Emergency kit phish from Google Gmail
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 12 Sep 2025 12:17:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1ux8Jg-00000000NMO-01oG
for dave@doctor.nl2k.ab.ca;
Fri, 12 Sep 2025 12:16:12 -0600
Resent-From: The Doctor
Resent-Date: Fri, 12 Sep 2025 12:16:11 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-il1-f169.google.com ([209.85.166.169]:43258)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1ux8CA-00000000Mdr-3oC6
for root@nl2k.ab.ca;
Fri, 12 Sep 2025 12:08:35 -0600
Received: by mail-il1-f169.google.com with SMTP id e9e14a558f8ab-3fe48646d40so17503865ab.0
for; Fri, 12 Sep 2025 11:07:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=ziip-quickcartstores-com.20230601.gappssmtp.com; s=20230601; t=1757700454; x=1758305254; darn=nl2k.ab.ca;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:from:to:cc:subject:date
:message-id:reply-to;
bh=8cMnRnz8y45wYuvIaJO7x4VUEuKuJVkzbqITkyzg2oc=;
b=IgZyNQm1fYe9vR4mA7pc5PpJJNoVzG352POFXJXNvfTuSmFSToD7NAof10dyKtAXld
CUf0KAYSv7+S2Fkgqgz6DUDQqNLHM9cfS8fiMawykpdXeGNpVRAKO6CfmgiG+v0YIvG2
WiHpOLAzwc2cJFycUafrKDWAe+8lMOE5aHEU+Gj8F8DTonUklsqAqzgXM273kM0YAtcd
ZI/aEHHK8u+g7+F1JWclIxP1QLt0e/LNn92cUZd9/p9pp5d3T4pjiCZrkoLi6GfIV3jG
senvLa7pmdpcO0HZCkXzgrBbhSQ8R52+583KcuenIk8+x8mMV4p8LS5FLjpiJqCye8/S
Z9wQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1757700454; x=1758305254;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:x-gm-message-state:from:to:cc
:subject:date:message-id:reply-to;
bh=8cMnRnz8y45wYuvIaJO7x4VUEuKuJVkzbqITkyzg2oc=;
b=I8jZholi0zjX/+ZuWEqVsJTvrBCtnVnFkW7ESkR+fMiLjWeyc5kDsbRlXHMjGKcOPM
pjMNrooIWLv7mmTukrO6kAY0A42ihlLDf1gfg3K4o4+THH3oMe/0I7hURab4JVwta4z2
dRkPrLkfNWWhPhCO6al5q+cheCJJO5APRznKm7Rh/d98prX8S8mvulWQAipSgSefu9ou
siE1FKN+RFDuxN1YJPeKSaRa8vzAefUQ2lT8vB7huHFZS3wfusNGfPIWOiGPqkzca6+I
Kd0Jk+bZcmUPof2GXzF3fIbcwQOX2VbRo5QpnBFC4ewm4yqaHot50Kflbo7HwCgrgtG+
5Atg==
X-Gm-Message-State: AOJu0YwbEvvwFsisx+CvQ9wc+KxbIbaRdMOjgCFLa1OnbHEaekzzJvni
L0X1Z9oi40pfwugVxKptqQgRIFWkuqTeWkyjhpg/enUkJa1qgNLosfdcrG0sTdX1+i6crLMMfqw
CoUUBKFGC5g==
X-Gm-Gg: ASbGnctJY7G2HQWfCQX5LQ28xcCScAJGajfLnr+rph7vkdo+dF9CtuYvI53FXktFfN8
tSWnuK/umkISTW5WvDh3fKjmtTg3FyzptvW+nR1y1uqi4uqezI56StuShMgC+4EFznqSqvscKy9
9oZUgHsJZB2e0Dm7wxRntqpvgeF5N40yeHYE1Ghdu6YgjcKaWu4bdhkmvOE95knPGyLhsTUteAO
3D9QCnfc4d9npji0ndN0TfJJxTGipxX5bABXf2bDGCExAXAmzLBNpXSMMIPptsKypOsanV5Zo9/
zEalOEKuK/fLkL8B2MJXAoyjHWzzERD+L36Nj5hxx8YvLuOf1pDse9cwKZRepCVCcjOJ/l8oJw+
hXg==
X-Google-Smtp-Source: AGHT+IFyE8YNYkTQBIwWP7X0UUlJEHUsfI5lgSAkYFnpfP23AMhADuvYqVNLXskm8+pRl8SQLcRhwg==
X-Received: by 2002:a05:6e02:270a:b0:423:378b:7af6 with SMTP id e9e14a558f8ab-423378b7d38mr22503685ab.4.1757700453276;
Fri, 12 Sep 2025 11:07:33 -0700 (PDT)
Received: from wzciuarpiqt.com ([52.176.7.21])
by smtp.gmail.com with ESMTPSA id e9e14a558f8ab-41df02f4e8csm22937445ab.19.2025.09.12.11.07.32
for
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 12 Sep 2025 11:07:32 -0700 (PDT)
From: CAA Car Emergency Kit Department
X-Google-Original-From: CAA Car Emergency Kit Department
Received: by wzciuarpiqt.com for; Fri, 12 Sep 2025 19:07:32 +0100 (envelope-from <>)
