phish from yourbestnetwork.net Warsaw

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 11 Jul 2023 09:00:06 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qJEpx-000CpE-0r

for dave@doctor.nl2k.ab.ca;

Tue, 11 Jul 2023 08:59:33 -0600

Resent-From: The Doctor

Resent-Date: Tue, 11 Jul 2023 08:59:33 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [77.83.196.100] (port=47213 helo=inbox0.zyz46.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.96 (FreeBSD))

(envelope-from )

id 1qJ8O1-00079v-2Y

for doctor@nl2k.ab.ca;

Tue, 11 Jul 2023 02:06:21 -0600

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default; d=zyz46.com;

h=From:To:Subject:Date:Message-ID:MIME-Version:List-Unsubscribe:Content-Type:

Content-Transfer-Encoding; i=admin03655@zyz46.com;

bh=zyqsjPhpCT6RzhneR+xlBeWfpCG5Udj5xBivWBbgEW4=;

b=BpJkyHKnxtOsdLVQK215dxu54+RkhFSqYpQgzRbmj8wZUqh5HU5e20hUNDZd5U6HJp4JPtC23dY/

bv0on/atSY9mn6asB58J6pKj0+a0Y1okGo78uF+RB9qZpWQuFcaDFPDrlpTWJnKC4ZUPfeV1dDXZ

Q8z2Wv7p1pVDcTmBkF4=

From: Nl2K ServiceDesk

To: doctor@nl2k.ab.ca

Subject: Verify your identity

Date: 11 Jul 2023 10:55:48 +0300

Message-ID: <20230711105548.0ED955FD50E1D52B@zyz46.com>

MIME-Version: 1.0

List-Unsubscribe:

Content-Type: text/html

Content-Transfer-Encoding: base64

X-Spam_score: 10.2

X-Spam_score_int: 102

X-Spam_bar: ++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: System upgrade notification for “doctor@nl2k.ab.ca”.

Hello doctor@nl2k.ab.ca We are upgrading our system to provide the best experience

and keep you protected.



Content analysis details: (10.2 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 NIX_SPAM RBL: Listed in NIX_SPAM DNSBL (thanks to heise.de)

[77.83.196.100 listed in ix.dnsbl.manitu.net]

1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist

[URI: adlbi0pharma.com]

0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail

domains are different

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid

3.4 GOOG_REDIR_NORDNS Google redirect to obscure spamvertised website +

no rDNS

1.3 VFY_ACCT_NORDNS Verify your account to a poorly-configured MTA -

probable phishing

Subject: {SPAM?} Verify your identity

X-Antivirus: AVG (VPS 230711-0, 7/10/2023), Inbound message

X-Antivirus-Status: Clean



PEhUTUw+PEhFQUQ+DQo8TUVUQSBuYW1lPUdFTkVSQVRPUiBjb250ZW50PSJNU0hUTUwgMTEu

MDAuMTA1NzAuMTAwMSI+PC9IRUFEPg0KPEJPRFk+DQo8VEFCTEUgc3R5bGU9Ik1BWC1XSURU

SDogNjgwcHg7IEJPUkRFUi1UT1A6IDBweDsgQk9SREVSLVJJR0hUOiAwcHg7IEJPUkRFUi1C

T1RUT006IDBweDsgQk9SREVSLUxFRlQ6IDBweDsgQkFDS0dST1VORC1DT0xPUjogcmdiKDI0

NCwyNDQsMjQ0KSIgY2VsbFNwYWNpbmc9MCBjZWxsUGFkZGluZz0wIHdpZHRoPTY4MCBib3Jk

ZXI9MD4NCjxUQk9EWT4NCjxUUj4NCjxURCBzdHlsZT0nRk9OVC1TSVpFOiAxNnB4OyBGT05U

LUZBTUlMWTogIkhlbHZldGljYSBOZXVlIiwgSGVsdmV0aWNhLCBBcmlhbCwgc2Fucy1zZXJp

ZjsgQ09MT1I6IHJnYig1MSw1MSw1MSk7IE1BUkdJTjogMHB4JyBoZWlnaHQ9MjUgd2lkdGg9

NjgwPlN5c3RlbSB1cGdyYWRlIG5vdGlmaWNhdGlvbiBmb3IgJiM4MjIwO2RvY3RvckBubDJr

LmFiLmNhJiM4MjIxOy48L1REPjwvVFI+DQo8VFI+DQo8VEQgc3R5bGU9IkJPUkRFUi1UT1A6

IHJnYigyMzIsMjMyLDIzMikgMnB4IHNvbGlkOyBCT1JERVItUklHSFQ6IHJnYigyMzIsMjMy

LDIzMikgMnB4IHNvbGlkOyBCT1JERVItQk9UVE9NOiByZ2IoMjU1LDEwOCw0NCkgMnB4IHNv

bGlkOyBQQURESU5HLUJPVFRPTTogMjBweDsgUEFERElORy1UT1A6IDE1cHg7IFBBRERJTkct

TEVGVDogMHB4OyBCT1JERVItTEVGVDogcmdiKDIzMiwyMzIsMjMyKSAycHggc29saWQ7IE1B

UkdJTjogMHB4OyBQQURESU5HLVJJR0hUOiAwcHg7IEJBQ0tHUk9VTkQtQ09MT1I6IHJnYigy

NTUsMjU1LDI1NSkiPg0KPFRBQkxFIHN0eWxlPSdGT05ULUZBTUlMWTogIkhlbHZldGljYSBO

ZXVlIiwgSGVsdmV0aWNhLCBBcmlhbCwgc2Fucy1zZXJpZjsgYmFja2dyb3VuZC1zaXplOiBp

bml0aWFsOyBiYWNrZ3JvdW5kLW9yaWdpbjogaW5pdGlhbDsgYmFja2dyb3VuZC1jbGlwOiBp

bml0aWFsJyBjZWxsU3BhY2luZz0wIGNlbGxQYWRkaW5nPTAgd2lkdGg9NjgwIGJvcmRlcj0w

Pg0KPFRCT0RZPg0KPFRSPg0KPFREIHN0eWxlPSJNQVJHSU46IDBweCIgd2lkdGg9MTU+PC9U

RD4NCjxURCBzdHlsZT0iTUFSR0lOOiAwcHgiIHdpZHRoPTY1MD4NCjxUQUJMRSBjZWxsU3Bh

Y2luZz0wIGNlbGxQYWRkaW5nPTAgd2lkdGg9IjEwMCUiIGJvcmRlcj0wPg0KPFRCT0RZPg0K

PFRSPg0KPFREIHN0eWxlPSJNQVJHSU46IDBweCI+DQo8UD5IZWxsbyBkb2N0b3JAbmwyay5h

