Dragonfly/Intelcom phish
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 02 Jul 2026 14:37:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wfO8w-00000000AQb-3MB8
for dave@doctor.nl2k.ab.ca;
Thu, 02 Jul 2026 14:36:18 -0600
Resent-From: The Doctor
Resent-Date: Thu, 2 Jul 2026 14:36:18 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [216.158.90.90] (port=52461 helo=oix4.emoneyhosting.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wfHvP-000000006ce-2jsM
for root@doctor.nl2k.ab.ca;
Thu, 02 Jul 2026 07:58:11 -0600
Comment: DomainKeys? See http://domainkeys.sourceforge.net/
DomainKey-Signature: a=rsa-sha256; q=dns; c=nofws;
s=default; d=divinegiftfashion.com;
b=hdGDdwrwLrNQtGeNopyJ6TyXizC+ocswlKJgrIgN9l6WnP++TDNItJd0nmYt/1XsLW4Yy+anrn8dIfU3q8BFoe+XXgejtab9aryY+v5hf1pCCQfGTwdYUNn3PO1xVtkSbGMz3jgUM0znwVXneKmit8qOvILmfs7+OeKRslF/FsnzhNwtoS7CznIQKxZ0/7nV6YQBJNbE95RK7Gh78bac8MnHsDlgpgnt/vyZcxbkhGyfi8uu43Yek4qzh+icKc9D8l6T2J4uHG5dak7UPsCxdibYfVAegg5V7rI7RzUZtl67AjEkynwVYrWc6MBy11PrcNwCVmSvEl8ryNKdLUDn8Q==;
h=Received:Received:Received:Content-Type:From:To:Subject:Message-ID:Content-Transfer-Encoding:Date:MIME-Version;
Received: (qmail 2934012 invoked by uid 108); 2 Jul 2026 13:56:50 +0000
Received: from unknown (HELO oix4.emoneyhosting.com) (127.0.0.1)
by oix4.emoneyhosting.com with SMTP; 2 Jul 2026 13:56:50 +0000
Received: from [127.0.0.1] ([196.65.222.62])
by oix4.emoneyhosting.com with ESMTPSA
id mm4HHiFuRmpoxCwAPcmbyA
(envelope-from
for
Content-Type: text/html
From: Intelcom
To: root@doctor.nl2k.ab.ca
Subject: Intelcom Delivery Notification
Message-ID:
Content-Transfer-Encoding: quoted-printable
Date: Thu, 02 Jul 2026 13:56:48 +0000
MIME-Version: 1.0
X-Spam_score: 13.5
X-Spam_score_int: 135
X-Spam_bar: +++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Intelcom Delivery Update
Content analysis details: (13.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[196.65.222.62 listed in dnsbl.ahbl.org]
[196.65.222.62 listed in dnsbl.ahbl.org]
[196.65.222.62 listed in dnsbl.ahbl.org]
[196.65.222.62 listed in dnsbl.ahbl.org]
[216.158.90.90 listed in dnsbl.ahbl.org]
[216.158.90.90 listed in dnsbl.ahbl.org]
[216.158.90.90 listed in dnsbl.ahbl.org]
[216.158.90.90 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[196.65.222.62 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[196.65.222.62 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[196.65.222.62 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[196.65.222.62 listed in dnsbl.ahbl.org]
1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[216.158.90.90 listed in bl.score.senderscore.com]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[196.65.222.62 listed in zen.spamhaus.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[196.65.222.62 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
[216.158.90.90 listed in will-spam-for-food.eu.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[196.65.222.62 listed in sbl-xbl.spamhaus.org]
[196.65.222.62 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
0.0 NO_RDNS2 Sending MTA has no reverse DNS
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
Subject: {SPAM?} Intelcom Delivery Notification
hidden; MAX-WIDTH: 600px; BACKGROUND: #ffffff; MARGIN: 30px auto; =
border-radius: 10px; box-shadow: 0 4px 10px rgba(0,0,0,0.08)">
center; PADDING-TOP: 20px; PADDING-LEFT: 20px; PADDING-RIGHT: 20px">
Intelcom
TEXT-ALIGN: center; PADDING-TOP: 30px; PADDING-LEFT: 30px; PADDING-RIGHT: =
30px">
Delivery Update
Your package is currently being processed and =
requires a small fee for customs handling.
18px; FONT-WEIGHT: bold; COLOR: #04ab94">Amount due: 2.96 CAD
Please confirm your delivery =
details to ensure a smooth delivery experience.
eu/Intelcom/Contactez-support-Intelcom.ca/" style=3D"TEXT-DECORATION: none;=
BACKGROUND: #04ab94; MARGIN-TOP: 20px; FONT-WEIGHT: bold; COLOR: #ffffff; =
PADDING-BOTTOM: 12px; PADDING-TOP: 12px; PADDING-LEFT: 25px; DISPLAY: =
inline-block; PADDING-RIGHT: 25px; border-radius: 6px">Manage My Delivery =
#f1f1f1; COLOR: #888; PADDING-BOTTOM: 20px; TEXT-ALIGN: center; =
PADDING-TOP: 20px; PADDING-LEFT: 20px; PADDING-RIGHT: 20px">
This is an automated message. Please do not reply.=
© 2026 Intelcom Express