Centex phish from Japan
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 12 May 2026 13:29:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1wMsmQ-00000000Fle-1j1H
for dave@doctor.nl2k.ab.ca;
Tue, 12 May 2026 13:28:34 -0600
Resent-From: The Doctor
Resent-Date: Tue, 12 May 2026 13:28:34 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from ns1.robo.co.jp ([219.166.6.18]:52906 helo=mail.robo.co.jp)
by doctor.nl2k.ab.ca with esmtp (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1wMsTS-00000000DYy-034f
for sales@nk.ca;
Tue, 12 May 2026 13:09:24 -0600
Received: from synergyhub.com.my (unknown [104.223.84.134])
by mail.robo.co.jp (Postfix) with ESMTPA id 38BE760DA1
for; Wed, 13 May 2026 04:04:11 +0900 (JST)
From: "Accounts Payable - (Stephanie Delanoy)"
To: sales@nk.ca
Subject: Centex Petroleum has sent you an EFT Payment for Inv#55165
Date: 12 May 2026 12:07:08 -0700
Message-ID: <20260512120707.78254B737FAF1DAD@synergyhub.com.my>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0012_405F30B9.6D3C539C"
X-Spam_score: 6.1
X-Spam_score_int: 61
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear sales, Please find below your electronic remittance
advice for Inv#27789
Content analysis details: (6.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
[219.166.6.18 listed in dnsbl.ahbl.org]
[219.166.6.18 listed in dnsbl.ahbl.org]
[219.166.6.18 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[104.223.84.134 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[219.166.6.18 listed in bl.score.senderscore.com]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 T_HTML_ATTACH HTML attachment to bypass scanning?
Subject: {SPAM?} Centex Petroleum has sent you an EFT Payment for Inv#55165
Dear sales,
Please find below your electronic remittance advice for Inv#27789
Payments will be post to your account within 1-5 business days of the attached remittance advise document.
Payment Secure Document for:sales@nk.ca
Scanned by: nk.ca Trusted AI Scanner Detector.
Attachment type: PDF
Date:5/12/2026 12:07:07 p.m.
If you do not receive this payment or have questions please do not hesitate to contact and reach out to us.
Thanks
Credit Team
CONFIDENTIALITY NOTE: This message is intended only for the use of the individual or entity to which it is addressed and may contain information that is privileged, confidential and exempt from disclosure under applicable law. If the reader of the message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately and delete this message permanently from your files
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 12 May 2026 13:29:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1wMsmQ-00000000Fle-1j1H
for dave@doctor.nl2k.ab.ca;
Tue, 12 May 2026 13:28:34 -0600
Resent-From: The Doctor
Resent-Date: Tue, 12 May 2026 13:28:34 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from ns1.robo.co.jp ([219.166.6.18]:52906 helo=mail.robo.co.jp)
by doctor.nl2k.ab.ca with esmtp (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1wMsTS-00000000DYy-034f
for sales@nk.ca;
Tue, 12 May 2026 13:09:24 -0600
Received: from synergyhub.com.my (unknown [104.223.84.134])
by mail.robo.co.jp (Postfix) with ESMTPA id 38BE760DA1
for
From: "Accounts Payable - (Stephanie Delanoy)"
To: sales@nk.ca
Subject: Centex Petroleum has sent you an EFT Payment for Inv#55165
Date: 12 May 2026 12:07:08 -0700
Message-ID: <20260512120707.78254B737FAF1DAD@synergyhub.com.my>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0012_405F30B9.6D3C539C"
X-Spam_score: 6.1
X-Spam_score_int: 61
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear sales, Please find below your electronic remittance
advice for Inv#27789
Content analysis details: (6.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
[219.166.6.18 listed in dnsbl.ahbl.org]
[219.166.6.18 listed in dnsbl.ahbl.org]
[219.166.6.18 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
[104.223.84.134 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[219.166.6.18 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[104.223.84.134 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
[219.166.6.18 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[104.223.84.134 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[219.166.6.18 listed in bl.score.senderscore.com]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 T_HTML_ATTACH HTML attachment to bypass scanning?
Subject: {SPAM?} Centex Petroleum has sent you an EFT Payment for Inv#55165
Dear sales,
Please find below your electronic remittance advice for Inv#27789
Payments will be post to your account within 1-5 business days of the attached remittance advise document.
Payment Secure Document for:sales@nk.ca
Scanned by: nk.ca Trusted AI Scanner Detector.
Attachment type: PDF
Date:5/12/2026 12:07:07 p.m.
If you do not receive this payment or have questions please do not hesitate to contact and reach out to us.
Thanks
Credit Team
CONFIDENTIALITY NOTE: This message is intended only for the use of the individual or entity to which it is addressed and may contain information that is privileged, confidential and exempt from disclosure under applicable law. If the reader of the message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately and delete this message permanently from your files