172-8723-8c3af7086583.pub.instances.scw.cloud (unknown)
by geopod-ismtpd-0 (SG) with ESMTP id VlCg49csQCyiuvAE1n8Yrg
for; Fri, 28 Apr 2023 15:57:39.864 +0000 (UTC)
Message-ID: <0819608472_4138805123_8141174944@rMoLVrC2p9.johormous.com>
From: "Mcafee-Anti-Virus."
Subject: Reminder Your McFee Protection Expred Today d8ez
Date: Fri, 28 Apr 2023 15:57:40 +0000 (UTC)
List-Id: doctor.virginmedia.com (http://doctor.virginmedia.com/)
X-Mailer: 7pXcWIb23JuZvYV7WvFGe1zbeUhb1YHZdv2033TW
X-Unsubscribe:
X-SG-EID:
=?us-ascii?Q?vasJryaBgzKftuMacv0hJ0pC1fkzoA2RJE4RNpRlUjUW7sGUVQ1Py05IiFrGW2?=
=?us-ascii?Q?PJp+4I5CNNvghv6ablypTRSiEjlBzeLldXVlxjV?=
=?us-ascii?Q?c2d4IfvEuzCRSFTsz6lvnXRtPn=2FzjC5m=2FYoBhGB?=
=?us-ascii?Q?rNzeQgj0cQTYQP61cIiB=2FBGJUGvcOJoyKavfhT9?=
=?us-ascii?Q?PI74xOS32HMuySAMxVSkXik4et+CJayCZa1fsGH?=
=?us-ascii?Q?DRFu8N9RC3+x5TncuRO9cCgSvKi8bwGYVf48LV?=
To: doctor@nk.ca
X-Entity-ID: jUmwKISBrVEvupYj2WBvVQ==
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Spam_score: 6.1
X-Spam_score_int: 61
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Your Protection From Viruses Has Ended {91EBD84A-3C00-41E8-AFC8-03759CD6678B}
{908CC59F-6D9A-45BC-8D24-B17B9837E5C7} {B7D3AFAF-24F8-4AF5-B8F0-69FF75EF5934}
{44D53895-FDFF-430F-9E77-E767E79D9026} {FDD56A38-6F2A-4494-A7EE-DD2CAC339568}
{C294 [...]
Content analysis details: (6.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[167.89.10.181 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
Subject: {SPAM?} Reminder Your McFee Protection Expred Today d8ez
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 28 Apr 2023 10:19:40 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))
(envelope-from
id 1psQnD-0007tc-DR
for dave@doctor.nl2k.ab.ca;
Fri, 28 Apr 2023 10:17:55 -0600
Resent-From: The Doctor
Resent-Date: Fri, 28 Apr 2023 10:17:55 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from xtrwhxbr.outbound-mail.sendgrid.net ([167.89.10.181]:43298)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.95 (FreeBSD))
(envelope-from
id 1psQVd-000O5s-OT
for doctor@nk.ca;
Fri, 28 Apr 2023 10:00:06 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=whatscamaleon.com;
h=from:subject:list-id:to:content-type:content-transfer-encoding:cc:
content-type:from:subject:to;
s=s1; bh=rhkuToRPInE/qBSNB+jDFWsBBjFU2as7PEQ49GQWgy4=;
b=KbJyswTt5KyhkfULCr7lDt7SdwAub1Wp1V/l2CP9W9fAxadfvFTwcWiIsqSlm66KN4WG
Ye8Rp9KDQ7NGzpeNgc7MKuisldmQUGyjNrsPKvpJ2eq0dvW/eBMXfRhczOeQCGA5uJEGzj
SQyhSheQSDPzWRjmSsNERA+bOcdRa6ZLXD+NH7ta6nkswPIrt+2OhuiVq6Mhhod2Npef65
3vmOJgMhXDKz5LhIkqq7IE8fDBKlTM0xWPnGJslrm1EnXULzdvFOZdUTyYyu+t9j+j+Ek9
ylj73CU6nAk72fi1CepvJquEu2HYUpoDp9W3hjSqKE5esIfrdCiiATyKKi2sFkig==
Received: by filterdrecv-849fc8479d-z5m2l with SMTP id filterdrecv-849fc8479d-z5m2l-1-644BECF3-C2
2023-04-28 15:57:40.002690233 +0000 UTC m=+5675009.439933933
Received: from 8227f904-2ae7-4172-8723-8c3af7086583.pub.instances.scw.cloud (unknown)
by geopod-ismtpd-0 (SG) with ESMTP id VlCg49csQCyiuvAE1n8Yrg
for
Message-ID: <0819608472_4138805123_8141174944@rMoLVrC2p9.johormous.com>
From: "Mcafee-Anti-Virus."
Subject: Reminder Your McFee Protection Expred Today d8ez
Date: Fri, 28 Apr 2023 15:57:40 +0000 (UTC)
List-Id: doctor.virginmedia.com (http://doctor.virginmedia.com/)
X-Mailer: 7pXcWIb23JuZvYV7WvFGe1zbeUhb1YHZdv2033TW
X-Unsubscribe:
X-SG-EID:
=?us-ascii?Q?vasJryaBgzKftuMacv0hJ0pC1fkzoA2RJE4RNpRlUjUW7sGUVQ1Py05IiFrGW2?=
=?us-ascii?Q?PJp+4I5CNNvghv6ablypTRSiEjlBzeLldXVlxjV?=
=?us-ascii?Q?c2d4IfvEuzCRSFTsz6lvnXRtPn=2FzjC5m=2FYoBhGB?=
=?us-ascii?Q?rNzeQgj0cQTYQP61cIiB=2FBGJUGvcOJoyKavfhT9?=
=?us-ascii?Q?PI74xOS32HMuySAMxVSkXik4et+CJayCZa1fsGH?=
=?us-ascii?Q?DRFu8N9RC3+x5TncuRO9cCgSvKi8bwGYVf48LV?=
To: doctor@nk.ca
X-Entity-ID: jUmwKISBrVEvupYj2WBvVQ==
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Spam_score: 6.1
X-Spam_score_int: 61
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Your Protection From Viruses Has Ended {91EBD84A-3C00-41E8-AFC8-03759CD6678B}
{908CC59F-6D9A-45BC-8D24-B17B9837E5C7} {B7D3AFAF-24F8-4AF5-B8F0-69FF75EF5934}
{44D53895-FDFF-430F-9E77-E767E79D9026} {FDD56A38-6F2A-4494-A7EE-DD2CAC339568}
{C294 [...]
Content analysis details: (6.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[167.89.10.181 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
Subject: {SPAM?} Reminder Your McFee Protection Expred Today d8ez
Trackbacks
Trackback specific URI for this entryThis link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.
No Trackbacks
Comments
Display comments as Linear | ThreadedNo comments