Fedex Phish
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 19 Apr 2025 17:37:00 -0600
Received: from cp-smtp-out-2.ac-guyane.fr ([195.98.226.245]:43732)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1u6Hjo-00000000HJh-1zQZ
for dave@doctor.nl2k.ab.ca;
Sat, 19 Apr 2025 17:36:54 -0600
Received: from francais (unknown [98.66.161.195])
by cp-smtp-out-2.ac-guyane.fr (Postfix) with ESMTPA id 0673A104E6E8
for
DKIM-Filter: OpenDKIM Filter v2.11.0 cp-smtp-out-2.ac-guyane.fr 0673A104E6E8
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ac-guyane.fr; s=mail;
t=1745105683; bh=5zX4cSwWU1hpBsRnUABDA+zuz8NlvczjooCtK0ED7U8=;
h=From:Subject:To:Reply-To:Date:From;
b=BHQjaRq+HpxLkz0VETd+nXKUKKumYEPAgI5RWKif8XyVCU7T/LjqoG6rND7w5Nj6R
XJzq2Fk00of2+qjYor5ZJoQbjdv/x6mXoX6Xt3+rdOio54hutRVt9cv+FxbJpIoEL3
QkvFECiuleXxkwsziliUbroMh/EpgALqVBgnNB8o=
From: "VotreLIvreur-CA"
Subject: Votre livreur vous informe : CA-1000014254775
To:
Content-Type: multipart/alternative; boundary="Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU"
MIME-Version: 1.0
Reply-To:
Date: Sat, 19 Apr 2025 23:34:43 +0000
Message-Id: <194120250434239E47E51FC7-27083BB1CD@ac-guyane.fr>
X-Rectorat-Guyane-MailScanner-Information: Rectorat de la Guyane
X-Rectorat-Guyane-MailScanner-ID: 0673A104E6E8.AA4BE
X-Rectorat-Guyane-MailScanner: Clean Message
X-Rectorat-Guyane-MailScanner-SpamCheck: polluriel
X-Rectorat-Guyane-MailScanner-SpamScore: sssssss
X-Rectorat-Guyane-MailScanner-From: samira.raymond@ac-guyane.fr
X-Rectorat-Guyane-MailScanner-Watermark: 1745710484.08417@NQ1Leca8Ih6VXvL+LP2G9Q
X-Spam-Status: Yes
X-Spam_score: 12.5
X-Spam_score_int: 125
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: FedEx Madame, Monsieur, Nous vous informons qu'une tentative
de livraison de votre colis a eu lieu ce matin à 9h. Cependant, celle-ci
n’a pas pu être finalisée en raison d’informations incomplètes dans
l’adresse co [...]
Content analysis details: (12.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
[98.66.161.195 listed in dnsbl.ahbl.org]
[98.66.161.195 listed in dnsbl.ahbl.org]
[98.66.161.195 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
2.5 URIBL_DBL_PHISH Contains a Phishing URL listed in the DBL blocklist
[URI: bigfactspod.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[195.98.226.245 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_LARGE BODY: HTML font size is large
2.0 MIXED_HREF_CASE Has href in mixed case
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} Votre livreur vous informe : CA-1000014254775
This is a multi-part message in MIME format
--Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
FedEx
Madame, Monsieur,
Nous vous informons qu'une tentative de livraison de votre colis a eu =
lieu ce matin =C3=A0 9h. Cependant, celle-ci n=E2=80=99a pas pu =C3=AA=
tre finalis=C3=A9e en raison d=E2=80=99informations incompl=C3=A8tes d=
ans l=E2=80=99adresse communiqu=C3=A9e, notamment l=E2=80=99absence du=
num=C3=A9ro d=E2=80=99appartement et/ou de l=E2=80=99=C3=A9tage. Cela=
a emp=C3=AAch=C3=A9 notre chauffeur d=E2=80=99acc=C3=A9der au lieu de=
livraison.
Afin de planifier une nouvelle livraison dans les plus brefs d=C3=A9la=
is, nous vous invitons =C3=A0 corriger votre adresse via le lien suiva=
nt :
Compl=C3=A9ter mon adresse pour une nouvelle livraison https://bigfact=
spod.com/shshbhsbhshbshbshb.html
Une fois le formulaire soumis, une nouvelle tentative de livraison ser=
a automatiquement programm=C3=A9e selon vos indications.
Nous vous remercions pour votre compr=C3=A9hension et restons =C3=A0 v=
otre disposition pour toute demande compl=C3=A9mentaire.
Bien cordialement,
--Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
8">
=3D1">
Votre livreur vous informe : CA-1000014254775
NG>Fed
a>Ex
Madame=
, Monsieur,
Nous vous informons qu'une tentative=
de livraison de votre colis a eu lieu ce matin =C3=A0 9h. Cependant, =
celle-ci n=E2=80=99a pas pu =C3=AAtre finalis=C3=A9e en raison d=E2=80=
=99informations incompl=C3=A8tes dans l=E2=80=99adresse communiqu=C3=A9=
e, notamment l=E2=80=99absence du num=C3=A9ro d=E2=80=99appartement et=
/ou de l=E2=80=99=C3=A9tage. Cela a emp=C3=AAch=C3=A9 notre chauffeur =
d=E2=80=99acc=C3=A9der au lieu de livraison.
Afin de planifier u=
ne nouvelle livraison dans les plus brefs d=C3=A9lais, nous vous invit=
ons =C3=A0 corriger votre adresse via le lien suivant :
=
tml">Compl=C3=A9ter mon adresse pour une nouvelle livra=
ison
Une fois le formulaire soumis, u=
ne nouvelle tentative de livraison sera automatiquement programm=C3=A9=
e selon vos indications.
Nous vous remercions pour votre compr=C3=
=A9hension et restons =C3=A0 votre disposition pour toute demande comp=
l=C3=A9mentaire.
Bien cordialement,
--Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU--