Nk.ca credential phishing from google
Posted by Dave Yadallee on
Return-path: <>
Envelope-to: dave@nk.ca
Delivery-date: Sun, 01 Dec 2024 06:33:00 -0700
Received: from 244.127.168.34.bc.googleusercontent.com ([34.168.127.244]:37984 helo=[10.88.0.5])
by doctor.nl2k.ab.ca with esmtp (Exim 4.98 (FreeBSD))
id 1tHk3z-0000000072X-43uv
for dave@nk.ca;
Sun, 01 Dec 2024 06:32:44 -0700
Content-Type: multipart/related; boundary="===============3105601158357750148=="
MIME-Version: 1.0
From: "Nagindas Khandwala College ."
To: dave@nk.ca
Subject: =?utf-8?q?MailBox_Requesting_Authentication!_For_dave=40nk=2Eca_=3A?=
X-Priority: 2
X-Spam_score: 22.6
X-Spam_score_int: 226
X-Spam_bar: ++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Dave , You have an important mailbox update, please
click below to mailbox update complete. Update Mailbox You have 24 hours to
complete the update to avoid being logged out of your mailbox. Dis [...]
Content analysis details: (22.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.4 MISSING_DATE Missing Date: header
0.1 MISSING_MID Missing Message-Id: header
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[34.168.127.244 listed in sbl-xbl.spamhaus.org]
[34.168.127.244 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
[34.168.127.244 listed in dnsbl.ahbl.org]
[34.168.127.244 listed in dnsbl.ahbl.org]
[34.168.127.244 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
0.7 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[34.168.127.244 listed in zen.spamhaus.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[34.168.127.244 listed in zen.spamhaus.org]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.0 TVD_RCVD_IP Message was received from an IP address
3.0 RECEIVED_MULTICAST A multicast IP adress appears in Received header
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see]
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: ipfs.io/209.94.90.1]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
0.4 RDNS_DYNAMIC Delivered to internal network by host with
dynamic-looking rDNS
3.2 URI_IPFSIO References Interplanetary File System PtP content via
ipfs.io, likely phishing
0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
0.1 TO_IN_SUBJ To address is in Subject
0.2 TO_EQ_FM_DOM_HTML_ONLY To domain == From domain and HTML only
1.0 XPRIO Has X-Priority header
0.0 URI_IPFS References Interplanetary File System PtP content, probable
phishing
Subject: {SPAM?} =?utf-8?q?MailBox_Requesting_Authentication!_For_dave=40nk=2Eca_=3A?=
--===============3105601158357750148==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
PEhUTUw+PEhFQUQ+DQo8TUVUQSBuYW1lPUdFTkVSQVRPUiBjb250ZW50PSJNU0hUTUwgMTEuMDAu
OTYwMC4xOTU5NyI+PC9IRUFEPg0KPEJPRFk+DQo8VEFCTEUgc3R5bGU9IkZPTlQtU0laRTogMTRw
eDsgRk9OVC1GQU1JTFk6IGFyaWFsOyBCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlOyBDT0xPUjog
cmdiKDQ0LDU0LDU4KSIgY2VsbFNwYWNpbmc9MCBjZWxsUGFkZGluZz0wIHdpZHRoPSIxMDAlIiBh
bGlnbj1jZW50ZXIgYmdDb2xvcj0jZjVmN2Y4IGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gt
U0laSU5HOiBib3JkZXItYm94Ij4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+
DQo8VEQgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giIGhlaWdodD0zMCB2QWxpZ249dG9w
IGFsaWduPWNlbnRlcj4mbmJzcDs8L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJv
cmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiB2QWxpZ249dG9w
IHdpZHRoPTYwMCBhbGlnbj1jZW50ZXI+DQo8VEFCTEUgc3R5bGU9Ik1BWC1XSURUSDogNjAwcHg7
IEJPUkRFUi1UT1A6IHJnYigyNDAsMjQxLDI0NikgMXB4IHNvbGlkOyBCT1JERVItUklHSFQ6IHJn
YigyNDAsMjQxLDI0NikgMXB4IHNvbGlkOyBCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlOyBCT1JE
RVItQk9UVE9NOiByZ2IoMjQwLDI0MSwyNDYpIDFweCBzb2xpZDsgQk9SREVSLUxFRlQ6IHJnYigy
NDAsMjQxLDI0NikgMXB4IHNvbGlkIiBjZWxsU3BhY2luZz0wIGNlbGxQYWRkaW5nPTAgYWxpZ249
Y2VudGVyIGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4N
CjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJPWC1TSVpJ
Tkc6IGJvcmRlci1ib3g7IE1BWC1XSURUSDogNjAwcHgiIGJnQ29sb3I9I2ZmZmZmZiB2QWxpZ249
dG9wIHdpZHRoPTYwMCBhbGlnbj1jZW50ZXI+DQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xMQVBT
RTogY29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCB3aWR0aD0iMTAwJSIgYWxp
Z249Y2VudGVyIGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94
Ij4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJPWC1T
SVpJTkc6IGJvcmRlci1ib3giIHZBbGlnbj10b3AgYWxpZ249Y2VudGVyPg0KPFRBQkxFIHN0eWxl
PSJCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlIiBjZWxsU3BhY2luZz0wIGNlbGxQYWRkaW5nPTAg
d2lkdGg9IjkyJSIgYWxpZ249Y2VudGVyIGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gtU0la
SU5HOiBib3JkZXItYm94Ij4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8
VEQgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giIHZBbGlnbj10b3AgYWxpZ249Y2VudGVy
Pg0KPFRBQkxFIHN0eWxlPSJCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlIiBjZWxsU3BhY2luZz0w
IGNlbGxQYWRkaW5nPTAgd2lkdGg9IjEwMCUiIGFsaWduPWNlbnRlcj4NCjxUQk9EWSBzdHlsZT0i
Qk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1i
b3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWlnaHQ9MzA+Jm5ic3A7
PC9URD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHls
ZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCIgaGVpZ2h0PTMyPiZuYnNwOzwvVEQ+PC9UUj4NCjxU
UiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJPWC1TSVpJTkc6
IGJvcmRlci1ib3giIHZBbGlnbj10b3A+DQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xMQVBTRTog
Y29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCB3aWR0aD0iOTAlIj4NCjxUQk9E
WSBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6
IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94OyBGT05ULVNJ
WkU6IDEycHg7IEZPTlQtRkFNSUxZOiBSb2JvdG8sIEFyaWFsOyBDT0xPUjogcmdiKDUxLDUxLDUx
KTsgTElORS1IRUlHSFQ6IDE4cHgiIHZBbGlnbj10b3A+PFNQQU4gc3R5bGU9IkJPWC1TSVpJTkc6
IGJvcmRlci1ib3g7IEZPTlQtV0VJR0hUOiBib2xkZXIiPkRlYXIgRGF2ZSAsPC9TUEFOPjwvVEQ+
PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9URD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBi
b3JkZXItYm94Ij4NCjxURCBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCIgdkFsaWduPXRv
cD4NCjxUQUJMRSBzdHlsZT0iQk9SREVSLUNPTExBUFNFOiBjb2xsYXBzZSIgY2VsbFNwYWNpbmc9
MCBjZWxsUGFkZGluZz0wIHdpZHRoPSIxMDAlIiBib3JkZXI9MD4NCjxUQk9EWSBzdHlsZT0iQk9Y
LVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3gi
Pg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWlnaHQ9MjU+Jm5ic3A7PC9U
RD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHlsZT0i
Qk9YLVNJWklORzogYm9yZGVyLWJveDsgRk9OVC1TSVpFOiAxM3B4OyBGT05ULUZBTUlMWTogUm9i
b3RvLCBBcmlhbDsgQ09MT1I6IHJnYigxMDIsMTAyLDEwMik7IExJTkUtSEVJR0hUOiAxOXB4Ij5Z
b3UgaGF2ZSBhbiBpbXBvcnRhbnQgbWFpbGJveCB1cGRhdGUsIHBsZWFzZSBjbGljayBiZWxvdyB0
byBtYWlsYm94IHVwZGF0ZSBjb21wbGV0ZS48L1REPjwvVFI+PC9UQk9EWT48L1RBQkxFPjwvVEQ+
PC9UUj4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJP
WC1TSVpJTkc6IGJvcmRlci1ib3giIGhlaWdodD0yMCB2QWxpZ249dG9wIGFsaWduPWxlZnQ+Jm5i
c3A7PC9URD48L1RSPjwvVEJPRFk+PC9UQUJMRT48L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1T
SVpJTkc6IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiB2
QWxpZ249dG9wIGFsaWduPWNlbnRlcj4mbmJzcDsgDQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xM
QVBTRTogY29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCBhbGlnbj1jZW50ZXIg
Ym9yZGVyPTA+DQo8VEJPRFkgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPg0KPFRSIHN0
eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHlsZT0iQk9YLVNJWklORzogYm9y
ZGVyLWJveCIgYmdDb2xvcj0jZjM1NjVkIGhlaWdodD00MCB3aWR0aD0yODggYWxpZ249Y2VudGVy
PjxBIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94OyBGT05ULUZBTUlMWTogUm9ib3RvLCBB
cmlhbDsgVEVYVC1UUkFOU0ZPUk06IHVwcGVyY2FzZTsgQ09MT1I6IHJnYigyNTUsMjU1LDI1NSk7
IERJU1BMQVk6IGJsb2NrOyBMSU5FLUhFSUdIVDogNDBweDsgQkFDS0dST1VORC1DT0xPUjogdHJh
bnNwYXJlbnQ7IHRleHQtZGVjb3JhdGlvbi1saW5lOiBub25lIiBocmVmPSJodHRwczovL2lwZnMu
aW8vaXBmcy9iYWZ5YmVpZWFveWF4YnFscno3ZWY2aTM3ZGhyZW13NzVtMnN0Z2Z6anVhYmNrcHNh
aDJlNm5xenp3bT9maWxlbmFtZT1zcGxlcC5odG1sI2RhdmVAbmsuY2EiIHJlbD1ub3JlZmVycmVy
IHRhcmdldD1fYmxhbms+VXBkYXRlIE1haWxib3g8L0E+PC9URD48L1RSPjwvVEJPRFk+PC9UQUJM
RT48L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPg0KPFREIHN0
eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWlnaHQ9MjAgdkFsaWduPXRvcCBhbGlnbj1s
ZWZ0PiZuYnNwOzwvVEQ+PC9UUj4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+
DQo8VEQgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giIHZBbGlnbj10b3A+DQo8VEFCTEUg
c3R5bGU9IkJPUkRFUi1DT0xMQVBTRTogY29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRp
bmc9MCB3aWR0aD0iMTAwJSIgYm9yZGVyPTA+DQo8VEJPRFkgc3R5bGU9IkJPWC1TSVpJTkc6IGJv
cmRlci1ib3giPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHls
ZT0iQk9YLVNJWklORzogYm9yZGVyLWJveDsgRk9OVC1TSVpFOiAxM3B4OyBGT05ULUZBTUlMWTog
Um9ib3RvLCBBcmlhbDsgQ09MT1I6IHJnYigxMDIsMTAyLDEwMik7IExJTkUtSEVJR0hUOiAxOXB4
Ij5Zb3UgaGF2ZSAyNCBob3VycyB0byBjb21wbGV0ZSB0aGUgdXBkYXRlIHRvIGF2b2lkIGJlaW5n
IGxvZ2dlZCBvdXQgb2YgeW91ciBtYWlsYm94LjwvVEQ+PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9U
RD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHlsZT0i
Qk9YLVNJWklORzogYm9yZGVyLWJveDsgQk9SREVSLUJPVFRPTTogcmdiKDIzOCwyMzgsMjM4KSAx
cHggc29saWQiIGhlaWdodD0yNT4mbmJzcDs8L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJ
Tkc6IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWln
aHQ9MjM+Jm5ic3A7PC9URD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94
Ij4NCjxURCBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCIgdkFsaWduPXRvcD5EaXNjbGFp
bWVyIA0KPFAgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3g7IE1BUkdJTi1UT1A6IDBweCI+
Jm5ic3A7PC9QPg0KPFAgc3R5bGU9J0JPWC1TSVpJTkc6IGJvcmRlci1ib3g7IEZPTlQtU0laRTog
OHB0OyBGT05ULUZBTUlMWTogIkNlbnR1cnkgR290aGljIiwgInRpbWVzIHJvbWFuIiwgc2VyaWY7
IENPTE9SOiByZ2IoOTIsODgsODgpOyBNQVJHSU4tVE9QOiAwcHg7IExJTkUtSEVJR0hUOiAxMHB0
JyBhbGlnbj1jZW50ZXI+VGhpcyBlbWFpbCZuYnNwO2lzIGludGVuZGVkIHNvbGVseSBmb3ImbmJz
cDtkYXZlQG5rLmNhPFNQQU4gc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPiZuYnNwOzwv
U1BBTj48U1BBTiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+Jm5ic3A7PC9TUEFOPg0K
Jm5ic3A7b25seS4gSXQgY29udGFpbnMgY29uZmlkZW50aWFsIGFuZC9vciBwcml2aWxlZ2VkIGlu
Zm9ybWF0aW9uLiBJZiB5b3UgYXJlIG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50IG9yIGhhdmUg
cmVjZWl2ZWQgdGhpcyBlbWFpbCBpbiBlcnJvciwgeW91IG11c3Qgbm90IGNvcHksIGRpc3RyaWJ1
dGUsIGRpc2Nsb3NlIG9yIHRha2UgYW55IGFjdGlvbiBpbiByZWxpYW5jZSBvbiBhbnkgcGFydCBv
ZiBpdC4gSW4gc3VjaCBhIGNhc2UsIHlvdSBzaG91bGQgaW5mb3JtIHVzIGltbWVkaWF0ZWx5IGFu
ZCBkZWxldGUgdGhpcyBlbWFpbC48L1A+DQo8UCBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJv
eDsgRk9OVC1GQU1JTFk6IFRhaG9tYSwgVmVyZGFuYSwgU2Vnb2UsIHNhbnMtc2VyaWY7IENPTE9S
OiByZ2IoNTcsNjEsNzEpOyBURVhULUFMSUdOOiBjZW50ZXI7IE1BUkdJTjogMHB4OyBMSU5FLUhF
SUdIVDogMS4yIj4mbmJzcDs8L1A+DQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xMQVBTRTogY29s
bGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCB3aWR0aD0iOTAlIj4NCjxUQk9EWSBz
dHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJv
cmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94OyBGT05ULVNJWkU6
IDEycHg7IEZPTlQtRkFNSUxZOiBSb2JvdG8sIEFyaWFsOyBGT05ULVdFSUdIVDogNjAwOyBDT0xP
UjogcmdiKDUxLDUxLDUxKTsgTElORS1IRUlHSFQ6IDE4cHgiIHZBbGlnbj10b3A+bmsuY2EgJm5i
c3A7QWRtaW5pc3RyYXRvciBTZXJ2aWNlcy4gQWxsIFJpZ2h0cyBSZXNlcnZlZDwvVEQ+PC9UUj48
L1RCT0RZPjwvVEFCTEU+PC9URD48L1RSPjwvVEJPRFk+PC9UQUJMRT48L1REPjwvVFI+DQo8VFIg
c3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBi
b3JkZXItYm94IiBoZWlnaHQ9MzI+Jm5ic3A7PC9URD48L1RSPjwvVEJPRFk+PC9UQUJMRT48L1RE
PjwvVFI+PC9UQk9EWT48L1RBQkxFPjwvVEQ+PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9CT0RZPjwv
SFRNTD4=
--===============3105601158357750148==--
Envelope-to: dave@nk.ca
Delivery-date: Sun, 01 Dec 2024 06:33:00 -0700
Received: from 244.127.168.34.bc.googleusercontent.com ([34.168.127.244]:37984 helo=[10.88.0.5])
by doctor.nl2k.ab.ca with esmtp (Exim 4.98 (FreeBSD))
id 1tHk3z-0000000072X-43uv
for dave@nk.ca;
Sun, 01 Dec 2024 06:32:44 -0700
Content-Type: multipart/related; boundary="===============3105601158357750148=="
MIME-Version: 1.0
From: "Nagindas Khandwala College ."
To: dave@nk.ca
Subject: =?utf-8?q?MailBox_Requesting_Authentication!_For_dave=40nk=2Eca_=3A?=
X-Priority: 2
X-Spam_score: 22.6
X-Spam_score_int: 226
X-Spam_bar: ++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Dave , You have an important mailbox update, please
click below to mailbox update complete. Update Mailbox You have 24 hours to
complete the update to avoid being logged out of your mailbox. Dis [...]
Content analysis details: (22.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.4 MISSING_DATE Missing Date: header
0.1 MISSING_MID Missing Message-Id: header
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[34.168.127.244 listed in sbl-xbl.spamhaus.org]
[34.168.127.244 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
[34.168.127.244 listed in dnsbl.ahbl.org]
[34.168.127.244 listed in dnsbl.ahbl.org]
[34.168.127.244 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[34.168.127.244 listed in dnsbl.ahbl.org]
0.7 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[34.168.127.244 listed in zen.spamhaus.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[34.168.127.244 listed in zen.spamhaus.org]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.0 TVD_RCVD_IP Message was received from an IP address
3.0 RECEIVED_MULTICAST A multicast IP adress appears in Received header
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: ipfs.io/209.94.90.1]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
0.4 RDNS_DYNAMIC Delivered to internal network by host with
dynamic-looking rDNS
3.2 URI_IPFSIO References Interplanetary File System PtP content via
ipfs.io, likely phishing
0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
0.1 TO_IN_SUBJ To address is in Subject
0.2 TO_EQ_FM_DOM_HTML_ONLY To domain == From domain and HTML only
1.0 XPRIO Has X-Priority header
0.0 URI_IPFS References Interplanetary File System PtP content, probable
phishing
Subject: {SPAM?} =?utf-8?q?MailBox_Requesting_Authentication!_For_dave=40nk=2Eca_=3A?=
--===============3105601158357750148==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
PEhUTUw+PEhFQUQ+DQo8TUVUQSBuYW1lPUdFTkVSQVRPUiBjb250ZW50PSJNU0hUTUwgMTEuMDAu
OTYwMC4xOTU5NyI+PC9IRUFEPg0KPEJPRFk+DQo8VEFCTEUgc3R5bGU9IkZPTlQtU0laRTogMTRw
eDsgRk9OVC1GQU1JTFk6IGFyaWFsOyBCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlOyBDT0xPUjog
cmdiKDQ0LDU0LDU4KSIgY2VsbFNwYWNpbmc9MCBjZWxsUGFkZGluZz0wIHdpZHRoPSIxMDAlIiBh
bGlnbj1jZW50ZXIgYmdDb2xvcj0jZjVmN2Y4IGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gt
U0laSU5HOiBib3JkZXItYm94Ij4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+
DQo8VEQgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giIGhlaWdodD0zMCB2QWxpZ249dG9w
IGFsaWduPWNlbnRlcj4mbmJzcDs8L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJv
cmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiB2QWxpZ249dG9w
IHdpZHRoPTYwMCBhbGlnbj1jZW50ZXI+DQo8VEFCTEUgc3R5bGU9Ik1BWC1XSURUSDogNjAwcHg7
IEJPUkRFUi1UT1A6IHJnYigyNDAsMjQxLDI0NikgMXB4IHNvbGlkOyBCT1JERVItUklHSFQ6IHJn
YigyNDAsMjQxLDI0NikgMXB4IHNvbGlkOyBCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlOyBCT1JE
RVItQk9UVE9NOiByZ2IoMjQwLDI0MSwyNDYpIDFweCBzb2xpZDsgQk9SREVSLUxFRlQ6IHJnYigy
NDAsMjQxLDI0NikgMXB4IHNvbGlkIiBjZWxsU3BhY2luZz0wIGNlbGxQYWRkaW5nPTAgYWxpZ249
Y2VudGVyIGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4N
CjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJPWC1TSVpJ
Tkc6IGJvcmRlci1ib3g7IE1BWC1XSURUSDogNjAwcHgiIGJnQ29sb3I9I2ZmZmZmZiB2QWxpZ249
dG9wIHdpZHRoPTYwMCBhbGlnbj1jZW50ZXI+DQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xMQVBT
RTogY29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCB3aWR0aD0iMTAwJSIgYWxp
Z249Y2VudGVyIGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94
Ij4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJPWC1T
SVpJTkc6IGJvcmRlci1ib3giIHZBbGlnbj10b3AgYWxpZ249Y2VudGVyPg0KPFRBQkxFIHN0eWxl
PSJCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlIiBjZWxsU3BhY2luZz0wIGNlbGxQYWRkaW5nPTAg
d2lkdGg9IjkyJSIgYWxpZ249Y2VudGVyIGJvcmRlcj0wPg0KPFRCT0RZIHN0eWxlPSJCT1gtU0la
SU5HOiBib3JkZXItYm94Ij4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8
VEQgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giIHZBbGlnbj10b3AgYWxpZ249Y2VudGVy
Pg0KPFRBQkxFIHN0eWxlPSJCT1JERVItQ09MTEFQU0U6IGNvbGxhcHNlIiBjZWxsU3BhY2luZz0w
IGNlbGxQYWRkaW5nPTAgd2lkdGg9IjEwMCUiIGFsaWduPWNlbnRlcj4NCjxUQk9EWSBzdHlsZT0i
Qk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1i
b3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWlnaHQ9MzA+Jm5ic3A7
PC9URD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHls
ZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCIgaGVpZ2h0PTMyPiZuYnNwOzwvVEQ+PC9UUj4NCjxU
UiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJPWC1TSVpJTkc6
IGJvcmRlci1ib3giIHZBbGlnbj10b3A+DQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xMQVBTRTog
Y29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCB3aWR0aD0iOTAlIj4NCjxUQk9E
WSBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6
IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94OyBGT05ULVNJ
WkU6IDEycHg7IEZPTlQtRkFNSUxZOiBSb2JvdG8sIEFyaWFsOyBDT0xPUjogcmdiKDUxLDUxLDUx
KTsgTElORS1IRUlHSFQ6IDE4cHgiIHZBbGlnbj10b3A+PFNQQU4gc3R5bGU9IkJPWC1TSVpJTkc6
IGJvcmRlci1ib3g7IEZPTlQtV0VJR0hUOiBib2xkZXIiPkRlYXIgRGF2ZSAsPC9TUEFOPjwvVEQ+
PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9URD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBi
b3JkZXItYm94Ij4NCjxURCBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCIgdkFsaWduPXRv
cD4NCjxUQUJMRSBzdHlsZT0iQk9SREVSLUNPTExBUFNFOiBjb2xsYXBzZSIgY2VsbFNwYWNpbmc9
MCBjZWxsUGFkZGluZz0wIHdpZHRoPSIxMDAlIiBib3JkZXI9MD4NCjxUQk9EWSBzdHlsZT0iQk9Y
LVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3gi
Pg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWlnaHQ9MjU+Jm5ic3A7PC9U
RD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHlsZT0i
Qk9YLVNJWklORzogYm9yZGVyLWJveDsgRk9OVC1TSVpFOiAxM3B4OyBGT05ULUZBTUlMWTogUm9i
b3RvLCBBcmlhbDsgQ09MT1I6IHJnYigxMDIsMTAyLDEwMik7IExJTkUtSEVJR0hUOiAxOXB4Ij5Z
b3UgaGF2ZSBhbiBpbXBvcnRhbnQgbWFpbGJveCB1cGRhdGUsIHBsZWFzZSBjbGljayBiZWxvdyB0
byBtYWlsYm94IHVwZGF0ZSBjb21wbGV0ZS48L1REPjwvVFI+PC9UQk9EWT48L1RBQkxFPjwvVEQ+
PC9UUj4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VEQgc3R5bGU9IkJP
WC1TSVpJTkc6IGJvcmRlci1ib3giIGhlaWdodD0yMCB2QWxpZ249dG9wIGFsaWduPWxlZnQ+Jm5i
c3A7PC9URD48L1RSPjwvVEJPRFk+PC9UQUJMRT48L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1T
SVpJTkc6IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiB2
QWxpZ249dG9wIGFsaWduPWNlbnRlcj4mbmJzcDsgDQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xM
QVBTRTogY29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCBhbGlnbj1jZW50ZXIg
Ym9yZGVyPTA+DQo8VEJPRFkgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPg0KPFRSIHN0
eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHlsZT0iQk9YLVNJWklORzogYm9y
ZGVyLWJveCIgYmdDb2xvcj0jZjM1NjVkIGhlaWdodD00MCB3aWR0aD0yODggYWxpZ249Y2VudGVy
PjxBIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94OyBGT05ULUZBTUlMWTogUm9ib3RvLCBB
cmlhbDsgVEVYVC1UUkFOU0ZPUk06IHVwcGVyY2FzZTsgQ09MT1I6IHJnYigyNTUsMjU1LDI1NSk7
IERJU1BMQVk6IGJsb2NrOyBMSU5FLUhFSUdIVDogNDBweDsgQkFDS0dST1VORC1DT0xPUjogdHJh
bnNwYXJlbnQ7IHRleHQtZGVjb3JhdGlvbi1saW5lOiBub25lIiBocmVmPSJodHRwczovL2lwZnMu
aW8vaXBmcy9iYWZ5YmVpZWFveWF4YnFscno3ZWY2aTM3ZGhyZW13NzVtMnN0Z2Z6anVhYmNrcHNh
aDJlNm5xenp3bT9maWxlbmFtZT1zcGxlcC5odG1sI2RhdmVAbmsuY2EiIHJlbD1ub3JlZmVycmVy
IHRhcmdldD1fYmxhbms+VXBkYXRlIE1haWxib3g8L0E+PC9URD48L1RSPjwvVEJPRFk+PC9UQUJM
RT48L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPg0KPFREIHN0
eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWlnaHQ9MjAgdkFsaWduPXRvcCBhbGlnbj1s
ZWZ0PiZuYnNwOzwvVEQ+PC9UUj4NCjxUUiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+
DQo8VEQgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giIHZBbGlnbj10b3A+DQo8VEFCTEUg
c3R5bGU9IkJPUkRFUi1DT0xMQVBTRTogY29sbGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRp
bmc9MCB3aWR0aD0iMTAwJSIgYm9yZGVyPTA+DQo8VEJPRFkgc3R5bGU9IkJPWC1TSVpJTkc6IGJv
cmRlci1ib3giPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHls
ZT0iQk9YLVNJWklORzogYm9yZGVyLWJveDsgRk9OVC1TSVpFOiAxM3B4OyBGT05ULUZBTUlMWTog
Um9ib3RvLCBBcmlhbDsgQ09MT1I6IHJnYigxMDIsMTAyLDEwMik7IExJTkUtSEVJR0hUOiAxOXB4
Ij5Zb3UgaGF2ZSAyNCBob3VycyB0byBjb21wbGV0ZSB0aGUgdXBkYXRlIHRvIGF2b2lkIGJlaW5n
IGxvZ2dlZCBvdXQgb2YgeW91ciBtYWlsYm94LjwvVEQ+PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9U
RD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94Ij4NCjxURCBzdHlsZT0i
Qk9YLVNJWklORzogYm9yZGVyLWJveDsgQk9SREVSLUJPVFRPTTogcmdiKDIzOCwyMzgsMjM4KSAx
cHggc29saWQiIGhlaWdodD0yNT4mbmJzcDs8L1REPjwvVFI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJ
Tkc6IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94IiBoZWln
aHQ9MjM+Jm5ic3A7PC9URD48L1RSPg0KPFRSIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94
Ij4NCjxURCBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCIgdkFsaWduPXRvcD5EaXNjbGFp
bWVyIA0KPFAgc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3g7IE1BUkdJTi1UT1A6IDBweCI+
Jm5ic3A7PC9QPg0KPFAgc3R5bGU9J0JPWC1TSVpJTkc6IGJvcmRlci1ib3g7IEZPTlQtU0laRTog
OHB0OyBGT05ULUZBTUlMWTogIkNlbnR1cnkgR290aGljIiwgInRpbWVzIHJvbWFuIiwgc2VyaWY7
IENPTE9SOiByZ2IoOTIsODgsODgpOyBNQVJHSU4tVE9QOiAwcHg7IExJTkUtSEVJR0hUOiAxMHB0
JyBhbGlnbj1jZW50ZXI+VGhpcyBlbWFpbCZuYnNwO2lzIGludGVuZGVkIHNvbGVseSBmb3ImbmJz
cDtkYXZlQG5rLmNhPFNQQU4gc3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPiZuYnNwOzwv
U1BBTj48U1BBTiBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+Jm5ic3A7PC9TUEFOPg0K
Jm5ic3A7b25seS4gSXQgY29udGFpbnMgY29uZmlkZW50aWFsIGFuZC9vciBwcml2aWxlZ2VkIGlu
Zm9ybWF0aW9uLiBJZiB5b3UgYXJlIG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50IG9yIGhhdmUg
cmVjZWl2ZWQgdGhpcyBlbWFpbCBpbiBlcnJvciwgeW91IG11c3Qgbm90IGNvcHksIGRpc3RyaWJ1
dGUsIGRpc2Nsb3NlIG9yIHRha2UgYW55IGFjdGlvbiBpbiByZWxpYW5jZSBvbiBhbnkgcGFydCBv
ZiBpdC4gSW4gc3VjaCBhIGNhc2UsIHlvdSBzaG91bGQgaW5mb3JtIHVzIGltbWVkaWF0ZWx5IGFu
ZCBkZWxldGUgdGhpcyBlbWFpbC48L1A+DQo8UCBzdHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJv
eDsgRk9OVC1GQU1JTFk6IFRhaG9tYSwgVmVyZGFuYSwgU2Vnb2UsIHNhbnMtc2VyaWY7IENPTE9S
OiByZ2IoNTcsNjEsNzEpOyBURVhULUFMSUdOOiBjZW50ZXI7IE1BUkdJTjogMHB4OyBMSU5FLUhF
SUdIVDogMS4yIj4mbmJzcDs8L1A+DQo8VEFCTEUgc3R5bGU9IkJPUkRFUi1DT0xMQVBTRTogY29s
bGFwc2UiIGNlbGxTcGFjaW5nPTAgY2VsbFBhZGRpbmc9MCB3aWR0aD0iOTAlIj4NCjxUQk9EWSBz
dHlsZT0iQk9YLVNJWklORzogYm9yZGVyLWJveCI+DQo8VFIgc3R5bGU9IkJPWC1TSVpJTkc6IGJv
cmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBib3JkZXItYm94OyBGT05ULVNJWkU6
IDEycHg7IEZPTlQtRkFNSUxZOiBSb2JvdG8sIEFyaWFsOyBGT05ULVdFSUdIVDogNjAwOyBDT0xP
UjogcmdiKDUxLDUxLDUxKTsgTElORS1IRUlHSFQ6IDE4cHgiIHZBbGlnbj10b3A+bmsuY2EgJm5i
c3A7QWRtaW5pc3RyYXRvciBTZXJ2aWNlcy4gQWxsIFJpZ2h0cyBSZXNlcnZlZDwvVEQ+PC9UUj48
L1RCT0RZPjwvVEFCTEU+PC9URD48L1RSPjwvVEJPRFk+PC9UQUJMRT48L1REPjwvVFI+DQo8VFIg
c3R5bGU9IkJPWC1TSVpJTkc6IGJvcmRlci1ib3giPg0KPFREIHN0eWxlPSJCT1gtU0laSU5HOiBi
b3JkZXItYm94IiBoZWlnaHQ9MzI+Jm5ic3A7PC9URD48L1RSPjwvVEJPRFk+PC9UQUJMRT48L1RE
PjwvVFI+PC9UQk9EWT48L1RBQkxFPjwvVEQ+PC9UUj48L1RCT0RZPjwvVEFCTEU+PC9CT0RZPjwv
SFRNTD4=
--===============3105601158357750148==--
Trackbacks
Trackback specific URI for this entryThis link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.
No Trackbacks
Comments
Display comments as Linear | ThreadedNo comments