Invoice Phish
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 14 Jul 2025 16:08:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ubRKL-000000005Nk-2eKw
for dave@doctor.nl2k.ab.ca;
Mon, 14 Jul 2025 16:07:13 -0600
Resent-From: The Doctor
Resent-Date: Mon, 14 Jul 2025 16:07:13 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [38.180.65.10] (port=33949 helo=youthful-villani.38-180-65-10.plesk.page)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ubP4m-00000000NEM-1cPp
for sales@netknow.ca;
Mon, 14 Jul 2025 13:43:23 -0600
Received: from EC2AMAZ-MLP7N87 (ec2-35-182-250-215.ca-central-1.compute.amazonaws.com [35.182.250.215])
by youthful-villani.38-180-65-10.plesk.page (Postfix) with ESMTPSA id 2A4A1967E9
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=webbmailing.com;
s=default; t=1752522042;
bh=za7D5V9+TefsCyb6DAMBud+gv7IHbbJc1+tqgJXXx+I=; h=From:To:Subject;
b=9MQzsCSxliI05Q9UmY2OfqIaQIyZ5dj2VpIkGIB/7v4dohhc5Ne3NwzpIlAhSPLDl
q2hcNcUUZQNU40N7muxbLi4YgRbvd2o+WGsGObaimNp26U0+b54foRkUBCzXz5+p60
4bfNKr+p+HJJaBlGtHCRxIJlruqkvV1YTYxiymD5LqL3FGXUY1e4jxzTCxs0r0GbfF
IoekDXCBpB6fHvEqMR/hIPZg8CE2MolLTJMaHJH1Xv4hPqzElS23YD2YG3y3oSEmuh
QxdolfhN157GaAoANff2cLYjS4nGN/uaKeEjq3nr6NN9eF49dnyH+1gZPYD7BJB1aw
7xczPdxgmzXPw==
Authentication-Results: youthful-villani.38-180-65-10.plesk.page;
spf=pass (sender IP is 35.182.250.215) smtp.mailfrom=inv@webbmailing.com smtp.helo=EC2AMAZ-MLP7N87
Received-SPF: pass (youthful-villani.38-180-65-10.plesk.page: connection is authenticated)
Reply-To:
From: "JOHN H DANCEY"
To: "sales"
Subject: MacDon Invoice #849527
List-Unsubscribe:
Precedence: bulk
Message-ID:
Date: Mon, 14 Jul 2025 19:40:36 +0000
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0001_BAB4D44C.5FC14B40"
X-Priority: 3
X-PPP-Message-ID:
<175252204268.636610.13649187133129896875@youthful-villani.38-180-65-10.plesk.page>
X-PPP-Vhost: webbmailing.com
X-Spam_score: 6.8
X-Spam_score_int: 68
X-Spam_bar: ++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Customer, Please see attached Invoice #849527 dated
2025-07-07.
Content analysis details: (6.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[35.182.250.215 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
[38.180.65.10 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[35.182.250.215 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[35.182.250.215 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
[38.180.65.10 listed in will-spam-for-food.eu.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
Subject: {SPAM?} MacDon Invoice #849527
This is a multi-part message in MIME format.
------=_NextPart_000_0001_BAB4D44C.5FC14B40
Content-Type: multipart/alternative;
boundary="----=_NextPart_001_0002_FF6B30D9.F8DC354B"
------=_NextPart_001_0002_FF6B30D9.F8DC354B
Content-Type: text/plain;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
------=_NextPart_001_0002_FF6B30D9.F8DC354B
Content-Type: text/html;
charset="utf-8"
Content-Transfer-Encoding: quoted-printable
=0D=0A
TML>=0D=0A
001">=0D=0A=0D=0A
FONT-FAMILY: monospace, "courier new", courier; WHITE-SPACE: =
normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FLOAT: none; =
FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: =
2; WIDOWS: 2; DISPLAY: inline !important; LETTER-SPACING: normal; =
BACKGROUND-COLOR: rgb(255,255,255); TEXT-INDENT: 0px; font-variant-lig=
atures: normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>Dear Customer,
new", courier; WHITE-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM:=
none; FONT-WEIGHT: 400; COLOR: rgb(0,0,0); FONT-STYLE: normal; =
ORPHANS: 2; WIDOWS: 2; LETTER-SPACING: normal; BACKGROUND-COLOR: =
rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: =
normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>
13px; FONT-FAMILY: monospace, "courier new", courier; WHITE-SPACE: =
normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: =
400; COLOR: rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: =
2; LETTER-SPACING: normal; BACKGROUND-COLOR: rgb(255,255,255); =
TEXT-INDENT: 0px; font-variant-ligatures: normal; font-variant-caps: =
normal; -webkit-text-stroke-width: 0px; text-decoration-thickness: =
initial; text-decoration-style: initial; text-decoration-color: =
initial'>
"courier new", courier; WHITE-SPACE: normal; WORD-SPACING: 0px; =
TEXT-TRANSFORM: none; FLOAT: none; FONT-WEIGHT: 400; COLOR: =
rgb(0,0,0); FONT-STYLE: normal; ORPHANS: 2; WIDOWS: 2; DISPLAY: =
inline !important; LETTER-SPACING: normal; BACKGROUND-COLOR: =
rgb(255,255,255); TEXT-INDENT: 0px; font-variant-ligatures: =
normal; font-variant-caps: normal; -webkit-text-stroke-width: =
0px; text-decoration-thickness: initial; text-decoration-style: =
initial; text-decoration-color: initial'>Please see attached =
Invoice #849527 dated 2025-07-07.