AAA Emergency Kit Phish Part 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 28 Jan 2026 10:04:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vl8we-00000000PZq-3FAj
for dave@doctor.nl2k.ab.ca;
Wed, 28 Jan 2026 10:03:08 -0700
Resent-From: The Doctor
Resent-Date: Wed, 28 Jan 2026 10:03:08 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [89.185.81.110] (port=47751 helo=maxdulsin.com)
by doctor.nl2k.ab.ca with esmtp (Exim 4.98.2 (FreeBSD))
id 1vl8Ib-00000000KEt-3HGZ
for doctor@nl2k.ab.ca;
Wed, 28 Jan 2026 09:21:54 -0700
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=smtp; d=nl2k.ab.ca;
h=Date:To:From:Subject:Content-Type:Mime-Version; i=doctor@nl2k.ab.ca;
bh=dvChNaXys5enYm8YiS7ZibX8sSg=;
b=YkInBBrT6a4F4aqqN6j6JbPsrYogHvJZltTZ+/OlIjWNh2YYOBy4k/JUJjI81JJ52e9/fPfSHA39
GaPEtshATMsk1UgGzUTbMCyWL3kC4eP/s+yVtit3jROR5rf4Q7UxrzIGSAzOwHGO5DmR/FkCZueA
29qqdesY2Hcn9JjQkqg=
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=smtp; d=nl2k.ab.ca;
b=2SsbFRwoSpPsArlj1BSrG1fJb2DevYaKG67ErQUkJxzydUaUxtX/MdxMBhQVrxBNzHg9b6KBYHME
dqtxbP0YXvc6mL3Tixfwfc2DUUgJhlMwaQL5irlSI2VwzSzW80O+9Bi8vs6vNS7Iu0P5+jzZon8A
IXjPARE5M7zqXQS/Cos=;
Date: Wed, 28 Jan 2026 16:20:54 +0000
To: doctor@nl2k.ab.ca
From: AAA
Subject: Final notice coming for Car Emergency Kit Reward
Content-Type: text/html
Mime-Version: 1.0
X-Spam_score: 21.6
X-Spam_score_int: 216
X-Spam_bar: +++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Stocksy Email AAA Member Benefits Hello , Today's Winner
is doctor.
Content analysis details: (21.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.1 MISSING_MID Missing Message-Id: header
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
[89.185.81.110 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[89.185.81.110 listed in dnsbl.ahbl.org]
[89.185.81.110 listed in dnsbl.ahbl.org]
[89.185.81.110 listed in dnsbl.ahbl.org]
[89.185.81.110 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[89.185.81.110 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[89.185.81.110 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[89.185.81.110 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[89.185.81.110 listed in dnsbl.ahbl.org]
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
2.4 HTML_OBFUSCATE_20_30 BODY: Message is 20% to 30% HTML obfuscation
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
3.5 HTML_TAG_BALANCE_CENTER Malformatted HTML
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.5 HTML_SINGLET_MANY Many single-letter HTML format blocks
0.4 TO_EQ_FM_DIRECT_MX To == From and direct-to-MX
0.0 T_STY_INVIS_DIRECT HTML hidden text + direct-to-MX
3.6 TO_EQ_FM_DOM_HTML_ONLY To domain == From domain and HTML only
1.4 TO_EQ_FM_HTML_DIRECT To == From and HTML only, direct-to-MX
Subject: {SPAM?} Final notice coming for Car Emergency Kit Reward