Invoice Phish
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 14 Jul 2025 16:08:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ubRKQ-000000005O2-2j5M
for dave@doctor.nl2k.ab.ca;
Mon, 14 Jul 2025 16:07:18 -0600
Resent-From: The Doctor
Resent-Date: Mon, 14 Jul 2025 16:07:18 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [38.180.65.10] (port=49961 helo=youthful-villani.38-180-65-10.plesk.page)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ubP4m-00000000NEJ-1cg3
for doctor@nl2k.ab.ca;
Mon, 14 Jul 2025 13:43:28 -0600
Received: from EC2AMAZ-MLP7N87 (ec2-35-182-250-215.ca-central-1.compute.amazonaws.com [35.182.250.215])
by youthful-villani.38-180-65-10.plesk.page (Postfix) with ESMTPSA id 6E175967EC
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=webbmailing.com;
s=default; t=1752522045;
bh=za7D5V9+TefsCyb6DAMBud+gv7IHbbJc1+tqgJXXx+I=; h=From:To:Subject;
b=WjRmCJRFZ4x5XKlZCypF5HewBC0+rybSog2aA+aAYSpwXyFwSjub4QhjI3WZY01kL
d0Nc1o9DMFalXFlB11udwTlQYXRV/CxNBCzJUa9jdRis5lL0gUGy6Q1QNCttEvi7Ck
+RbbN2s3HwnaROvVp41prNkBFbpQYmphBd7WTsbTjzpBO5SGR5AR/xgGrHovxCXqBC
KXk+91JiEuyZEx51SFfGZQKDZW9uO3dkKNIcSXcRNQXA3lOGRlchf3ZUn10AtWlt1U
Ovb4w5Dhe2EtIdbCg72FJfewBDO8L9GQRsS5SMES0GQFCCY9GEXiM0KYrCxdkUXtn6
biWxyIUWlmzrA==
Authentication-Results: youthful-villani.38-180-65-10.plesk.page;
spf=pass (sender IP is 35.182.250.215) smtp.mailfrom=inv@webbmailing.com smtp.helo=EC2AMAZ-MLP7N87
Received-SPF: pass (youthful-villani.38-180-65-10.plesk.page: connection is authenticated)
Reply-To:
From: "JOHN H DANCEY"
To: "doctor"
Subject: MacDon Invoice #849527
List-Unsubscribe:
Precedence: bulk
Message-ID:
Date: Mon, 14 Jul 2025 19:40:39 +0000
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0001_BAB4D44C.5FC14B40"
X-Priority: 3
X-PPP-Message-ID:
<175252204494.636625.10417307584400002336@youthful-villani.38-180-65-10.plesk.page>
X-PPP-Vhost: webbmailing.com
X-Spam_score: 6.8
X-Spam_score_int: 68
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Customer, Please see attached Invoice #849527 dated
2025-07-07.
Content analysis details: (6.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
Subject: {SPAM?} MacDon Invoice #849527
This is a multi-part message in MIME format.
------=_NextPart_000_0001_BAB4D44C.5FC14B40
Content-Type: multipart/alternative;
boundary="----=_NextPart_001_0002_FF6B30D9.F8DC354B"
------=_NextPart_001_0002_FF6B30D9.F8DC354B
Content-Type: text/plain;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
------=_NextPart_001_0002_FF6B30D9.F8DC354B
Content-Type: text/html;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
=0D=0A
TML>=0D=0A
001">=0D=0A=0D=0A
FONT-FAMILY: monospace, "courier new", courier; WHITE-SPACE: =
normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; =
FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: =
2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; =
BACKGROUND-COLOR: rgb(255,255,255); TEXT-INDENT: 0px; font-variant-lig=
atures: normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>Dear Customer,
new", courier; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM:=
none; FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; =
ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR: =
rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: =
normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>
13px; FONT-FAMILY: monospace, "courier new", courier; WHITE-SPACE: =
normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: =
400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: =
2; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(255,255,255); =
TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: =
normal; -webkit-text-stroke-width: 0px; text-decoration-thickness: =
initial; text-decoration-style: initial; text-decoration-color: =
initial'>
"courier new", courier; WHITE-SPACE: normal; WORD-SPACING: 0px; =
TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: 400; COLOR: =
rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: =
inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: =
rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: =
normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>Please see attached =
Invoice #849527 dated 2025-07-07.