nk.ca credential phish
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 20 Aug 2026 19:28:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.5 (FreeBSD))
(envelope-from
id 1wxE2O-00000000OsM-0HtK
for dave@doctor.nl2k.ab.ca;
Thu, 20 Aug 2026 19:27:16 -0600
Resent-From: The Doctor
Resent-Date: Thu, 20 Aug 2026 19:27:15 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail.ncfs-group.com ([62.173.139.11]:38048)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.5 (FreeBSD))
(envelope-from
id 1wx8tP-00000000NhH-0M3k
for sales@nk.ca;
Thu, 20 Aug 2026 13:57:48 -0600
X-Virus-Scanned: amavis at ncfs-group.com
DKIM-Filter: OpenDKIM Filter v2.10.3 mail.ncfs-group.com 7B93D901DBC
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=neoline.ru;
s=340039CC-AF37-11EC-9A4C-5024C616B834; t=1787255650;
bh=/1BXD3t+q/DQhOhORCK2k1hwE8LfPZRUwZOuV4kCreQ=;
h=MIME-Version:From:To:Date:Message-ID;
b=kiMO0bBY/WH3LzT1WqPWxylpeW4WbFeHCSAlh/rwKmiGtsIr1YqbBCFXD2Ql14lTo
H+qepZfwP7JDcvCVFINqlFYd+RqJcDmsjcDkkZnVOs8ItxU3tAWc8e5TDoqm1Mc1Wf
oHEfDw2OjRGK7xIzqxQiklVqpUAuo5dya9cipaMG0pS3USCVuQ8t02I2DDN9WXJiP8
Aixhlm7y7ij1OYjR2r+43oHRbgHk2esqJjm1zmr5xjypf1Jl02UaRyqPZCvi2jKoAK
r8IItedsRkBwmMu7MJqZWaBT7xdSejeBqCoara+8iTtsr9gPKT2KyMzrUlGEiY+fk7
xH4ml5VL7MOSA==
Content-Type: multipart/mixed; boundary="===============3819221178257673643=="
MIME-Version: 1.0
From: Admin Nk Helpdesk online mail support account
ccyftllmsezzcvcawhzncpemwgktauijwuweawitahqwvmnvyzsduxrpiwlyhcyyckhfzm
To: sales@nk.ca
Subject: Sales Nk Closure last notice update
Date: Thu, 20 Aug 2026 19:54:05 -0000
Message-ID: <178725564564.31080.1602677049960032651@neoline.ru>
X-JWUAYNE: XDYIYBBAM
X-DAJBNOJUL: SVSSCDD
X-MADFXOO: AZAMCF
X-YIOKCY: HMPWILG
X-DWTVZPAO: NQWDRIA
X-Accept-Language: en-us, en
X-Spam_score: 7.4
X-Spam_score_int: 74
X-Spam_bar: +++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview:
Content analysis details: (7.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[62.173.139.11 listed in dnsbl.ahbl.org]
[62.173.139.11 listed in dnsbl.ahbl.org]
[62.173.139.11 listed in dnsbl.ahbl.org]
[62.173.139.11 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[62.173.139.11 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[62.173.139.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[62.173.139.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[62.173.139.11 listed in dnsbl.ahbl.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
0.1 URIBL_CSS_A Contains URL's A record listed in the Spamhaus CSS
blocklist
[URI: neoline.ru/151.248.126.87]
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: neoline.ru/151.248.126.87]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
[62.173.139.11 listed in will-spam-for-food.eu.org]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[62.173.139.11 listed in bl.score.senderscore.com]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
3.5 VOWEL_FROM_7 Impronouncable from header (7+ consecutive vowels)
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.3 HTML_IMAGE_ONLY_04 BODY: HTML: images with 0-400 bytes of words
0.1 MXG_EMAIL_FRAG BODY: URI with email in fragment
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 DC_PNG_UNO_LARGO Message contains a single large inline gif
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
0.1 DC_IMAGE_SPAM_TEXT Possible Image-only spam with little text
0.1 DC_IMAGE_SPAM_HTML Possible Image-only spam
0.2 GMD_PDF_EMPTY_BODY BODY: Attached PDF with empty message body
Subject: {SPAM?} Sales Nk Closure last notice update
--===============3819221178257673643==
Content-Type: multipart/alternative;
boundary="===============4492393812424537886=="
MIME-Version: 1.0
--===============4492393812424537886==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
--===============4492393812424537886==
Content-Type: multipart/related;
boundary="===============0465683040721914027=="
MIME-Version: 1.0
--===============0465683040721914027==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
--===============0465683040721914027==
Content-Type: image/png
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline; filename= "BJPNTJUHMKI.png"
Content-ID:
...
--===============0465683040721914027==--
--===============4492393812424537886==--
--===============3819221178257673643==
Content-Type: application/pdf
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="Nk closure.pdf"
...
--===============3819221178257673643==--