Invoice Phish
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 14 Jul 2025 16:08:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ubRKE-000000005NK-0qdr
for dave@doctor.nl2k.ab.ca;
Mon, 14 Jul 2025 16:07:06 -0600
Resent-From: The Doctor
Resent-Date: Mon, 14 Jul 2025 16:07:06 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [38.180.65.10] (port=59543 helo=youthful-villani.38-180-65-10.plesk.page)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ubP4m-00000000NEG-1cie
for root@nk.ca;
Mon, 14 Jul 2025 13:43:23 -0600
Received: from EC2AMAZ-MLP7N87 (ec2-35-182-250-215.ca-central-1.compute.amazonaws.com [35.182.250.215])
by youthful-villani.38-180-65-10.plesk.page (Postfix) with ESMTPSA id 83958967E4
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=webbmailing.com;
s=default; t=1752522039;
bh=za7D5V9+TefsCyb6DAMBud+gv7IHbbJc1+tqgJXXx+I=; h=From:To:Subject;
b=xGF1KRh93ef/8+s7xyfYygG1Kbt5+AdqNFAET0dBogw8wtwI5XXMlmb6sGeCWrQb0
Ci8fifO1t5+AqWl82xdR3d0DML5mzRIGTNNYgrdBhLDG+18SDPbGQrHcRTbC109Isa
vIxfPTDRWA/H7SCv8ilTo/EF+mmzW5JBqD6Sn132PspATmcUlM/y0tkUqpRoXuvtpx
GjKj5STrhBcbYw7bcZR+UfU2pA3CSX+IIRwU8fHLNs3D/jyDM5hFR5stAwnUVK7i1h
y8sI9pO2zlRtlXYnNjTPw4hXcpX+wa1Gv6PQfMkUXPnLJlGyIosvKFX05246oD7qOs
sz0cwU5/fePbA==
Authentication-Results: youthful-villani.38-180-65-10.plesk.page;
spf=pass (sender IP is 35.182.250.215) smtp.mailfrom=inv@webbmailing.com smtp.helo=EC2AMAZ-MLP7N87
Received-SPF: pass (youthful-villani.38-180-65-10.plesk.page: connection is authenticated)
Reply-To:
From: "JOHN H DANCEY"
To: "root"
Subject: MacDon Invoice #849527
List-Unsubscribe:
Precedence: bulk
Message-ID:
Date: Mon, 14 Jul 2025 19:40:33 +0000
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0001_BAB4D44C.5FC14B40"
X-Priority: 3
X-PPP-Message-ID:
<175252203902.636584.3895494957753402282@youthful-villani.38-180-65-10.plesk.page>
X-PPP-Vhost: webbmailing.com
X-Spam_score: 6.8
X-Spam_score_int: 68
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Customer, Please see attached Invoice #849527 dated
2025-07-07.
Content analysis details: (6.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
Subject: {SPAM?} MacDon Invoice #849527
This is a multi-part message in MIME format.
------=_NextPart_000_0001_BAB4D44C.5FC14B40
Content-Type: multipart/alternative;
boundary="----=_NextPart_001_0002_FF6B30D9.F8DC354B"
------=_NextPart_001_0002_FF6B30D9.F8DC354B
Content-Type: text/plain;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
------=_NextPart_001_0002_FF6B30D9.F8DC354B
Content-Type: text/html;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
=0D=0A
TML>=0D=0A
001">=0D=0A=0D=0A
FONT-FAMILY: monospace, "courier new", courier; WHITE-SPACE: =
normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; =
FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: =
2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; =
BACKGROUND-COLOR: rgb(255,255,255); TEXT-INDENT: 0px; font-variant-lig=
atures: normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>Dear Customer,
new", courier; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM:=
none; FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; =
ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR: =
rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: =
normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>
13px; FONT-FAMILY: monospace, "courier new", courier; WHITE-SPACE: =
normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: =
400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: =
2; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(255,255,255); =
TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: =
normal; -webkit-text-stroke-width: 0px; text-decoration-thickness: =
initial; text-decoration-style: initial; text-decoration-color: =
initial'>
"courier new", courier; WHITE-SPACE: normal; WORD-SPACING: 0px; =
TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: 400; COLOR: =
rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: =
inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: =
rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: =
normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>Please see attached =
Invoice #849527 dated 2025-07-07.