Cloud Credential Phish from Google Gmail Part 1
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 18 Mar 2026 20:55:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1w33WV-0000000042R-0zqV
for dave@doctor.nl2k.ab.ca;
Wed, 18 Mar 2026 20:54:11 -0600
Resent-From: The Doctor
Resent-Date: Wed, 18 Mar 2026 20:54:11 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-oo1-f72.google.com ([209.85.161.72]:50297)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1w32PB-00000000Ov3-2ILx
for sales@nk.ca;
Wed, 18 Mar 2026 19:42:41 -0600
Received: by mail-oo1-f72.google.com with SMTP id 006d021491bc7-67bbb4e5f24so3960609eaf.0
for; Wed, 18 Mar 2026 18:41:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1773884500; x=1774489300; darn=nk.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=/3+bXlCfctZRvS8zBQDZNPOOGdM2Y+9efjH86RmuTAo=;
b=It59XSg9wg34sq6aNOFwcMc8cspHDp6h7wjiuoJhTOA4Fhvl2RbnNNoLywzRUvaiRi
fOT3rzJxpU/0+HHTsqHyYLy9Ug9vNZWd4vPR4lSrbJWXgqpCeuh4AqJGftt9RvqOkYur
TuyNSJS/MErRpnqLAEXV6SSIYQpMwZkjjAMGHIlibZkP/vGuForp6bKjcLuw3xSUKizq
RBK1m3PPTK3rj3TVnziuhPjQnFZ2E2/JKJiHU2LVdSlLhvqGVZ/iMWq/Yc5kswzwLkiI
qLOgGbwJRWzUSOSwf76KOnp2zCvnzMUSFeMs7Kj+LqkM0cCVdgIaf5HOKRIkR1caaV7s
0grQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1773884500; x=1774489300;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=/3+bXlCfctZRvS8zBQDZNPOOGdM2Y+9efjH86RmuTAo=;
b=V1VJN/jT6wmphmaV7nFayJ3lq1mEoeMTTkBAwuWqdQNGEh33s8SZln1hJ1IUUigHYl
4AGEc3VBNlk++KfRYRvhLZxzpvY4IShPtTLMUybreTerL+WQEVbDhogrfodeHMdqYr1J
RoydtKN0B9BdbqTksXEg8674CLgd9iP+3QQBoMz9ntuJAxtZWoxrep+KyFuZkNyUwYQk
4LeBgju9d4cbzXnuYV07XihjPIw7VdG335f4ECsNk8usnn069BInDgCB7lXnXvkda7ZU
lpkPAMWF99OHTivDjSX2dLXr5rTXzrfPtPKD4nlErLribmbeBVv3eYpW0NVifaReTSPD
I1Ng==
X-Gm-Message-State: AOJu0YzfVSVB3GnJCpDM/DmmyGlrHQtS7DkR4mMsoizE7/pWvHqd9uFV
QDEKdNIrWM2Ss2z6JsrFmSJcjutvMoQfr12olbQZ5MZq3YmpaBBhshYj0ySVAsMfTM1uiknyjyl
QiseAuSiLKA==
MIME-Version: 1.0
X-Received: by 2002:a05:6820:2112:b0:676:96fa:299e with SMTP id
006d021491bc7-67c0daa1a7amr3376336eaf.27.1773884499895; Wed, 18 Mar 2026
18:41:39 -0700 (PDT)
Message-ID: <0000000000007d286e064d56ab1e@google.com>
Date: Thu, 19 Mar 2026 01:41:39 +0000
Subject: Your files are about to be lost
From: FINAL WARNING
To: sales@nk.ca
Content-Type: multipart/alternative; boundary="0000000000007d2857064d56ab1b"
X-Spam_score: 5.8
X-Spam_score_int: 58
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: âš ï¸ CRITICAL ALERT: SYSTEM FULL âš ï¸ USER: sales@nk.ca
Storage 100% Full
Content analysis details: (5.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
[209.85.161.72 listed in dnsbl.ahbl.org]
[209.85.161.72 listed in dnsbl.ahbl.org]
[209.85.161.72 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)
[209.85.161.72 listed in wl.mailspike.net]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders
0.8 UPPERCASE_50_75 message body is 50-75% uppercase
Subject: {SPAM?} Your files are about to be lost
--0000000000007d2857064d56ab1b
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
Content-Transfer-Encoding: base64
4pqg77iPIENSSVRJQ0FMIEFMRVJUOiBTWVNURU0gRlVMTCDimqDvuI8NCg0KDQoNCg0KVVNFUjog
c2FsZXNAbmsuY2ENCg0KDQoNCg0KU3RvcmFnZSAxMDAlIEZ1bGwNCg0KREVMRVRJT04gV0lMTCBT
VEFSVCBBVVRPTUFUSUNBTExZDQoNCg0KDQoNCkNSSVRJQ0FMIENBUEFDSVRZIHJlYWNoZWQNCg0K
DQoNCuKcmCBQaG90byAmIFZpZGVvIFN5bmM6IEZBSUxFRA0K4pyYIEFjY291bnQgRGF0YTogQVQg
UklTSw0K4pyYIENsb3VkIEJhY2t1cDogRElTQUJMRUQNCg0KDQpSRUNPVkVSIFNUT1JBR0UgTk9X
DQoNCg0KDQpJTkNJREVOVCBJRDogI01BUi0yMDI2LVNZUw0KDQoNCg0KDQo=
--0000000000007d2857064d56ab1b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 18 Mar 2026 20:55:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w33WV-0000000042R-0zqV
