Nk.ca credential phishing from Google Gmail Part 2
Posted by Dave Yadallee on0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[155.2.192.102 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[155.2.192.102 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[155.2.192.102 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[155.2.192.102 listed in dnsbl.ahbl.org]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: vortix.vu]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: vortix.vu]
[URI: hes.it]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: vortix.vu]
[URI: hes.it]
2.5 URIBL_DBL_PHISH Contains a Phishing URL listed in the DBL blocklist
[URI: vortix.vu]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.160.229 listed in list.dnswl.org]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[209.85.160.229 listed in bl.score.senderscore.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.160.229 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.9 URG_BIZ BODY: Contains urgent matter
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.1 MXG_EMAIL_FRAG BODY: URI with email in fragment
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 TVD_PH_SUBJ_META1 Email has a Phishy looking subject line
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 NO_RDNS2 Sending MTA has no reverse DNS
Subject: {SPAM?} Urgent Notice on sales@nk.ca 6/26/2026 5:53:48 p.m.
cebook.com/","twitter.com/","youtube-nocookie.com/embed=
/","//vk.com/","//www.vk.com/","linkedin.com/=
","//www.linkedin.com/","//instagram.com/","/=
/www.instagram.com/","//www.google.com/recaptcha/api2/",&quo=
t;//hangouts.google.com/webchat/","//www.google.com/calendar/&quo=
t;,"//www.google.com/maps/embed","spotify.com/","s=
oundcloud.com/","//player.vimeo.com/","//disqus.com/&qu=
ot;,"//tgwidget.com/","//js.driftt.com/","friends2=
follow.com","/widget","login","//video.bigmir=
=2Enet/","blogger.com","//smartlock.google.com/",&=
quot;//keep.google.com/","/web.tolstoycomments.com/","m=
oz-extension://","chrome-extension://","/auth/",&q=
uot;//analytics.google.com/","adclarity.com","paddle.co=
m/checkout","hcaptcha.com","recaptcha.net","2=
captcha.com","accounts.google.com","www.google.com/shop=
ping/customerreviews","buy.tinypass.com","gstatic.com&q=
uot;,"secureir.ebaystatic.com","docs.google.com","=
contacts.google.com","github.com","mail.google.com"=
;,"chat.google.com","audio.xpleer.com","keepa.com&=
quot;,"static.xx.fbcdn.net","sas.selleramp.com","1=
plus1.video","console.googletagservices.com","//lnkd.de=
mdex.net/","//radar.cedexis.com/","//li.protechts.net/&=
quot;,"challenges.cloudflare.com/","ogs.google.com"]" s=
rc=3D"chrome-extension://eppiocemhmnlbhjplcgkofciiegomcon/executors/traffic=
=2Ejs" type=3D"text/javascript">
nk.ca=
Dear sales,
Your sales@nk.ca ac=
count password is set to expire. 6/26/2026 5:53:48 p.m.
e=3D"font-size: 14px; font-family: inherit; width: 168px; vertical-align: b=
aseline; color: white; padding: 0px; text-align: center; margin: 0px; displ=
ay: inline-block; line-height: 40px; background-color: #0078d4; font-stretc=
h: inherit; border-radius: 2px; font-kerning: inherit; font-feature-setting=
s: inherit; border: 0px none currentcolor;" href=3D"https://vortix.vu/youru=
rl/exgam-MX2-script.htm#sales@nk.ca" rel=3D"noopener noreferrer">Keep same =
password
This link expires in 48hours.
get=3D"_blank" rel=3D"noopener" data-saferedirecturl=3D"{domain}">nk.ca=
=2E
>