Credential phishing
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 15 Dec 2025 22:09:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1vVNIb-000000004ab-2voJ
for dave@doctor.nl2k.ab.ca;
Mon, 15 Dec 2025 22:08:37 -0700
Resent-From: The Doctor
Resent-Date: Mon, 15 Dec 2025 22:08:37 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from web6.fvds.ru ([83.136.232.195]:51586)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1vVC7J-000000006Gr-2amF
for doctor@netknow.ca;
Mon, 15 Dec 2025 10:12:21 -0700
Received: from hotlider by web6.fvds.ru with local (Exim 4.92)
(envelope-from)
id 1vVC6Z-000mbV-3V
for doctor@netknow.ca; Mon, 15 Dec 2025 20:11:27 +0300
To: doctor@netknow.ca
Subject: InMail: You have 11 messages on hold 12/15/2025 08:11:27 pm.
Date: Mon, 15 Dec 2025 20:11:27 +0300
From: =?UTF-8?B?QWRtaW5pc3RyYXRvciDinKo=?=
Message-ID: <8106416f46e0dfc7193515579b10341b@hotlider.ru>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="b1_8106416f46e0dfc7193515579b10341b"
Content-Transfer-Encoding: 8bit
X-Spam_score: 8.8
X-Spam_score_int: 88
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: e�-�A�l�e�r�t Ti�ck�e�t N�o�tiϲ�
(#33511398550537980147742) Message Restriction P�o�r�t�a�l
Content analysis details: (8.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
[83.136.232.195 listed in dnsbl.ahbl.org]
[83.136.232.195 listed in dnsbl.ahbl.org]
[83.136.232.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: ec46.ru/62.109.1.44]
0.1 URIBL_CSS_A Contains URL's A record listed in the Spamhaus CSS
blocklist
[URI: ec46.ru/62.109.1.44]
1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 FROM_LOCAL_DIGITS From: localpart has long digit sequence
0.3 FROM_LOCAL_HEX From: localpart has long hexadecimal sequence
2.3 MANGLED_LOW BODY: mangled low
0.0 T_MXG_EMAIL_FRAG BODY: URI with email in fragment
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_IMAGE_ONLY_32 BODY: HTML: images with 2800-3200 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
Subject: {SPAM?} InMail: You have 11 messages on hold 12/15/2025 08:11:27 pm.
This is a multi-part message in MIME format.
--b1_8106416f46e0dfc7193515579b10341b
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
e-Alert Ticket Notiϲå (#33511398550537980147742)
Message Restriction Portal
11 nåw måssàgås hàvå båån put on hold from gåtting to your doctor@netknow.ca inbox .
Uså thå TAB bålow to rålåàså thåm to your inbox.
Release Messages
Thanks,
Administrator.Legal Disclaimer: This e-mail message and any attachments
may contain legally privileged, confidential or proprietary
information. If you are not the intended recipient(s), or the employee
or agent responsible for delivery of this message to the intended
recipient(s), you are hereby notified that any dissemination,
distribution or copying of this e-mail message is strictly prohibited.
If you have received this message in error, please immediately notify
the sender and delete this e-mail message
from your computer.
--b1_8106416f46e0dfc7193515579b10341b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
--b1_8106416f46e0dfc7193515579b10341b--
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 15 Dec 2025 22:09:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vVNIb-000000004ab-2voJ
for dave@doctor.nl2k.ab.ca;
Mon, 15 Dec 2025 22:08:37 -0700
Resent-From: The Doctor
Resent-Date: Mon, 15 Dec 2025 22:08:37 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from web6.fvds.ru ([83.136.232.195]:51586)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vVC7J-000000006Gr-2amF
for doctor@netknow.ca;
Mon, 15 Dec 2025 10:12:21 -0700
Received: from hotlider by web6.fvds.ru with local (Exim 4.92)
(envelope-from
id 1vVC6Z-000mbV-3V
for doctor@netknow.ca; Mon, 15 Dec 2025 20:11:27 +0300
To: doctor@netknow.ca
Subject: InMail: You have 11 messages on hold 12/15/2025 08:11:27 pm.
Date: Mon, 15 Dec 2025 20:11:27 +0300
From: =?UTF-8?B?QWRtaW5pc3RyYXRvciDinKo=?=
Message-ID: <8106416f46e0dfc7193515579b10341b@hotlider.ru>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="b1_8106416f46e0dfc7193515579b10341b"
Content-Transfer-Encoding: 8bit
X-Spam_score: 8.8
X-Spam_score_int: 88
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: e�-�A�l�e�r�t Ti�ck�e�t N�o�tiϲ�
(#33511398550537980147742) Message Restriction P�o�r�t�a�l
Content analysis details: (8.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
[83.136.232.195 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
[83.136.232.195 listed in dnsbl.ahbl.org]
[83.136.232.195 listed in dnsbl.ahbl.org]
[83.136.232.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[83.136.232.195 listed in dnsbl.ahbl.org]
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: ec46.ru/62.109.1.44]
0.1 URIBL_CSS_A Contains URL's A record listed in the Spamhaus CSS
blocklist
[URI: ec46.ru/62.109.1.44]
1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 FROM_LOCAL_DIGITS From: localpart has long digit sequence
0.3 FROM_LOCAL_HEX From: localpart has long hexadecimal sequence
2.3 MANGLED_LOW BODY: mangled low
0.0 T_MXG_EMAIL_FRAG BODY: URI with email in fragment
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_IMAGE_ONLY_32 BODY: HTML: images with 2800-3200 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
Subject: {SPAM?} InMail: You have 11 messages on hold 12/15/2025 08:11:27 pm.
This is a multi-part message in MIME format.
--b1_8106416f46e0dfc7193515579b10341b
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
e-Alert Ticket Notiϲå (#33511398550537980147742)
Message Restriction Portal
11 nåw måssàgås hàvå båån put on hold from gåtting to your doctor@netknow.ca inbox .
Uså thå TAB bålow to rålåàså thåm to your inbox.
Release Messages
Thanks,
Administrator.Legal Disclaimer: This e-mail message and any attachments
may contain legally privileged, confidential or proprietary
information. If you are not the intended recipient(s), or the employee
or agent responsible for delivery of this message to the intended
recipient(s), you are hereby notified that any dissemination,
distribution or copying of this e-mail message is strictly prohibited.
If you have received this message in error, please immediately notify
the sender and delete this e-mail message
from your computer.
--b1_8106416f46e0dfc7193515579b10341b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
| e-Alert Ticket Notiϲå (#4463642824358856110) | |
| Message Restriction Portal | |
| 11 nåw måssàgås hàvå båån put on hold from gåtting to your doctor@netknow.ca inbox . | |
| Uså thå TAB bålow to rålåàså thåm to your inbox. | |
| |
| Thanks, | |
| Administrator. Legal Disclaimer: This e-mail message and any attachments may contain legally privileged, confidential or proprietary information. If you are not the intended recipient(s), or the employee or agent responsible for delivery of this message to the intended recipient(s), you are hereby notified that any dissemination, distribution or copying of this e-mail message is strictly prohibited. If you have received this message in error, please immediately notify the sender and delete this e-mail message from your computer. |
--b1_8106416f46e0dfc7193515579b10341b--