for dave@doctor.nl2k.ab.ca;
Wed, 18 Mar 2026 20:54:11 -0600
Resent-From: The Doctor
Resent-Date: Wed, 18 Mar 2026 20:54:11 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-oo1-f72.google.com ([209.85.161.72]:50297)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w32PB-00000000Ov3-2ILx
for sales@nk.ca;
Wed, 18 Mar 2026 19:42:41 -0600
Received: by mail-oo1-f72.google.com with SMTP id 006d021491bc7-67bbb4e5f24so3960609eaf.0
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1773884500; x=1774489300; darn=nk.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=/3+bXlCfctZRvS8zBQDZNPOOGdM2Y+9efjH86RmuTAo=;
b=It59XSg9wg34sq6aNOFwcMc8cspHDp6h7wjiuoJhTOA4Fhvl2RbnNNoLywzRUvaiRi
fOT3rzJxpU/0+HHTsqHyYLy9Ug9vNZWd4vPR4lSrbJWXgqpCeuh4AqJGftt9RvqOkYur
TuyNSJS/MErRpnqLAEXV6SSIYQpMwZkjjAMGHIlibZkP/vGuForp6bKjcLuw3xSUKizq
RBK1m3PPTK3rj3TVnziuhPjQnFZ2E2/JKJiHU2LVdSlLhvqGVZ/iMWq/Yc5kswzwLkiI
qLOgGbwJRWzUSOSwf76KOnp2zCvnzMUSFeMs7Kj+LqkM0cCVdgIaf5HOKRIkR1caaV7s
0grQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1773884500; x=1774489300;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=/3+bXlCfctZRvS8zBQDZNPOOGdM2Y+9efjH86RmuTAo=;
b=V1VJN/jT6wmphmaV7nFayJ3lq1mEoeMTTkBAwuWqdQNGEh33s8SZln1hJ1IUUigHYl
4AGEc3VBNlk++KfRYRvhLZxzpvY4IShPtTLMUybreTerL+WQEVbDhogrfodeHMdqYr1J
RoydtKN0B9BdbqTksXEg8674CLgd9iP+3QQBoMz9ntuJAxtZWoxrep+KyFuZkNyUwYQk
4LeBgju9d4cbzXnuYV07XihjPIw7VdG335f4ECsNk8usnn069BInDgCB7lXnXvkda7ZU
lpkPAMWF99OHTivDjSX2dLXr5rTXzrfPtPKD4nlErLribmbeBVv3eYpW0NVifaReTSPD
I1Ng==
X-Gm-Message-State: AOJu0YzfVSVB3GnJCpDM/DmmyGlrHQtS7DkR4mMsoizE7/pWvHqd9uFV
QDEKdNIrWM2Ss2z6JsrFmSJcjutvMoQfr12olbQZ5MZq3YmpaBBhshYj0ySVAsMfTM1uiknyjyl
QiseAuSiLKA==
MIME-Version: 1.0
X-Received: by 2002:a05:6820:2112:b0:676:96fa:299e with SMTP id
006d021491bc7-67c0daa1a7amr3376336eaf.27.1773884499895; Wed, 18 Mar 2026
18:41:39 -0700 (PDT)
Message-ID: <0000000000007d286e064d56ab1e@google.com>
Date: Thu, 19 Mar 2026 01:41:39 +0000
Subject: Your files are about to be lost
From: FINAL WARNING
To: sales@nk.ca
Content-Type: multipart/alternative; boundary="0000000000007d2857064d56ab1b"
X-Spam_score: 5.8
X-Spam_score_int: 58
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: âš ï¸ CRITICAL ALERT: SYSTEM FULL âš ï¸ USER: sales@nk.ca
Storage 100% Full
Content analysis details: (5.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
[209.85.161.72 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
[209.85.161.72 listed in dnsbl.ahbl.org]
[209.85.161.72 listed in dnsbl.ahbl.org]
[209.85.161.72 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.161.72 listed in dnsbl.ahbl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)
[209.85.161.72 listed in wl.mailspike.net]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders
0.8 UPPERCASE_50_75 message body is 50-75% uppercase
Subject: {SPAM?} Your files are about to be lost
--0000000000007d2857064d56ab1b
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
Content-Transfer-Encoding: base64
4pqg77iPIENSSVRJQ0FMIEFMRVJUOiBTWVNURU0gRlVMTCDimqDvuI8NCg0KDQoNCg0KVVNFUjog
c2FsZXNAbmsuY2ENCg0KDQoNCg0KU3RvcmFnZSAxMDAlIEZ1bGwNCg0KREVMRVRJT04gV0lMTCBT
VEFSVCBBVVRPTUFUSUNBTExZDQoNCg0KDQoNCkNSSVRJQ0FMIENBUEFDSVRZIHJlYWNoZWQNCg0K
DQoNCuKcmCBQaG90byAmIFZpZGVvIFN5bmM6IEZBSUxFRA0K4pyYIEFjY291bnQgRGF0YTogQVQg
UklTSw0K4pyYIENsb3VkIEJhY2t1cDogRElTQUJMRUQNCg0KDQpSRUNPVkVSIFNUT1JBR0UgTk9X
DQoNCg0KDQpJTkNJREVOVCBJRDogI01BUi0yMDI2LVNZUw0KDQoNCg0KDQo=
--0000000000007d2857064d56ab1b
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable