Health spam from Microsoft Outlook
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 04 Mar 2024 08:27:03 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rh9rp-00000000Dbl-1Mcd
for dave@doctor.nl2k.ab.ca;
Mon, 04 Mar 2024 08:04:37 -0700
Resent-From: The Doctor
Resent-Date: Mon, 4 Mar 2024 08:04:37 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-eastasiaazon11021007.outbound.protection.outlook.com ([52.101.128.7]:27112 helo=HK3PR03CU002.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rh7n3-00000000I3G-3a9v
for sales@nk.ca;
Mon, 04 Mar 2024 05:51:39 -0700
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=GcaAFR+CXqs/ACJ+DTW/UHWO7HpC29qLtoXkSjPNnaIA5DnfReylQdsuR5v76vDh+Tu0QPgHiVZTcQtgOR9dN5yF+NR7YJ57giw4lqrHdpyyxDhEQgr/NrTVEbT6pc2FWgKun4cknvarawnHv6lEOoMoTEaDZUyGg4m2FW2lRJAHTdmulkHJqr1PVg32YboRncanbfs0nlykRRC1Mjh69Ots2XQAsWOdGG4HsXU8fg9FauXe81i3D0MTG+Z0zbb3ZiECMfe42MeGEQ8efZl6X4DwtBpTGXZhqJOFg/DQMJMo/XyaBHRacz/Ks6F2JalpA8e+0UxaKfY9xJJrs9rOow==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=WWh2DvyHd8AqC7m7Q8at6hMQbQJB6A1bmhld67mPdbY=;
b=JJc5hhzdo3Xp/SEwsoYI2qgyYw/HCqA3ueGwWGHEwer0y2bISZM+G7HfDm9auovUll+kQMVtn9z60G5hNN5iOSsx3QjcXb6F5OI7V/tiCEACaAmcoYJioG+vowrSSYDksB+Ckr9oTPgoTZ+p0r18lwj5tX0IRiLvYZSnRNvR3NatF7iBxBMrzjTv21Si2FOAIQRqDOx/vfKljtAuyDYKb+flc9jXRWgdMvPP7Fb0TM8mSGfYS7yJGG+Rv0rZk7BZllUbZ0IXUvsCPDkvyMIIsFaP7QG94mB+icRWxTVLMUNgh5Fl1JzhBVJy9hxt0GwgKQJE9P5TIp2GdCV1fWTHHA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
172.105.21.95) smtp.rcpttodomain=nk.ca
smtp.mailfrom=15dguhgfjg.volcanicallyactive.store; dmarc=bestguesspass
action=none header.from=15dguhgfjg.volcanicallyactive.store; dkim=none
(message not signed); arc=none (0)
Received: from SG2PR02CA0014.apcprd02.prod.outlook.com (2603:1096:3:17::26) by
TY0PR02MB6218.apcprd02.prod.outlook.com (2603:1096:400:273::12) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7339.37; Mon, 4 Mar
2024 12:49:29 +0000
Received: from SG1PEPF000082E3.apcprd02.prod.outlook.com
(2603:1096:3:17:cafe::61) by SG2PR02CA0014.outlook.office365.com
(2603:1096:3:17::26) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7339.38 via Frontend
Transport; Mon, 4 Mar 2024 12:49:29 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 172.105.21.95)
smtp.mailfrom=15dguhgfjg.volcanicallyactive.store; dkim=none (message not
signed) header.d=none;dmarc=bestguesspass action=none
header.from=15dguhgfjg.volcanicallyactive.store;
Received-SPF: Pass (protection.outlook.com: domain of
15dguhgfjg.volcanicallyactive.store designates 172.105.21.95 as permitted
sender) receiver=protection.outlook.com; client-ip=172.105.21.95;
helo=15dguhgfjg.volcanicallyactive.store; pr=C
Received: from 15dguhgfjg.volcanicallyactive.store (172.105.21.95) by
SG1PEPF000082E3.mail.protection.outlook.com (10.167.240.6) with Microsoft
SMTP Server id 15.20.7362.11 via Frontend Transport; Mon, 4 Mar 2024 12:49:27
+0000
From: "=?UTF-8?Q?Health Affiliate ?="
Subject: =?UTF-8?Q?It started out innocently enough=E2=80=A6?=
To: sales@nk.ca
Sender: YedqQhZrZafh@15dguhgfjg.volcanicallyactive.store
Cc: sales@outlook.com
Content-Type: multipart/alternative;
boundary="_80786f1d-6ee3-4249-abe5-8080ca445fa0_"
Date: Mon, 04 Mar 2024 12:48:50 +0000
MIME-Version: 1.0
Message-ID:
<5b11febe-f98b-4884-9e53-ddebb15372d7@SG1PEPF000082E3.apcprd02.prod.outlook.com>
X-EOPAttributedMessage: 0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SG1PEPF000082E3:EE_|TY0PR02MB6218:EE_
X-MS-Office365-Filtering-Correlation-Id: 5114fd84-0c79-4adc-a92b-08dc3c498742
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
MCdMAb5zrSWV4DP0Pqnx509lokpK4SvuNTp6OSUPOeEwRDppg98ifdr3SzwjFhVHLtCht2vU3tsWnW6L5F3FF1dEZW2UX1bCbi8g7DN5AHlqLCoQdOyZjnLuV9U/7F7wsNtqddNJNT380tn9NoRRs65GWWf+4o1jDjyIABwuyQP1Ak9/S3XarWr6XdlCyWCEkQWAHw+nEi8VAjvSbOQoFakaXOdfUYXr4pwc8eO0Do/PDOA9uNj74H/O4pSKMhiY282gAn+kRfT7cSxdIP3TxO1EZkIlC3Ac9mPJ2DuSevazUNS1VlI06PHvejdlF+UJiKI0byq8Q340cVcEsAQtxwtta22Jaz5YBjiBjhUjcKsT87740Y7Wrf8DQYthpmuExdVw2ezKPK9GFuRDD4Ojf+GNQUJQpDovad56zlkw0yYiNzSTk0ktnnb+rybsKhULrlkTsSitZBc6Q9EJBcXPCLDcevOSXoVKy/P8jKsdDBfLcZgebyCtfTNEgIz74WACqUq1iCPQKQzp0FxEX4He57zhfnBE1QXFeDk2Y0zdw4Y29lvEYAgISfKIolxnYCmk0zo+fpfWswyuR2k1weVVoPVTXXSLa9aAb+sRFVV+QqzPnBw/nEOpTrgj8MK0MWHEpE0SS6O6Rjo8NVD060DJVed2lOjcK8k/DBrL8TmHkIO4gWOsdVYkQkG6S9DetCVDX7qMP9aCIJ8uc7+iO6Ri5w==
X-Forefront-Antispam-Report:
CIP:172.105.21.95;CTRY:CA;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:15dguhgfjg.volcanicallyactive.store;PTR:172-105-21-95.ip.linodeusercontent.com;CAT:NONE;SFS:(13230031)(82310400014)(41320700004)(34070700005)(61400799018)(36860700004)(376005);DIR:OUT;SFP:1102;
X-OriginatorOrg: 15dguhgfjg.volcanicallyactive.store
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Mar 2024 12:49:27.4652
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 5114fd84-0c79-4adc-a92b-08dc3c498742
X-MS-Exchange-CrossTenant-Id: 495b80d5-d650-4a23-be96-124d50507823
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=495b80d5-d650-4a23-be96-124d50507823;Ip=[172.105.21.95];Helo=[15dguhgfjg.volcanicallyactive.store]
X-MS-Exchange-CrossTenant-AuthSource:
SG1PEPF000082E3.apcprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: TY0PR02MB6218
X-Spam_score: 5.4
X-Spam_score_int: 54
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Find Out How To Save Your Brain And Your Memories Today!
It started out innocently enough… Working with limited resources in rural
China, a doctor by the name of Chung T’Hsu sought to cure the ringing in
his ears that was driving him mad.
Content analysis details: (5.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.101.128.7 listed in list.dnswl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.101.128.7 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.0 ARC_VALID Message has a valid ARC signature
0.0 ARC_SIGNED Message has a ARC signature
0.0 BAD_ENC_HEADER Message has bad MIME encoding in the header
0.3 FROM_LOCAL_HEX From: localpart has long hexadecimal sequence
0.0 FROM_LOCAL_DIGITS From: localpart has long digit sequence
0.0 NORMAL_HTTP_TO_IP URI: URI host has a public dotted-decimal IPv4
address
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
-0.0 T_SCC_BODY_TEXT_LINE No description available.
0.0 T_REMOTE_IMAGE Message contains an external image
1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
above 50%
[cf: 100]
0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
Subject: {SPAM?} =?UTF-8?Q?It started out innocently enough=E2=80=A6?=
--_80786f1d-6ee3-4249-abe5-8080ca445fa0_
Content-Type: text/plain; charset="UTF-8";
--_80786f1d-6ee3-4249-abe5-8080ca445fa0_
Content-Type: text/html; charset="UTF-8";
Find Out How To Save Your Brain And Your Memories Today!
|
--_80786f1d-6ee3-4249-abe5-8080ca445fa0_--
Trackbacks
Trackback specific URI for this entryThis link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.
No Trackbacks
Comments
Display comments as Linear | ThreadedNo comments