Fedex phish from Microsoft Outlook
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 20 Apr 2025 12:39:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1u6ZZ8-000000005Nf-1ZqX
for dave@doctor.nl2k.ab.ca;
Sun, 20 Apr 2025 12:38:54 -0600
Resent-From: The Doctor
Resent-Date: Sun, 20 Apr 2025 12:38:54 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from cp-smtp-out-2.ac-guyane.fr ([195.98.226.245]:56392)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1u6ZK1-000000004Wf-0vBO
for doctor@doctor.nl2k.ab.ca;
Sun, 20 Apr 2025 12:23:25 -0600
Received: from francais (unknown [98.66.161.195])
by cp-smtp-out-2.ac-guyane.fr (Postfix) with ESMTPA id C0A9E104DD86
for
DKIM-Filter: OpenDKIM Filter v2.11.0 cp-smtp-out-2.ac-guyane.fr C0A9E104DD86
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ac-guyane.fr; s=mail;
t=1745173278; bh=tsZnUt1iuqc33JHq/+v7k1T/z57AQ4kovLuo02coO/I=;
h=From:Subject:To:Reply-To:Date:From;
b=dQekNxXHyGUAVoMYmPX3Vy1fyyfHcAukopr+0bKS8TBfi5Ock/F3Yn7ke7CDjkuNQ
ZJ4RRqImRWZoeh6TjbJmwjPq/PVFIGHNGki/7jidfFWPDMA9SNti7WhS+J3ZAifCKN
rrzY5p5kZeV4Wx5N55hcwOraNQKNHIt/j38veQzQ=
From: "TrackExpress"
Subject: update your address to let it through 112000115555
To:
Content-Type: multipart/alternative; boundary="Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU"
MIME-Version: 1.0
Reply-To:
Date: Sun, 20 Apr 2025 18:21:18 +0000
Message-Id: <20172025042118A34A514CCE$9107B17224@ac-guyane.fr>
X-Rectorat-Guyane-MailScanner-Information: Rectorat de la Guyane
X-Rectorat-Guyane-MailScanner-ID: C0A9E104DD86.AEB1F
X-Rectorat-Guyane-MailScanner: Clean Message
X-Rectorat-Guyane-MailScanner-SpamCheck: n'est pas un polluriel
X-Rectorat-Guyane-MailScanner-SpamScore: s
X-Rectorat-Guyane-MailScanner-From: odile.antoinette@ac-guyane.fr
X-Rectorat-Guyane-MailScanner-Watermark: 1745778079.08314@z81ttcZskB1nKmxpV0ymCQ
X-Spam-Status: No
X-Spam_score: 12.5
X-Spam_score_int: 125
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: FedEx Hello, The delivery address you provided is not sufficiently
precise, which prevented the successful delivery of your parcel.
Content analysis details: (12.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
[98.66.161.195 listed in dnsbl.ahbl.org]
[98.66.161.195 listed in dnsbl.ahbl.org]
[98.66.161.195 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
[195.98.226.245 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[98.66.161.195 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[98.66.161.195 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
[195.98.226.245 listed in will-spam-for-food.eu.org]
2.5 URIBL_DBL_PHISH Contains a Phishing URL listed in the DBL blocklist
[URI: bigfactspod.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[195.98.226.245 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_LARGE BODY: HTML font size is large
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
2.0 MIXED_HREF_CASE Has href in mixed case
Subject: {SPAM?} update your address to let it through 112000115555
This is a multi-part message in MIME format
--Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
FedEx
Hello,
The delivery address you provided is not sufficiently precise, which p=
revented the successful delivery of your parcel.
As a result, your parcel has been returned to our sorting centre.
To allow us to arrange a new delivery as soon as possible, please upda=
te your address by clicking the link below:
CORRECTION FORM https://bigfactspod.com/hdvhbvhdbvhdvbhd.html
Thank you for your understanding. Please don't hesitate to contact us =
if you have any questions.
Kind regards,
--Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
8">
=3D1">
update your address to let it through 112000115555
NG>Fed
a>Ex
Hello,=
The delivery address you =
provided is not sufficiently precise, which prevented the successful d=
elivery of your parcel.
As a result=
, your parcel has been returned to our sorting centre.
ONT color=3D#000000>To allow us to arrange a new delivery as soon as p=
ossible, please update your address by clicking the link below:=
ctspod.com/hdvhbvhdbvhdvbhd.html" target=3D_blank>
f size=3D6>CORRECTION FORM
r=3D#000000>Thank you for your understanding. Please don't hesitate to=
contact us if you have any questions.
000>Kind regards,
--Y24pSxpWV7ft4YgcO2rYtze=_AKUWsBwPU--