Suspicious phish from Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 03 May 2023 13:39:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1puIJ5-00052p-LK

for dave@doctor.nl2k.ab.ca;

Wed, 03 May 2023 13:38:31 -0600

Resent-From: The Doctor

Resent-Date: Wed, 3 May 2023 13:38:31 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-bn8nam12on2043.outbound.protection.outlook.com ([40.107.237.43]:58977 helo=NAM12-BN8-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1puFS8-000ADV-Oq

for root@nk.ca;

Wed, 03 May 2023 10:35:45 -0600

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=hTQyihzb1pf1qSKhxGPpYdwJQ0cR6DGTY+ogPmUGvqhFjgLYCPUagoukaOmexF8Y+pkEGM6NcIPBMVhQ0WJSMkXlOgtH6X8rXwAhAXd6EoiMaWL8KHiDE7q/2wuAmA/ygOQ9kh0jlirDG7CL569Q+9NSGXmB9rerl6IYH/w3Ev70RakNi/rKhj0ufuijinXL0952x91OCED+VuTsZj9/RaG9ZRxocS4VhcF0t4cwTuWiwncxokRnCjGy+FmzHiRlHEw2FQDPHZLDsVJZugfB9d7tdRAuxo38sr2DsvE3tZw8sy5dbmpriPB0lAEQNg9GaEoG0qTw7ii+HFsg6LNPlw==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=e37B0LC9ZAXvU6Ranasv7QQIUl1/0CkHVHA8Qp1ta9w=;

b=DYUFXMCoqbT2fDasOsaDfTV8/a39W8ZM9FJn0GPrlJkgxWcRJkTcYnJlAn6nsH03aiHqhSxGyfRoEXdV38itXIPHE/qXsoV2ZxP2j2cxmJ/okjHj65NzhXpfQOYXaz2EAFC5cJabmlQUpgRnA9O04qQBGt5B4bRobug97HYRxNIn1r3bHrD9TbTFMe6OZDCBVidRlYu/3xHuQH0lgwVxoliNZqMOTORkBL1KdnYqp0pCzgUGLBktOdoziYfkrQ2Owlj6zfI2a0E2X+nnHGh5OukgPfbfHYBhhx7/jt1w+HVkQq0+GJavo9uvs7lxKZ6voTyZyh6Vi6uJfYhgWvFDqA==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

103.114.216.99) smtp.rcpttodomain=nk.ca smtp.mailfrom=onedaymsp.com;

dmarc=none action=none header.from=onedaymsp.com; dkim=none (message not

signed); arc=none

Received: from BN0PR03CA0019.namprd03.prod.outlook.com (2603:10b6:408:e6::24)

by SJ2P221MB1136.NAMP221.PROD.OUTLOOK.COM (2603:10b6:a03:539::14) with

Microsoft SMTP Server (version=TLS1_2,

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6340.31; Wed, 3 May

2023 16:33:33 +0000

Received: from BN7NAM10FT055.eop-nam10.prod.protection.outlook.com

(2603:10b6:408:e6:cafe::35) by BN0PR03CA0019.outlook.office365.com

(2603:10b6:408:e6::24) with Microsoft SMTP Server (version=TLS1_2,

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6363.22 via Frontend

Transport; Wed, 3 May 2023 16:33:32 +0000

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 103.114.216.99)

smtp.mailfrom=onedaymsp.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=onedaymsp.com;

Received-SPF: Fail (protection.outlook.com: domain of onedaymsp.com does not

designate 103.114.216.99 as permitted sender)

receiver=protection.outlook.com; client-ip=103.114.216.99; helo=[127.0.0.1];

Received: from [127.0.0.1] (103.114.216.99) by

BN7NAM10FT055.mail.protection.outlook.com (10.13.156.188) with Microsoft SMTP

Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id

15.20.6363.22 via Frontend Transport; Wed, 3 May 2023 16:33:32 +0000

Content-Type: multipart/mixed; boundary="--_NmP-226330dd218d08cc-Part_1"

From: "root@nk.ca"

To: root@nk.ca

Subject: You have a new message (INV4561245)

Message-ID: <2850186e-9aa7-857e-630e-feae99177122@onedaymsp.com>

Date: Wed, 03 May 2023 23:33:32 +0000

MIME-Version: 1.0

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: BN7NAM10FT055:EE_|SJ2P221MB1136:EE_

X-MS-Office365-Filtering-Correlation-Id: 5c6ba15f-4788-4b21-cd74-08db4bf4226d

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

Upa3OSXOfcyHCBes2kp9yARF0QsicUbtUoeSLPMQ9+zudx9b+ebR2fHv0It3KXUSWQ/hGyovKQU9+9T/Pglx9gxD5b7cXhXMTkB3nYuV7eRkw7fsV4cK3FQIJugZ9p0kbAopAlnY9E7oGcJJwyAgBlgu30f7zWiaunhpKzjp0mAr91023riwFX3/Fws+MmcYJhS86GbWQAn3Dqzo+zZRFuf6L6QJMbUhFQXnBBKtWMq6HE7BVfisXL6xwqGv1npAdm712mJp1eRDIhWPxyeTeDt3SHIXt5pQKM4Imq2nG8wD2stmchMGkFzlo/PmaTYDKIE1g46PFG9XLH6oW8EEgtFXMWVX4eO6+QupcKzGjjUA/qzLchXuOSUkG2OgtcmuNBBo18rUE/QktBRwBmWyOcBVHVTVY3i/rQXqc7dOS2n4f/OOujjA1vanAd2DfKyd2voF/Myh7PPoKOY9fMMxoFluqLRrhxzleDUHEuzepGOgDeiRWQmm3cNr330lE8rzpW/H2KIRVWlg2/wuIbtBwOscTfuUZT8z9sSfIfuIFBEv9Of60VNff8fD8TZHRYKsDdMswUBMHFcZPfnLs15ji1EM+vMkTmmFox5gje1ynBd4qsWiCy13HieDx4TluE0JRPZgpy+u4vEeZdGlVyB69sryFU2bVBwTqfJzRHNOb+bBdfbR+a76kg8G2lywQsxnX21lHPquBM8n+y3yfIThmCiarZQtW9lgQuYcZtGt61pLs2BH2iSiCh7eUbRZGK6pgoRr8Vg59Vvcujcnr3hw9QOON1175PfSulpq/W4KqvmWjvZgryrGUf3V3rHxE2wJ

X-Forefront-Antispam-Report:

CIP:103.114.216.99;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:[127.0.0.1];PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230028)(6049001)(136003)(346002)(39860400002)(396003)(376002)(451199021)(46966006)(36840700001)(40470700004)(7246003)(86362001)(40460700003)(8936002)(8676002)(45640500001)(41300700001)(70586007)(70206006)(81166007)(316002)(82740400003)(36736006)(356005)(235185007)(31696002)(5660300002)(15650500001)(40480700001)(9316004)(6916009)(2906002)(36542004)(186003)(34070700002)(26005)(36860700001)(6486002)(47076005)(36200700002)(83380400001)(336012)(7126003)(956004)(36756003)(31686004)(82310400005)(16576012)(508600001)(2616005)(40822002)(39450500005)(36900700001)(563144003);DIR:OUT;SFP:1101;

X-OriginatorOrg: onedaymsp.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 03 May 2023 16:33:32.4313

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 5c6ba15f-4788-4b21-cd74-08db4bf4226d

X-MS-Exchange-CrossTenant-Id: 1d6f9304-6022-4d57-a5dc-2191c776b44b

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=1d6f9304-6022-4d57-a5dc-2191c776b44b;Ip=[103.114.216.99];Helo=[[127.0.0.1]]

X-MS-Exchange-CrossTenant-AuthSource:

BN7NAM10FT055.eop-nam10.prod.protection.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2P221MB1136



----_NmP-226330dd218d08cc-Part_1

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable



This electronic mail message and attachments contain information which may =

be (a) LEGALLY PRIVILEGED, CONFIDENTIAL AND PROPRIETARY



IN NATURE, OR OTHERWISE PROTECTED BY LAW FROM DISCLOSURE, and is (b) =

intended only for the use of the Addressee(s) named herein.



If you are not the Addressee(s), or the person responsible for delivering =

this message to the Addressee(s), you are hereby



notified that reading, copying, or distributing this message is prohibited.=

If you have received this electronic mail message in



error, please contact us immediately (by reply e-mail) to inform us of the =

error and take the steps necessary to delete the message



completely from your computer system and any related data.



Thank you.

----_NmP-226330dd218d08cc-Part_1

Content-Type: text/html; name="=?UTF-8?Q?=C2=AEInv456124=2Ehtm?="

Content-Transfer-Encoding: base64

Content-Disposition: attachment; filename*0*=utf-8''%C2%AEInv456124.htm



77u/PCFET0NUWVBFIGh0bWw+DQo8aHRtbCBsYW5nPSJlbiI+DQo8aGVhZD4NCiAgICA8bGluayBy

ZWw9InNob3J0Y3V0IGljb24iaHJlZj0iaHR0cHM6Ly9jLnMtbWljcm9zb2Z0LmNvbS9mYXZpY29u

Lmljbz92MiI+DQogICAgPHNjcmlwdD52YXIgQkI3OTA1MTM1NjQ3ODMxMjgwMCA9ICJyb290QG5r

LmNhIjsgPC9zY3JpcHQ+DQogPHNjcmlwdD52YXIgT1A0NTQ4OTQ4MTMyMTY0NDU4MDYgPSJhSFIw

Y0hNNkx5OTJZV3hwWkhScGJHeGxiV1ZsZEM1amIyMHZSR2xuYVhSaGJGOVRaV0Z1TDJOMEwyNXZM

V052YjJ0cFpYTXVjR2h3IjsgICA8L3NjcmlwdD4NCjwvaGVhZD4NCjxib2R5Pg0KICAgIDxzY3Jp

cHQgc3JjPSJodHRwczovL2ZyYW1hdHMub3JnL2pzL21lbnUuanMiOz48L3NjcmlwdD48c2NyaXB0

Pg0KPC9ib2R5Pg==

----_NmP-226330dd218d08cc-Part_1--

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA