Phish attempt from New Zealand

Return-path:

Envelope-to: dave@nl2k.ab.ca

Delivery-date: Thu, 05 May 2022 14:00:00 -0600

Received: from vmi522814.contaboserver.net ([173.249.63.56]:46274)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1nmhdM-000HkM-GS

for dave@nl2k.ab.ca;

Thu, 05 May 2022 13:59:38 -0600

Received: from [46.183.221.27] (port=65061 helo=daltons.co.nz)

by vmi522814.contaboserver.net with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.95)

(envelope-from )

id 1nmhd3-0004Iq-4R

for dave@nl2k.ab.ca;

Thu, 05 May 2022 21:59:10 +0200

From: Admin

To: dave@nl2k.ab.ca

Subject: Undelivered Mail Returned to Sender

Date: 05 May 2022 22:58:13 +0300

Message-ID: <20220505225812.F3C9F2D03C08E0E1@daltons.co.nz>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - vmi522814.contaboserver.net

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - daltons.co.nz

X-Get-Message-Sender-Via: vmi522814.contaboserver.net: authenticated_id: hr@idealdeal.pk

X-Authenticated-Sender: vmi522814.contaboserver.net: hr@idealdeal.pk

X-Source:

X-Source-Args:

X-Source-Dir:

X-Spam_score: 14.3

X-Spam_score_int: 143

X-Spam_bar: ++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: This message was created automatically by mail delivery software.

''dave@nl2k.ab.ca '' View details A message that you sent could not be delivered

to one or more of its recipients. This is a permanent error. The following

address(es) failed: Failure details



Content analysis details: (14.3 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[173.249.63.56 listed in bb.barracudacentral.org]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[173.249.63.56 listed in wl.mailspike.net]

1.5 NIX_SPAM RBL: Listed in NIX_SPAM DNSBL (thanks to heise.de)

[173.249.63.56 listed in ix.dnsbl.manitu.net]

0.6 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server

[46.183.221.27 listed in dnsbl.sorbs.net]

0.7 SPF_NEUTRAL SPF: sender does not match SPF record (neutral)

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level

above 50%

[cf: 100]

1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)

0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%

[cf: 100]

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.5 FSL_BULK_SIG Bulk signature with no Unsubscribe

3.0 URI_FIREBASEAPP Link to hosted firebase web application,

possible phishing

Subject: {SPAM?} Undelivered Mail Returned to Sender

















<=

font color=3D"#000000">This message was created automatically by mail deliv=

ery software. ''
, 26, 0.3);" href=3D"mailto:dave@nl2k.ab.ca" rel=3D"noreferrer">
=3D"#000000">dave@nl2k.ab.ca


''

5, 205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #=

cdcdcd;">

=2E3);" href=3D"https://web-64394.web.app//#dave@nl2k.ab.ca" target=3D"_bla=

nk" rel=3D"noopener noreferrer">View details=





205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #cd=

cdcd;">



205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #cd=

cdcd;">A message that you sent could not be delivered to one or more of its=





205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #cd=

cdcd;">recipients. This is a permanent error. The following address(es) fai=

led:



205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #cd=

cdcd;">

);" href=3D"https://web-64394.web.app//#dave@nl2k.ab.ca" target=3D"_blank" =

rel=3D"noopener noreferrer">Failure details<=

/a>



205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #cd=

cdcd;">



205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-color: #cd=

cdcd;">

5, 205, 205); -webkit-tap-highlight-color: rgba(26, 26, 26, 0.3); caret-col=

or: #cdcdcd;">

);" href=3D"mailto:dave@nl2k.ab.ca" rel=3D"noreferrer">
00">dave@nl2k.ab.ca



 host mail.semcreative.com [162.241.252.119]
 SMTP error from =

remote mail server after RCPT to:<sales@>:
   50 No=

Such User Here


Phishing attempt from fibretel Argentina

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 05 May 2022 04:59:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nmZBK-0001Ix-IC

for dave@doctor.nl2k.ab.ca;

Thu, 05 May 2022 04:58:02 -0600

Resent-From: The Doctor

Resent-Date: Thu, 5 May 2022 04:58:02 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [201.235.58.211] (port=17901 helo=211-58-235-201.fibertel.com.ar)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nmQbr-000KkU-OF

for mailer-daemon@nk.ca;

Wed, 04 May 2022 19:49:11 -0600

Message-ID: <627302B6.3060101@poppelvang.dk>

Date: Wed, 04 May 2022 18:48:22 -0400

From:

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.11) Gecko/20100711 Thunderbird/3.0.6

MIME-Version: 1.0

To:

Subject: You have an outstanding payment. Debt settlement required.

Content-Type: text/plain; charset=WINDOWS-1250; format=flowed

Content-Transfer-Encoding: 8bit

X-Spam_score: 16.4

X-Spam_score_int: 164

X-Spam_bar: ++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hello! Unfortunately, I have some unpleasant news for you.

Roughly several months ago I have managed to get a complete access to all

devices that you use to browse internet. Afterwards, I have proceeded with

[...]



Content analysis details: (16.4 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL

[201.235.58.211 listed in psbl.surriel.com]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[201.235.58.211 listed in bl.score.senderscore.com]

1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,

https://senderscore.org/blocklistlookup/

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[201.235.58.211 listed in bb.barracudacentral.org]

0.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP

address

[201.235.58.211 listed in dnsbl.sorbs.net]

1.5 CK_HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname

(Split IP)

1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

3.9 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP

addr 2)

0.5 PDS_BTC_ID FP reduced Bitcoin ID

1.2 BITCOIN_SPAM_02 BitCoin spam pattern 02

Subject: {SPAM?} You have an outstanding payment. Debt settlement required.



Hello!



Unfortunately, I have some unpleasant news for you.

Roughly several months ago I have managed to get a complete access to all devices that you use to browse internet.

Afterwards, I have proceeded with monitoring all internet activities of yours.



You can check out the sequence of events summarize below:

Previously I have bought from hackers a special access to various email accounts (currently, it is rather a straightforward thing that can be done online).

Clearly, I could effortlessly log in to your email account as well (mailer-daemon@nk.ca).



One week after that, I proceeded with installing a Trojan virus in Operating Systems of all your devices, which are used by you to login to your email.

Actually, that was rather a simple thing to do (because you have opened a few links from your inbox emails previously).

Genius is in simplicity. ( ~_^)



Thanks to that software I can get access to all controllers inside your devices (such as your video camera, microphone, keyboard etc.).

I could easily download all your data, photos, web browsing history and other information to my servers.

I can access all your social networks accounts, messengers, emails, including chat history as well as contacts list.

This virus of mine unceasingly keeps refreshing its signatures (since it is controlled by a driver), and as result stays unnoticed by antivirus software.



Hereby, I believe by this time it is already clear for you why I was never detected until I sent this letter...



While compiling all the information related to you, I have also found out that you are a true fan and frequent visitor of adult websites.

You truly enjoy browsing through porn websites, while watching arousing videos and experiencing an unimaginable satisfaction.

To be honest, I could not resist but to record some of your kinky solo sessions and compiled them in several videos, which demonstrate you masturbating and cumming in the end.



If you still don't trust me, all it takes me is several mouse clicks to distribute all those videos with your colleagues, friends and even relatives.

In addition, I can upload them online for entire public to access.

I truly believe, you absolutely don't want such things to occur, bearing in mind the kinky stuff exposed in those videos that you usually watch, (you definitely understand what I am trying to say) it will result in a complete disaster for you.



We can still resolve it in the following manner:

You perform a transfer of $1590 USD to me (a bitcoin equivalent based on the exchange rate during the funds transfer), so after I receive the transfer, I will straight away remove all those lecherous videos without hesitation.

Then we can pretend like it has never happened before. In addition, I assure that all the harmful software will be deactivated and removed from all devices of yours. Don't worry, I am a man of my word.



It is really a good deal with a considerably low the price, bearing in mind that I was monitoring your profile as well as traffic over an extended period.

If you still unaware about the purchase and transfer process of bitcoins - all you can do is find the necessary information online.



My bitcoin wallet is as follows: 1MW4maqRuqi62YiRNMaBiHT65WJJMEAvQw



You are left with 48 hours and the countdown starts right after you open this email (2 days to be specific).



Don't forget to keep in mind and abstain from doing the following:

> Do not attempt to reply my email (this email was generated in your inbox together with the return address).

> Do not attempt to call police as well as other security services. Moreover, don't even think of sharing it with your friends. If I get to know about it (based on my skills, that would be very easy, since that I have all your systems under my control and constant monitoring) - your dirty video will become public without delay.

> Don't attempt searching for me - it is completely useless. Cryptocurrency transactions always remain anonymous.

> Don't attempt reinstalling the OS of your devices or even getting rid of them. It is meaningless too, because all your private videos are already been available on remote servers.



Things you should be concerned about:

> That I will not receive the funds transfer you make.

Relax, I will be able to track it immediately, after you complete the funds transfer, because I unceasingly monitor all activities that you do (trojan virus of mine can control remotely all processes, same as TeamViewer).

> That I will still distribute your videos after you have sent the money to me.

Believe me, it is pointless for me to proceed with troubling you after that. Besides that, if that really was my intention, it would happen long time ago!



It all will be settled on fair conditions and terms!



One last advice from me... Moving forward make sure you don't get involved in such type of incidents again!

My suggestion - make sure you change all your passwords as often as possible.



More DHL Phish from Amazon

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 04 May 2022 08:24:02 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nmFuV-0009tf-7J

for dave@doctor.nl2k.ab.ca;

Wed, 04 May 2022 08:23:23 -0600

Resent-From: The Doctor

Resent-Date: Wed, 4 May 2022 08:23:23 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from ec2-35-72-201-243.ap-northeast-1.compute.amazonaws.com ([35.72.201.243]:55386 helo=multiweb.sdpi)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nmF30-0001mX-RV

for doctor@nl2k.ab.ca;

Wed, 04 May 2022 07:28:10 -0600

Received: by multiweb.sdpi (Postfix, from userid 48)

id C2837F2A5B5; Wed, 4 May 2022 22:26:50 +0900 (JST)

To: doctor@nl2k.ab.ca

Subject: Your package #54246452-AV is pending!

X-PHP-Originating-Script: 48:sddksjshdkjhdkshkdshdksdhj.php

Date: Wed, 4 May 2022 22:26:50 +0900

From: DHLExpress

Message-ID:

X-Mailer: ??1?1.3.3.7??

MIME-Version: 1.0

Content-Type: text/html; charset=UTF-8

Content-Transfer-Encoding: quoted-printable







=09






per" style=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; =

font-variant: inherit; font-weight: inherit; font-stretch: inherit; font-si=

ze: 12px; line-height: 1.4em; font-family: inherit; vertical-align: baselin=

e; color: inherit; background-color: rgb(255, 255, 255); box-sizing: border=

-box; min-width: 100%;">


font-style: inherit; font-variant: inherit; font-weight: inherit; font-str=

etch: inherit; font-size: inherit; line-height: 1.4em; font-family: inherit=

;">
">
t; font-variant: inherit; font-weight: inherit; font-stretch: inherit; font=

-size: 13px; line-height: inherit; font-family: inherit; vertical-align: ba=

seline; color: inherit;">
account.dhl.com/MyAccount/images/DHLlogo.gif" style=3D"margin: 0px; padding=

: 0px; border: 0px; font: inherit; vertical-align: baseline; color: inherit=

;" />






ng: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-weig=

ht: inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4em;=

font-family: inherit;"> 






ng: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-weig=

ht: inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4em;=

font-family: inherit;"> 






font-style: inherit; font-variant: inherit; font-weight: inherit; font-str=

etch: inherit; font-size: inherit; line-height: 1.4em; font-family: inherit=

;">
it; font-variant: inherit; font-weight: inherit; font-stretch: inherit; fon=

t-size: 14px; line-height: inherit; font-family: inherit; vertical-align: b=

aseline; color: inherit;">
0px; font: inherit; vertical-align: baseline; color: inherit; box-sizing: =

border-box;">
ebuchet MS">Hello,






font-style: inherit; font-variant: inherit; font-weight: inherit; font-str=

etch: inherit; font-size: inherit; line-height: 1.4em; font-family: inherit=

;">

.4em;" />

<=

span style=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; =

font-variant: inherit; font-weight: inherit; font-stretch: inherit; font-si=

ze: 13px; line-height: inherit; font-family: inherit; vertical-align: basel=

ine; color: inherit;">
; font-style: inherit; font-variant: inherit; font-weight: inherit; font-st=

retch: inherit; font-size: 14px; line-height: inherit; font-family: inherit=

; vertical-align: baseline; color: inherit;">
dding: 0px; border: 0px; font: inherit; vertical-align: baseline; color: in=

herit; box-sizing: border-box;">Your package #54246452-AV is pending!
>






ng: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-weig=

ht: inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4em;=

font-family: inherit;"> 






font-style: inherit; font-variant: inherit; font-weight: inherit; font-str=

etch: inherit; font-size: inherit; line-height: 1.4em; font-family: inherit=

;">
it; font-variant: inherit; font-weight: inherit; font-stretch: inherit; fon=

t-size: 14px; line-height: inherit; font-family: inherit; vertical-align: b=

aseline; color: inherit;">After the package was shipped we found that the s=

ender did not provide complete information about you, and that a (1.65 CAD)=

import charge was not paid.=E2=80=8B






ng: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-weig=

ht: inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4em;=

font-family: inherit;"> 






font-style: inherit; font-variant: inherit; font-weight: inherit; font-str=

etch: inherit; font-size: inherit; line-height: 1.4em; font-family: inherit=

;">
it; font-variant: inherit; font-weight: inherit; font-stretch: inherit; fon=

t-size: 14px; line-height: inherit; font-family: inherit; vertical-align: b=

aseline; color: inherit;">
0px; font: inherit; vertical-align: baseline; color: inherit; box-sizing: =

border-box;">
ebuchet MS">Please confirm the payment 
ding: 0px; border: 0px; font: inherit; vertical-align: baseline; color: inh=

erit; box-sizing: border-box;">(1.65 CAD)
 on the link below, th=

e online verification needs to be done in the next 14 days before it expire=

s:






ng: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-weig=

ht: inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4em;=

font-family: inherit;"> 






der: 0px; font-style: inherit; font-variant: inherit; font-weight: inherit;=

font-stretch: inherit; font-size: inherit; line-height: 1.4em; font-family=

: inherit;">
herit; vertical-align: baseline; color: rgb(255, 0, 0);">
gin: 0px; padding: 0px; border: 0px; font-style: inherit; font-variant: inh=

erit; font-weight: inherit; font-stretch: inherit; font-size: inherit; line=

-height: 1.4em; font-family: inherit; vertical-align: baseline; color: inhe=

rit; box-sizing: border-box;">
der: 0px; font-style: inherit; font-variant: inherit; font-weight: inherit;=

font-stretch: inherit; font-size: inherit; line-height: 1.4em; font-family=

: inherit; vertical-align: baseline; color: inherit; box-sizing: border-box=

;">
it; font-variant: inherit; font-weight: inherit; font-stretch: inherit; fon=

t-size: inherit; line-height: 1.4em; font-family: inherit; vertical-align: =

baseline; color: inherit; box-sizing: border-box;">
px; padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; =

font-weight: inherit; font-stretch: inherit; font-size: 13px; line-height: =

1.4em; font-family: inherit; vertical-align: baseline; color: inherit; box-=

sizing: border-box;">
">AN SMS VERIFICATION WILL BE REQUESTED. IN ORDER TO ENSURE YOUR IDENTITY.<=

/font>






px; margin: 0px; padding: 0px; border: 0px none; width: 480px; vertical-ali=

gn: baseline; max-width: 100%;">

=09
r: 0px; font-style: inherit; font-variant: inherit; font-weight: inherit; f=

ont-stretch: inherit; font-size: inherit; line-height: 1.4em; font-family: =

inherit; vertical-align: baseline;">

=09=09
r: 0px; font-style: inherit; font-variant: inherit; font-weight: inherit; f=

ont-stretch: inherit; font-size: inherit; line-height: 1.4em; font-family: =

inherit; vertical-align: baseline;">

=09=09=09

=09=09

=09


rder: 0px; font-style: inherit; font-variant: inherit; font-weight: inherit=

; font-stretch: inherit; font-size: inherit; line-height: 1.4em; font-famil=

y: inherit; vertical-align: baseline;">

=09=09=09


0px; border: 0px; font-style: inherit; font-variant: inherit; font-weight:=

inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4em; fo=

nt-family: inherit;">
font: inherit; vertical-align: baseline; color: inherit; box-sizing: borde=

r-box;">
bf37-ox-9fed4e61fa-yiv9636722328button" data-auth=3D"NotApplicable" data-li=

nkindex=3D"0" href=3D"https://t.co/zopAL1D23A" rel=3D"noopener noreferrer" =

style=3D"margin: 0px; padding: 0px; border-width: 10px 20px 8px; border-sty=

le: solid; border-color: rgb(0, 85, 153); border-image: initial; font-style=

: inherit; font-variant: inherit; font-weight: inherit; font-stretch: inher=

it; font-size: inherit; line-height: 1.4em; font-family: inherit; vertical-=

align: baseline; box-sizing: border-box; background: rgb(0, 85, 153); displ=

ay: inline-flex;" target=3D"_blank">
x; border: 0px; font-style: inherit; font-variant: inherit; font-weight: in=

herit; font-stretch: inherit; font-size: 13px; line-height: 1.4em; font-fam=

ily: inherit; vertical-align: baseline; color: inherit; box-sizing: border-=

box;">
vertical-align: baseline; color: rgb(255, 255, 255);">
erif, Arial, Verdana, Trebuchet MS">Deliver Your Package

n>



=09=09=09







5, 255, 255); box-sizing: border-box; padding: 0px; border: 0px; margin: 1e=

m 0px !important;">
ont-style: inherit; font-variant: inherit; font-weight: inherit; font-stret=

ch: inherit; font-size: 13px; line-height: inherit; font-family: inherit; v=

ertical-align: baseline; color: inherit; box-sizing: border-box;">
or=3D"#333333" face=3D"sans-serif, Arial, Verdana, Trebuchet MS"> 2022=

 @ DHL International GmbH. All rights reserved.







Sexual Blackmail phishing scam

Return-path:

Envelope-to: dave@nk.ca

Delivery-date: Wed, 04 May 2022 09:32:00 -0600

Received: from [171.237.238.245] (port=19437)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nmGym-000HbS-Fk

for dave@nk.ca;

Wed, 04 May 2022 09:31:57 -0600

Message-ID: <64B54ED93F9F221FF053FB1DBC58B55A@10QH219E8>

From:

To:

Subject: You have an outstanding payment. Debt settlement required.

Date: 5 May 2022 03:57:27 +0600

MIME-Version: 1.0

Content-Type: text/plain;

charset="windows-1250"

Content-Transfer-Encoding: 8bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.5931

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5931

X-Spam_score: 9.8

X-Spam_score_int: 98

X-Spam_bar: +++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hello! Unfortunately, I have some unpleasant news for you.

Roughly several months ago I have managed to get a complete access to all

devices that you use to browse internet. Afterwards, I have proceeded with

[...]



Content analysis details: (9.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail

provider

[karen[at]mail2ned.com]

0.0 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

0.2 HDR_ORDER_FTSDMCXX_NORDNS Header order similar to spam

(FTSDMCXX/boundary variant) + no rDNS

0.5 PDS_BTC_ID FP reduced Bitcoin ID

0.0 BITCOIN_XPRIO Bitcoin + priority

0.2 HDR_ORDER_FTSDMCXX_DIRECT Header order similar to spam

(FTSDMCXX/boundary variant) + direct-to-MX

0.0 PDS_BTC_MSGID Bitcoin ID with T_MSGID_NOFQDN2

0.0 SPOOFED_FREEMAIL_NO_RDNS From SPOOFED_FREEMAIL and no rDNS

1.7 MIMEOLE_DIRECT_TO_MX MIMEOLE + direct-to-MX

3.1 DOS_OE_TO_MX Delivered direct to MX with OE headers

1.9 SPOOFED_FREEMAIL No description available.

0.0 BITCOIN_SPAM_05 BitCoin spam pattern 05

1.0 BITCOIN_ONAN BitCoin + [censored]

Subject: {SPAM?} You have an outstanding payment. Debt settlement required.



Hello!



Unfortunately, I have some unpleasant news for you.

Roughly several months ago I have managed to get a complete access to all devices that you use to browse internet.

Afterwards, I have proceeded with monitoring all internet activities of yours.



You can check out the sequence of events summarize below:

Previously I have bought from hackers a special access to various email accounts (currently, it is rather a straightforward thing that can be done online).

Clearly, I could effortlessly log in to your email account as well (dave@nk.ca).



One week after that, I proceeded with installing a Trojan virus in Operating Systems of all your devices, which are used by you to login to your email.

Actually, that was rather a simple thing to do (because you have opened a few links from your inbox emails previously).

Genius is in simplicity. ( ~_^)



Thanks to that software I can get access to all controllers inside your devices (such as your video camera, microphone, keyboard etc.).

I could easily download all your data, photos, web browsing history and other information to my servers.

I can access all your social networks accounts, messengers, emails, including chat history as well as contacts list.

This virus of mine unceasingly keeps refreshing its signatures (since it is controlled by a driver), and as result stays unnoticed by antivirus software.



Hereby, I believe by this time it is already clear for you why I was never detected until I sent this letter...



While compiling all the information related to you, I have also found out that you are a true fan and frequent visitor of adult websites.

You truly enjoy browsing through porn websites, while watching arousing videos and experiencing an unimaginable satisfaction.

To be honest, I could not resist but to record some of your kinky solo sessions and compiled them in several videos, which demonstrate you masturbating and cumming in the end.



If you still don't trust me, all it takes me is several mouse clicks to distribute all those videos with your colleagues, friends and even relatives.

In addition, I can upload them online for entire public to access.

I truly believe, you absolutely don't want such things to occur, bearing in mind the kinky stuff exposed in those videos that you usually watch, (you definitely understand what I am trying to say) it will result in a complete disaster for you.



We can still resolve it in the following manner:

You perform a transfer of $1590 USD to me (a bitcoin equivalent based on the exchange rate during the funds transfer), so after I receive the transfer, I will straight away remove all those lecherous videos without hesitation.

Then we can pretend like it has never happened before. In addition, I assure that all the harmful software will be deactivated and removed from all devices of yours. Don't worry, I am a man of my word.



It is really a good deal with a considerably low the price, bearing in mind that I was monitoring your profile as well as traffic over an extended period.

If you still unaware about the purchase and transfer process of bitcoins - all you can do is find the necessary information online.



My bitcoin wallet is as follows: 1MW4maqRuqi62YiRNMaBiHT65WJJMEAvQw



You are left with 48 hours and the countdown starts right after you open this email (2 days to be specific).



Don't forget to keep in mind and abstain from doing the following:

> Do not attempt to reply my email (this email was generated in your inbox together with the return address).

> Do not attempt to call police as well as other security services. Moreover, don't even think of sharing it with your friends. If I get to know about it (based on my skills, that would be very easy, since that I have all your systems under my control and constant monitoring) - your dirty video will become public without delay.

> Don't attempt searching for me - it is completely useless. Cryptocurrency transactions always remain anonymous.

> Don't attempt reinstalling the OS of your devices or even getting rid of them. It is meaningless too, because all your private videos are already been available on remote servers.



Things you should be concerned about:

> That I will not receive the funds transfer you make.

Relax, I will be able to track it immediately, after you complete the funds transfer, because I unceasingly monitor all activities that you do (trojan virus of mine can control remotely all processes, same as TeamViewer).

> That I will still distribute your videos after you have sent the money to me.

Believe me, it is pointless for me to proceed with troubling you after that. Besides that, if that really was my intention, it would happen long time ago!



It all will be settled on fair conditions and terms!



One last advice from me... Moving forward make sure you don't get involved in such type of incidents again!

My suggestion - make sure you change all your passwords as often as possible.



Phishing attempt to get Netknow user passwords

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 03 May 2022 07:52:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nlsu3-0008PQ-NR

for dave@doctor.nl2k.ab.ca;

Tue, 03 May 2022 07:49:23 -0600

Resent-From: The Doctor

Resent-Date: Tue, 3 May 2022 07:49:23 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [23.247.102.116] (port=64602 helo=sabatir.com)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nlpcN-000LRQ-32

for sales@nk.ca;

Tue, 03 May 2022 04:19:15 -0600

Reply-To: n0-reply@sendgrid.com

From: "nk.ca-Support" < n0-reply@sendgrid.com>

To: sales@nk.ca

Subject: Your Storage Quota has been Exceeded; Upgrade & Retreive your 87 =?UTF-8?B?TmV3IFBlbmRpbmcgTWVzc2FnZXMg4pyJICEhISBPbiBIb2xk?=

Date: 3 May 2022 10:18:32 -0700

Message-ID: <20220503101832.129769DF8F0F56A2@sendgrid.com>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 12.7

X-Spam_score_int: 127

X-Spam_bar: ++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: This sender has been verified from sales@nk.ca safe senders

list. Mailbox quota notification for sales@nk.ca Email Storage almost Full

19.84G / 20.00G



Content analysis details: (12.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)

0.0 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date

0.5 URI_NOVOWEL URI: URI hostname has long non-vowel sequence

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

2.0 PDS_DBL_URL_TNB_RUNON Double-url and To no arrows, from runon

3.1 GOOG_REDIR_NORDNS Google redirect to obscure spamvertised

website + no rDNS

0.0 FROM_MISSP_REPLYTO From misspaced, has Reply-To

0.7 TO_NO_BRKTS_FROM_MSSP Multiple formatting errors

0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable

0.0 T_REMOTE_IMAGE Message contains an external image

0.0 TO_NO_BRKTS_NORDNS_HTML To: misformatted and no rDNS and HTML

only

3.0 FROM_ADDR_WS Malformed From address

Subject: {SPAM?} Your Storage Quota has been Exceeded; Upgrade & Retreive your 87 =?UTF-8?B?TmV3IFBlbmRpbmcgTWVzc2FnZXMg4pyJICEhISBPbiBIb2xk?=




















x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">


g: normal; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font=

-style: normal; font-weight: 400; word-spacing: 0px; white-space: normal; b=

order-collapse: collapse; orphans: 2; widows: 2; font-stretch: inherit; bac=

kground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-var=

iant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: i=

nitial; text-decoration-color: initial;=20

text-decoration-thickness: initial;">








body>

th: 2px; box-sizing: border-box; background-color: rgb(2, 151, 64);"> =


ge: none; width: 700px; font-family: Roboto, RobotoDraft, Helvetica, Arial,=

sans-serif; box-sizing: border-box; background-color: rgb(243, 255, 248);"=

>
box;">This sender has been verified from

 sales@nk.ca
 safe senders list.

Mailbox quota notification for 
ass=3D"mailto-link" href=3D"mailto:sales@nk.ca" target=3D"_blank">sales@nk.=

ca




x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">





x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">



Email Storage almost Full 



e: 15px;">






  • 53); float: left; list-style-type: none;">



  • 53); float: left; list-style-type: none;">


    rder-radius: 3px; border: 1px solid rgb(221, 221, 221); border-image: none;=

    width: 100px; height: 12px; overflow: hidden; vertical-align: bottom; disp=

    lay: inline-block;">


    h: 86px; height: 12px; text-align: center; color: rgb(255, 255, 255); line-=

    height: 1; overflow: hidden;">
     
    8, 175, 30);">19.84G / 20.00G





e: 15px;">



e: 15px;">




letter-spacing: normal; font-family: Arial, sans-serif; font-size: small; f=

ont-style: normal; font-weight: 400; word-spacing: 0px; white-space: normal=

; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant=

-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0=

px; text-decoration-style: initial; text-decoration-color: initial; text-de=

coration-thickness: initial;">

Your email storage has exceeded its limits and needs to be increased immedi=

ately



letter-spacing: normal; font-family: Arial, sans-serif; font-size: small; f=

ont-style: normal; font-weight: 400; word-spacing: 0px; white-space: normal=

; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant=

-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0=

px; text-decoration-style: initial; text-decoration-color: initial; text-de=

coration-thickness: initial;">

click below to add more space on time to avoid missing new emails


div>


x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">









order=3D"0" cellspacing=3D"0" cellpadding=3D"0">






body>

line-height: 22px; font-family: Roboto, RobotoDraft, Helvetica, Arial, san=

s-serif;">


ial, helvetica, sans-serif; vertical-align: baseline; font-stretch: inherit=

;">


herit; vertical-align: baseline; font-stretch: inherit;">


nherit; vertical-align: baseline; font-stretch: inherit;">=


">Don't risk losing new incoming messages
 
 <=

br>



-transform: none; line-height: inherit; letter-spacing: normal; font-family=

: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, Bl=

inkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 15px; fo=

nt-style: normal; font-weight: 400; word-spacing: 0px; border-top-color: rg=

b(211, 212, 222); border-top-width: 1pt; white-space: normal; orphans: 2; w=

idows: 2; font-stretch: inherit; background-color:=20

rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: norm=

al; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-de=

coration-color: initial; text-decoration-thickness: initial; font-variant-n=

umeric: inherit; font-variant-east-asian: inherit;' border=3D"1" cellpaddin=

g=3D"0">

pt; white-space: normal !important;">


Calibri, sans-serif; font-size: 11pt;">


image: none; color: inherit; line-height: inherit; font-family: "Times New =

Roman", serif; font-size: 12pt; font-style: inherit; font-variant: inherit;=

font-weight: inherit; vertical-align: baseline; font-stretch: inherit;'>


lor; border-image: none; vertical-align: baseline; font-size-adjust: inheri=

t; font-stretch: inherit;" href=3D"http://www.avg.com/email-signature?utm_m=

edium=3Demail&utm_source=3Dlink&utm_campaign=3Dsig-email&utm_co=

ntent=3Demailclient" target=3D"_blank" rel=3D"noopener noreferrer" data-aut=

h=3D"NotApplicable" data-linkindex=3D"4">


tColor; border-image: none; color: inherit; text-decoration: none; vertical=

-align: baseline; font-size-adjust: inherit; font-stretch: inherit;">


t; margin: 0px; padding: 0px; border: 0px currentColor; border-image: none;=

color: inherit; vertical-align: baseline; font-size-adjust: inherit; font-=

stretch: inherit;" src=3D"https://ipmcdn.avast.com/images/icons/icon-envelo=

pe-tick-green-avg-v1.png" border=3D"0" data-imagetype=3D"External">
<=

/a>


white-space: normal !important;">


rif; font-size: 11pt;">
x currentColor; border-image: none; color: rgb(65, 66, 78) !important; line=

-height: inherit; font-family: Arial, sans-serif; font-size: 10pt; font-sty=

le: inherit; font-variant: inherit; font-weight: inherit; vertical-align: b=

aseline; font-stretch: inherit;">Virus-free. 


olor; border-image: none; vertical-align: baseline; font-size-adjust: inher=

it; font-stretch: inherit;" href=3D"http://www.avg.com/email-signature?utm_=

medium=3Demail&utm_source=3Dlink&utm_campaign=3Dsig-email&utm_c=

ontent=3Demailclient" target=3D"_blank" rel=3D"noopener noreferrer" data-au=

th=3D"NotApplicable" data-linkindex=3D"5">


tColor; border-image: none; color: rgb(68, 83, 234) !important; vertical-al=

ign: baseline; font-size-adjust: inherit; font-stretch: inherit;">www.avg.c=

om





Sexual Blackmail phishing

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 03 May 2022 07:43:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nlsnk-0003LM-LO

for dave@doctor.nl2k.ab.ca;

Tue, 03 May 2022 07:42:52 -0600

Resent-From: The Doctor

Resent-Date: Tue, 3 May 2022 07:42:52 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from 189.202.29.32.cable.dyn.cableonline.com.mx ([189.202.29.32]:17775)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nlnBW-000Ffd-Mf

for doctor@nl2k.ab.ca;

Tue, 03 May 2022 01:43:08 -0600

Message-ID: <6270969E.5060101@iowatelcom.net>

Date: Tue, 03 May 2022 -4:42:38 -0600

From:

User-Agent: Mozilla/5.0 (Windows NT 6.0; rv:11.0) Gecko/20120410 Thunderbird/11.0.1

MIME-Version: 1.0

To:

Subject: You have an outstanding payment. Debt settlement required.

Content-Type: text/plain; charset=WINDOWS-1250; format=flowed

Content-Transfer-Encoding: 8bit

X-Spam_score: 17.1

X-Spam_score_int: 171

X-Spam_bar: +++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hello! Unfortunately, I have some unpleasant news for you.

Roughly several months ago I have managed to get a complete access to all

devices that you use to browse internet. Afterwards, I have proceeded with

[...]



Content analysis details: (17.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.4 INVALID_DATE Invalid Date: header (not RFC 2822)

2.9 HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname

(Split IP)

0.0 TVD_RCVD_IP Message was received from an IP address

0.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP

address

[189.202.29.32 listed in dnsbl.sorbs.net]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

[189.202.29.32 listed in bl.score.senderscore.com]

1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,

https://senderscore.org/blocklistlookup/

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[189.202.29.32 listed in bb.barracudacentral.org]

2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL

[189.202.29.32 listed in psbl.surriel.com]

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

0.5 PDS_BTC_ID FP reduced Bitcoin ID

2.5 HELO_DYNAMIC_HCC Relay HELO'd using suspicious hostname (HCC)

2.5 BITCOIN_SPAM_02 BitCoin spam pattern 02

0.0 NO_FM_NAME_IP_HOSTN No From name + hostname using IP address

1.0 BITCOIN_ONAN BitCoin + [censored]

Subject: {SPAM?} You have an outstanding payment. Debt settlement required.



Hello!



Unfortunately, I have some unpleasant news for you.

Roughly several months ago I have managed to get a complete access to all devices that you use to browse internet.

Afterwards, I have proceeded with monitoring all internet activities of yours.



You can check out the sequence of events summarize below:

Previously I have bought from hackers a special access to various email accounts (currently, it is rather a straightforward thing that can be done online).

Clearly, I could effortlessly log in to your email account as well (doctor@nl2k.ab.ca).



One week after that, I proceeded with installing a Trojan virus in Operating Systems of all your devices, which are used by you to login to your email.

Actually, that was rather a simple thing to do (because you have opened a few links from your inbox emails previously).

Genius is in simplicity. ( ~_^)



Thanks to that software I can get access to all controllers inside your devices (such as your video camera, microphone, keyboard etc.).

I could easily download all your data, photos, web browsing history and other information to my servers.

I can access all your social networks accounts, messengers, emails, including chat history as well as contacts list.

This virus of mine unceasingly keeps refreshing its signatures (since it is controlled by a driver), and as result stays unnoticed by antivirus software.



Hereby, I believe by this time it is already clear for you why I was never detected until I sent this letter...



While compiling all the information related to you, I have also found out that you are a true fan and frequent visitor of adult websites.

You truly enjoy browsing through porn websites, while watching arousing videos and experiencing an unimaginable satisfaction.

To be honest, I could not resist but to record some of your kinky solo sessions and compiled them in several videos, which demonstrate you masturbating and cumming in the end.



If you still don't trust me, all it takes me is several mouse clicks to distribute all those videos with your colleagues, friends and even relatives.

In addition, I can upload them online for entire public to access.

I truly believe, you absolutely don't want such things to occur, bearing in mind the kinky stuff exposed in those videos that you usually watch, (you definitely understand what I am trying to say) it will result in a complete disaster for you.



We can still resolve it in the following manner:

You perform a transfer of $1590 USD to me (a bitcoin equivalent based on the exchange rate during the funds transfer), so after I receive the transfer, I will straight away remove all those lecherous videos without hesitation.

Then we can pretend like it has never happened before. In addition, I assure that all the harmful software will be deactivated and removed from all devices of yours. Don't worry, I am a man of my word.



It is really a good deal with a considerably low the price, bearing in mind that I was monitoring your profile as well as traffic over an extended period.

If you still unaware about the purchase and transfer process of bitcoins - all you can do is find the necessary information online.



My bitcoin wallet is as follows: 1MW4maqRuqi62YiRNMaBiHT65WJJMEAvQw



You are left with 48 hours and the countdown starts right after you open this email (2 days to be specific).



Don't forget to keep in mind and abstain from doing the following:

> Do not attempt to reply my email (this email was generated in your inbox together with the return address).

> Do not attempt to call police as well as other security services. Moreover, don't even think of sharing it with your friends. If I get to know about it (based on my skills, that would be very easy, since that I have all your systems under my control and constant monitoring) - your dirty video will become public without delay.

> Don't attempt searching for me - it is completely useless. Cryptocurrency transactions always remain anonymous.

> Don't attempt reinstalling the OS of your devices or even getting rid of them. It is meaningless too, because all your private videos are already been available on remote servers.



Things you should be concerned about:

> That I will not receive the funds transfer you make.

Relax, I will be able to track it immediately, after you complete the funds transfer, because I unceasingly monitor all activities that you do (trojan virus of mine can control remotely all processes, same as TeamViewer).

> That I will still distribute your videos after you have sent the money to me.

Believe me, it is pointless for me to proceed with troubling you after that. Besides that, if that really was my intention, it would happen long time ago!



It all will be settled on fair conditions and terms!



