Cloud Credential Phish from Google Gmail Part 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 20 Mar 2026 05:41:01 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w3YDU-00000000PyK-2Hmy
for dave@doctor.nl2k.ab.ca;
Fri, 20 Mar 2026 05:40:36 -0600
Resent-From: The Doctor
Resent-Date: Fri, 20 Mar 2026 05:40:36 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-ot1-f70.google.com ([209.85.210.70]:56637)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w3Vgm-00000000CjH-0b9O
for root@nk.ca;
Fri, 20 Mar 2026 02:58:47 -0600
Received: by mail-ot1-f70.google.com with SMTP id 46e09a7af769-7d7e995a87cso8629137a34.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1773997065; x=1774601865; darn=nk.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=QOHq7jyCdSP8vzHUidZSCnti7MOpsZPIfQEjn/+cFXc=;
b=BVVHOWmHj9ud9scEpE24XjGENVEliNImQP9QT20poGmiwJeDnwf0Y2JqZ9sSzeUMI1
NUZx5P3AZoo7hQOHS6HytqhNLquDine8xVazBjFhCNbwXF6AQQfsD/e7FhAdgFQmjwtS
Nk/FFzlolR2Qsv2lWJiFEHRvni3m8tVoLO9Kqb1sObkDqKL0P+1Hiy58b1/zavzvb19p
yjdZaCUoTh8WPGaf36vE3FiU7So79u3l+Svt3smoSeVtIDJ/p95zQWsjdiI3nJV/6EOZ
p+vsl2xJ16OJn3fTLbafPGVl4GfKFiSBrxUWr316fDSiYKRcNRSybf/r0YIU08z9xsij
NMQQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1773997065; x=1774601865;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=QOHq7jyCdSP8vzHUidZSCnti7MOpsZPIfQEjn/+cFXc=;
b=AXimz4t4lALRt+S7rTH+wNVmxef8s2NCTxYicdT3F8pRmZMvVSQ4jPVE16cuANRu6K
zAlm6sBHwzVUrnR6BfaTESVBDYQuoz5+lY8GI0p2ytCBcOVfWTSB9xPd7YcLJMSwgQU3
EJps5n4Iag9AFirYm5CKNQQjmXzQIVnWWYlVflnh/EtNCXImsK/mSYhnhCUNEO8rKmql
O1uNfN80nXh5zNFOtJpxcjUvGP/DOY9RLuaRMR7QLwhPTOgInurkkLAB/dsQMq7LsZF6
l08DEjRMDa4iOjT/rgnzRbacqHoScbeNhe6rAQfpYiBZAKseldNCRmEQJQtA5I0MwgSa
kTOA==
X-Gm-Message-State: AOJu0YzBlP1ONDh71stGa0XWV8QrLnmiFd3pSazw/W/bEc9aXYI5Zu+L
B2dDrLPtusTkGPypqq5viTrt7YBRGDK85E5gGD4G9qRT9FsJECE2bMH9gfFmvKiJAWCVJPtWFHp
yisgKz0O3/Q==
MIME-Version: 1.0
X-Received: by 2002:a05:6820:138f:b0:67b:f1c8:edc2 with SMTP id
006d021491bc7-67c22fab1d8mr1865478eaf.54.1773997065471; Fri, 20 Mar 2026
01:57:45 -0700 (PDT)
Message-ID: <000000000000eb867e064d70e02e@google.com>
Date: Fri, 20 Mar 2026 08:57:45 +0000
Subject: Storage Limit Reached (100%)
From: Cloud Storage
To: root@nk.ca
Content-Type: multipart/alternative; boundary="000000000000eb866e064d70e02b"
X-Spam_score: 5.0
X-Spam_score_int: 50
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: ! System Alert: Uploads Paused Disabled Your Cloud is Disabled
Content analysis details: (5.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
[209.85.210.70 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.210.70 listed in dnsbl.ahbl.org]
[209.85.210.70 listed in dnsbl.ahbl.org]
[209.85.210.70 listed in dnsbl.ahbl.org]
[209.85.210.70 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.210.70 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.210.70 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.210.70 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.210.70 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.210.70 listed in list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)
[209.85.210.70 listed in wl.mailspike.net]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} Storage Limit Reached (100%)
--000000000000eb866e064d70e02b
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
!
System Alert: Uploads Paused
Disabled
Your Cloud is Disabled
We cannot sync your photos or documents because your storage is full and
your subscription is inactive.
Used: 50.0 GB Limit: 50.0 GB
Reactivate Storage Now
Sent automatically by Cloud Services. Unsubscribe.
--000000000000eb866e064d70e02b
Content-Type: text/html; charset="UTF-8"