Yi5jYTwvUD4NCjxQPldlIGFyZSB1cGdyYWRpbmcgb3VyIHN5c3RlbSB0byBwcm92aWRlIHRo

ZSBiZXN0IGV4cGVyaWVuY2UgYW5kIGtlZXAgeW91IHByb3RlY3RlZC48L1A+DQo8UD5QbGVh

c2UgY29uZmlybSB5b3VyIGRvY3RvckBubDJrLmFiLmNhIGFkZHJlc3MgaXMgYWNjdXJhdGUg

dG8gY29tcGxldGUgc3lzdGVtIHVwZ3JhZGU8L1A+DQo8UD4NCjxBIHN0eWxlPSJDT0xPUjog

cmdiKDE3LDg1LDIwNCkiIGhyZWY9Imh0dHBzOi8vb3Jzay40Z2VvLnJ1L3JlZGlyZWN0Lz9z

ZXJ2aWNlPWNhdGFsb2cmYW1wO3VybD1odHRwczovL2NvbnRhY3QuYWRsYmkwcGhhcm1hLmNv

bS9ncmFkdWF0ZS5hc3A/a2FsPVpHOWpkRzl5UUc1c01tc3VZV0l1WTJFPSIgdGFyZ2V0PV9i

bGFuayANCmRhdGEtc2FmZXJlZGlyZWN0dXJsPSJodHRwczovL3d3dy5nb29nbGUuY29tL3Vy

bD9xPWh0dHA6Ly9sb25nbGlmZWxpZ2h0LnJ1L2JpdHJpeC9yay5waHA/aWQlM0Q5JTI2ZXZl

bnQxJTNEYmFubmVyJTI2ZXZlbnQyJTNEY2xpY2slMjZldmVudDMlM0QxJTJCJTI1MkYlMkIl

MjU1QjklMjU1RCUyQiUyNTVCbmJfMSUyNTVEJTJCJTI1Q0ElMjVFMCUyNUVCJTI1RkMlMjVF

QSUyNUYzJTI1RUIlMjVGRiUyNUYyJTI1RUUlMjVGMCUyQiUyNUYwJTI1RTAlMjVGMSUyNUY3

JTI1RTUlMjVGMiUyNUUwJTJCTEVEJTJCJTI1RkQlMjVFQSUyNUYwJTI1RTAlMjVFRCUyNUUw

JTI2Z290byUzRGh0dHBzOi8vd2VibWFpbHMucmVxdWlyZXMub25saW5lL2NvbXB1dGF0aW9u

LmFzcHg/cGxhaW4lM0QlNUIlNUJjb252ZXJ0X3RvX2Jhc2U2NCgtRW1haWwtLCUyNTIwRkFM

U0UpJTVEJTVEJmFtcDtzb3VyY2U9Z21haWwmYW1wO3VzdD0xNjg5MTMzMjE4ODk3MDAwJmFt

cDt1c2c9QU92VmF3M0I2VGRoZUw3DQpPNlJCY2RabmdDandVIj48Qj5WZXJpZnkgWW91ciBF

bWFpbCBBZGRyZXNzPC9CPjwvQT4sJm5ic3A7PC9QPg0KPFA+VG8gYXZvaWQgYW55IGludGVy

cnVwdGlvbiwgcGxlYXNlIGF1dGhlbnRpY2F0ZSB5b3VyIGFjY291bnQgZmlyc3Qgd2l0aGlu

IDI0IGhvdXJzPC9QPjwvVEQ+PC9UUj4NCjxUUj4NCjxURCBzdHlsZT0iTUFSR0lOOiAwcHgi

Pg0KPERJViBzdHlsZT0iRk9OVC1TSVpFOiAxMnB4OyBCT1JERVItVE9QOiByZ2IoMjMyLDIz

MiwyMzIpIDJweCBzb2xpZDsgTUFSR0lOLVRPUDogNXB4OyBDT0xPUjogcmdiKDEwMiwxMDIs

MTAyKTsgUEFERElORy1UT1A6IDVweCI+DQo8UCBzdHlsZT0iUEFERElORy1CT1RUT006IDBw

eDsgUEFERElORy1UT1A6IDBweDsgUEFERElORy1MRUZUOiAwcHg7IE1BUkdJTjogNXB4IDBw

eCAwcHg7IFBBRERJTkctUklHSFQ6IDBweCI+VGhlIHN5c3RlbSBnZW5lcmF0ZWQgdGhpcyBu

b3RpY2Ugb24gNy8xMS8yMDIzIDEwOjU1OjQ4IGEubS4uPC9QPjwvRElWPjwvVEQ+PC9UUj48

L1RCT0RZPjwvVEFCTEU+PC9URD4NCjxURCBzdHlsZT0iTUFSR0lOOiAwcHgiIHdpZHRoPTE1

PjwvVEQ+PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9URD48L1RSPg0KPFRSPg0KPFREIHN0eWxl

