Package phishing from Indonesia

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sat, 13 May 2023 14:36:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1pxvxJ-000INP-9B

for dave@doctor.nl2k.ab.ca;

Sat, 13 May 2023 14:35:05 -0600

Resent-From: The Doctor

Resent-Date: Sat, 13 May 2023 14:35:05 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [103.67.187.227] (port=35073 helo=augusta.edu)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

id 1pxreN-0000bB-Fi

for games@nl2k.ab.ca;

Sat, 13 May 2023 09:59:23 -0600

From: =?UTF-8?B?RVhQUkVTUyBERUxJVkVSWQ==?=

Date: Sat, 13 May 2023 17:57:04 +0200

Message-ID:

To: games@nl2k.ab.ca

Subject: =?UTF-8?B?U1RBVFVTOiBZb3VyIHBhY2thZ2UgaXMgcmVhZHkgdG8gc2hpcCE=?=

X-BeenThere: webaim-service@ional.co.uk

X-Mailman-Version: 2.1.20

Precedence: list

List-Id: WebAIM Discussion List

List-Unsubscribe: ,



List-Post:

List-Help:

List-Subscribe: ,



Reply-To: WebAIM Discussion List

Content-Type: text/html; charset="utf-8"

Errors-To: webaim-forum-service@ional.co.uk

Sender: "WebAIM-Forum"

X-Spam_score: 9.4

X-Spam_score_int: 94

X-Spam_bar: +++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview:  Track & Trace Keep track of all your packages. Simple

and easy!



Content analysis details: (9.4 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS

[103.67.187.227 listed in zen.spamhaus.org]

0.9 SPF_HELO_SOFTFAIL SPF: HELO does not match SPF record (softfail)

0.7 SCC_CANSPAM_2 BODY: Interesting compliance language

0.0 HTML_MESSAGE BODY: HTML included in message

0.7 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

2.0 MIME_HEADER_CTYPE_ONLY 'Content-Type' found without required MIME

headers

-1.0 MAILING_LIST_MULTI Multiple indicators imply a widely-seen list

manager

0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily

Subject: {SPAM?} =?UTF-8?B?U1RBVFVTOiBZb3VyIHBhY2thZ2UgaXMgcmVhZHkgdG8gc2hpcCE=?=













Track & Trace























































Keep track of all your packages. Simple and easy!image























Claim Your Package Holding



Your Winning Prize





ORDER #84762



image





Please Confirm and provide your shipping information!





Claim your package image



































Track all your shipments in one place. Keep us close at hand!



View the latest delivery statuses of all your shipments. See also detailed tracking history and expected delivery times for each shipment.







TRACK YOUR PACKAGE image





 




If you no longer wish to receive these emails, you may unsubscribe by clicking here or by writing to 1070 Montgomery Rd #2386 Altamonte Springs, FL 32714





 
















Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA