Shoppers surprise phish from Google Gmail
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 07 Oct 2025 11:33:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1v6BYF-00000000E3N-1CjF
for dave@doctor.nl2k.ab.ca;
Tue, 07 Oct 2025 11:32:39 -0600
Resent-From: The Doctor
Resent-Date: Tue, 7 Oct 2025 11:32:39 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-vk1-f198.google.com ([209.85.221.198]:56761)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1v6Axi-00000000624-1hho
for support@nk.ca;
Tue, 07 Oct 2025 10:55:01 -0600
Received: by mail-vk1-f198.google.com with SMTP id 71dfb90a1353d-54a939c158bso10287671e0c.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1759856041; x=1760460841; darn=nk.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=c5IyRDwh1B0yYZI+nZowWaI8kHX1FV7RpCbCGpP2AcA=;
b=cMtzYig5+SE4rLibYGKCj2xHHJLuA6rr0uwgxqeboDCpoaTZWOHC49G0yl2M9rDLAK
4Z6pmlraGlpimzYxbwHi/uq/AEiCju8GA8kL2oI/dCJ2wfkQehnwdqFrZZlZ5/ZVUSO9
daIhvgZ4WfJS0syvAlJFTNCyVpPiolpwMYha1+zSr3RV1cRXC8APAqXoHQsBdrNbJv2K
EXBcndQMyvTspZr2vUNEMoo7b42F2cTPuYauWqXE4zDgw2HorhVuqrwa1UOrUTq0xKY5
/KpCii5A49Qqv1CDUqUGngkGTT1IOklrLgj6oFo9zaTmMOsLcdOkTHZBvQzv8P2sLhaA
tNcw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1759856041; x=1760460841;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=c5IyRDwh1B0yYZI+nZowWaI8kHX1FV7RpCbCGpP2AcA=;
b=LKkchie3GueaGoThVu4VYcUajJEerWKKPUTJk3oEojn04JSRkrcv7Vw3SWMTXG5g3o
yt2M9RJ5Ng2Lp77nl9YeOi6FBVWzFu/rRJsTtue9v3GsztwWU5Nxr/4FSNNlYLvt5oA/
d/4Ch5ilMvoFydnuTCMfm2z+SodpRfQIiAD1ptCGcL9v/y7bfMWnyEorL+QK7038ripZ
1mAzpP1dHpkddtPYt+B7MAH45BMybxHKDRmEHueYUGE/fkL7PC9zUBL0fDut933xwtnM
g+7hqLw8y9rAGLxf1EyjJCmSUZA96dSvUJKRQ+KiSEiokD6CG3br9ZvUaCWpflc3P32X
36/w==
X-Gm-Message-State: AOJu0YwhYSfdobRA8b5GQJunBpOFy9X4lsnAAf/d0FYvw3HYhq5jbzQd
Bi6Iy94I3UBUdZaIVHM5ztLcq7FJ+Chjg4y7Ed7O9zRdMT2wRwJGtlc/UZ5MqBqTpTPKkJNQjCI
Z4F5huIhKSg==
X-Google-Smtp-Source: AGHT+IFJOMMwsm8y3yH+QP0otqqFZ5z2wjOMd/BLeXi7MaNYOLwvx0dEw+OA0hTNF0AAt+q+Zit7zKcltybv2KI=
MIME-Version: 1.0
X-Received: by 2002:a05:6122:c87:b0:54a:9fe8:171e with SMTP id
71dfb90a1353d-554b8b167a1mr147995e0c.7.1759856041649; Tue, 07 Oct 2025
09:54:01 -0700 (PDT)
Message-ID: <00000000000037e8e80640946a53@google.com>
Date: Tue, 07 Oct 2025 16:54:01 +0000
Subject: =?UTF-8?Q?=E2=9A=A1_Conrgratulations=2C_You=27ve_been_chosen_to_receive_?=
=?UTF-8?Q?your_Free_Oral=2DB_Kit_Today?=
From: Shoppers Surprise
To: support@nk.ca
Content-Type: multipart/alternative; boundary="00000000000037e8df0640946a50"
X-Spam_score: 11.8
X-Spam_score_int: 118
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Your smile deserves this! Only a few free Oral-B kits left
- confirm yours now. Your smile deserves this! Only a few free Oral-B kits
left - confirm yours now.
Content analysis details: (11.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
[209.85.221.198 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.221.198 listed in dnsbl.ahbl.org]
[209.85.221.198 listed in dnsbl.ahbl.org]
[209.85.221.198 listed in dnsbl.ahbl.org]
[209.85.221.198 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.221.198 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.221.198 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.221.198 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.221.198 listed in dnsbl.ahbl.org]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: eblink6.com]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: eblinks.cc]
0.0 URIBL_RED Contains an URL listed in the URIBL redlist
[URI: eblink6.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.221.198 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
1.0 OFFER_URI URI: Offer in link address
0.8 HTML_IMAGE_RATIO_02 BODY: HTML has a low ratio of text to image area
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
1.0 VOWEL_URI_5 URI hostname with 5 consecutive vowels
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 T_REMOTE_IMAGE Message contains an external image
Subject: {SPAM?} =?UTF-8?Q?=E2=9A=A1_Conrgratulations=2C_You=27ve_been_chosen_to_receive_?=
=?UTF-8?Q?your_Free_Oral=2DB_Kit_Today?=
--00000000000037e8df0640946a50
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
Your smile deserves this! Only a few free Oral-B kits left - confirm yours
now.
--00000000000037e8df0640946a50
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
ft-com:vml" xmlns:o=3D"urn:schemas-microsoft-com:office:office">
=20
=20
=20
=20
/>=20
1" />=20
=20
=20
=20
=20
0,700" rel=3D"stylesheet" type=3D"text/css" />=20
=20
=20
=20
=20
=20
=20
=20
=20
rmal; background-color: #ffffff;" class=3D" eb-drag-and-drop-builder">=20
role=3D"presentation" style=3D"width:100%;">=20
=20
=20
=3D"0" role=3D"presentation" style=3D"width:100%;">=20
=20
;text-align:center;">=20
=20
-eb_f4498a85-ab6f-471b-afd3-d22280a702e2" style=3D"background:#ffffff;backg=
round-color:#ffffff;margin:0px auto;max-width:700px;">=20
cing=3D"0" role=3D"presentation" style=3D"background:#ffffff;background-col=
or:#ffffff;width:100%;">=20
10px 10px;text-align:center;">=20
=20
column-eb_70aa9164-3db5-43bf-8fd6-0b852b823ccd" style=3D"font-size:0px;text=
-align:left;direction:ltr;display:inline-block;vertical-align:top;width:100=
%;">=20
ole=3D"presentation" width=3D"100%">=20
x ;">=20
0" role=3D"presentation" style=3D"" width=3D"100%">=20
b4c5-22d1-4821-854c-ddf7f0952595 eb-image-full-width max-width-100 eb-image=
" style=3D"background:transparent;font-size:0px;padding:5px 5px 0px 5px;wor=
d-break:break-word;">=20
=3D"0" role=3D"presentation" style=3D"min-width:100%;max-width:100%;width:6=
70px;border-collapse:collapse;border-spacing:0px;width:100%;" class=3D"mj-f=
ull-width-mobile">=20
th-mobile">
lid=3D5030782218010624&nid=3D5023440206299136&" target=3D"_blank" style=3D"=
color: #c7c7c7; text-decoration: none;" data-eblinkid=3D"5030782218010624">=
69312/Screenshot_2025_10_07_at_18_29_07_AT_T_North_Face_Backpack_Max_Offer.=
png" style=3D"border:0px solid #3498DB;border-radius:0px;display:block;outl=
ine:none;text-decoration:none;height:auto;min-width:100%;width:100%;max-wid=
th:100%;font-size:13px;max-width:100%;box-sizing: border-box;width:100%;" w=
idth=3D"670" height=3D"auto" /> =20
=20
d40f-7a11-40f0-96e8-7e60702f0dc0 eb-image-full-width max-width-100 eb-image=
" style=3D"background:transparent;font-size:0px;padding:0px 5px 5px 5px;wor=
d-break:break-word;">=20
=3D"0" role=3D"presentation" style=3D"min-width:100%;max-width:100%;width:6=
70px;border-collapse:collapse;border-spacing:0px;width:100%;" class=3D"mj-f=
ull-width-mobile">=20
th-mobile">
lid=3D6046258884771840&nid=3D5023440206299136&" target=3D"_blank" s=
tyle=3D"color: #c7c7c7; text-decoration: none;" data-eblinkid=3D"6046258884=
771840">
5726607939469312/Screenshot_2025_10_07_at_18_34_23_AT_T_North_Face_Backpack=
_Max_Offer.png" style=3D"border:0px solid #3498DB;border-radius:0px;display=
:block;outline:none;text-decoration:none;height:auto;min-width:100%;width:1=
00%;max-width:100%;font-size:13px;max-width:100%;box-sizing: border-box;wid=
th:100%;" width=3D"670" height=3D"auto" /> =20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
role=3D"presentation" style=3D"width:100%;">=20
=20
=20
=3D"0" role=3D"presentation" style=3D"width:100%;">=20
=20
;text-align:center;">=20
=20
eb_ad6c6978-d121-4253-b9b1-65a8dc477eb3" style=3D"background:#ffffff;backgr=
ound-color:#ffffff;margin:0px auto;max-width:700px;">=20
cing=3D"0" role=3D"presentation" style=3D"background:#ffffff;background-col=
or:#ffffff;width:100%;">=20
10px 10px;text-align:center;">=20
=20
column-eb_a7a3f9c9-2ca5-41ce-992a-ba1f3403cad6" style=3D"font-size:0px;text=
-align:left;direction:ltr;display:inline-block;vertical-align:top;width:100=
%;">=20
ole=3D"presentation" width=3D"100%">=20
x ;">=20
0" role=3D"presentation" style=3D"" width=3D"100%">=20
a6-a753-4e12-82bc-517e9d2e1cb1" style=3D"font-size:0px;padding:0;word-break=
:break-word;">=20
l, sans-serif;font-size:13px;font-weight:normal;line-height:1.6;text-align:=
left;color:#000000;"> =20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
role=3D"presentation" style=3D"width:100%;">=20
=20
=20
=3D"0" role=3D"presentation" style=3D"width:100%;">=20
=20
;text-align:center;">=20
=20
round:transparent;background-color:transparent;margin:0px auto;max-width:70=
0px;">=20
cing=3D"0" role=3D"presentation" style=3D"background:transparent;background=
-color:transparent;width:100%;">=20
x 0px;text-align:center;">=20
=20
column-undefined" style=3D"font-size:0px;text-align:left;direction:ltr;disp=
lay:inline-block;vertical-align:top;width:100%;">=20
ole=3D"presentation" width=3D"100%">=20
0" role=3D"presentation" style=3D"" width=3D"100%">=20
dc63668febe6" style=3D"background:transparent;font-size:0px;word-break:brea=
k-word;">=20
=E2=80=8A=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
--00000000000037e8df0640946a50--