Webroot phish from Google Gmail Part 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 02 Mar 2026 14:23:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vxAiU-00000000AWR-18Pr
for dave@doctor.nl2k.ab.ca;
Mon, 02 Mar 2026 14:22:14 -0700
Resent-From: The Doctor
Resent-Date: Mon, 2 Mar 2026 14:22:14 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-ot1-f73.google.com ([209.85.210.73]:44401)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vx6M3-00000000Fp3-04G3
for doctor@nl2k.ab.ca;
Mon, 02 Mar 2026 09:42:56 -0700
Received: by mail-ot1-f73.google.com with SMTP id 46e09a7af769-7d4d668425dso59056268a34.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=google.com; s=20230601; t=1772469714; x=1773074514; darn=nl2k.ab.ca;
h=from:subject:date:message-id:sender:reply-to:mime-version:from:to
:cc:subject:date:message-id:reply-to;
bh=ZCBIqVtZVNl+G6J+Fl5gNaPQmMHju/xNfINhIFb9ge0=;
b=C1JFcg8PDSI8e7qdI3Lasp9fRVykd0ELNxo1H/3PiUZKFYzeaOEb/x4hIIBxBpy/6n
mB9juvWPyJUfEwo92SOD+Mvq+Uy4D8NoVCKPRCFJf0vuT46dLffrTrjXAarxXtxasBmw
ZOJhzemZjaUWbjyNK8jssNQhmiIpXPVLPppmusAR2ZfxjshdOsTN+TtTF8I0BW6JmbFw
70geH3qThTwT8e7g810p9QJhGixszSrdPWwgezcEk2cLOxcAJ6xVF5BHJusGsA55bIAi
aRFPgCt5UXwDVK5YhOMtQBgFU5BYCviohCx/6MBVL5tSBtE3Ers5qZTUPzC7J4+S+OkH
Rnsg==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=webuserupdate-org.20230601.gappssmtp.com; s=20230601; t=1772469714; x=1773074514; darn=nl2k.ab.ca;
h=from:subject:date:message-id:sender:reply-to:mime-version:from:to
:cc:subject:date:message-id:reply-to;
bh=ZCBIqVtZVNl+G6J+Fl5gNaPQmMHju/xNfINhIFb9ge0=;
b=SGDRlzsyqlFKVlFGiTaLgSYKqFJdEdLO6Mjr3y+aYtmmklg5chd/Heze/glIT3OMg5
XhnJyv0s2yJTjoTdBgbgNsjnCmBSaaPC9hli+lz83n7bp2wfp5BPlUozRb1+mHr7GyX/
1ap0B5e9xDq3xAFgbk7esh5tEePhTZQrc3W6f/jjJAD5dmzLuk8NowJlt8aFKsRjVvJb
06v6Wu3b9VyQ6p9tEFGPEDcS9kBZrecs77qyPeZglSjryaGNEZquH9qnB1fq6H7cI0So
vBB7fJuGSk+saqR/gCrlmnGCCtz+SXUT4iBObcuTpRS6Z3b+W4b81trc9H87Kk6ByoeT
r9dQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1772469714; x=1773074514;
h=from:subject:date:message-id:sender:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=ZCBIqVtZVNl+G6J+Fl5gNaPQmMHju/xNfINhIFb9ge0=;
b=pD8KTHO9ZMOvSsGQZeCBE7S/rz0IFA8yBnDyqMysT9+2f0z8XgaINB4QedMCbs2H2p
HXyqJZWUzsaOthltBGKL0Pw5+yVFEn1MoVW4eJIl8SjYPU/Wglr+uIPjm+olpPRabVsl
eSyNJy4xRN9+UjeboE2uoMDHDi5iH9XruLQY9TYIir14haY3TWGqm9P7IkKcWAJ9J/23
MMEQNLhNZxmZTEYOEAaLVHOXANWuX8QNLGQ+OuMasrGlR85roXEOJd/IxJC+OSGXRpoc
IG2q34fXfL9WTNgtj4spe1RyMlVijbLHQ/6lbF2O/hr6adsbUsRjFmlSatG4FWziCtxm
wfmg==
X-Forwarded-Encrypted: i=1; AJvYcCWUO2hVPxK9BigIr30pM8h9aoEI5Uu3Fu0yEFQ1rvr93rra80P4cGFKsfw0skikirxDVOYy1bM=@nl2k.ab.ca
X-Gm-Message-State: AOJu0Yw6dp1kgEQMjJn5nFHARG1AubgVmzVPDQyje6EsGbP1/rbUQqWJ
NsEGZDkpCjCkupTiLs/SxgnecNR325AiWw5X6ES7BI5DYYEgUnTmGYCBnaSb7OC6wCDiE8K4R+V
88/uBNmYxrOn2UF1/yraCaSyU1xRQNsSEqQ3DwWoVAMBrEw==
MIME-Version: 1.0
X-Received: by 2002:a05:6830:600b:b0:7ca:e8bf:8c4c with SMTP id
46e09a7af769-7d591b27b8dmt14534672a34.12.1772469714232; Mon, 02 Mar 2026
08:41:54 -0800 (PST)
Reply-To: Cindy Lowry
Sender: Google Calendar
Message-ID:
Date: Mon, 02 Mar 2026 16:41:54 +0000
Subject: Shipping Activity Confirmed
From: Cindy Lowry
Content-Type: multipart/alternative; boundary="000000000000b3e86f064c0d4376"
X-Spam_score: 12.8
X-Spam_score_int: 128
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Invoice date: 2026-03-03 Bill Number: 1021-845-AQY Account
Update, Thank you for being a valued customer of Webroot Tech Support. Your
subscription term of 5 Years has now concluded. For clarification [...]
Content analysis details: (12.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
[209.85.210.73 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.210.73 listed in dnsbl.ahbl.org]
[209.85.210.73 listed in dnsbl.ahbl.org]
[209.85.210.73 listed in dnsbl.ahbl.org]
[209.85.210.73 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.210.73 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.210.73 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.210.73 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.210.73 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.210.73 listed in list.dnswl.org]
1.2 MISSING_HEADERS Missing To: header
-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)
[209.85.210.73 listed in wl.mailspike.net]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders
1.9 REPLYTO_WITHOUT_TO_CC No description available.
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
2.6 LONG_INVISIBLE_TEXT Long block of hidden text - bayes poison?
Subject: {SPAM?} Shipping Activity Confirmed