Paypal Phish from Google Gmail Part 1
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 21 Jan 2026 15:34:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1viglu-00000000A5e-3Qmr
for dave@doctor.nl2k.ab.ca;
Wed, 21 Jan 2026 15:33:54 -0700
Resent-From: The Doctor
Resent-Date: Wed, 21 Jan 2026 15:33:54 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-vs1-f50.google.com ([209.85.217.50]:60590)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from <16917@rk.ac.th>)
id 1viakY-00000000Fnr-3wK2
for doctor@doctor.nl2k.ab.ca;
Wed, 21 Jan 2026 09:08:15 -0700
Received: by mail-vs1-f50.google.com with SMTP id ada2fe7eead31-5f52e500e89so260847137.0
for; Wed, 21 Jan 2026 08:07:20 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=rk-ac-th.20230601.gappssmtp.com; s=20230601; t=1769011634; x=1769616434; darn=doctor.nl2k.ab.ca;
h=mime-version:subject:from:to:date:message-id:from:to:cc:subject
:date:message-id:reply-to;
bh=RBJQqhVM+Q3BWN6snnUcK3NC4MhE5OxnM1cAKi4VugE=;
b=o2pxt6oKe9WgSpAaBxq8ljhtnMj+RhcauAhdE+CPn/rU+hHKu0apySm5SUyegz3QS8
lK3DE0LIh6ianY9Aup8FeDrxmNMG+jhtyMuiuQTODfzhYIKvyaTyM1g/6aLecKOiXaea
4FD/D1GP0U9rvnfb0+nOMRUPU1lRGtTWAJjneM8i3L4C0NoMUuQn210G76VfFmyoHoGz
sZZgJeAHsGMJz+d2SkpYo5AIn5BjhNZqFhBgSik9fmbiSEE2JYVQ2JXsRf3aRK91Ozfq
1uX77UcAsvBjl71UNtoUyzTV59Bqlz794Vi5iULpDb1nfsFuu8vpKry2KqLEZ9EN6ukg
O4Cw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1769011634; x=1769616434;
h=mime-version:subject:from:to:date:message-id:x-gm-gg
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=RBJQqhVM+Q3BWN6snnUcK3NC4MhE5OxnM1cAKi4VugE=;
b=oXiYNE9ZKzNFJWA9qeLmCwammT6R4tAeOrRvmfQMaqWrDauASyHe6bb5cHePPTgvMZ
uFPMLaJHeSx8EfWFfMNqtp96uRDVPsmbEX4Svw+XTpCLLEe3fx1q719wPvwEqOjnxr+i
svhIRt+WgQpeWDo3jKSbdq5UrMWkzV0Cps9XM3HrJ7zCfaquLqUTzXOiETvBLhPSDSPG
ck77SkVlVnKcpXKq0uoNJOyqt+S4+y7/zougXRztZa7UUs6tQ6YeykatZWTMzxNjkooE
7eTbWURiiAK2akxoFh7068HzFqR32Zb9ToX3rGvhePsbjw4/MfxfvpDp4c75JYovyrtM
e8Pg==
X-Gm-Message-State: AOJu0YzhY/GC9smPKolTLScHdfvrmZecXmOZiKSdwao/KN+Jk87Fk2rN
ny/VN+ji/ViyUdZVZ5jQ8dfeCr9cEd6CjrtFly3sLQ+fy6CTuZ00K4WxB2BCU8WoAyrD2Q+gRWk
DQiyp
X-Gm-Gg: AZuq6aIU2a2mKDiQgahNdiUTfkFkkYcXY/hy4btTZHIwI8dBhvSK/dgCVjE4HFfsQCX
fguRNQ2PTPdq8vh4P0+/KDicMlQHVXvexnveLeGdV158Due8gSGWIEC8a4ECPkFUedqZ+VXimE6
Qj50Im2oCLrop5KyhRwvH+ZxSGZdswqLMcXBxiw7ABLGQ4r1jCkfZFYDxB1Vo2xd52GzKRECd34
v19m0i+EDlsltG7FpwLQKXtLfAy9ORZcyBn+03gN4xmK0CDmy8Ky+BOqjvNe062Rrjd3LCahBRs
Ss3kcVFEDBJquuJRmYedhf17tbE9JzRSDkfUeYRmnE4dS1C0ixY38Q83BEGeI/VZ/nHrL2R27Cj
5MTFsT7rqxn8n4FVeOJZXOBADTT5cqEauC2HKNRfwa1HuuSc0Omv0OQiEEukTZwhfXpRJpoS6xM
UmeJVlmmim+0XQeXs=
X-Received: by 2002:a17:903:1ac4:b0:295:8dbb:b3cd with SMTP id d9443c01a7336-2a769eb9dd3mr50290885ad.27.1769011199326;
Wed, 21 Jan 2026 07:59:59 -0800 (PST)
Received: from pc ([59.153.17.129])
by smtp.gmail.com with ESMTPSA id d9443c01a7336-2a719415f0asm103181965ad.89.2026.01.21.07.59.58
for
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Wed, 21 Jan 2026 07:59:58 -0800 (PST)
Message-ID: <6970f7fe.170a0220.233e6d.5e8b@mx.google.com>
Date: Wed, 21 Jan 2026 07:59:58 -0800 (PST)
To:
From: Invoice Confirmation!! <16917@rk.ac.th>
Subject: Good news! ID G4S6ND has been unlocked.
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary=QedYcNJaRuaUzMDRZ30Jsj
X-Spam_score: 15.3
X-Spam_score_int: 153
X-Spam_bar: +++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Ord Date: January 21,2026 Bill ID: ZB-05JH-XHER-765478 Transaction
ID: 0023132
Content analysis details: (15.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
[209.85.217.50 listed in dnsbl.ahbl.org]
[209.85.217.50 listed in dnsbl.ahbl.org]
[209.85.217.50 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[59.153.17.129 listed in sbl-xbl.spamhaus.org]
[59.153.17.129 listed in sbl-xbl.spamhaus.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.217.50 listed in list.dnswl.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[59.153.17.129 listed in zen.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.217.50 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 TW_FD BODY: Odd Letter Triples with FD
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.7 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags
2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length
greater than 79 characters
0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or Formatted
Colors in HTML
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 NO_RDNS2 Sending MTA has no reverse DNS
Subject: {SPAM?} Good news! ID G4S6ND has been unlocked.
Date: January 21,2026
Bill ID: ZB-05JH-XHER-765478
Transaction ID: 0023132
Thank You For Your Order!
In response to Member,
We are proud to be your favourite payment system provider and we appreciate your transaction with us.
Kindly check the order details below. Also the order can be cancelled or modified within 12 hours of the transaction.
Reach out to us on +1 (805) 221-4237. in case you change your mind.
PayPal Customer Id :
WCgfQhfdzWRw
PurchasedRItem
Amazon Prime
@$499.99 USD
Quantity @(4 Devices)
TOTAL @$499.99 USD
Payment Method: Auto debit from your bank account.
If you didn't initiate this purchase or this payment is not made by you, directly reach out our support at +1 (805) 221-4237.
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 21 Jan 2026 15:34:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1viglu-00000000A5e-3Qmr
for dave@doctor.nl2k.ab.ca;
Wed, 21 Jan 2026 15:33:54 -0700
Resent-From: The Doctor
Resent-Date: Wed, 21 Jan 2026 15:33:54 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-vs1-f50.google.com ([209.85.217.50]:60590)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from <16917@rk.ac.th>)
id 1viakY-00000000Fnr-3wK2
for doctor@doctor.nl2k.ab.ca;
Wed, 21 Jan 2026 09:08:15 -0700
Received: by mail-vs1-f50.google.com with SMTP id ada2fe7eead31-5f52e500e89so260847137.0
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=rk-ac-th.20230601.gappssmtp.com; s=20230601; t=1769011634; x=1769616434; darn=doctor.nl2k.ab.ca;
h=mime-version:subject:from:to:date:message-id:from:to:cc:subject
:date:message-id:reply-to;
bh=RBJQqhVM+Q3BWN6snnUcK3NC4MhE5OxnM1cAKi4VugE=;
b=o2pxt6oKe9WgSpAaBxq8ljhtnMj+RhcauAhdE+CPn/rU+hHKu0apySm5SUyegz3QS8
lK3DE0LIh6ianY9Aup8FeDrxmNMG+jhtyMuiuQTODfzhYIKvyaTyM1g/6aLecKOiXaea
4FD/D1GP0U9rvnfb0+nOMRUPU1lRGtTWAJjneM8i3L4C0NoMUuQn210G76VfFmyoHoGz
sZZgJeAHsGMJz+d2SkpYo5AIn5BjhNZqFhBgSik9fmbiSEE2JYVQ2JXsRf3aRK91Ozfq
1uX77UcAsvBjl71UNtoUyzTV59Bqlz794Vi5iULpDb1nfsFuu8vpKry2KqLEZ9EN6ukg
O4Cw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1769011634; x=1769616434;
h=mime-version:subject:from:to:date:message-id:x-gm-gg
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=RBJQqhVM+Q3BWN6snnUcK3NC4MhE5OxnM1cAKi4VugE=;
b=oXiYNE9ZKzNFJWA9qeLmCwammT6R4tAeOrRvmfQMaqWrDauASyHe6bb5cHePPTgvMZ
uFPMLaJHeSx8EfWFfMNqtp96uRDVPsmbEX4Svw+XTpCLLEe3fx1q719wPvwEqOjnxr+i
svhIRt+WgQpeWDo3jKSbdq5UrMWkzV0Cps9XM3HrJ7zCfaquLqUTzXOiETvBLhPSDSPG
ck77SkVlVnKcpXKq0uoNJOyqt+S4+y7/zougXRztZa7UUs6tQ6YeykatZWTMzxNjkooE
7eTbWURiiAK2akxoFh7068HzFqR32Zb9ToX3rGvhePsbjw4/MfxfvpDp4c75JYovyrtM
e8Pg==
X-Gm-Message-State: AOJu0YzhY/GC9smPKolTLScHdfvrmZecXmOZiKSdwao/KN+Jk87Fk2rN
ny/VN+ji/ViyUdZVZ5jQ8dfeCr9cEd6CjrtFly3sLQ+fy6CTuZ00K4WxB2BCU8WoAyrD2Q+gRWk
DQiyp
X-Gm-Gg: AZuq6aIU2a2mKDiQgahNdiUTfkFkkYcXY/hy4btTZHIwI8dBhvSK/dgCVjE4HFfsQCX
fguRNQ2PTPdq8vh4P0+/KDicMlQHVXvexnveLeGdV158Due8gSGWIEC8a4ECPkFUedqZ+VXimE6
Qj50Im2oCLrop5KyhRwvH+ZxSGZdswqLMcXBxiw7ABLGQ4r1jCkfZFYDxB1Vo2xd52GzKRECd34
v19m0i+EDlsltG7FpwLQKXtLfAy9ORZcyBn+03gN4xmK0CDmy8Ky+BOqjvNe062Rrjd3LCahBRs
Ss3kcVFEDBJquuJRmYedhf17tbE9JzRSDkfUeYRmnE4dS1C0ixY38Q83BEGeI/VZ/nHrL2R27Cj
5MTFsT7rqxn8n4FVeOJZXOBADTT5cqEauC2HKNRfwa1HuuSc0Omv0OQiEEukTZwhfXpRJpoS6xM
UmeJVlmmim+0XQeXs=
X-Received: by 2002:a17:903:1ac4:b0:295:8dbb:b3cd with SMTP id d9443c01a7336-2a769eb9dd3mr50290885ad.27.1769011199326;
Wed, 21 Jan 2026 07:59:59 -0800 (PST)
Received: from pc ([59.153.17.129])
by smtp.gmail.com with ESMTPSA id d9443c01a7336-2a719415f0asm103181965ad.89.2026.01.21.07.59.58
for
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Wed, 21 Jan 2026 07:59:58 -0800 (PST)
Message-ID: <6970f7fe.170a0220.233e6d.5e8b@mx.google.com>
Date: Wed, 21 Jan 2026 07:59:58 -0800 (PST)
To:
From: Invoice Confirmation!! <16917@rk.ac.th>
Subject: Good news! ID G4S6ND has been unlocked.
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary=QedYcNJaRuaUzMDRZ30Jsj
X-Spam_score: 15.3
X-Spam_score_int: 153
X-Spam_bar: +++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Ord Date: January 21,2026 Bill ID: ZB-05JH-XHER-765478 Transaction
ID: 0023132
Content analysis details: (15.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
[209.85.217.50 listed in dnsbl.ahbl.org]
[209.85.217.50 listed in dnsbl.ahbl.org]
[209.85.217.50 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
[59.153.17.129 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.217.50 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[59.153.17.129 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
[209.85.217.50 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[59.153.17.129 listed in sbl-xbl.spamhaus.org]
[59.153.17.129 listed in sbl-xbl.spamhaus.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.217.50 listed in list.dnswl.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[59.153.17.129 listed in zen.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.217.50 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 TW_FD BODY: Odd Letter Triples with FD
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.7 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags
2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length
greater than 79 characters
0.0 T_KAM_HTML_FONT_INVALID BODY: Test for Invalidly Named or Formatted
Colors in HTML
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 NO_RDNS2 Sending MTA has no reverse DNS
Subject: {SPAM?} Good news! ID G4S6ND has been unlocked.
Date: January 21,2026
Bill ID: ZB-05JH-XHER-765478
Transaction ID: 0023132
Thank You For Your Order!
In response to Member,
We are proud to be your favourite payment system provider and we appreciate your transaction with us.
Kindly check the order details below. Also the order can be cancelled or modified within 12 hours of the transaction.
Reach out to us on +1 (805) 221-4237. in case you change your mind.
PayPal Customer Id :
WCgfQhfdzWRw
PurchasedRItem
Amazon Prime
@$499.99 USD
Quantity @(4 Devices)
TOTAL @$499.99 USD
Payment Method: Auto debit from your bank account.
If you didn't initiate this purchase or this payment is not made by you, directly reach out our support at +1 (805) 221-4237.