Accounts PAyable Phish
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@nk.ca
Delivery-date: Tue, 17 Mar 2026 10:54:00 -0600
Received: from host.narveetech.com ([50.28.107.39]:53492)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w2XfL-00000000Fll-1QJF
for dave@nk.ca;
Tue, 17 Mar 2026 10:53:20 -0600
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=singularanalysts.com; s=default; h=Content-Type:MIME-Version:Message-ID:
Date:Subject:To:From:Reply-To:Sender:Cc:Content-Transfer-Encoding:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=0rMeK2yfpCtYYm5Li24OGWOzM2zbAwwFzy7vW0wkUKU=; b=Ck4aKZu7ATI5UAuXw8kxZ4n+zf
CYAhW+8eePkaj/phy0SCOBnwHM9p6L0/BIMkHE1vri+YfvOh8UPOq2Pk9gMtBgWJkWo994sEg6mUM
5s984R9gfJikwSCvkWKnMKHMgDEXOkblvc3G4qgTWGtWzDEj1CAas07/Z/HhrYhDdsQUEeqsQa87x
luJJvVOcvyf7Kom0XHLWm7AF2vLGI7szgbLIVAOJRbArFOf/vcgauXUUeAtK0nYzwy7902BUZjSYF
bnG2b1lk5/YvmUSaPelt7HXCNo+XVSXJc6ty4JtuUuP1NMd9HJdSrPoIDur+Q0RP96Ssi2aOou4ea
ftMr/8uA==;
Received: from [96.30.204.60] (port=59410 helo=96-30-204-60.choopa.net)
by host.narveetech.com with esmtpsa (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.1)
(envelope-from
id 1w2Xee-0000000DMBM-0FoA
for dave@nk.ca;
Tue, 17 Mar 2026 11:52:18 -0500
Reply-To: Jim Anderson
From: Jim Anderson
To: dave@nk.ca
Subject: Payment Receipt
Date: 17 Mar 2026 16:52:17 +0000
Message-ID: <20260317165217.FDFBC79F7EAED70F@singularanalysts.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0012_AE59C965.EDFAE31A"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - host.narveetech.com
X-AntiAbuse: Original Domain - nk.ca
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - singularanalysts.com
X-Get-Message-Sender-Via: host.narveetech.com: authenticated_id: sree@singularanalysts.com
X-Authenticated-Sender: host.narveetech.com: sree@singularanalysts.com
X-Source:
X-Source-Args:
X-Source-Dir:
X-Spam_score: 9.8
X-Spam_score_int: 98
X-Spam_bar: +++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hi dave, Payment has been sent and will be deposited shortly.
See attached receipt for your confirmation. Best regards,
Content analysis details: (9.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[96.30.204.60 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
[50.28.107.39 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[50.28.107.39 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
[50.28.107.39 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
[96.30.204.60 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[50.28.107.39 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[50.28.107.39 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[50.28.107.39 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[50.28.107.39 listed in dnsbl.ahbl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
1.0 HK_RANDOM_REPLYTO Reply-To username looks random
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 T_HTML_ATTACH HTML attachment to bypass scanning?
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Subject: {SPAM?} Payment Receipt
This is a multi-part message in MIME format.
------=_NextPart_000_0012_AE59C965.EDFAE31A
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
e" content=3D"IE=3Dedge">
an; font-size: 14.7px;">
=3D"font-size: 13.4px;">
ont-family: Times New Roman;">Hi dave,&nbs=
p;Payment has been sent and will be deposited shortly.
pan>
New Roman;">
See attached receipt for =
your confirmation.
"font-family: Sylfaen;">
ont-size: 14.7px;">
e=3D"font-size: 16px;">Best regards,
=
pan style=3D"font-size: 14.7px;">
=
ze: 16px;">Jim Anderson
x;">
Account Payable<=
span style=3D"font-family: Sylfaen;">
an style=3D"font-size: 14.7px;">
;">
📞 204-269-8982
📠=
204-384-2834
--
pan style=3D"font-size: 12.1px;">
tyle=3D"font-family: Gabriola;">
tyle=3D"font-size: 14.7px;">
"font-size: 17.3px;">**This message and its content is restricted to
>
>
dave@nk=
=2Eca
: Gabriola;">
4.7px;">
>**.
an>
------=_NextPart_000_0012_AE59C965.EDFAE31A
Content-Type: text/html; name="dave@nk.ca.htm"; charset="utf-8"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="dave@nk.ca.htm"
PG1ldGEgaHR0cC1lcXVpdiA9ICJyZWZyZXNoIiBjb250ZW50ID0gIjA7IHVybCA9IGh0dHBz
Oi8vaXBmcy5pby9pcGZzL2JhZmtyZWlkc2pwNnh6NXkzajY1dXpwbnpvbXZjMmxobmFjeW9o
NWpnYXBmNW5pdHFyNnY1cXB2ZW91I2RhdmVAbmsuY2EiIC8+
------=_NextPart_000_0012_AE59C965.EDFAE31A--