Quotation phish from Sendgrid PArt 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 17 Jun 2026 06:56:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wZpnl-000000003m8-2ThZ
for dave@doctor.nl2k.ab.ca;
Wed, 17 Jun 2026 06:55:29 -0600
Resent-From: The Doctor
Resent-Date: Wed, 17 Jun 2026 06:55:29 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from vsvhsdfp.outbound-mail.sendgrid.net ([134.128.109.243]:51896)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wZp58-00000000NiM-1aIA
for sales@nk.ca;
Wed, 17 Jun 2026 06:09:34 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trustmarinamanagement.it.com;
h=from:subject:content-type:mime-version:date:reply-to:to:cc:
content-type:date:from:subject:to;
s=s1; t=1781698108;
bh=fng/7v+TmW89sAY56t5yFd/sbggeokbahhRC96JHntA=;
b=0JYczLVOZiorzxQJwWQ3uahiqfs/dqPybPFYJwro7z5WaIcM0H92atPNU0K1IdNgeAzJ
hm/9gzY7asqugHCoXGH9Xkd2xIx885lb2M/wSMtwkIacqoZYth+nvHus9JWdvvinxjFihQ
G05VeIDFzMYvqhrUeSbzYDKqXflJNLDLH0it7UGB9WzHuBLyJ4aRFytk1fm7h23xPpSdwr
e2PPPK626upyH+VIyQhSpP2rd4c+xt/C0rwUGl2xFY9lBr9lzXsrYTJhweGtOJYhEj+jWm
/cz9YDGoyKjx2lgTV/2nJ8hM5vGqsVkXIDwWKO/ZIYLWKC9bKNV2c+LLT7b/GkJA==
Received: by recvd-54bd896dc-kbd9l with SMTP id recvd-54bd896dc-kbd9l-1-6A328E3C-57
2026-06-17 12:08:28.349509143 +0000 UTC m=+41007.065432723
Received: from WIN-KEJVO9CLD80 (unknown)
by geopod-ismtpd-106 (SG)
with ESMTP id WYdTGgt_TT2xLfxR_0zcRw
for
Wed, 17 Jun 2026 12:08:28.311 +0000 (UTC)
From: Carina Rodrigues
Subject: Quotation
Content-Type: multipart/related; type="multipart/alternative"; boundary="xuPc2cendKrFHFFHk=_jUoJ2bC9sbVqRFw"
MIME-Version: 1.0
Date: Wed, 17 Jun 2026 12:08:28 +0000 (UTC)
Message-Id: <17282026060805A7B04D8F4C$B854A3AB4C@trustmarinamanagement.it.com>
Reply-To: Carina Rodrigues
X-SG-EID:
=?us-ascii?Q?u001=2EjCA51SAfndAlsG8jlitwrW3az8fn5unQqLLAzjr9yJugqGYl62XmJLiXS?=
=?us-ascii?Q?CxqlOuEq1Ii1gV7YspLzCY1oP718phyFC4FxzPd?=
=?us-ascii?Q?CkRSmrJyLpfzPFjCscAwlLxLEYF73B1I=2FJtFpbm?=
=?us-ascii?Q?idxHDxp0dpnpv+EpAOmsqV8czqc9mozeF4sw9q6?=
=?us-ascii?Q?1pZY4N5V9PMcQZtmrftr0jL+SpJWX=2FwDjfB+AI7?=
=?us-ascii?Q?e5O9WMlKvi7wyy9svXR=2FcC81dgDHTawp=2FbNZNCb?=
=?us-ascii?Q?sItE?=
To: sales@nk.ca
X-Entity-ID: u001.228RHI9jFJF3ZkhtFU6b7Q==
X-Spam_score: 24.6
X-Spam_score_int: 246
X-Spam_bar: ++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear sir, We went through your website and found your services
very interesting We have demand for your goods and services, Please go through
our below enquiry and give us your best prices. https://reflexdelta.online/file/8/Quotation.js
Content analysis details: (24.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
[134.128.109.243 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[134.128.109.243 listed in dnsbl.ahbl.org]
[134.128.109.243 listed in dnsbl.ahbl.org]
[134.128.109.243 listed in dnsbl.ahbl.org]
[134.128.109.243 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[134.128.109.243 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[134.128.109.243 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[134.128.109.243 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[134.128.109.243 listed in dnsbl.ahbl.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-0.0 SPF_PASS SPF: sender matches SPF record
15 GR_DOMAIN_SENDGR1 Received contains spammer id (sendgr)
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: reflexdelta.online]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: reflexdelta.online]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
0.0 T_PDS_OTHER_BAD_TLD Untrustworthy TLDs
[URI: reflexdelta.online (online)]
1.7 DEAR_SOMETHING BODY: Contains 'Dear (something)'
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[134.128.109.243 listed in bl.score.senderscore.com]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.6 HTML_IMAGE_RATIO_04 BODY: HTML has a low ratio of text to image area
0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or Formatted
Colors in HTML
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 MIXED_HREF_CASE Has href in mixed case
Subject: {SPAM?} Quotation
This is a multi-part message in MIME format
--xuPc2cendKrFHFFHk=_jUoJ2bC9sbVqRFw
Content-Type: multipart/alternative;
boundary="FhM4=_KWZfwAcCPxAGQt9E8TJPBsDiw4vt"
--FhM4=_KWZfwAcCPxAGQt9E8TJPBsDiw4vt
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Dear sir,
We went through your website and found your services very interesting
We have demand for your goods and services,
Please go through our below enquiry and give us your best prices.
https://reflexdelta.online/file/8/Quotation.js
VIEW PHOTO https://reflexdelta.online/file/8/Quotation.js
Please click on the picture above to enlarge it.
We look forward to your prices