Sendgrid phish tricking nk.ca users about e-mailboxes

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 24 Jan 2024 05:35:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rScSR-00000000LSm-02jA

for dave@doctor.nl2k.ab.ca;

Wed, 24 Jan 2024 05:34:19 -0700

Resent-From: The Doctor

Resent-Date: Wed, 24 Jan 2024 05:34:18 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from wrqvzzxs.outbound-mail.sendgrid.net ([149.72.238.166]:16702)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rSWkR-000000005nt-2Ugk

for root@nk.ca;

Tue, 23 Jan 2024 23:28:36 -0700

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sendgrid.net;

h=from:subject:mime-version:to:content-type:content-transfer-encoding:

cc:content-type:from:subject:to;

s=smtpapi; bh=86dNKRlhJE8gqDYrb0VOZrsNR3we9qCJWUz18B5ObtQ=;

b=K4C/uTeIFBuynG8XocmJVfeFTAAOdVU+x/J2rJJaZppNFWXSnoMKe92ok8HmV0ICoN52

mQCmDEUs8LdvCZx2FwyHdU1QecKmNv/NzUlDv5id6BD5EQNzYng7Kb7M4Lzgiq9jXOqrbe

7uVi+MnMToXe6kvkdjtUJBpa2qm1fGFqg=

Received: by filterdrecv-6dcccbbbfd-m64rc with SMTP id filterdrecv-6dcccbbbfd-m64rc-1-65B0AD96-36

2024-01-24 06:26:30.987262594 +0000 UTC m=+8509515.195424562

Received: from 107.150.19.13.static.quadranet.com (unknown)

by geopod-ismtpd-15 (SG) with ESMTP id zqZhDtOJS9Sj2uCFtkxcMQ

for ; Wed, 24 Jan 2024 06:26:30.896 +0000 (UTC)

From: "nk.ca SYSTEM"

Subject: root@nk.ca NEESDS UPGRADE IMMEDIATELY

Date: Wed, 24 Jan 2024 06:26:31 +0000 (UTC)

Message-ID: <20240123222630.07E1F62B7474A5A7@bitbang.cl>

MIME-Version: 1.0

X-SG-EID:

=?us-ascii?Q?p2UXCMhhwhz+EY4W7xyNiWRHu6C3zx7xdVDiA5uNDdzuFB4H7SCUJB+6msGsTj?=

=?us-ascii?Q?WCR4epTwLmTCBcozlQgGkGMzpXloID5hyAmK=2FxG?=

=?us-ascii?Q?H3vnnxdT5hyXhhM7jIf8p0sd69n0Q5XMy4A7u91?=

=?us-ascii?Q?PZepRdQXmu+7+rM4ADHnNLsQsXq5jtD23DTfZKK?=

=?us-ascii?Q?sSDhO6RSt6l4z37e47ApKQXM9AvM0k38jJNxlSa?=

=?us-ascii?Q?ldPx7h8k=2FYPzuc9lk=3D?=

To: root@nk.ca

X-Entity-ID: doc2xi0tmoUA64sN9yUoxw==

Content-Type: text/html; charset=us-ascii

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 6.2

X-Spam_score_int: 62

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Dear root, We are closing all mailbox users that are still

using the old version of the nk.ca mailbox. Your email (root@nk.ca ) is still

using this old version. Please tap the blue button below to upgrade to the

latest version and get 105GB Free Space.



Content analysis details: (6.2 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.1 URIBL_GREY Contains an URL listed in the URIBL greylist

[URI: sendgrid.net]

-0.0 SPF_PASS SPF: sender matches SPF record

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from

envelope-from domain

0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail

domains are different

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

1.3 URI_HEX URI: URI hostname has long hexadecimal sequence

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to

background

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

-0.0 T_SCC_BODY_TEXT_LINE No description available.

2.2 LONGLN_LOW_CONTRAST Excessively long line + hidden text

0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag

-0.0 DKIMWL_WL_MED DKIMwl.org - Medium trust sender

0.0 SENDGRID_REDIR Redirect URI via Sendgrid

Subject: {SPAM?} root@nk.ca NEESDS UPGRADE IMMEDIATELY










al;font-variant-caps:normal;letter-spacing:normal;text-align:start;text-ind=

ent:0px;text-transform:none;word-spacing:0px;white-space:normal;text-decora=

tion-style:initial;text-decoration-color:initial;font-family:Arial,sans-ser=

if;line-height:normal">
an style=3D"color:rgb(102,102,102);line-height:normal">
cal-align:inherit;line-height:normal">
;line-height:normal">
height:normal">Dear 
root
nt-weight:bold;line-height:normal">
ne-height:normal">
>
ont-family:"Agency FB";line-height:normal">,
=


