TD Phish Part 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 13 Dec 2025 19:45:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vUc5v-00000000K4P-3p9c
for dave@doctor.nl2k.ab.ca;
Sat, 13 Dec 2025 19:44:23 -0700
Resent-From: The Doctor
Resent-Date: Sat, 13 Dec 2025 19:44:23 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from smtprelay.ch-dns.net ([46.231.205.10]:17420)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vUalz-00000000FRK-2yBN
for sales@nk.ca;
Sat, 13 Dec 2025 18:19:51 -0700
Received: from accuratio.sk (localhost [127.0.0.1]) by smtprelay.ch-dns.net (Postfix) with ESMTPSA id AB43EC071C69;
Sun, 14 Dec 2025 02:07:29 +0100 (CET)
Date: Sat, 13 Dec 2025 23:49:37 +0100
To: undisclosed-recipients:;
From: =?UTF-8?B?VEQgQ2FuYWRh?=
Subject: =?UTF-8?B?8J+UlCBBY3Rpb24gbsOpY2Vzc2FpcmU=?=
Message-ID: <2c34678942e9fdc9ae989d89de50eb41@smtprelay.ch-dns.net>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="1904fdf5a921fffaf4498a4db5564d55a"
X-PPP-Message-ID: <176567445265.2793.6554720630181568784@smtprelay.ch-dns.net>
X-PPP-Vhost: smtprelay.ch-dns.net
X-Spam_score: 8.3
X-Spam_score_int: 83
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: cSB7S4zNg Yyyu0TTZw Mise à jour du compte requise — TD
EasyWeb TD-EasyWeb
Content analysis details: (8.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
[46.231.205.10 listed in will-spam-for-food.eu.org]
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[46.231.205.10 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[46.231.205.10 listed in dnsbl.ahbl.org]
[46.231.205.10 listed in dnsbl.ahbl.org]
[46.231.205.10 listed in dnsbl.ahbl.org]
[46.231.205.10 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[46.231.205.10 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[46.231.205.10 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[46.231.205.10 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[46.231.205.10 listed in dnsbl.ahbl.org]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
1.5 GR_DOMAIN_UNDISC1 To contains undisclosed recipient (undisc)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.6 J_CHICKENPOX_44 BODY: 4alpha-pock-4alpha
0.6 J_CHICKENPOX_26 BODY: 2alpha-pock-6alpha
0.7 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.5 VOWEL_FROM_5 Impronouncable from header (6 consecutive vowels)
0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily
0.0 T_REMOTE_IMAGE Message contains an external image
Subject: {SPAM?} =?UTF-8?B?8J+UlCBBY3Rpb24gbsOpY2Vzc2FpcmU=?=
This is a multi-part message in MIME format.