X-Google-Original-Sender: info_pmhajavyli@uses-quality.namecheap.com
MIME-Version: 1.0
subject:Expires soon: your CAA Car Emergency Kit reward
date:Fri, 12 Sep 2025 11:07:32 -0700
to:root@nl2k.ab.ca
Precedence: bulk
X-Mailer-id:<487068814-root@ruVHc11H.com>
List-Unsubscribe:,
reply-to:
Content-Disposition: inline
Message-Id:<232369-487068814-104539-TbpCuh@ruVHc11H.com>
X-Rival-Recipient: J7n6h0H327374Oe7h627007NmQ7dsO215KBe17t53310Q65j5bv51009159W
X-Gm-Features: 66fJ6ktZd4I5Zpa3Qd3ev70707v6o2PnT7V5839k_1IUb499668YZ5T26_-46rAB
Content-Type: multipart/alternative;
boundary="==00000000000053K153le8348706881453K153le83"
X-Spam_score: 12.5
X-Spam_score_int: 125
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Home Depot Confirmation [#38235-124] - CAA Car Emergency
Kit
Content analysis details: (12.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.166.169 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
[52.176.7.21 listed in dnsbl.ahbl.org]
[52.176.7.21 listed in dnsbl.ahbl.org]
[52.176.7.21 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.3 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
2.5 HDRS_MISSP Misspaced headers
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.166.169 listed in wl.mailspike.net]
1.8 COMBO_IMAGEONLY1 Appears to be an image only message
Subject: {SPAM?} Expires soon: your CAA Car Emergency Kit reward
--==00000000000053K153le8348706881453K153le83
Content-Type:text/html; charset=UTF-8
Home Depot
--==00000000000053K153le8348706881453K153le83--
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 12 Sep 2025 12:17:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ux8Jg-00000000NMO-01oG
for dave@doctor.nl2k.ab.ca;
Fri, 12 Sep 2025 12:16:12 -0600
Resent-From: The Doctor
Resent-Date: Fri, 12 Sep 2025 12:16:11 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-il1-f169.google.com ([209.85.166.169]:43258)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1ux8CA-00000000Mdr-3oC6
for root@nl2k.ab.ca;
Fri, 12 Sep 2025 12:08:35 -0600
Received: by mail-il1-f169.google.com with SMTP id e9e14a558f8ab-3fe48646d40so17503865ab.0
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=ziip-quickcartstores-com.20230601.gappssmtp.com; s=20230601; t=1757700454; x=1758305254; darn=nl2k.ab.ca;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:from:to:cc:subject:date
:message-id:reply-to;
bh=8cMnRnz8y45wYuvIaJO7x4VUEuKuJVkzbqITkyzg2oc=;
b=IgZyNQm1fYe9vR4mA7pc5PpJJNoVzG352POFXJXNvfTuSmFSToD7NAof10dyKtAXld
CUf0KAYSv7+S2Fkgqgz6DUDQqNLHM9cfS8fiMawykpdXeGNpVRAKO6CfmgiG+v0YIvG2
WiHpOLAzwc2cJFycUafrKDWAe+8lMOE5aHEU+Gj8F8DTonUklsqAqzgXM273kM0YAtcd
ZI/aEHHK8u+g7+F1JWclIxP1QLt0e/LNn92cUZd9/p9pp5d3T4pjiCZrkoLi6GfIV3jG
senvLa7pmdpcO0HZCkXzgrBbhSQ8R52+583KcuenIk8+x8mMV4p8LS5FLjpiJqCye8/S
Z9wQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1757700454; x=1758305254;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:x-gm-message-state:from:to:cc
:subject:date:message-id:reply-to;
bh=8cMnRnz8y45wYuvIaJO7x4VUEuKuJVkzbqITkyzg2oc=;
b=I8jZholi0zjX/+ZuWEqVsJTvrBCtnVnFkW7ESkR+fMiLjWeyc5kDsbRlXHMjGKcOPM
pjMNrooIWLv7mmTukrO6kAY0A42ihlLDf1gfg3K4o4+THH3oMe/0I7hURab4JVwta4z2
dRkPrLkfNWWhPhCO6al5q+cheCJJO5APRznKm7Rh/d98prX8S8mvulWQAipSgSefu9ou
siE1FKN+RFDuxN1YJPeKSaRa8vzAefUQ2lT8vB7huHFZS3wfusNGfPIWOiGPqkzca6+I
Kd0Jk+bZcmUPof2GXzF3fIbcwQOX2VbRo5QpnBFC4ewm4yqaHot50Kflbo7HwCgrgtG+
5Atg==
X-Gm-Message-State: AOJu0YwbEvvwFsisx+CvQ9wc+KxbIbaRdMOjgCFLa1OnbHEaekzzJvni
L0X1Z9oi40pfwugVxKptqQgRIFWkuqTeWkyjhpg/enUkJa1qgNLosfdcrG0sTdX1+i6crLMMfqw
CoUUBKFGC5g==
X-Gm-Gg: ASbGnctJY7G2HQWfCQX5LQ28xcCScAJGajfLnr+rph7vkdo+dF9CtuYvI53FXktFfN8
tSWnuK/umkISTW5WvDh3fKjmtTg3FyzptvW+nR1y1uqi4uqezI56StuShMgC+4EFznqSqvscKy9
9oZUgHsJZB2e0Dm7wxRntqpvgeF5N40yeHYE1Ghdu6YgjcKaWu4bdhkmvOE95knPGyLhsTUteAO
3D9QCnfc4d9npji0ndN0TfJJxTGipxX5bABXf2bDGCExAXAmzLBNpXSMMIPptsKypOsanV5Zo9/
zEalOEKuK/fLkL8B2MJXAoyjHWzzERD+L36Nj5hxx8YvLuOf1pDse9cwKZRepCVCcjOJ/l8oJw+
hXg==
X-Google-Smtp-Source: AGHT+IFyE8YNYkTQBIwWP7X0UUlJEHUsfI5lgSAkYFnpfP23AMhADuvYqVNLXskm8+pRl8SQLcRhwg==
X-Received: by 2002:a05:6e02:270a:b0:423:378b:7af6 with SMTP id e9e14a558f8ab-423378b7d38mr22503685ab.4.1757700453276;
Fri, 12 Sep 2025 11:07:33 -0700 (PDT)
Received: from wzciuarpiqt.com ([52.176.7.21])
by smtp.gmail.com with ESMTPSA id e9e14a558f8ab-41df02f4e8csm22937445ab.19.2025.09.12.11.07.32
for
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 12 Sep 2025 11:07:32 -0700 (PDT)
From: CAA Car Emergency Kit Department
X-Google-Original-From: CAA Car Emergency Kit Department
Received: by wzciuarpiqt.com for
X-Google-Original-Sender: info_pmhajavyli@uses-quality.namecheap.com
MIME-Version: 1.0
subject:Expires soon: your CAA Car Emergency Kit reward
date:Fri, 12 Sep 2025 11:07:32 -0700
to:root@nl2k.ab.ca
Precedence: bulk
X-Mailer-id:<487068814-root@ruVHc11H.com>
List-Unsubscribe:
reply-to:
Content-Disposition: inline
Message-Id:<232369-487068814-104539-TbpCuh@ruVHc11H.com>
X-Rival-Recipient: J7n6h0H327374Oe7h627007NmQ7dsO215KBe17t53310Q65j5bv51009159W
X-Gm-Features: 66fJ6ktZd4I5Zpa3Qd3ev70707v6o2PnT7V5839k_1IUb499668YZ5T26_-46rAB
Content-Type: multipart/alternative;
boundary="==00000000000053K153le8348706881453K153le83"
X-Spam_score: 12.5
X-Spam_score_int: 125
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Home Depot Confirmation [#38235-124] - CAA Car Emergency
Kit
Content analysis details: (12.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[52.176.7.21 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
[209.85.166.169 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.166.169 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
[52.176.7.21 listed in dnsbl.ahbl.org]
[52.176.7.21 listed in dnsbl.ahbl.org]
[52.176.7.21 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
[209.85.166.169 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.176.7.21 listed in dnsbl.ahbl.org]
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.3 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
2.5 HDRS_MISSP Misspaced headers
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.166.169 listed in wl.mailspike.net]
1.8 COMBO_IMAGEONLY1 Appears to be an image only message
Subject: {SPAM?} Expires soon: your CAA Car Emergency Kit reward
--==00000000000053K153le8348706881453K153le83
Content-Type:text/html; charset=UTF-8
--==00000000000053K153le8348706881453K153le83--