-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:n=

ormal;text-align:start;text-indent:0px;text-transform:none;word-spacing:0px=

;white-space:normal;text-decoration-style:initial;text-decoration-color:ini=

tial;font-size:14px;font-family:-apple-system,BlinkMacSystemFont,"Sego=

e UI",Roboto,Oxygen-Sans,Ubuntu,Cantarell,"Helvetica Neue",s=

ans-serif;margin:1em 0px;line-height:normal">
font-family:Arial,sans-serif;color:rgb(102,102,102);line-height:normal">We =

are closing all mailbox users that are still using the old version of =

 the 
 
t/ls/click?upn=3DyfnFmImRpgaioSCA1SRYdWgMYSVmbWxr3ZbPz51DJlI-3DIG-2_au8KhoA=

RU0pHZsVFxriXkLi7phM1J-2B7coVmEk-2FHes9m7tw7ZLTYPKux2HfhNDCpnfMYP7tfulKLnGD=

I-2F3-2BJ-2F0FARLKLc6jXq4DWkSoVgHLdZqEynqBcoYEUkuggcg7K5nnvFXf2lRTvdahbTbME=

wSVVUz-2FHzI9gSQHhsasoLsGguYKNDNdb0-2FFvBIFlGqGK-2BpyMpzPiNwRoRvBTJbobZnA-3=

D-3D" target=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?=

q=3Dhttp://cyberia.net.lb&source=3Dgmail&ust=3D1705641269598000&=

;usg=3DAOvVaw2r1XQfkWLolLbKFDsvYVq-">nk.ca
 

an style=3D"font-size:12px;font-family:Arial,sans-serif;color:rgb(102,102,1=

02);line-height:normal">mailbox.

ily:Arial,sans-serif;color:rgb(0,0,0);line-height:normal">

-size:12px;font-family:Arial,sans-serif;color:rgb(0,0,0);line-height:normal=

">
102,102);line-height:normal">Your email 

e:12px;font-family:Arial,sans-serif;font-weight:bold;color:rgb(102,102,102)=

;line-height:normal"> 
it;line-height:normal"> 
ght:normal">(
0WQ5VbRURtkhFQQ4MdkIOGkntYaotaTf3w8yBmo-3DiSDz_au8KhoARU0pHZsVFxriXkLi7phM1=

J-2B7coVmEk-2FHes9m7tw7ZLTYPKux2HfhNDCpnw9u5wLaGyhRYRJOkfO7r4FBpFrtReSjJbEc=

n72w-2B7RfJgWKNHE1UeM4OORqAwc70dmmw26mylxIixCax3U7-2BRgsi3olOTyDseFIjJu4vJw=

cWKMUj4FQDuRjNOJPgbMu2o1UzTX7cOTzAtvysBwQr4Q-3D-3D" rel=3D"noopener" style=

=3D"text-decoration:underline;line-height:normal" target=3D"_blank" data-sa=

feredirecturl=3D"https://www.google.com/url?q=3Dhttps://pub-a1b30030c0ce4b4=

c81a65267e8524410.r2.dev/web3.html%23auto@cyberia.net.lb&source=3Dgmail=

&ust=3D1705641269598000&usg=3DAOvVaw0fV4ZpqkwoMRlkkK2QsGDS">root@nk=

.ca

al"> 
ht:normal">)
 
 
n style=3D"font-size:12px;font-family:Arial,sans-serif;color:rgb(102,102,10=

2);line-height:normal">is still using this old version. Please tap the blue=

button below to upgrade to the latest version and get 105GB Free Space.
pan>

0);line-height:normal">

erif;color:rgb(0,0,0);line-height:normal">
t-family:Arial,sans-serif;font-weight:bold;color:rgb(0,0,0);line-height:nor=

mal">
tical-align:inherit;line-height:normal">
it;line-height:normal">NOTE

2,102,102);line-height:normal"> 
lign:inherit;line-height:normal">
-height:normal">:
 

