E-bike phish from Google Gmail
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 26 Oct 2025 05:21:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vCynj-0000000081m-0on7
for dave@doctor.nl2k.ab.ca;
Sun, 26 Oct 2025 05:20:43 -0600
Resent-From: The Doctor
Resent-Date: Sun, 26 Oct 2025 05:20:43 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-vk1-f200.google.com ([209.85.221.200]:50463)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vCyYm-000000006M3-3XhK
for doctor@nk.ca;
Sun, 26 Oct 2025 05:05:24 -0600
Received: by mail-vk1-f200.google.com with SMTP id 71dfb90a1353d-557d1d2751cso5702543e0c.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1761476664; x=1762081464; darn=nk.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=lIqWZ84XPIPz15hohDCKBCPSj6vYDz8fELdw4eqKxD8=;
b=WnI5d9lAzVgrSG4aZxOEBKQwZVQWk5qf1c6Ppwsn8s1jvpJWEthoQqUv6do6pEzSMu
Jmzru1x4+iqyW8c8Wc1VBvVj+IzPPxvB9l5dWACNqMyVKnhuiPtT2d+oNhlC31oTqhaJ
LSLIouRzt6zxgaqQMq1+Rd85PHa2Xo4TzbeEDHnJsYqGI1G/xGGH+ieR2xuqvhbPV5SG
964RF6TYvPQmsGsKBmC/gjrYyS+iRdUICNSfonf7+f7YaZWisY2FLQ8x6dmxvRTlyA0p
hJT849O+PYac8JBI0dq+ekXtxNsREGYlC3Qgn+x4Kvmcy1ARKIviMlz7A/DhQFY2h633
XbCQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1761476664; x=1762081464;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=lIqWZ84XPIPz15hohDCKBCPSj6vYDz8fELdw4eqKxD8=;
b=mNpQ7OT1F+hbR87ShzspdzzMy9UfH8pH2Q1ZSJzgpacB341Fff9oFfGdhmtk2V3EjI
QANEFMcnsH3HmeDgmzQLKR0Ckl1wdQuSV39GDEMs5NvS2CEsI/hjHU2ma8ajOfoWd1Cl
sKhTC85P2NLwquMO26V2AcwK+pB2iis5o8Fz8mF7fIxwXxfGocIFCvOTXGVL5kukpvFx
lcHxu2JI0ZTDaKY5XO41y1xC8/avjny1wAeOjcHJ8/wGRO1SlM299UKkh59Ynlx4aJN2
OhAQUcFsVjQLtTWFgdie8p9OsQwZowbpSHK/a9ZlCtq7/+MdyOuU8ew115smM1JI4nm9
5CzA==
X-Gm-Message-State: AOJu0YxRLA7laJ2ohbGU56K5P5f0sGp3AM2GDundeNAGmjSIDeXvjFFE
+ginaz32AsENi01qyAqWFzq6AD2F4y5uXdwYvEYg6IKCxT4oWBod0hjpjlqmDxQIOzDIohpH7FM
6Nrswes9EUg==
X-Google-Smtp-Source: AGHT+IE5N3rTBBVkLzryxZ1nz7/CAySFzwtNorGk/hTnWvOskncCmxthOXpkea5hYjNZkVi9Q5VBFlyxhQ/wa3U=
MIME-Version: 1.0
X-Received: by 2002:a05:6122:4695:b0:542:d782:2522 with SMTP id
71dfb90a1353d-5564ef1b76dmr11742534e0c.14.1761476664305; Sun, 26 Oct 2025
04:04:24 -0700 (PDT)
Message-ID: <000000000000db28e406420dbefd@google.com>
Date: Sun, 26 Oct 2025 11:04:24 +0000
Subject: =?UTF-8?B?8J+atOKAjeKZgu+4jyBDb25ncmF0dWxhdGlvbnMsIHlvdXIgSmFzaW9uIEVCNSBSb2FtZQ==?=
=?UTF-8?B?ciBFYmlrZSBpcyB3YWl0aW5nIGZvciB5b3UhIPCfjoE=?=
From: =?UTF-8?Q?Exclusive_Offer_=E2=80=93_Temu?=
To: doctor@nk.ca
Content-Type: multipart/alternative; boundary="000000000000db28d706420dbefa"
X-Spam_score: 10.1
X-Spam_score_int: 101
X-Spam_bar: ++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: It will take you only a minute to receive this fantastic prize!
TAKE A SURVEY AND WIN A REWARD! Jasion EB5 Roamer Ebike
Content analysis details: (10.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.221.200 listed in list.dnswl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
[209.85.221.200 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.221.200 listed in dnsbl.ahbl.org]
[209.85.221.200 listed in dnsbl.ahbl.org]
[209.85.221.200 listed in dnsbl.ahbl.org]
[209.85.221.200 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.221.200 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.221.200 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.221.200 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.221.200 listed in dnsbl.ahbl.org]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: eblink4.com]
1.8 URIBL_CT_SURBL Contains an URL listed in the CT SURBL blocklist
[URI: omniwatchsmartwatch26.eblink4.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.221.200 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
1.0 VOWEL_URI_5 URI hostname with 5 consecutive vowels
Subject: {SPAM?} =?UTF-8?B?8J+atOKAjeKZgu+4jyBDb25ncmF0dWxhdGlvbnMsIHlvdXIgSmFzaW9uIEVCNSBSb2FtZQ==?=
=?UTF-8?B?ciBFYmlrZSBpcyB3YWl0aW5nIGZvciB5b3UhIPCfjoE=?=
--000000000000db28d706420dbefa
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
It will take you only a minute to receive this fantastic prize!
TAKE A SURVEY AND WIN A REWARD!
Jasion EB5 Roamer Ebike
Congratulations!
Share your valuable insights and win big! You've been chosen for a quick
survey about store promotions at Temu. By participating, you could win a
Jasion EB5 Roamer Ebike
To claim, simply take this short survey about your experience with Temu.
GET STARTED NOW
If you no longer wish to receive these emails, you may unsubscribe by
clicking here
--000000000000db28d706420dbefa
Content-Type: text/html; charset="UTF-8"
It will take you only a minute to receive this fantastic prize!


TAKE A SURVEY AND WIN A REWARD!
Jasion EB5 Roamer Ebike

--000000000000db28d706420dbefa--