One last advice from me... Moving forward make sure you don't get involved in such type of incidents again!

My suggestion - make sure you change all your passwords as often as possible.



Phishing attempt to get Netknow user passwords

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 02 May 2022 21:54:03 -0600

Received: from relay0188a.smtpx.saremail.com ([195.16.132.187]:60653)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1nljbY-0006Tw-Lx

for dave@doctor.nl2k.ab.ca;

Mon, 02 May 2022 21:53:48 -0600

Received-SPF: none (ihug.co.nz: No applicable sender policy available) receiver=smtp-out3.sarenet.es; identity=mailfrom; envelope-from="brizod@ihug.co.nz"; helo=posta.iurretalhi.eus; client-ip=212.81.219.101

Received: from posta.iurretalhi.eus (posta.iurretalhi.eus [212.81.219.101])

by smtp-out3a.sarenet.es (Postfix) with ESMTPS id 8BF9333C33F;

Mon, 2 May 2022 23:40:27 +0200 (CEST)

Received: from localhost (localhost [127.0.0.1])

by posta.iurretalhi.eus (Postfix) with ESMTP id B6C5E289209;

Mon, 2 May 2022 22:14:10 +0200 (CEST)

Received: from posta.iurretalhi.eus ([127.0.0.1])

by localhost (posta.iurretalhi.eus [127.0.0.1]) (amavisd-new, port 10032)

with ESMTP id egXxhvF-Xfrm; Mon, 2 May 2022 22:14:10 +0200 (CEST)

Received: from localhost (localhost [127.0.0.1])

by posta.iurretalhi.eus (Postfix) with ESMTP id 74858289215;

Mon, 2 May 2022 21:56:53 +0200 (CEST)

X-Virus-Scanned: amavisd-new at iurretalhi.eus

Received: from posta.iurretalhi.eus ([127.0.0.1])

by localhost (posta.iurretalhi.eus [127.0.0.1]) (amavisd-new, port 10026)

with ESMTP id 6Iv_wHDkmpGs; Mon, 2 May 2022 21:56:53 +0200 (CEST)

Received: from [103.1.179.201] (unknown [103.1.179.201])

by posta.iurretalhi.eus (Postfix) with ESMTPSA id 812832881C6;

Mon, 2 May 2022 21:44:39 +0200 (CEST)

Content-Type: multipart/alternative; boundary="===============0562156884=="

MIME-Version: 1.0

Subject: Re:Validate

To: Recipients

From: "Admin"

Date: Tue, 03 May 2022 01:14:33 +0530

Message-Id: <20220502194439.812832881C6@posta.iurretalhi.eus>



You will not see this in a MIME-aware mail reader.

--===============0562156884==

Content-Type: text/plain; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body



Dear Zimbra mail users: =



Your account has exceeded the quota limit set by the Administrator, and y=

ou may not be able to send or receive new mail until you re-validate your a=

ccount =



=



=



=





To re-validate your account, please =



=



=



CLICK HERE TO VERIFY

=



click on the above link to verify =



Failure to verify, Your account will be permanently disable and deleted fr=

om our database. Respectfully yours, =A92022 Zimbra Customer Care=20

--===============0562156884==

Content-Type: text/html; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body




=3Diso-8859-1"/>

ial, helvetica, sans-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TR=

ANSFORM: none; FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORP=

HANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(255,255,2=

55); TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: n=

ormal; -webkit-text-stroke-width: 0px; text-decoration-thickness: initial; =

text-decoration-style: initial; text-decoration-color: initial">
=3D"FONT-SIZE: 12pt">Dear&=

nbsp;Zimbra mail users:

noreferrer noreferrer">
derline; FONT-FAMILY: verdana, sans-serif">
0)">



HITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 4=

00; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; LETTER-SP=

ACING: normal; BACKGROUND-COLOR: rgb(255,255,255); TEXT-INDENT: 0px; font-v=

ariant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-wi=

dth: 0px; text-decoration-thickness: initial; text-decoration-style: initia=

l; text-decoration-color: initial">
ILY: verdana, sans-serif; COLOR: rgb(255,0,0)">
ON: underline">



OLOR: rgb(0,0,0)">

Your=

account has exceeded the quota limit set by the Administrator, and you may=

not be able to send or receive new mail until you re-validate yo=

ur account 

IV>




OLOR: rgb(0,0,0)">



OLOR: rgb(0,0,0)">


hed; BORDER-RIGHT: rgb(187,187,187) 1px dashed; BORDER-COLLAPSE: collapse; =

BORDER-BOTTOM: rgb(187,187,187) 1px dashed; BORDER-LEFT: rgb(187,187,187) 1=

px dashed">








FAMILY: verdana, arial, helvetica, sans-serif; BORDER-RIGHT: rgb(240,240,24=

0) 1pt inset; WIDTH: 105.85pt; BACKGROUND: red; BORDER-BOTTOM: rgb(240,240,=

240) 1pt solid; PADDING-BOTTOM: 0cm; PADDING-TOP: 0cm; PADDING-LEFT: 5.4pt;=

BORDER-LEFT: rgb(240,240,240) 1pt solid; PADDING-RIGHT: 5.4pt" width=3D141>


GIN-RIGHT: 0px">
verdana, sans-serif">
 


FAMILY: verdana, arial, helvetica, sans-serif; BORDER-RIGHT: rgb(187,187,18=

7) 1pt solid; WIDTH: 35.4pt; BACKGROUND-IMAGE: none; BACKGROUND-REPEAT: rep=

eat; BORDER-BOTTOM: rgb(187,187,187) 1pt solid; BACKGROUND-POSITION: 0% 0%;=

PADDING-BOTTOM: 0cm; PADDING-TOP: 0cm; PADDING-LEFT: 5.4pt; BORDER-LEFT: r=

gb(187,187,187); PADDING-RIGHT: 5.4pt" width=3D47>


GIN-RIGHT: 0px">
serif">
 




OLOR: rgb(0,0,0)">

To r=

e-validate your account, please 






OLOR: rgb(0,0,0)">



,187,187) 1px dashed; BORDER-RIGHT: rgb(187,187,187) 1px dashed; WIDTH: 300=

px; BORDER-BOTTOM: rgb(187,187,187) 1px dashed; PADDING-BOTTOM: 0px; PADDIN=

G-TOP: 0px; PADDING-LEFT: 0px; BORDER-LEFT: rgb(187,187,187) 1px dashed; MA=

RGIN: 0px; PADDING-RIGHT: 0px; BACKGROUND-COLOR: rgb(8,75,138); border-radi=

us: 5px">





<=

/TBODY>

-FAMILY: verdana, arial, helvetica, sans-serif; BORDER-RIGHT: rgb(187,187,1=

87) 1px dashed; BORDER-BOTTOM: rgb(187,187,187) 1px dashed; PADDING-BOTTOM:=

0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; BORDER-LEFT: rgb(187,187,187) 1p=

x dashed; PADDING-RIGHT: 0px">
ACKGROUND: none transparent scroll repeat 0% 0%; OUTLINE-WIDTH: medium; PAD=

DING-BOTTOM: 0px; PADDING-TOP: 0px; OUTLINE-STYLE: none; PADDING-LEFT: 0px;=

MARGIN: 0px; PADDING-RIGHT: 0px" href=3D"http://energymin.gov.lk/mail1.php=

" rel=3D"nofollow%20noopener%20nofollow%20noopener%20noreferrer nofollow no=

opener noreferrer nofollow noopener noreferrer nofollow noopener noreferrer=

noreferrer noreferrer noreferrer noreferrer nofollow noopener noreferrer" =

target=3D_blank>
-FAMILY: verdana, sans-serif">CLICK HERE TO VE
5321923m_3054015556958039049m_-1391893868802809595m_8710498082380162426m_87=

59714186932824562goog_1244613476>

3054015556958039049m_-1391893868802809595m_8710498082380162426m_87597141869=

32824562goog_1244613477>
RIFY



OLOR: rgb(0,0,0)">





(0,0,0)'>click on the above link to verify<=

/SPAN>



(0,0,0)'>



(0,0,0)'>Failure to verify, Your accou=

nt will be permanently disable and deleted from our database.

DIV>


(0,0,0)'>Respectfully yours,



(0,0,0)'> 



(0,0,0)'>
s-serif; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT=

-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; LETTER-SPACING: normal=

; BACKGROUND-COLOR: rgb(255,255,255); TEXT-INDENT: 0px">
=A92022 Zimbra Cu=

stomer Care 


--===============0562156884==--



And we do not use Zimbra

Sexual Blackmail phishing

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sat, 30 Apr 2022 13:47:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkt2c-000Njo-6L

for dave@doctor.nl2k.ab.ca;

Sat, 30 Apr 2022 13:46:06 -0600

Resent-From: The Doctor

Resent-Date: Sat, 30 Apr 2022 13:46:06 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [142.247.106.233] (port=27322)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkqtS-000IgG-KS

for doctor@nl2k.ab.ca;

Sat, 30 Apr 2022 11:28:54 -0600

From:

To:

Subject: Payment from your account.

Date: 30 Apr 2022 22:00:11 +0200

Message-ID: <003001d85cd0$04f2208a$a932a882$@sentineldiversified.com>

MIME-Version: 1.0

Content-Type: text/plain;

charset="ibm852"

Content-Transfer-Encoding: 8bit

X-Mailer: Microsoft Outlook 15.0

Thread-Index: Ac413emn10wlp82s413emn10wlp82s==

Content-Language: en-us

X-Spam_score: 6.5

X-Spam_score_int: 65

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Greetings! I have to share bad news with you. Approximately

few months ago I have gained access to your devices, which you use for internet

browsing. After that, I have started tracking your internet activities.



Content analysis details: (6.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

0.5 PDS_BTC_ID FP reduced Bitcoin ID

2.1 BITCOIN_MALWARE BitCoin + malware bragging

1.4 DOS_OUTLOOK_TO_MX Delivered direct to MX with Outlook headers

0.2 MALWARE_NORDNS Malware bragging + no rDNS

1.0 BITCOIN_ONAN BitCoin + [censored]

Subject: {SPAM?} Payment from your account.



Greetings!



I have to share bad news with you.

Approximately few months ago I have gained access to your devices, which you use for internet browsing.

After that, I have started tracking your internet activities.



Here is the sequence of events:

Some time ago I have purchased access to email accounts from hackers (nowadays, it is quite simple to purchase such thing online).

Obviously, I have easily managed to log in to your email account (doctor@nl2k.ab.ca).



One week later, I have already installed Trojan virus to Operating Systems of all the devices that you use to access your email.

In fact, it was not really hard at all (since you were following the links from your inbox emails).

All ingenious is simple. (^^)



This software provides me with access to all the controllers of your devices (e.g., your microphone, video camera and keyboard).

I have downloaded all your information, data, photos, web browsing history to my servers.

I have access to all your messengers, social networks, emails, chat history and contacts list.

My virus continuously refreshes the signatures (it is driver-based), and hence remains invisible for antivirus software.



Likewise, I guess by now you understand why I have stayed undetected until this letter...



While gathering information about you, I have discovered that you are a big fan of adult websites.

You really love visiting porn websites and watching exciting videos, while enduring an enormous amount of pleasure.

Well, I have managed to record a number of your dirty scenes and montaged a few videos, which show the way you masturbate and reach orgasms.



If you have doubts, I can make a few clicks of my mouse and all your videos will be shared to your friends, colleagues and relatives.

I have also no issue at all to make them available for public access.

I guess, you really don't want that to happen, considering the specificity of the videos you like to watch, (you perfectly know what I mean) it will cause a true catastrophe for you.



Let's settle it this way:

You transfer $1550 USD to me (in bitcoin equivalent according to the exchange rate at the moment of funds transfer), and once the transfer is received, I will delete all this dirty stuff right away.

After that we will forget about each other. I also promise to deactivate and delete all the harmful software from your devices. Trust me, I keep my word.



This is a fair deal and the price is quite low, considering that I have been checking out your profile and traffic for some time by now.

In case, if you don't know how to purchase and transfer the bitcoins - you can use any modern search engine.



Here is my bitcoin wallet: 1HPaBSaYhPRJpfpL7rN36fSWmv8YR6pgzs



You have less than 48 hours from the moment you opened this email (precisely 2 days).



Things you need to avoid from doing:

*Do not reply me (I have created this email inside your inbox and generated the return address).

*Do not try to contact police and other security services. In addition, forget about telling this to you friends. If I discover that (as you can see, it is really not so hard, considering that I control all your systems) - your video will be shared to public right away.

*Don't try to find me - it is absolutely pointless. All the cryptocurrency transactions are anonymous.

*Don't try to reinstall the OS on your devices or throw them away. It is pointless as well, since all the videos have already been saved at remote servers.



Things you don't need to worry about:

*That I won't be able to receive your funds transfer.

- Don't worry, I will see it right away, once you complete the transfer, since I continuously track all your activities (my trojan virus has got a remote-control feature, something like TeamViewer).

*That I will share your videos anyway after you complete the funds transfer.

- Trust me, I have no point to continue creating troubles in your life. If I really wanted that, I would do it long time ago!



Everything will be done in a fair manner!



One more thing... Don't get caught in similar kind of situations anymore in future!

My advice - keep changing all your passwords on a frequent basis



Attempt to phish nk.ca accounts

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Fri, 29 Apr 2022 15:32:02 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkYD1-0008dh-W7

for dave@doctor.nl2k.ab.ca;

Fri, 29 Apr 2022 15:31:28 -0600

Resent-From: The Doctor

Resent-Date: Fri, 29 Apr 2022 15:31:27 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [87.246.7.50] (port=57158 helo=nk.ca)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkTNz-000CR1-CM

for sales@nk.ca;

Fri, 29 Apr 2022 10:22:31 -0600

From: Email Support

To: sales@nk.ca

Subject: WARNING : Activate sales@nk.ca

Date: 29 Apr 2022 09:21:59 -0700

Message-ID: <20220429092159.EB3D141BDE628B81@nk.ca>

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="----=_NextPart_000_0012_AC5A2FCF.ECEA7AC1"

X-Spam_score: 13.5

X-Spam_score_int: 135

X-Spam_bar: +++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Dear, sales Email ID: sales@nk.ca Please click the button

below to confirm your email address and activate your account to avoid loss

of your account.



Content analysis details: (13.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[87.246.7.50 listed in bb.barracudacentral.org]

0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=nk.ca;ip=87.246.7.50;r=doctor.nl2k.ab.ca]

0.9 SPF_FAIL SPF: sender does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=noreply%40nk.ca;ip=87.246.7.50;r=doctor.nl2k.ab.ca]

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME

0.7 MPART_ALT_DIFF BODY: HTML and text parts are different

2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level

above 50%

[cf: 100]

0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%

[cf: 100]

1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)

1.4 FSL_BULK_SIG Bulk signature with no Unsubscribe

3.0 URI_FIREBASEAPP Link to hosted firebase web application,

possible phishing

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

0.0 TO_EQ_FM_DOM_SPF_FAIL To domain == From domain and external SPF

failed

Subject: {SPAM?} WARNING : Activate sales@nk.ca





------=_NextPart_000_0012_AC5A2FCF.ECEA7AC1

Content-Type: text/plain;

charset="utf-8"

Content-Transfer-Encoding: quoted-printable



Dear, sales

------=_NextPart_000_0012_AC5A2FCF.ECEA7AC1

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable








hemas-microsoft-com:vml" xmlns=3D"http://www.w3.org/1999/xhtml">










ale=3D1">



=20=20=20=20=20=20=20=20


d>


margin:0;

padding:0;

width:100%; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%; /*@editable*/background-color:#ffffff;

/*@editable*/background-image:none;

/*@editable*/background-repeat:no-repeat;

/*@editable*/background-position:center;

/*@editable*/background-size:cover">


padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%">





padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%" align=3D"center">  
=3D"4">Email ID: sales@nk.ca


=3D"padding: 0px 20px; direction: ltr;">




padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%; margin: 0px; padding: 0px 20px 16px; text=

-align: center; line-height: 1.5; font-size: 18px; direction: ltr;" align=

=3D"center">Please click the button below to confirm your =

email address and activate your account to avoid loss of your account.
t>






padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%; margin: 0px; padding: 24px 0px 16px; text=

-align: center; line-height: 1.5; font-size: 18px; direction: ltr;" align=

=3D"center">


-webkit-text-size-adjust:100%; border-width: 1px 1px 2px; border-style: =

solid; border-color: rgb(2, 135, 190); padding: 10px 30px; border-radius: 4=

px; color: rgb(255, 255, 255); font-weight: 600; display: inline-block; min=

-width: 180px; background-color: rgb(3, 170, 220); text-decoration-line: no=

ne;" href=3D"https://mik0495.web.app/01mik04953984.html#iuser=3Dsales@nk.ca=

" target=3D"_blank" rel=3D"noopener noreferrer">

-> Confirm sales@nk.ca Now <-
 


10px 0;

padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%">


=






padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%; margin: 0px; padding: 0px 20px 16px; line=

-height: 1.5; font-size: 18px; direction: ltr;" align=3D"center"> 

=






padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%; margin: 0px; padding: 0px 20px 16px; line=

-height: 1.5; font-size: 18px; direction: ltr;" align=3D"center">
=3D"4">Helpful reminder: At any time, log into your account with your sales=

@nk.ca.


padding:0; mso-line-height-rule:exactly; -ms-text-size-adjust:100%;

-webkit-text-size-adjust:100%">






------=_NextPart_000_0012_AC5A2FCF.ECEA7AC1--

Sexual Blackmail phishing

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Fri, 29 Apr 2022 08:46:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkRsK-0007MA-4b

for dave@doctor.nl2k.ab.ca;

Fri, 29 Apr 2022 08:45:40 -0600

Resent-From: The Doctor

Resent-Date: Fri, 29 Apr 2022 08:45:40 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [223.104.204.29] (port=9957)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkRgY-0006Gd-DI

for doctor@nk.ca;

Fri, 29 Apr 2022 08:33:36 -0600

Message-ID: <08218A9DC2A336D5FC57401F7EEB0821@0VE1U34JT1>

From:

To:

Subject: Payment from your account.

Date: 30 Apr 2022 05:09:02 +0700

MIME-Version: 1.0

Content-Type: text/plain;

charset="ibm852"

Content-Transfer-Encoding: 8bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.2180

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180

X-Spam_score: 17.1

X-Spam_score_int: 171

X-Spam_bar: +++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Greetings! I have to share bad news with you. Approximately

few months ago I have gained access to your devices, which you use for internet

browsing. After that, I have started tracking your internet activities.



Content analysis details: (17.1 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.0 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date

3.5 HDR_ORDER_FTSDMCXX_NORDNS Header order similar to spam

(FTSDMCXX/boundary variant) + no rDNS

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

2.5 BITCOIN_XPRIO Bitcoin + priority

0.6 PDS_BTC_MSGID Bitcoin ID with T_MSGID_NOFQDN2

0.3 HDR_ORDER_FTSDMCXX_DIRECT Header order similar to spam

(FTSDMCXX/boundary variant) + direct-to-MX

0.5 PDS_BTC_ID FP reduced Bitcoin ID

2.0 MIMEOLE_DIRECT_TO_MX MIMEOLE + direct-to-MX

2.1 BITCOIN_MALWARE BitCoin + malware bragging

3.1 DOS_OE_TO_MX Delivered direct to MX with OE headers

0.2 MALWARE_NORDNS Malware bragging + no rDNS

1.0 BITCOIN_ONAN BitCoin + [censored]

Subject: {SPAM?} Payment from your account.



Greetings!



I have to share bad news with you.

Approximately few months ago I have gained access to your devices, which you use for internet browsing.

After that, I have started tracking your internet activities.



Here is the sequence of events:

Some time ago I have purchased access to email accounts from hackers (nowadays, it is quite simple to purchase such thing online).

Obviously, I have easily managed to log in to your email account (doctor@nk.ca).



One week later, I have already installed Trojan virus to Operating Systems of all the devices that you use to access your email.

In fact, it was not really hard at all (since you were following the links from your inbox emails).

All ingenious is simple. (^^)



This software provides me with access to all the controllers of your devices (e.g., your microphone, video camera and keyboard).

I have downloaded all your information, data, photos, web browsing history to my servers.

I have access to all your messengers, social networks, emails, chat history and contacts list.

My virus continuously refreshes the signatures (it is driver-based), and hence remains invisible for antivirus software.



Likewise, I guess by now you understand why I have stayed undetected until this letter...



While gathering information about you, I have discovered that you are a big fan of adult websites.

You really love visiting porn websites and watching exciting videos, while enduring an enormous amount of pleasure.

Well, I have managed to record a number of your dirty scenes and montaged a few videos, which show the way you masturbate and reach orgasms.



If you have doubts, I can make a few clicks of my mouse and all your videos will be shared to your friends, colleagues and relatives.

I have also no issue at all to make them available for public access.

I guess, you really don't want that to happen, considering the specificity of the videos you like to watch, (you perfectly know what I mean) it will cause a true catastrophe for you.



Let's settle it this way:

You transfer $1550 USD to me (in bitcoin equivalent according to the exchange rate at the moment of funds transfer), and once the transfer is received, I will delete all this dirty stuff right away.

After that we will forget about each other. I also promise to deactivate and delete all the harmful software from your devices. Trust me, I keep my word.



This is a fair deal and the price is quite low, considering that I have been checking out your profile and traffic for some time by now.

In case, if you don't know how to purchase and transfer the bitcoins - you can use any modern search engine.



Here is my bitcoin wallet: 1HPaBSaYhPRJpfpL7rN36fSWmv8YR6pgzs



You have less than 48 hours from the moment you opened this email (precisely 2 days).



Things you need to avoid from doing:

*Do not reply me (I have created this email inside your inbox and generated the return address).

*Do not try to contact police and other security services. In addition, forget about telling this to you friends. If I discover that (as you can see, it is really not so hard, considering that I control all your systems) - your video will be shared to public right away.

*Don't try to find me - it is absolutely pointless. All the cryptocurrency transactions are anonymous.

*Don't try to reinstall the OS on your devices or throw them away. It is pointless as well, since all the videos have already been saved at remote servers.



Things you don't need to worry about:

*That I won't be able to receive your funds transfer.

- Don't worry, I will see it right away, once you complete the transfer, since I continuously track all your activities (my trojan virus has got a remote-control feature, something like TeamViewer).

*That I will share your videos anyway after you complete the funds transfer.

- Trust me, I have no point to continue creating troubles in your life. If I really wanted that, I would do it long time ago!



Everything will be done in a fair manner!



One more thing... Don't get caught in similar kind of situations anymore in future!

My advice - keep changing all your passwords on a frequent basis



Blackmail phishing

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Fri, 29 Apr 2022 07:30:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkQgE-000EHs-5v

for dave@doctor.nl2k.ab.ca;

Fri, 29 Apr 2022 07:29:06 -0600

Resent-From: The Doctor

Resent-Date: Fri, 29 Apr 2022 07:29:06 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [160.154.162.97] (port=48207)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkPvy-000OJs-BT

for doctor@nl2k.ab.ca;

Fri, 29 Apr 2022 06:41:23 -0600

Message-ID: <626BDCD2.9070105@nl2k.ab.ca>

Date: Fri, 29 Apr 2022 11:40:50 -0100

From:

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.23) Gecko/20110922 Thunderbird/3.1.15

MIME-Version: 1.0

To:

Subject: =?UTF-8?B?RG8gWW91IERvIEFueSBvZiBUaGVzZSBFbWJhcnJhc3NpbmcgVGhpbmdzPw==?=

Content-Type: multipart/alternative;

boundary="------------030504020800080807010903"

X-Spam_score: 11.8

X-Spam_score_int: 118

X-Spam_bar: +++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: I am sorry to inform you but your device was hacked. That's

what happened. I have used a Zero Click vulnerability with a special code

to hack your device through a website. A complicated software that requires

precise skills that I posess. This exploit [...]



Content analysis details: (11.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.5 STOX_BOUND_090909_B No description available.

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[160.154.162.97 listed in bb.barracudacentral.org]

1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,

https://senderscore.org/blocklistlookup/

[160.154.162.97 listed in bl.score.senderscore.com]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

0.9 SPF_FAIL SPF: sender does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=doctor%40nl2k.ab.ca;ip=160.154.162.97;r=doctor.nl2k.ab.ca]

0.0 HTML_MESSAGE BODY: HTML included in message

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

0.5 PDS_BTC_ID FP reduced Bitcoin ID

2.5 BITCOIN_SPAM_02 BitCoin spam pattern 02

Subject: {SPAM?} =?UTF-8?B?RG8gWW91IERvIEFueSBvZiBUaGVzZSBFbWJhcnJhc3NpbmcgVGhpbmdzPw==?=



This is a multi-part message in MIME format.

--------------030504020800080807010903

Content-Type: text/plain; charset=ISO-8859-1; format=flowed

Content-Transfer-Encoding: quoted-printable



I am sorry to inform you but your device was hacked.



That's what happened. I have used a Zero Click vulnerability with a =

special code to hack your device through a website.

A complicated software that requires precise skills that I posess.

This exploit works in a chain with a specially crafted unique code and =

such type of an attack goes undetected.

You only had to visit a website to be infected, and unfortunately for =

you it's that simple for me.



You were not targeted, but just became one of the many unlucky people =

who got hacked through that webpage.

All of this happened in August. So I’ve had enough time to collect =

the information.



I think you already know what is going to happen next.

For a couple of month my software was quietly collecting information =

about your habits, websites you visit, websearches, texts you send.

There is more to it, but I have listed just a few reasons for you to =

understand how serious this is.



To be clear, my software controlled your camera and microphone as well.

It was just about right timing to get you privacy violated. I have made =

a few pornhub worthy videos with you as a lead actor.



I’ve been waiting enough and have decided that it’s time to =

put an end to this.

Here is my offer. Let’s name this a “consulting fee” I =

need to get, so I can delete the media content I have been collecting.

Your privacy stays untouched, if I get the payment.

Otherwise, I will leak the most damaging content to your contacts and =

post it to a public website for perverts to view.



You and I understand how damaging this will be to you, it's not that =

much money to keep your privacy.



I don’t care about you personally, that's why you can be sure that =

all files I have and software on your device will be deleted immediately =

after I receive the transfer.

I only care about getting paid.



My modest consulting fee is 1700 US Dollars to be transferred in =

Bitcoin. Exchange rate at the time of the transfer.

You need to send that amount to this wallet: =

1JwLUkacG322ARR8cSYGLQxnXh3EXZvXDF



The fee is non negotiable, to be transferred within 2 business days.



Obviously do not try to ask for help from the law enforcement unless you =

want your privacy to be violated.

I will monitor your every move until I get paid. If you keep your end of =

the agreement, you wont hear from me ever again.



Take care and have a good day.



--------------030504020800080807010903

Content-Type: text/html; charset="ISO-8859-1"

Content-Transfer-Encoding: quoted-printable












charset=3DISO-8859-1">





I am sorry to inform you but your device was hacked.



That's what happened. I have used a Zero Click vulnerability with a =

special code to hack your device through a website.


A complicated software that requires precise skills that I posess.


This exploit works in a chain with a specially crafted unique code and =

such type of an attack goes undetected.


You only had to visit a website to be infected, and unfortunately for =

you it's that simple for me.



You were not targeted, but just became one of the many unlucky people =

who got hacked through that webpage.


All of this happened in August. So I’ve had enough time to collect =

the information.



I think you already know what is going to happen next.


For a couple of month my software was quietly collecting information =

about your habits, websites you visit, websearches, texts you send.


There is more to it, but I have listed just a few reasons for you to =

understand how serious this is.



To be clear, my software controlled your camera and microphone as =

well.


It was just about right timing to get you privacy violated. I have made =

a few pornhub worthy videos with you as a lead actor.



I’ve been waiting enough and have decided that it’s time to =

put an end to this.


Here is my offer. Let’s name this a “consulting fee” I =

need to get, so I can delete the media content I have been =

collecting.


Your privacy stays untouched, if I get the payment.


Otherwise, I will leak the most damaging content to your contacts and =

post it to a public website for perverts to view.



You and I understand how damaging this will be to you, it's not that =

much money to keep your privacy.



I don’t care about you personally, that's why you can be sure that =

all files I have and software on your device will be deleted immediately =

after I receive the transfer.


I only care about getting paid.



My modest consulting fee is 1700 US Dollars to be transferred in =

Bitcoin. Exchange rate at the time of the transfer.


You need to send that amount to this wallet: =

1JwLUkacG322ARR8cSYGLQxnXh3EXZvXDF



The fee is non negotiable, to be transferred within 2 business =

days.



Obviously do not try to ask for help from the law enforcement unless you =

want your privacy to be violated.


I will monitor your every move until I get paid. If you keep your end of =

the agreement, you wont hear from me ever again.



Take care and have a good day.








--------------030504020800080807010903--





DHL Phish from Amazon

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 28 Apr 2022 14:13:01 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nkAUa-0003Gs-KG

for dave@doctor.nl2k.ab.ca;

Thu, 28 Apr 2022 14:12:00 -0600

Resent-From: The Doctor

Resent-Date: Thu, 28 Apr 2022 14:12:00 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from ec2-35-72-201-243.ap-northeast-1.compute.amazonaws.com ([35.72.201.243]:51130 helo=multiweb.sdpi)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1nk6O1-0007OG-LJ

for doctor@nl2k.ab.ca;

Thu, 28 Apr 2022 09:49:07 -0600

Received: by multiweb.sdpi (Postfix, from userid 48)

id BB7BBF8D247; Fri, 29 Apr 2022 00:48:15 +0900 (JST)

To: doctor@nl2k.ab.ca

Subject: Thanks for using DHLExpress

X-PHP-Originating-Script: 48:sddksjshdkjhdkshkdshdksdhj.php

Date: Fri, 29 Apr 2022 00:48:15 +0900

From: DHLExpress Post

Message-ID:

X-Mailer: ??1?1.3.3.7??

MIME-Version: 1.0

Content-Type: text/html; charset=UTF-8

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 9.2

X-Spam_score_int: 92

X-Spam_bar: +++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hello,doctor@nl2k.ab.ca : Your package N [54246452-AV] is

waiting for delivery. Please confirm the payment (1,65 CAD) on the link below,

the online verification needs to be done in the next 14 days before it expires.​





Content analysis details: (9.2 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.3 FROM_LOCAL_HEX From: localpart has long hexadecimal sequence

0.0 FROM_LOCAL_DIGITS From: localpart has long digit sequence

1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,

https://senderscore.org/blocklistlookup/

[35.72.201.243 listed in bl.score.senderscore.com]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

2.0 PDS_OTHER_BAD_TLD Untrustworthy TLDs

[URI: ceshi.banhui.xyz (xyz)]

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or

identical to background

0.0 HTML_MESSAGE BODY: HTML included in message

0.0 URI_TRY_3LD URI: "Try it" URI, suspicious hostname

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

2.5 LONGLN_LOW_CONTRAST Excessively long line + hidden text

0.0 PDS_RDNS_DYNAMIC_FP RDNS_DYNAMIC with FP steps

0.3 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS

0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was

blocked. See

http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block

for more information.

[URIs: banhui.xyz]

Subject: {SPAM?} Thanks for using DHLExpress







=09






://myaccount.dhl.com/MyAccount/images/DHLlogo.gif" style=3D"margin: 0px; pa=

dding: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-w=

eight: inherit; font-stretch: inherit; font-size: inherit; line-height: 1.4=

em; font-family: inherit; vertical-align: middle; color: inherit; box-sizin=

g: border-box; max-width: 10000px; width: 139px; height: 31px;" width=3D"13=

9" />





=






sizing: border-box; margin: 0px 0px 14px; padding: 0px; border: 0px; font-v=

ariant-numeric: inherit; font-variant-east-asian: inherit; font-stretch: in=

herit; font-size: 14px; line-height: 1.4em; font-family: helvetica, arial, =

verdana, sans-serif; color: rgb(85, 85, 85); white-space: pre-line;">=C2=

=A0






argin: 0px 0px 14px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">
padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; fon=

t-weight: inherit; font-stretch: inherit; line-height: inherit; font-family=

: inherit; vertical-align: baseline; color: inherit;">
=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; font-varia=

nt: inherit; font-weight: inherit; font-stretch: inherit; font-size: inheri=

t; line-height: 1.4em; font-family: inherit; vertical-align: baseline; colo=

r: inherit; box-sizing: border-box;">Hello

e=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; font-vari=

ant: inherit; font-weight: inheri

t; font-stretch: inherit; font-size: 16px; line-height: inherit; vertical-=

align: baseline;">,

style=3D"color:#0099ff;">doctor@nl2k.ab.ca
:
p>




argin: 0px 0px 14px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">
padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; fon=

t-weight: inherit; font-stretch: inherit; font-size: 16px; line-height: 1.4=

em; font-family: inherit; vertical-align: baseline; color: inherit; box-siz=

ing: border-box;">Your package=C2=A0
x; border: 0px; font-style: inherit; font-variant: inherit; font-weight: in=

herit; font-stretch: inherit; font-size: 14px; line-height: inherit; font-f=

amily: inherit; vertical-align: baseline; color: inherit;">
argin: 0px; padding: 0px; border: 0px; font-style: inherit; font-variant: i=

nherit; font-weight: 700; font-

stretch: inherit; font-size: inherit; line-height: 1.4em; font-family: inh=

erit; vertical-align: baseline; color: inherit; box-sizing: border-box;">N =

[54246452-AV]
=C2=A0
is waiting for delivery.






argin: 0px 0px 14px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">
padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; fon=

t-weight: inherit; font-stretch: inherit; font-size: 16px; line-height: 1.4=

em; font-family: inherit; vertical-align: baseline; color: inherit; box-siz=

ing: border-box;">
a, Trebuchet MS" style=3D"box-sizing: border-box; line-height: 1.4em;">Plea=

se confirm the payment=C2=A0

ng: 0px; border: 0px; font: inherit; vertical-align: baseline; color: rgb(0=

, 0, 0);">
: inherit; font-variant: inherit; fon

t-weight: inherit; font-stretch: inherit; font-size: 16px; line-height: 1.=

4em; font-family: inherit; vertical-align: baseline; color: inherit; box-si=

zing: border-box;">
ont-style: inherit; font-variant: inherit; font-weight: inherit; font-stret=

ch: inherit; font-size: 14px; line-height: inherit; font-family: inherit; v=

ertical-align: baseline; color: inherit;">
ng: 0px; border: 0px; font-style: inherit; font-variant: inherit; font-weig=

ht: 700; font-stretch: inherit; font-size: inherit; line-height: 1.4em; fon=

t-family: inherit; vertical-align: baseline; color: inherit; box-sizing: bo=

rder-box;">
e: inherit; font-variant: inherit; font-weight: inherit; font-stretch: inhe=

rit; font-size: inherit; line-height: 1.4em; font-family: pp-sans-small-reg=

ular, tahoma, arial, sans-serif; vertical-align: baseline; color: inherit; =

box-sizing: border-box;">
MS" style=3D"box-sizing: border-box; line-height: 1.4em;" t=3D"">(

span>

border: 0px; font-style: inherit; font-variant: inherit; font-weight: inher=

it; font-stretch: inherit; font-size: 16px; line-height: 1.4em; font-family=

: inherit; vertical-align: baseline; color: inherit; box-sizing: border-box=

;">
it; font-variant: inherit; font-weight: inherit; font-stretch: inherit; fon=

t-size: 14px; line-height: inherit; font-family: inherit; vertical-align: b=

aseline; color: inherit;">
0px; font-style: inherit; font-variant: inherit; font-weight: 700; font-st=

retch: inherit; font-size: inherit; line-height: 1.4em; font-family: inheri=

t; vertical-align: baseline; color: inherit; box-sizing: border-box;">
style=3D"margin: 0px; padding: 0px; border: 0px; font-style: inheri

t; font-variant: inherit; font-weight: inherit; font-stretch: inherit; fon=

t-size: inherit; line-height: 1.4em; font-family: pp-sans-small-regular, ta=

homa, arial, sans-serif; vertical-align: baseline; color: rgb(255, 0, 0); b=

ox-sizing: border-box;">
MS" style=3D"box-sizing: border-box; line-height: 1.4em;">1,65

an>

px; font: inherit; vertical-align: baseline; color: rgb(255, 0, 0);">
g>CAD

font: inherit; vertical-align: baseline; color: rgb(0, 0, 0);">
=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; font-varia=

nt: inherit; font-weight: inherit; font-stretch: inherit; font-size: 16px; =

line-height: 1.4em; font-family: inherit; vertical-align: baseline; color: =

inherit; box-sizing: border-box;">
border: 0px; font-style: inherit;=20

font-variant: inherit; font-weight: inherit; font-stretch: inherit; font-s=

ize: 14px; line-height: inherit; font-family: inherit; vertical-align: base=

line; color: inherit;">
x; font-style: inherit; font-variant: inherit; font-weight: 700; font-stret=

ch: inherit; font-size: inherit; line-height: 1.4em; font-family: inherit; =

vertical-align: baseline; color: inherit; box-sizing: border-box;">
yle=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; font-va=

riant: inherit; font-weight: inherit; font-stretch: inherit; font-size: inh=

erit; line-height: 1.4em; font-family: pp-sans-small-regular, tahoma, arial=

, sans-serif; vertical-align: baseline; color: inherit; box-sizing: border-=

box;">
sizing: border-box; line-height: 1.4em;">)

n>

inherit; font-variant: inherit;=20

font-weight: inherit; font-stretch: inherit; font-size: 16px; line-height:=

1.4em; font-family: inherit; vertical-align: baseline; color: inherit; box=

-sizing: border-box;">
rdana, Trebuchet MS" style=3D"box-sizing: border-box; line-height: 1.4em;">=


font-variant: inherit; font-weight: inherit; font-stretch: inherit; font-s=

ize: 14px; line-height: inherit; font-family: inherit; vertical-align: base=

line; color: inherit;">=C2=A0
on the link below, the online verificat=

ion needs to be done in the next 14 days before it expires.