=3D"font-size:12px;font-family:Arial,sans-serif;color:rgb(102,102,102);line=

-height:normal"> Failure to do this would lead to account termination.=


igatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:nor=

mal;text-align:start;text-indent:0px;text-transform:none;word-spacing:0px;w=

hite-space:normal;text-decoration-style:initial;text-decoration-color:initi=

al;font-size:14px;font-family:-apple-system,BlinkMacSystemFont,"Segoe =

UI",Roboto,Oxygen-Sans,Ubuntu,Cantarell,"Helvetica Neue",san=

s-serif;line-height:normal">

ily:"Times New Roman";font-size:medium;font-style:normal;font-var=

iant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spaci=

ng:normal;text-align:start;text-indent:0px;text-transform:none;word-spacing=

:0px;white-space:normal;text-decoration-style:initial;text-decoration-color=

:initial;display:inline;float:none">

font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;fo=

nt-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-t=

ransform:none;word-spacing:0px;white-space:normal;text-decoration-style:ini=

tial;text-decoration-color:initial;font-size:14px;font-family:-apple-system=

,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen-Sans,Ubuntu,Cantarel=

l,"Helvetica Neue",sans-serif;float:none;display:inline">
<=

span style=3D"color:rgb(0,0,0);font-family:"Times New Roman";font=

-size:medium;font-style:normal;font-variant-ligatures:normal;font-variant-c=

aps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-inde=

nt:0px;text-transform:none;word-spacing:0px;white-space:normal;text-decorat=

ion-style:initial;text-decoration-color:initial;display:inline;float:none">=


    es:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;te=

    xt-align:start;text-indent:0px;text-transform:none;word-spacing:0px;white-s=

    pace:normal;text-decoration-style:initial;text-decoration-color:initial;fon=

    t-size:12px;font-family:Arial,sans-serif;padding:0px 0px 0px 2em;margin:0px=

    ;line-height:normal">

  • n style=3D"color:rgb(0,0,0);line-height:normal">Follow  below to upgra=

    de and keep account active


t-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-=

weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-tran=

sform:none;word-spacing:0px;white-space:normal;text-decoration-style:initia=

l;text-decoration-color:initial;font-size:14px;font-family:-apple-system,Bl=

inkMacSystemFont,"Segoe UI",Roboto,Oxygen-Sans,Ubuntu,Cantarell,&=

quot;Helvetica Neue",sans-serif;margin:1em 0px;line-height:normal">
an style=3D"font-size:12px;font-family:Arial,sans-serif;color:rgb(0,0,0);li=

ne-height:normal">
sans-serif;color:rgb(0,0,0);line-height:normal">
,31,30);line-height:normal">
n>
 


ant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacin=

g:normal;text-align:start;text-indent:0px;text-transform:none;word-spacing:=

0px;white-space:normal;text-decoration-style:initial;text-decoration-color:=

initial;font-size:15px;font-family:Arial,sans-serif;margin:6px 0px;line-hei=

ght:normal">          &nb=

sp;            =

             &n=

bsp;            =

;   
t.sendgrid.net/ls/click?upn=3DWJXTuBqR0GoLFdzAbw-2BXyQNh-2B-2FhlaiTVUTXnwtc=

W7y057uBPhfar8IMHPb2n6zSdvc38WINMj4dLJ4bcEz7SWT6WWUUF1pR1pnNwS5RcVpI-3DhCNe=

_au8KhoARU0pHZsVFxriXkLi7phM1J-2B7coVmEk-2FHes9m7tw7ZLTYPKux2HfhNDCpnzSJzlO=

T4C8o85q9lj3yQEwhXXItPsqE7s-2B-2F9FhH1PPCkl4gbSSGOA9ra6VjEuecz-2F5HkfWwwLvH=

x95fsEOCi6bEP2X-2Bbm0EnegBz8Zbw66uewgA5CSdL2FPZKDLE2w-2BsRCB3i1RCuQGdDoNVmt=

EI3w-3D-3D" rel=3D"noopener" style=3D"border-width:0px;text-decoration:unde=

rline;vertical-align:baseline;background:rgb(0,120,215) 0% 50%;color:white;=

padding:10px 40px;margin:0px;line-height:normal" target=3D"_blank" data-saf=

eredirecturl=3D"https://www.google.com/url?q=3Dhttps://semasvicious.nl/regi=

stered/Autopage/index.html%23auto@cyberia.net.lb&source=3Dgmail&ust=

=3D1705641269598000&usg=3DAOvVaw2K4i60djUZpRdjWaR7Z2EV">
vertical-align:inherit;line-height:normal">Upgrade inbox Version 
n>


ures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;=

text-align:start;text-indent:0px;text-transform:none;word-spacing:0px;white=

-space:normal;text-decoration-style:initial;text-decoration-color:initial;f=

ont-size:12px;font-family:Arial,sans-serif;margin:0in 0in 0pt;line-height:n=

ormal">


r style=3D"line-height:normal">
mal">
=3D"vertical-align:inherit;line-height:normal">Connected to Mail-Porta=

l    


an style=3D"vertical-align:inherit;line-height:normal">
cal-align:inherit;line-height:normal"> 2023  Corporation. All rights r=

eserved.










Fragh7PjC3XDdjuTXWapJVxROpsVayUOz3wDuDFdJBihMNT-2BfnRFfNbnQ2VZfJ-2FIoW1rwmH=

ZMuXVeU1N6-2Bwo8nsfGlElu3QolHAYZUlU2WzDaJyDhZs5tJm2-2FB7ywAZE7JXVUngsAQbk-2=

FQcX11Mfan1bTBdSc6DDmLtbVL8RVNFYQp1V7uxy8RJyoZeNQ-2Fz9Yfty2cA-3D-3D" alt=3D=

"" width=3D"1" height=3D"1" border=3D"0" style=3D"height:1px !important;wid=

th:1px !important;border-width:0 !important;margin-top:0 !important;margin-=

bottom:0 !important;margin-right:0 !important;margin-left:0 !important;padd=

ing-top:0 !important;padding-bottom:0 !important;padding-right:0 !important=

;padding-left:0 !important;"/>

Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA