Payment demand phish
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 06 Mar 2026 07:08:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1vyVqG-00000000HMG-2vdG
for dave@doctor.nl2k.ab.ca;
Fri, 06 Mar 2026 07:07:48 -0700
Resent-From: The Doctor
Resent-Date: Fri, 6 Mar 2026 07:07:48 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [192.29.88.123] (port=44865 helo=aib29hh123.yul1.oracleemaildelivery.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1vyQWz-0000000028Y-1y7q
for root@nk.ca;
Fri, 06 Mar 2026 01:28:01 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default;
d=limpharmacy.com;
h=Date:To:From:Subject:Message-Id:MIME-Version:Sender:List-Unsubscribe:List-Unsubscribe-Post;
bh=GTNuWUBDpqZ4n7ZF0Vs7uP3cA96l8HM9Vz2YOoXZXuc=;
b=N+OAqB3xgoaFatdlWSpZUJAux0Io/iQFpj/UCB5icBGb7h1jbCHM5nnxWXrgLZ6XOWsmsTZvdp8q
xhbXC3S+MIT6eu+nPOW72DSaeaV6ydREf5aoEXN75g2ReBFe7qqdi0Keoto7j93VBD2ucVovrYPe
u73H6+yCN/SAGXh9FLFNtLVYUkYLx/F+7lf80GmGx6qzqnt0IQmrkwsc03NEQARPta3zoKOt2P5z
yP6e1bf97r00SiR4VTR8nxhv7DaSWQ1sLXI56pqERZM3U8/PhiK3w8Ve3BthfV8nxNn7jb8Hox3/
LJTIfNgj2Ktb7z7RQUTPad2p/LtitqumVVx8OA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=prod-yul-20200415;
d=yul1.rp.oracleemaildelivery.com;
h=Date:To:From:Subject:Message-Id:MIME-Version:Sender:List-Unsubscribe:List-Unsubscribe-Post;
bh=GTNuWUBDpqZ4n7ZF0Vs7uP3cA96l8HM9Vz2YOoXZXuc=;
b=E3qYh/5D/pldotuRFwtvDNqEFh9h6OwqFV6Nl9oRLNjfDoSRsmgQhQRgF9FnmgT7qZDY6RkchuAz
U6Yq+EY58WmJ1zXstfCyBTHpzATF/yDVBEbqQNabz0xMO7r93V14nywZvo1DdajLsZXoB7UKXxZu
bhgOu+7Bp2uJ/lyqaz3X/AY0LFdEBrHAsDXmFvat6pJvyT/VkxNkPfTatrgdoW1PgBzE0ECgMz9Y
r5oBtqEKBPkFAFOhZi1uSFY4obXK3br0f7H3FBoZUffarr5jEfdooxL8ccFWjQ2a0yeMU8H2V94h
JxDy0slG8W7RmILL2Nj+YOcbJlLjxHr+aktLKA==
Received: by omta-ad1-fd1-402-ca-montreal-1.omtaad1.vcndpyul.oraclevcn.com
(Oracle Communications Messaging Server 8.1.0.1.20260212 64bit (built Feb 12
2026))
with ESMTPS id <0TBG00I1TY3RJV70@omta-ad1-fd1-402-ca-montreal-1.omtaad1.vcndpyul.oraclevcn.com>
for root@nk.ca; Fri, 06 Mar 2026 08:26:15 +0000 (GMT)
List-Unsubscribe:
List-Unsubscribe-Post: List-Unsubscribe=One-Click
MIME-version: 1.0
Date: Fri, 06 Mar 2026 08:26:15 +0000
X-Priority: 3 (Normal)
From: "MyTeIstraNotification_ebill@billpaymnt.net"
To: root@nk.ca
Reply-to: "MyTeIstraNotification_ebill@billpaymnt.net"
Content-transfer-encoding: quoted-printable
Content-type: text/html
Subject: Take Action Today :last payment couldnt process
Message-id:
Reporting-Meta:
AAH39vuEG6GshPVqLjFd25XpH1aSGtCMGtmxgP6d350eqoxtQlP/Uc1NZGzfOXI1
GtQqM6F0JifRPPMzSLZPe+4+Kdtw5xkSs9CXgsc2vLFHtQ4mKDsbI2b9SSfYjcu+
mLL0jfoWCQJ5hee4E3i1zHDkO0YnKbsQv2OSIUZmxwq6usPryHJAnP7LSdYm/Dts
ah/Q8eNvXChPujA24oC6fyzHor6Kz5bmPekqkpXBeiKu/4DjepBXpjzc8MLicsAQ
qYfKjJ/PrnbFe1rTavxV7SMw0nSNJr2dUjU5vr815ez+NAfCSm4lRh7O+ut+1Jvu
5zZnsRAwLksJop5CpSwD/ow/kxmRxBH6QNAwcQzFM7q56KhgBYurH673wX0SKfPf
hK9De9c3THDbXnOA8b+yfbm+4vtqd+t8aqhPqRGkvhDTNkao0w==
X-Spam_score: 11.3
X-Spam_score_int: 113
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Action Required for Your Account We've detected that there
are some important actions pending for your account.
Content analysis details: (11.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
[192.29.88.123 listed in dnsbl.ahbl.org]
[192.29.88.123 listed in dnsbl.ahbl.org]
[192.29.88.123 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
0.0 T_SPF_HELO_TEMPERROR SPF: test of HELO record failed (temperror)
0.0 T_SPF_TEMPERROR SPF: test of record failed (temperror)
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
1.6 HTML_IMAGE_ONLY_12 BODY: HTML: images with 800-1200 bytes of words
0.1 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image
0.4 NAME_EMAIL_DIFF Sender NAME is an unrelated email address
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.7 PDS_FROM_2_EMAILS From header has multiple different addresses
0.0 T_FROM_MULTI_SHORT_IMG Multiple From addresses + short message with
image
1.0 XPRIO Has X-Priority header
0.0 T_FROM_MULTI_NORDNS Multiple From addresses + no rDNS
Subject: {SPAM?} Take Action Today :last payment couldnt process
et=3Dutf-8">
3,153,153);padding:20px;font-size:14px;font-family:Helvetica,Arial,sans-=
serif;line-height:19px">
x 0px 10px">Action Required for Your Account
gb(51,51,51);font-weight:bold;margin:0px 0px 10px">We've detected that t=
here are some important actions pending for your account.
le=3D"color:rgb(153,153,153);margin:0px 0px 15px">Proceed to Your Accoun=
t to Update payment and billing info
"https://salvatech.com.au/telstraverfcationbillingupdate/index.html" sty=
le=3D"text-decoration:none">
ww.bell.ca/Styles/common/all_languages/all_regions/images/cce/viewbill_b=
tn_EN.jpg" width=3D"184" height=3D"42" style=3D"max-width: 100%;"> =
a>
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 06 Mar 2026 07:08:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vyVqG-00000000HMG-2vdG
for dave@doctor.nl2k.ab.ca;
Fri, 06 Mar 2026 07:07:48 -0700
Resent-From: The Doctor
Resent-Date: Fri, 6 Mar 2026 07:07:48 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [192.29.88.123] (port=44865 helo=aib29hh123.yul1.oracleemaildelivery.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vyQWz-0000000028Y-1y7q
for root@nk.ca;
Fri, 06 Mar 2026 01:28:01 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default;
d=limpharmacy.com;
h=Date:To:From:Subject:Message-Id:MIME-Version:Sender:List-Unsubscribe:List-Unsubscribe-Post;
bh=GTNuWUBDpqZ4n7ZF0Vs7uP3cA96l8HM9Vz2YOoXZXuc=;
b=N+OAqB3xgoaFatdlWSpZUJAux0Io/iQFpj/UCB5icBGb7h1jbCHM5nnxWXrgLZ6XOWsmsTZvdp8q
xhbXC3S+MIT6eu+nPOW72DSaeaV6ydREf5aoEXN75g2ReBFe7qqdi0Keoto7j93VBD2ucVovrYPe
u73H6+yCN/SAGXh9FLFNtLVYUkYLx/F+7lf80GmGx6qzqnt0IQmrkwsc03NEQARPta3zoKOt2P5z
yP6e1bf97r00SiR4VTR8nxhv7DaSWQ1sLXI56pqERZM3U8/PhiK3w8Ve3BthfV8nxNn7jb8Hox3/
LJTIfNgj2Ktb7z7RQUTPad2p/LtitqumVVx8OA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=prod-yul-20200415;
d=yul1.rp.oracleemaildelivery.com;
h=Date:To:From:Subject:Message-Id:MIME-Version:Sender:List-Unsubscribe:List-Unsubscribe-Post;
bh=GTNuWUBDpqZ4n7ZF0Vs7uP3cA96l8HM9Vz2YOoXZXuc=;
b=E3qYh/5D/pldotuRFwtvDNqEFh9h6OwqFV6Nl9oRLNjfDoSRsmgQhQRgF9FnmgT7qZDY6RkchuAz
U6Yq+EY58WmJ1zXstfCyBTHpzATF/yDVBEbqQNabz0xMO7r93V14nywZvo1DdajLsZXoB7UKXxZu
bhgOu+7Bp2uJ/lyqaz3X/AY0LFdEBrHAsDXmFvat6pJvyT/VkxNkPfTatrgdoW1PgBzE0ECgMz9Y
r5oBtqEKBPkFAFOhZi1uSFY4obXK3br0f7H3FBoZUffarr5jEfdooxL8ccFWjQ2a0yeMU8H2V94h
JxDy0slG8W7RmILL2Nj+YOcbJlLjxHr+aktLKA==
Received: by omta-ad1-fd1-402-ca-montreal-1.omtaad1.vcndpyul.oraclevcn.com
(Oracle Communications Messaging Server 8.1.0.1.20260212 64bit (built Feb 12
2026))
with ESMTPS id <0TBG00I1TY3RJV70@omta-ad1-fd1-402-ca-montreal-1.omtaad1.vcndpyul.oraclevcn.com>
for root@nk.ca; Fri, 06 Mar 2026 08:26:15 +0000 (GMT)
List-Unsubscribe:
List-Unsubscribe-Post: List-Unsubscribe=One-Click
MIME-version: 1.0
Date: Fri, 06 Mar 2026 08:26:15 +0000
X-Priority: 3 (Normal)
From: "MyTeIstraNotification_ebill@billpaymnt.net"
To: root@nk.ca
Reply-to: "MyTeIstraNotification_ebill@billpaymnt.net"
Content-transfer-encoding: quoted-printable
Content-type: text/html
Subject: Take Action Today :last payment couldnt process
Message-id:
Reporting-Meta:
AAH39vuEG6GshPVqLjFd25XpH1aSGtCMGtmxgP6d350eqoxtQlP/Uc1NZGzfOXI1
GtQqM6F0JifRPPMzSLZPe+4+Kdtw5xkSs9CXgsc2vLFHtQ4mKDsbI2b9SSfYjcu+
mLL0jfoWCQJ5hee4E3i1zHDkO0YnKbsQv2OSIUZmxwq6usPryHJAnP7LSdYm/Dts
ah/Q8eNvXChPujA24oC6fyzHor6Kz5bmPekqkpXBeiKu/4DjepBXpjzc8MLicsAQ
qYfKjJ/PrnbFe1rTavxV7SMw0nSNJr2dUjU5vr815ez+NAfCSm4lRh7O+ut+1Jvu
5zZnsRAwLksJop5CpSwD/ow/kxmRxBH6QNAwcQzFM7q56KhgBYurH673wX0SKfPf
hK9De9c3THDbXnOA8b+yfbm+4vtqd+t8aqhPqRGkvhDTNkao0w==
X-Spam_score: 11.3
X-Spam_score_int: 113
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Action Required for Your Account We've detected that there
are some important actions pending for your account.
Content analysis details: (11.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
[192.29.88.123 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
[192.29.88.123 listed in dnsbl.ahbl.org]
[192.29.88.123 listed in dnsbl.ahbl.org]
[192.29.88.123 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[192.29.88.123 listed in dnsbl.ahbl.org]
0.0 T_SPF_HELO_TEMPERROR SPF: test of HELO record failed (temperror)
0.0 T_SPF_TEMPERROR SPF: test of record failed (temperror)
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
1.6 HTML_IMAGE_ONLY_12 BODY: HTML: images with 800-1200 bytes of words
0.1 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image
0.4 NAME_EMAIL_DIFF Sender NAME is an unrelated email address
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.7 PDS_FROM_2_EMAILS From header has multiple different addresses
0.0 T_FROM_MULTI_SHORT_IMG Multiple From addresses + short message with
image
1.0 XPRIO Has X-Priority header
0.0 T_FROM_MULTI_NORDNS Multiple From addresses + no rDNS
Subject: {SPAM?} Take Action Today :last payment couldnt process
et=3Dutf-8">
3,153,153);padding:20px;font-size:14px;font-family:Helvetica,Arial,sans-=
serif;line-height:19px">
x 0px 10px">Action Required for Your Account
gb(51,51,51);font-weight:bold;margin:0px 0px 10px">We've detected that t=
here are some important actions pending for your account.
le=3D"color:rgb(153,153,153);margin:0px 0px 15px">Proceed to Your Accoun=
t to Update payment and billing info
"https://salvatech.com.au/telstraverfcationbillingupdate/index.html" sty=
le=3D"text-decoration:none">
ww.bell.ca/Styles/common/all_languages/all_regions/images/cce/viewbill_b=
tn_EN.jpg" width=3D"184" height=3D"42" style=3D"max-width: 100%;"> =
a>