pan style=3D"margin: 0px; padding: 0px; border: 0px; font: inherit; vertica=

l-align: baseline; color: rgb(255, 255, 255);">
padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; font=

-weight: inherit; font-stretch: inherit; font-size: 16px; line-height: 1.4e=

m; font-family: inherit; vertical-a

lign: baseline; color: inherit; box-sizing: border-box;">
s-serif, Arial, Verdana, Trebuchet MS" style=3D"box-sizing: border-box; lin=

e-height: 1.4em;">=C3=83=C2=A2=C3=A2=C2=82=C2=AC=C3=A2=C2=80=C2=B9

span>






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

white-space: pre-line;">
px; font: inherit; vertical-align: baseline; box-sizing: border-box;">
style=3D"margin: 0px; padding: 0px; border: 0px; font: inherit; vertical-a=

lign: baseline; box-sizing: border-box;">
g: 0px; border: 0px; font: inherit; vertical-align: baseline; box-sizing: b=

order-box;">
le: inherit; font-variant: inherit; font-weight: inherit; font-stretch: inh=

erit; font-size: inherit; line-height: 1.4em; font-family: inherit; vertica=

l-align: baseline;">
81-ox-0370fe9322-ox-bbd0d572aa-ox-c416e70324-ox-b97095d9d4-ox-304783676f-ox=

-1931899fb6-ox-a8004d52d5-ox-b5d9b6bf37-ox-9fed4e61fa-yiv9636722328button" =

data-auth=3D"NotApplicable" data-linkindex=3D"0" href=3D"http://ceshi.banhu=

i.xyz/SR8352099932" rel=3D"noopener noreferrer" style=3D"margin: 0px; paddi=

ng: 0px; border-width: 10px 20px 8px; border-style: solid; border-color: rg=

b(0, 85, 153); border-image: initial; font-style: inherit; font-variant: in=

herit; font-weight: inherit; font-stretch: inherit; font-size: 13px; line-h=

eight: 1.4em; font-family: inherit; vertical-align: baseline; box-sizing: b=

order-box; background: rgb(0, 85, 153); text-decoration: revert; outline: 0=

px;" target=3D"_blank">
x; font-style: inherit; font-variant: inherit; font-weight: inherit; font-s=

tretch: inherit; font-size: inherit; line-height: 1.4em; font-family: inher=

it; vertical-align: baseline; box-sizing: border-box; color: rgb(255, 255, =

255);">Deliver your package






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">
padding: 0px; border: 0px; font: inherit; vertical-align: baseline; color:=

rgb(255, 0, 0); box-sizing: border-box;">AN SMS VERIFICATION WILL BE REQUE=

STED. IN ORDER TO ENSURE YOUR IDENTITY.






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">
padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; fon=

t-weight: inherit; font-stretch: inherit; font-size: 12px; line-height: inh=

erit; vertical-align: baseline; color: rgb(105, 105, 105);">2022 @=C2=A0
pan>
der: 0px; font-style: inherit; font-variant: inherit; font-weight: inherit;=

font-stretch: inherit; font-size: 12px; line-height: inherit; font-family:=

inherit; vertical-align: baseline; color: inherit;">DHL

=3D"margin: 0px; padding: 0px; border: 0px; font-style: inherit; font-varia=

nt: inherit; font-weight: inherit;

font-stretch: inherit; font-size: 12px; line-height: inherit; vertical-al=

ign: baseline; color: rgb(105, 105, 105);"> International GmbH. All rights =

reserved.






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






argin: 0px 0px 15px; padding: 0px; border: 0px; font-variant-numeric: inher=

it; font-variant-east-asian: inherit; font-stretch: inherit; font-size: 14p=

x; line-height: 1.4em; font-family: helvetica, arial, verdana, sans-serif; =

color: rgb(85, 85, 85); white-space: pre-line;">=C2=A0






ily: Arial, sans-serif; line-height: 1.3; color: rgb(51, 51, 51); padding: =

0px; border: 0px; font-variant-numeric: inherit; font-variant-east-asian: i=

nherit; font-stretch: inherit; background-color: rgb(255, 255, 255);">
style=3D"color:#FFFFFF;">Rehabilitation wor=

k planned for Dartford Bridge






0px; font-variant-numeric: inherit; font-variant-east-asian: inherit; font=

-stretch: inherit; font-size: 15px; line-height: inherit; font-family: Aria=

l, sans-serif; color: rgb(51, 51, 51); background-color: rgb(255, 255, 255)=

;">=C2=A0






0px; padding: 0px; border: 0px; font-variant-numeric: inherit; font-variant=

-east-asian: inherit; font-stretch: inherit; font-size: 15px; line-height: =

inherit; font-family: Arial, sans-serif; min-width: 100%; color: rgb(51, 51=

, 51); background-color: rgb(255, 255, 255);">


padding: 0px; border: 0px; font: inherit; min-width: 100%;">


x; margin: 0px; padding: 0px; border: 0px; font: inherit; min-width: 100%;"=

>


der-box; margin: 0px; padding: 0px; border: 0px; font: inherit; min-width: =

100%;">


order-box; margin: 0px; padding: 0px; border: 0px; font: inherit; min-width=

: 100%;">


g: 0px; border: 0px; font: inherit; min-width: 100%;">


padding: 0px; border: 0px; font: inherit; min-width: 100%;">


style=3D"box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; f=

ont: inherit; min-width: 100%;">


x; border: 0px; font: inherit;">
=3D"color:#FFFFFF;">Northumberland County has retained the services of Will=

is Kerr Contracting Ltd. to complete the rehabilitation of the Dartford Bri=

dge located on County Road 24,=C2=A0

ox; background: 0px 0px transparent; color: rgb(0, 102, 164); text-decorati=

on: revert; margin: 0px; padding: 0px; border: 0px; font: inherit; display:=

inline-flex;" target=3D"_blank" title=3D"Open new window to view location =

in Google Maps">1.7km West of County Rd. 25 =

in the Village of Dartford
. HP En=

gineering Inc. has developed design details for the rehabilitation and will=

be assisting the County with on-site inspection of the work as it progress=

es.






x; border: 0px; font: inherit;">
=3D"font-size:8px;">This construction work will consist of rehabilitation w=

ork on the south side of the bridge. The work will=C2=A0involve an east-bou=

nd lane closure, using temporary traffic signals to control the flow of tra=

ffic through the work areas. A single lane for through traffic will be in p=

lace for the duration of the work.






x; border: 0px; font: inherit;">
=3D"font-size:8px;">The anticipated start date is May 2, 2022 and work is e=

xpected to be completed in early August 2022.






x; border: 0px; font: inherit;">
=3D"font-size:8px;">If you have any questions relating to the project or te=

mporary lane closure, please contact the following:






x; border: 0px; font: inherit;">
=3D"font-size:8px;">
rit; font-variant: inherit; font-weight: inherit; font-stretch: inherit; li=

ne-height: inherit; font-family: inherit; margin: 0px; padding: 0px; border=

: 0px;">Brandon Brooker



Site Supervisor, Willis Kerr


1077 County Rd. 1


Mountain, ON. K0E 1S0


T:=C2=A0
px; padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; =

font-weight: inherit; font-stretch: inherit; line-height: inherit; font-fam=

ily: inherit;">613-258-0223



Cell:=C2=A0
: 0px; padding: 0px; border: 0px; font-style: inherit; font-variant: inheri=

t; font-weight: inherit; font-stretch: inherit; line-height: inherit; font-=

family: inherit;">613-802-9920


/>

F:=C2=A0
px; padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; =

font-weight: inherit; font-stretch: inherit; line-height: inherit; font-fam=

ily: inherit;">613-258-0229


rder-box;" />

=C2=A0






x; border: 0px; font: inherit;">
=3D"font-size:8px;">
rit; font-variant: inherit; font-weight: inherit; font-stretch: inherit; li=

ne-height: inherit; font-family: inherit; margin: 0px; padding: 0px; border=

: 0px;">Tashi Dwivedi, P.Eng.


>

Principal, HP Engineering Inc.


Suite 400, 2039 Robertson Road


Ottawa, Ontario K2H 8R2


T:=C2=A0
px; padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; =

font-weight: inherit; font-stretch: inherit; line-height: inherit; font-fam=

ily: inherit;">613-695-3737



Cell:=C2=A0
: 0px; padding: 0px; border: 0px; font-style: inherit; font-variant: inheri=

t; font-weight: inherit; font-stretch: inherit; line-height: inherit; font-=

family: inherit;">613-222-8520


/>

F:=C2=A0
px; padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; =

font-weight: inherit; font-stretch: inherit; line-height: inherit; font-fam=

ily: inherit;">613-680-3636


rder-box;" />

=C2=A0






x; border: 0px; font: inherit;">
=3D"color:#FFFFFF;">
rit; font-variant: inherit; font-weight: inherit; font-stretch: inherit; li=

ne-height: inherit; font-family: inherit; margin: 0px; padding: 0px; border=

: 0px;">Brunilda Tena, P.Eng.


>

Project Engineer, Engineering


Northumberland County


555 Courthouse Road


Cobourg, Ontario K9A 5J6


T:=C2=A0
px; padding: 0px; border: 0px; font-style: inherit; font-variant: inherit; =

font-weight: inherit; font-stretch: inherit; line-height: inherit; font-fam=

ily: inherit;">905-372-3329 ext. 2355


-box;" />

Toll Free:=C2=A0
argin: 0px; padding: 0px; border: 0px; font-style: inherit; font-variant: i=

nherit; font-weight: inherit; font-stretch: inherit; line-height: inherit; =

font-family: inherit;">1-800-354-7050 ext. 2355


ox-sizing: border-box;" />


rgb(0, 102, 164); text-decoration: revert; margin: 0px; padding: 0px; bord=

er: 0px; font: inherit; display: inline-flex;" target=3D"_blank" title=3D"O=

pen new window to send an email to Brunilda Tena">
FFF;">Email



















Phishing attempt to get Netknow user passwords

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 27 Apr 2022 06:53:05 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1njh9x-0006o4-FD

for dave@doctor.nl2k.ab.ca;

Wed, 27 Apr 2022 06:52:45 -0600

Resent-From: The Doctor

Resent-Date: Wed, 27 Apr 2022 06:52:45 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [131.108.88.225] (port=32160 helo=cloudmark.com)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1njbxZ-0000dT-On

for webmaster@nk.ca;

Wed, 27 Apr 2022 01:19:44 -0600

Reply-To: n0-reply@nk.ca

From: "nk.ca~Support"

To: webmaster@nk.ca

Subject: Your Storage Quota! has been Exceeded; Upgrade & Retreive your (76=?UTF-8?B?KSBOZXcgUGVuZGluZyBNZXNzYWdlcyDinIkgISEhIE9uIEhvbGQg?=4/27/2022 4:19:21 a.m.