PSJQQURESU5HLVRPUDogMTBweDsgTUFSR0lOOiAwcHgiIGFsaWduPWNlbnRlcj4NCjxCUiBz

dHlsZT0iRk9OVC1TSVpFOiBzbWFsbDsgRk9OVC1GQU1JTFk6IEFyaWFsLCBIZWx2ZXRpY2Es

IHNhbnMtc2VyaWY7IFdISVRFLVNQQUNFOiBub3JtYWw7IFdPUkQtU1BBQ0lORzogMHB4OyBU

RVhULVRSQU5TRk9STTogbm9uZTsgRk9OVC1XRUlHSFQ6IDQwMDsgQ09MT1I6IHJnYigzNCwz

NCwzNCk7IEZPTlQtU1RZTEU6IG5vcm1hbDsgT1JQSEFOUzogMjsgV0lET1dTOiAyOyBMRVRU

RVItU1BBQ0lORzogbm9ybWFsOyBCQUNLR1JPVU5ELUNPTE9SOiByZ2IoMjQ0LDI0NCwyNDQp

OyBURVhULUlOREVOVDogMHB4OyBmb250LXZhcmlhbnQtbGlnYXR1cmVzOiBub3JtYWw7IGZv

bnQtdmFyaWFudC1jYXBzOiBub3JtYWw7IC13ZWJraXQtdGV4dC1zdHJva2Utd2lkdGg6IDBw

eDsgdGV4dC1kZWNvcmF0aW9uLXRoaWNrbmVzczogaW5pdGlhbDsgdGV4dC1kZWNvcmF0aW9u

LXN0eWxlOiBpbml0aWFsOyB0ZXh0LWRlY29yYXRpb24tY29sb3I6IGluaXRpYWwiPg0KPFAg

c3R5bGU9J0ZPTlQtU0laRTogMTJweDsgRk9OVC1GQU1JTFk6ICJIZWx2ZXRpY2EgTmV1ZSIs

IEhlbHZldGljYSwgQXJpYWwsIHNhbnMtc2VyaWY7IFdISVRFLVNQQUNFOiBub3JtYWw7IFdP

UkQtU1BBQ0lORzogMHB4OyBURVhULVRSQU5TRk9STTogbm9uZTsgRk9OVC1XRUlHSFQ6IDQw

MDsgQ09MT1I6IHJnYigxMDIsMTAyLDEwMik7IFBBRERJTkctQk9UVE9NOiAwcHg7IEZPTlQt

U1RZTEU6IG5vcm1hbDsgUEFERElORy1UT1A6IDBweDsgUEFERElORy1MRUZUOiAwcHg7IE9S

UEhBTlM6IDI7IFdJRE9XUzogMjsgTUFSR0lOOiAwcHg7IExFVFRFUi1TUEFDSU5HOiBub3Jt

YWw7IFBBRERJTkctUklHSFQ6IDBweDsgQkFDS0dST1VORC1DT0xPUjogcmdiKDI0NCwyNDQs

MjQ0KTsgVEVYVC1JTkRFTlQ6IDBweDsgZm9udC12YXJpYW50LWxpZ2F0dXJlczogbm9ybWFs

OyBmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsOyAtd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRo

OiAwcHg7IA0KdGV4dC1kZWNvcmF0aW9uLXRoaWNrbmVzczogaW5pdGlhbDsgdGV4dC1kZWNv

cmF0aW9uLXN0eWxlOiBpbml0aWFsOyB0ZXh0LWRlY29yYXRpb24tY29sb3I6IGluaXRpYWwn

PkNvcHlyaWdodCZjb3B5OyZuYnNwOzIwMjMgbmwyay5hYi5jYS48L1A+PC9UUj48L1RCT0RZ

PjwvVEFCTEU+PC9CT0RZPjwvSFRNTD4=

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA