Digital cloud services phish from Google Gmail
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 19 Oct 2025 16:41:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vAc4m-00000000KBu-2Cmm
for dave@doctor.nl2k.ab.ca;
Sun, 19 Oct 2025 16:40:32 -0600
Resent-From: The Doctor
Resent-Date: Sun, 19 Oct 2025 16:40:32 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-ua1-f69.google.com ([209.85.222.69]:53464)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vAaNB-00000000Pdl-2B1M
for doctor@netknow.ca;
Sun, 19 Oct 2025 14:51:32 -0600
Received: by mail-ua1-f69.google.com with SMTP id a1e0cc1a2514c-932c8a0d8faso253617241.2
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1760907033; x=1761511833; darn=netknow.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=EHrGvPv7tQAMbFU+C2oENDZjRxh3hlgMt5B/MSlB+B8=;
b=TJFX3QZuB37g6zhYcgWcbYjWnW7wPTwf8f+TX6XxNmeXY4MNcbSP79FXj+ITQtTIDX
iCRmD1jTxZF2adTjgeFcYxcwrcgUEjq6RUaGPHCwLPn1VpyjhQpIJz20G+otr1O9exgo
fEbZcZy68vBSTHqjIvCXgwDq+2zjYRe2CFxhDeM5jxJY5eJNeHcXDtk3BvSNaMGtFnY2
7XNzM8K+cn/fLvqIoro4njmw3zz4jGAQH+yvC9Jba77uVsuxL8y+Z4uxYT7CFzlfdFTK
icuT+MB7ZOcDD+S5MbBHWWqDDz5wm/CFd6OiaTrNzKNU5cnj6cgip0ovkhp8aWVLQyUE
QcoQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1760907033; x=1761511833;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=EHrGvPv7tQAMbFU+C2oENDZjRxh3hlgMt5B/MSlB+B8=;
b=pqi3P151IqdzabGAyyzE7Pn9TouzS23gEi5ppVzIKA+1hiCE8g3o3EMKyPZLoBqLIU
IaZRHX9k/7MhG67zrlfvLTFQGKFzFO1edbDIvZKlPERlORc3/K6BnjRroXw6ZgpSM+YS
6K0y2uG0q6TqwZ8sikbrpdej7TmgsCn+ssEAnjH7ZJjDKVYiTKNv3vd96ka9uEhhPVGn
GQyU6nf999uLyTk2JDCNuXLpB3WsbTY8lmjLNU7nOnhRsBPOyWJiKloKHbJOB4Qkpvbu
6hj/BDo5FyDYj3RbAmjLJtvU0dcggfxbbkRaen4mDfElXotTrlaD56MY0zJdiVcrU4ni
bOOg==
X-Gm-Message-State: AOJu0YwQL7QDVWEjqG564f+07gG3KIzHrrx11hTbfroy1rn5jL9PesMI
yFNaWJ7eATkKZN/UdryEwHHE39f0Ea1otZlFseDCUPoM3p3zwPfPKBPqMZxja1L6PYG6Z6vENEQ
4ZjRGqafnjQ==
X-Google-Smtp-Source: AGHT+IGVvRY/AE/zPzg46iZpZSlar50m5yKSEUDQjsQmOOkMcckX3AlZQ1dBnX+7aF0RKmxXOFW4pA6q03QihdU=
MIME-Version: 1.0
X-Received: by 2002:a05:6102:3e91:b0:52a:4903:95af with SMTP id
ada2fe7eead31-5d7dd5d328amr3334436137.19.1760907032839; Sun, 19 Oct 2025
13:50:32 -0700 (PDT)
Message-ID: <0000000000002cc4e40641891e1c@google.com>
Date: Sun, 19 Oct 2025 20:50:32 +0000
Subject: =?UTF-8?Q?=F0=9F=92=94_Each_Day_You_Wait=2C_Another_Memory_Fades_Away_=2D_?=
=?UTF-8?Q?Save_Them_Before_It=E2=80=99s_Too_Late?=
From: =?UTF-8?Q?=F0=9F=92=8C_iMemories_Team?=
To: doctor@netknow.ca
Content-Type: multipart/alternative; boundary="0000000000002cc4d40641891e19"
X-Spam_score: 9.4
X-Spam_score_int: 94
X-Spam_bar: +++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Image 1 Image 2 Device Width Images
Content analysis details: (9.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
[209.85.222.69 listed in dnsbl.ahbl.org]
[209.85.222.69 listed in dnsbl.ahbl.org]
[209.85.222.69 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.222.69 listed in list.dnswl.org]
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: click.convertkit-mail2.com/3.141.222.179]
[URI: click.convertkit-mail2.com/18.220.225.51]
[URI: click.convertkit-mail2.com/3.18.56.123]
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[209.85.222.69 listed in psbl.surriel.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.222.69 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image
0.0 T_REMOTE_IMAGE Message contains an external image
Subject: {SPAM?} =?UTF-8?Q?=F0=9F=92=94_Each_Day_You_Wait=2C_Another_Memory_Fades_Away_=2D_?=
=?UTF-8?Q?Save_Them_Before_It=E2=80=99s_Too_Late?=
--0000000000002cc4d40641891e19
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
Image 1 Image 2
--0000000000002cc4d40641891e19
Content-Type: text/html; charset="UTF-8"
--0000000000002cc4d40641891e19--