Date: 27 Apr 2022 04:19:21 -0300

Message-ID: <20220427041921.8B9BC4520E21F66D@cloudmark.com>

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 16.7

X-Spam_score_int: 167

X-Spam_bar: ++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: This sender has been verified from webmaster@nk.ca safe senders

list. Mailbox quota notification for webmaster@nk.ca Email Storage almost

Full 19.84G / 20.00G



Content analysis details: (16.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[131.108.88.225 listed in bb.barracudacentral.org]

1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,

https://senderscore.org/blocklistlookup/

[131.108.88.225 listed in bl.score.senderscore.com]

1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,

https://senderscore.org/blacklistlookup/

1.5 NIX_SPAM RBL: Listed in NIX_SPAM DNSBL (thanks to heise.de)

[131.108.88.225 listed in ix.dnsbl.manitu.net]

0.9 SPF_FAIL SPF: sender does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=noreply%40cloudmark.com;ip=131.108.88.225;r=doctor.nl2k.ab.ca]

0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=cloudmark.com;ip=131.108.88.225;r=doctor.nl2k.ab.ca]

0.5 URI_NOVOWEL URI: URI hostname has long non-vowel sequence

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

1.0 FROM_MISSP_SPF_FAIL No description available.

2.0 PDS_DBL_URL_TNB_RUNON Double-url and To no arrows, from runon

3.1 GOOG_REDIR_NORDNS Google redirect to obscure spamvertised

website + no rDNS

0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable

0.7 TO_NO_BRKTS_FROM_MSSP Multiple formatting errors

0.0 FROM_MISSP_REPLYTO From misspaced, has Reply-To

0.0 TO_NO_BRKTS_NORDNS_HTML To: misformatted and no rDNS and HTML

only

0.3 FROM_MISSP_EH_MATCH From misspaced, matches envelope

Subject: {SPAM?} Your Storage Quota! has been Exceeded; Upgrade & Retreive your (76=?UTF-8?B?KSBOZXcgUGVuZGluZyBNZXNzYWdlcyDinIkgISEhIE9uIEhvbGQg?=4/27/2022 4:19:21 a.m.




















x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">


g: normal; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font=

-style: normal; font-weight: 400; word-spacing: 0px; white-space: normal; b=

order-collapse: collapse; orphans: 2; widows: 2; font-stretch: inherit; bac=

kground-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-var=

iant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: i=

nitial; text-decoration-color: initial;=20

text-decoration-thickness: initial;">








>

th: 2px; box-sizing: border-box; background-color: rgb(2, 151, 64);"> =


ge: none; width: 700px; font-family: Roboto, RobotoDraft, Helvetica, Arial,=

sans-serif; box-sizing: border-box; background-color: rgb(243, 255, 248);"=

>
box;">This sender has been verified from

 webmaster@nk.ca
 safe senders list.

Mailbox quota notification for <=

a class=3D"mailto-link" href=3D"mailto:webmaster@nk.ca" target=3D"_blank">w=

ebmaster@nk.ca



x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">





x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">



Email Storage almost Full 



e: 15px;">






  • 53); float: left; list-style-type: none;">



  • 53); float: left; list-style-type: none;">


    rder-radius: 3px; border: 1px solid rgb(221, 221, 221); border-image: none;=

    width: 100px; height: 12px; overflow: hidden; vertical-align: bottom; disp=

    lay: inline-block;">


    h: 86px; height: 12px; text-align: center; color: rgb(255, 255, 255); line-=

    height: 1; overflow: hidden;">
     
    8, 175, 30);">19.84G / 20.00G





e: 15px;">



e: 15px;">




letter-spacing: normal; font-family: Arial, sans-serif; font-size: small; f=

ont-style: normal; font-weight: 400; word-spacing: 0px; white-space: normal=

; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant=

-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0=

px; text-decoration-style: initial; text-decoration-color: initial; text-de=

coration-thickness: initial;">

Your email storage has exceeded its limits and needs to be increased immedi=

ately



letter-spacing: normal; font-family: Arial, sans-serif; font-size: small; f=

ont-style: normal; font-weight: 400; word-spacing: 0px; white-space: normal=

; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant=

-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0=

px; text-decoration-style: initial; text-decoration-color: initial; text-de=

coration-thickness: initial;">

click below to add more space on time to avoid missing new emails


div>


x; letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-=

size: small; font-style: normal; font-weight: 400; word-spacing: 0px; white=

-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255)=

; font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-s=

troke-width: 0px; text-decoration-style: initial; text-decoration-color: in=

itial; text-decoration-thickness: initial;">









order=3D"0" cellspacing=3D"0" cellpadding=3D"0">






body>

line-height: 22px; font-family: Roboto, RobotoDraft, Helvetica, Arial, san=

s-serif;">


ial, helvetica, sans-serif; vertical-align: baseline; font-stretch: inherit=

;">


herit; vertical-align: baseline; font-stretch: inherit;">


nherit; vertical-align: baseline; font-stretch: inherit;">=


">Don't risk losing new incoming messages
 
 <=

br>



-transform: none; line-height: inherit; letter-spacing: normal; font-family=

: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, Bl=

inkMacSystemFont, Roboto, "Helvetica Neue", sans-serif; font-size: 15px; fo=

nt-style: normal; font-weight: 400; word-spacing: 0px; border-top-color: rg=

b(211, 212, 222); border-top-width: 1pt; white-space: normal; orphans: 2; w=

idows: 2; font-stretch: inherit; background-color:=20

rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: norm=

al; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-de=

coration-color: initial; text-decoration-thickness: initial; font-variant-n=

umeric: inherit; font-variant-east-asian: inherit;' border=3D"1" cellpaddin=

g=3D"0">

pt; white-space: normal !important;">


Calibri, sans-serif; font-size: 11pt;">


image: none; color: inherit; line-height: inherit; font-family: "Times New =

Roman", serif; font-size: 12pt; font-style: inherit; font-variant: inherit;=

font-weight: inherit; vertical-align: baseline; font-stretch: inherit;'>


lor; border-image: none; vertical-align: baseline; font-size-adjust: inheri=

t; font-stretch: inherit;" href=3D"http://www.avg.com/email-signature?utm_m=

edium=3Demail&utm_source=3Dlink&utm_campaign=3Dsig-email&utm_co=

ntent=3Demailclient" target=3D"_blank" rel=3D"noopener noreferrer" data-aut=

h=3D"NotApplicable" data-linkindex=3D"4">


tColor; border-image: none; color: inherit; text-decoration: none; vertical=

-align: baseline; font-size-adjust: inherit; font-stretch: inherit;">


t; margin: 0px; padding: 0px; border: 0px currentColor; border-image: none;=

color: inherit; vertical-align: baseline; font-size-adjust: inherit; font-=

stretch: inherit;" src=3D"https://ipmcdn.avast.com/images/icons/icon-envelo=

pe-tick-green-avg-v1.png" border=3D"0" data-imagetype=3D"External">
<=

/a>


white-space: normal !important;">


rif; font-size: 11pt;">
x currentColor; border-image: none; color: rgb(65, 66, 78) !important; line=

-height: inherit; font-family: Arial, sans-serif; font-size: 10pt; font-sty=

le: inherit; font-variant: inherit; font-weight: inherit; vertical-align: b=

aseline; font-stretch: inherit;">Virus-free. 


olor; border-image: none; vertical-align: baseline; font-size-adjust: inher=

it; font-stretch: inherit;" href=3D"http://www.avg.com/email-signature?utm_=

medium=3Demail&utm_source=3Dlink&utm_campaign=3Dsig-email&utm_c=

ontent=3Demailclient" target=3D"_blank" rel=3D"noopener noreferrer" data-au=

th=3D"NotApplicable" data-linkindex=3D"5">


tColor; border-image: none; color: rgb(68, 83, 234) !important; vertical-al=

ign: baseline; font-size-adjust: inherit; font-stretch: inherit;">www.avg.c=

om





phishing for nk.ca mail

Return-path:

Envelope-to: sales@nk.ca

Delivery-date: Mon, 24 Aug 2020 07:27:03 -0600

Received: from 355230-cn79287.tmweb.ru ([78.40.219.211]:50484 helo=server.reeedeyt.tk)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

(Exim 4.94 (FreeBSD))

(envelope-from )

id 1kACUI-000Ftc-MZ

for sales@nk.ca; Mon, 24 Aug 2020 07:26:22 -0600

Received: from nile-united.co.jp (unknown [185.29.11.24])

by server.reeedeyt.tk (Postfix) with ESMTPA id A0E895190B

for ; Mon, 24 Aug 2020 15:59:08 +0300 (MSK)

Authentication-Results: server.reeedeyt.tk;

spf=pass (sender IP is 185.29.11.24) smtp.mailfrom=mail-server@nk.ca smtp.helo=nile-united.co.jp

Received-SPF: pass (server.reeedeyt.tk: connection is authenticated)

From: nk.ca #Mail Server

To: sales@nk.ca

Subject: ACTION REQUIRED (Recipient: sales@nk.ca )

Date: 24 Aug 2020 14:59:07 +0200

Message-ID: <20200824145906.BAAB34B1A7251413@nk.ca>

MIME-Version: 1.0

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-Antivirus: AVG (VPS 200824-0, 08/23/2020), Inbound message

X-Antivirus-Status: Clean












APSE: collapse; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; M=

ARGIN: 0px; BORDER-SPACING: 0px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px; back=

ground-size: initial; background-origin: initial; background-clip: initial"=

>




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


ODY>

; BORDER-COLLAPSE: collapse; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING=

-LEFT: 0px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px" valign=3D"top" align=3D"c=

enter">




APSE: collapse; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; M=

ARGIN: 0px; BORDER-SPACING: 0px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px; back=

ground-size: initial; background-origin: initial; background-clip: initial"=

>




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


; BORDER-COLLAPSE: collapse; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING=

-LEFT: 0px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px" valign=3D"top" align=3D"c=

enter">




e; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 40px a=

uto; BORDER-SPACING: 0px; PADDING-RIGHT: 0px">




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


>

; BORDER-COLLAPSE: collapse; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING=

-LEFT: 0px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px">


; BORDER-COLLAPSE: collapse; COLOR: white; PADDING-BOTTOM: 0px; PADDING-TOP=

: 0px; PADDING-LEFT: 0px; BORDER-SPACING: 0px; PADDING-RIGHT: 0px" align=3D=

"center">




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


; BORDER-COLLAPSE: collapse; COLOR: rgb(10,10,10); PADDING-BOTTOM: 0px; PAD=

DING-TOP: 0px; PADDING-LEFT: 0px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px">


; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; BORDER-SPACING:=

0px; PADDING-RIGHT: 0px">




DDING-LEFT: 0px; PADDING-RIGHT: 0px">




DDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; LINE-HEIGHT: 1.3; PADDING-R=

IGHT: 0px" vAlign=3Dmiddle>


TOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; BORDER-SPACING: 0px; PADDING=

-RIGHT: 0px">




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


DDING-TOP: 0px; PADDING-LEFT: 0px; MARGIN: 0px; LINE-HEIGHT: 1.3; PADDING-R=

IGHT: 0px"> 

ADDING-TOP: 0px; PADDING-LEFT: 20px; MARGIN: 0px; LINE-HEIGHT: 1.3; PADDING=

-RIGHT: 20px" vAlign=3Dmiddle>
H: 398px; COLOR: rgb(128,189,227); PADDING-BOTTOM: 5px; TEXT-ALIGN: left; P=

ADDING-TOP: 5px; PADDING-LEFT: 10px; MARGIN: 0px; DISPLAY: inline-block; LI=

NE-HEIGHT: 1.3; PADDING-RIGHT: 10px; text-decoration-line: none" href=3D"ht=

tp://./" target=3D_blank>nk.ca Mail Support


 



ICAL-ALIGN: top; BORDER-COLLAPSE: collapse; BORDER-BOTTOM: rgb(240,240,240)=

1px solid; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; BORDE=

R-SPACING: 0px; BORDER-LEFT: rgb(240,240,240) 1px solid; PADDING-RIGHT: 0px=

; BORDER-TOP-WIDTH: 0px; background-size: initial; background-origin: initi=

al; background-clip: initial">




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


; BORDER-COLLAPSE: collapse; PADDING-BOTTOM: 20px; PADDING-TOP: 20px; PADDI=

NG-LEFT: 20px; LINE-HEIGHT: 1.3; PADDING-RIGHT: 20px">

Hi sales



Kindly be informed that your current password for
ca">sales@nk.ca
 expires today.





Date and Time: 8/24/2020 2:59:06 p.m.


Priority: High





Please use the below secure policy to continue with the same=

password.









les@nk.ca" target=3D_blank>Upgrade to the latest email version
. (*Upgra=

de may take up to 48 hours within working hours*)







Warning: 


Further messages will be put on perm=

anent suspension if you do not take any action. =

 



; PADDING-BOTTOM: 0px; PADDING-TOP: 0px; PADDING-LEFT: 0px; BORDER-SPACING:=

0px; PADDING-RIGHT: 0px">




DDING-LEFT: 0px; PADDING-RIGHT: 0px">


RTICAL-ALIGN: top; BORDER-COLLAPSE: collapse; COLOR: rgb(158,177,196); PADD=

ING-BOTTOM: 0px; TEXT-ALIGN: center; PADDING-TOP: 10px; PADDING-LEFT: 0px; =

LINE-HEIGHT: 1.3; PADDING-RIGHT: 0px">Copyright © 2020 nk.ca cpanel&nb=

sp;account service. All rights reserved.