Dragonfly phish
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 26 Feb 2026 13:51:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1vviJJ-00000000E2C-1mgE
for dave@doctor.nl2k.ab.ca;
Thu, 26 Feb 2026 13:50:13 -0700
Resent-From: The Doctor
Resent-Date: Thu, 26 Feb 2026 13:50:13 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [178.238.45.181] (port=51396 helo=getluff.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1vvfrL-000000006rK-2Tge
for www@nl2k.ab.ca;
Thu, 26 Feb 2026 11:13:19 -0700
Received: by getluff.com (Postfix, from userid 33)
id 13A44416A4; Thu, 26 Feb 2026 18:12:22 +0000 (UTC)
Date: Thu, 26 Feb 2026 18:11:07 +0000
To: www@nl2k.ab.ca
From: =?UTF-8?Q?Dragonfly=C2=AE?=
Subject: Your merchant has handed us your package!
Message-ID: <8a3d9f2582e6a1fbadc15914fa21f493@getluff.com>
List-Unsubscribe: mailto:bounce180-ZloXp8odYebQYw0@getluff.com?subject=list-unsubscribe
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="1c3ebe9302f9768146a1cc3180b457a3e"
Content-Transfer-Encoding: 8bit
X-Spam_score: 10.0
X-Spam_score_int: 100
X-Spam_bar: ++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: notifications@ca.dragonflyinternational.com| French version
follows
Content analysis details: (10.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
[178.238.45.181 listed in dnsbl.ahbl.org]
[178.238.45.181 listed in dnsbl.ahbl.org]
[178.238.45.181 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.1 TW_UX BODY: Odd Letter Triples with UX
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.8 A_HREF_NOWHERE A link tag with empty href
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.2 HREF_EMPTY_NORDNS Empty href + no rDNS
2.5 NORDNS_LOW_CONTRAST No rDNS + hidden text
Subject: {SPAM?} Your merchant has handed us your package!
French version follows
Intelcom is now Dragonfly! Learn more
Tracking # INTLCMH868877879
Hi,
You have a package waiting to be delivered!
Your merchant has handed us your package INTLCMH868877879.
However, you have a package awaiting delivery due to non-payment of customs fees, taxes and brokerage to which it is subject in accordance with the terms and conditions of the Canada Border Services Agency in the amount of CA$ 4.95 payable via our secure form below:
Access the form
Questions? Take a look at our FAQ.
This is an automated email, please do not reply.
Intelcom est maintenant Dragonfly! En savoir plus
# de suivi INTLCMH868877879
Bonjour,
Vous avez un colis en attente de livraison!
Votre marchand nous a remis votre colis INTLCMH868877879.
Cependant, vous avez un colis en attente de livraison en raison du non-paiement des frais de douane, des taxes et des frais de courtage auxquels il est soumis conformément aux conditions générales de l'Agence des services frontaliers du Canada, d'un montant de 4.95 $ CA, payable via notre formulaire sécurisé ci-dessous :
Accéder au formulaire
Des questions? Consultez notre FAQ.
Ceci est un message automatisé, veuillez ne pas répondre à ce courriel.
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 26 Feb 2026 13:51:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vviJJ-00000000E2C-1mgE
for dave@doctor.nl2k.ab.ca;
Thu, 26 Feb 2026 13:50:13 -0700
Resent-From: The Doctor
Resent-Date: Thu, 26 Feb 2026 13:50:13 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [178.238.45.181] (port=51396 helo=getluff.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vvfrL-000000006rK-2Tge
for www@nl2k.ab.ca;
Thu, 26 Feb 2026 11:13:19 -0700
Received: by getluff.com (Postfix, from userid 33)
id 13A44416A4; Thu, 26 Feb 2026 18:12:22 +0000 (UTC)
Date: Thu, 26 Feb 2026 18:11:07 +0000
To: www@nl2k.ab.ca
From: =?UTF-8?Q?Dragonfly=C2=AE?=
Subject: Your merchant has handed us your package!
Message-ID: <8a3d9f2582e6a1fbadc15914fa21f493@getluff.com>
List-Unsubscribe: mailto:bounce180-ZloXp8odYebQYw0@getluff.com?subject=list-unsubscribe
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="1c3ebe9302f9768146a1cc3180b457a3e"
Content-Transfer-Encoding: 8bit
X-Spam_score: 10.0
X-Spam_score_int: 100
X-Spam_bar: ++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: notifications@ca.dragonflyinternational.com| French version
follows
Content analysis details: (10.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
[178.238.45.181 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
[178.238.45.181 listed in dnsbl.ahbl.org]
[178.238.45.181 listed in dnsbl.ahbl.org]
[178.238.45.181 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[178.238.45.181 listed in dnsbl.ahbl.org]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.1 TW_UX BODY: Odd Letter Triples with UX
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.8 A_HREF_NOWHERE A link tag with empty href
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.2 HREF_EMPTY_NORDNS Empty href + no rDNS
2.5 NORDNS_LOW_CONTRAST No rDNS + hidden text
Subject: {SPAM?} Your merchant has handed us your package!
French version follows
Intelcom is now Dragonfly! Learn more
Tracking # INTLCMH868877879
Hi,
You have a package waiting to be delivered!
Your merchant has handed us your package INTLCMH868877879.
However, you have a package awaiting delivery due to non-payment of customs fees, taxes and brokerage to which it is subject in accordance with the terms and conditions of the Canada Border Services Agency in the amount of CA$ 4.95 payable via our secure form below:
Access the form
Questions? Take a look at our FAQ.
This is an automated email, please do not reply.
Intelcom est maintenant Dragonfly! En savoir plus
# de suivi INTLCMH868877879
Bonjour,
Vous avez un colis en attente de livraison!
Votre marchand nous a remis votre colis INTLCMH868877879.
Cependant, vous avez un colis en attente de livraison en raison du non-paiement des frais de douane, des taxes et des frais de courtage auxquels il est soumis conformément aux conditions générales de l'Agence des services frontaliers du Canada, d'un montant de 4.95 $ CA, payable via notre formulaire sécurisé ci-dessous :
Accéder au formulaire
Des questions? Consultez notre FAQ.
Ceci est un message automatisé, veuillez ne pas répondre à ce courriel.