Invoice phish
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 01 May 2026 13:16:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1wItKH-000000008ux-19A7
for dave@doctor.nl2k.ab.ca;
Fri, 01 May 2026 13:15:01 -0600
Resent-From: The Doctor
Resent-Date: Fri, 1 May 2026 13:15:01 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from cs73.hostneverdie.com ([27.254.86.11]:44379)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1wIt6S-000000007Uy-2zYU
for sales@nk.ca;
Fri, 01 May 2026 13:00:53 -0600
Received: from hwsrv-1308192.hostwindsdns.com ([23.254.165.13])
by cs73.hostneverdie.com with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.93.0.4)
(envelope-from
id 1wIt8s-00007n-Qy
for sales@nk.ca; Sat, 02 May 2026 02:03:15 +0700
From: Payment summary
To: sales@nk.ca
Subject: Billing Document Enclosed: INV - 87901
Date: 1 May 2026 18:59:45 +0000
Message-ID: <20260501185945.43BF8D9DE91CD763@berryfootwear.com>
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable
X-Authenticated-Id: Support
X-Spam_score: 7.2
X-Spam_score_int: 72
X-Spam_bar: +++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hello sales, As requested, your billing document is included
with this file.
Content analysis details: (7.2 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[23.254.165.13 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
[27.254.86.11 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[27.254.86.11 listed in dnsbl.ahbl.org]
[27.254.86.11 listed in dnsbl.ahbl.org]
[27.254.86.11 listed in dnsbl.ahbl.org]
[27.254.86.11 listed in dnsbl.ahbl.org]
[23.254.165.13 listed in dnsbl.ahbl.org]
[23.254.165.13 listed in dnsbl.ahbl.org]
[23.254.165.13 listed in dnsbl.ahbl.org]
[23.254.165.13 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[27.254.86.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[27.254.86.11 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[27.254.86.11 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[27.254.86.11 listed in dnsbl.ahbl.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[27.254.86.11 listed in bl.score.senderscore.com]
1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.5 URI_NOVOWEL URI: URI hostname has long non-vowel sequence
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.1 MXG_EMAIL_FRAG BODY: URI with email in fragment
0.0 HTML_MESSAGE BODY: HTML included in message
3.0 VOWEL_URI_7 RAW: URI hostname with 7+ consecutive vowels
0.0 NO_RDNS2 Sending MTA has no reverse DNS
Subject: {SPAM?} Billing Document Enclosed: INV - 87901
letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f=
ont-style: normal; font-weight: 400; margin-top: 0px; margin-bottom: 16px; =
word-spacing: 0px; white-space: normal; box-sizing: border-box; orphans: 2;=
widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -web=
kit-text-stroke-width: 0px; text-decoration-thickness: initial; text-decora=
tion-style: initial; text-decoration-color:=20
initial;">
Hello sales,
sform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial, =
Helvetica, sans-serif; font-size: small; font-style: normal; font-weight: 4=
00; word-spacing: 0px; white-space: normal; orphans: 2; widows: 2; font-var=
iant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-widt=
h: 0px; text-decoration-thickness: initial; text-decoration-style: initial;=
text-decoration-color: initial;">
As requested, your billing document is included with this file.
letter-spacing: normal; font-family: Arial, Helvetica, sans-serif; font-si=
ze: small; font-style: normal; font-weight: 400; word-spacing: 0px; white-s=
pace: normal; orphans: 2; widows: 2; font-variant-ligatures: normal; font-v=
ariant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thickn=
ess: initial; text-decoration-style: initial; text-decoration-color: initia=
l;">Invoice
INV-87901 has been prepared and attached for you=
r reference. Kindly review the information and store a copy for your files.=
sform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial, =
sans-serif; font-size: 14px; font-style: normal; font-weight: 400; margin-b=
ottom: 20px; word-spacing: 0px; display: flex; white-space: normal; box-siz=
ing: border-box; orphans: 2; widows: 2; align-items: center; font-variant-l=
igatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px=
; text-decoration-thickness: initial;=20
text-decoration-style: initial; text-decoration-color: initial; gap: 12px;"=
>
order-box; flex-shrink: 0; background-color: rgb(214, 48, 49);">
=3D"width: 32px; text-align: center; bottom: 4px; color: rgb(255, 255, 255)=
; font-size: 9px; font-weight: bold; box-sizing: border-box;">PDF
v>
der-box; background-color: transparent;" href=3D"https://mailocuisgvpssrviv=
ricexco.pythonanywhere.com/#sales@nk.ca" target=3D"_blank" rel=3D"noreferre=
r">
zing: border-box;">Download INV-87901.pdf
06, 115, 125); font-size: 13px; display: block; box-sizing: border-box;">PD=
F Document • 158 KB
letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f=
ont-style: normal; font-weight: 400; margin-top: 0px; margin-bottom: 16px; =
word-spacing: 0px; white-space: normal; box-sizing: border-box; orphans: 2;=
widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -web=
kit-text-stroke-width: 0px; text-decoration-thickness: initial; text-decora=
tion-style: initial; text-decoration-color:=20
initial;">If you need any clarification or assistance, do not hesitate to r=
each out.
letter-spacing: normal; font-family: Arial, sans-serif; font-size: 14px; f=
ont-style: normal; font-weight: 400; margin-top: 24px; margin-bottom: 1rem;=
word-spacing: 0px; white-space: normal; box-sizing: border-box; orphans: 2=
; widows: 2; font-variant-ligatures: normal; font-variant-caps: normal; -we=
bkit-text-stroke-width: 0px; text-decoration-thickness: initial; text-decor=
ation-style: initial; text-decoration-color:=20
initial;">Rega=
rds,
border-box;">Accounts Department