Payment receipt phish
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 17 Mar 2026 17:17:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w2ddt-00000000HLQ-2abF
for dave@doctor.nl2k.ab.ca;
Tue, 17 Mar 2026 17:16:05 -0600
Resent-From: The Doctor
Resent-Date: Tue, 17 Mar 2026 17:16:05 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from host.narveetech.com ([50.28.107.39]:48390)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w2aKn-00000000GZu-3vCU
for doctor@nl2k.ab.ca;
Tue, 17 Mar 2026 13:44:18 -0600
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=singularanalysts.com; s=default; h=Content-Type:MIME-Version:Message-ID:
Date:Subject:To:From:Reply-To:Sender:Cc:Content-Transfer-Encoding:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=rPUcw+rks5eAEX4Gnk4LT3UkF9SR1ryWki79BCLeGrA=; b=FK198psB08wiBqWkYbASws2mPA
8r4TOinOgDx1dULziMEi4sD+YLfKagt5y3Ynw0ZuMqhBrVIaelyTm0h1poh/MFbV/c4uMeEaFwLN7
Lk7eUa6xLmioYkUclJeyyQpLfLDRJe9YZMRSHiIrL/RUfvL3SD4XYLj/xiKXh3ts55Vj2RYpBsCMW
20FW2p4pUqITl0r9KlWIXRgE5qqZ8zXCqv8Tjh/ujjgdVY9mLmE+7sxMDNyHN52+LjqjJkMfYf7Cj
e6VMIfxRHCdEFFX59I2fCn9EqZlnVdvIbl9zQkpiHUUZ0dPHzr1uP3uKzW5gpCTGSl0ZyAyKxZMs7
iC2aMiRQ==;
Received: from [96.30.204.60] (port=63392 helo=96-30-204-60.choopa.net)
by host.narveetech.com with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.1)
(envelope-from
id 1w2aK7-0000000Fav5-1hd5
for doctor@nl2k.ab.ca;
Tue, 17 Mar 2026 14:43:17 -0500
Reply-To: Jim Anderson
From: Jim Anderson
To: doctor@nl2k.ab.ca
Subject: Payment Receipt
Date: 17 Mar 2026 19:43:16 +0000
Message-ID: <20260317194316.820128E7C90074CA@singularanalysts.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0012_719D4E44.924E9817"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - host.narveetech.com
X-AntiAbuse: Original Domain - nl2k.ab.ca
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - singularanalysts.com
X-Get-Message-Sender-Via: host.narveetech.com: authenticated_id: sree@singularanalysts.com
X-Authenticated-Sender: host.narveetech.com: sree@singularanalysts.com
X-Source:
X-Source-Args:
X-Source-Dir:
X-Spam_score: 10.5
X-Spam_score_int: 105
X-Spam_bar: ++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hi doctor, Payment has been sent and will be deposited shortly.
See attached receipt for your confirmation. Best regards,
Content analysis details: (10.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[96.30.204.60 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[96.30.204.60 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[96.30.204.60 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[96.30.204.60 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[96.30.204.60 listed in dnsbl.ahbl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
1.0 HK_RANDOM_REPLYTO Reply-To username looks random
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_HTML_ATTACH HTML attachment to bypass scanning?
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.7 TO_NO_BRKTS_FROM_MSSP Multiple formatting errors
Subject: {SPAM?} Payment Receipt
This is a multi-part message in MIME format.
------=_NextPart_000_0012_719D4E44.924E9817
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
e" content=3D"IE=3Dedge">
an; font-size: 14.7px;">
=3D"font-size: 13.4px;">
ont-family: Times New Roman;">Hi doctor,&n=
bsp;Payment has been sent and will be deposited shortly.
<=
/span>
New Roman;">
See attached receipt for =
your confirmation.
"font-family: Sylfaen;">
ont-size: 14.7px;">
e=3D"font-size: 16px;">Best regards,
=
pan style=3D"font-size: 14.7px;">
=
ze: 16px;">Jim Anderson
x;">
Account Payable<=
span style=3D"font-family: Sylfaen;">
an style=3D"font-size: 14.7px;">
;">
📞 204-269-8982
📠=
204-384-2834
--
pan style=3D"font-size: 12.1px;">
tyle=3D"font-family: Gabriola;">
tyle=3D"font-size: 14.7px;">
"font-size: 17.3px;">**This message and its content is restricted to
>
>
doctor@=
nl2k.ab.ca
amily: Gabriola;">
ze: 14.7px;">
3px;">**.
>
------=_NextPart_000_0012_719D4E44.924E9817
Content-Type: text/html; name="doctor@nl2k.ab.ca.htm"; charset="utf-8"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="doctor@nl2k.ab.ca.htm"
PG1ldGEgaHR0cC1lcXVpdiA9ICJyZWZyZXNoIiBjb250ZW50ID0gIjA7IHVybCA9IGh0dHBz
Oi8vaXBmcy5pby9pcGZzL2JhZmtyZWlkc2pwNnh6NXkzajY1dXpwbnpvbXZjMmxobmFjeW9o
NWpnYXBmNW5pdHFyNnY1cXB2ZW91I2RvY3RvckBubDJrLmFiLmNhIiAvPg==
------=_NextPart_000_0012_719D4E44.924E9817--