nk.ca credential phishing from velcom.com
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 09 Jul 2025 15:26:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1uZcHz-000000004nH-3N4o
for dave@doctor.nl2k.ab.ca;
Wed, 09 Jul 2025 15:25:15 -0600
Resent-From: The Doctor
Resent-Date: Wed, 9 Jul 2025 15:25:15 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [98.142.254.53] (port=52490 helo=rdns0.belgicastore.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1uZbIN-000000000hg-3lQi
for root@nk.ca;
Wed, 09 Jul 2025 14:21:48 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default; d=belgicastore.com;
h=From:To:Subject:Date:Message-ID:MIME-Version:Content-Type:
Content-Transfer-Encoding; i=support@belgicastore.com;
bh=Pce7v/yHMV92iAE8hEDt+KHHgqc5Ve5PKGetRf9IdDk=;
b=lGbQyPA8eJN/+sjtKd9fulQqs64Y2mcs54vFFaUnDx1/YKv8OM/VTMznkzGizKlovrGVW8RC3s7U
DHebpJUXkxrg6Gwtm+TqTtIqDGU9ZXoDjjqTBgDAHN7i1pHIYxDg26a5+spgigk/xmB6IfnrhHvJ
PcGpvskSmzD7DrGtHmM=
From: nk.ca
To: root@nk.ca
Subject: Did you login your email root@nk.ca now?
Date: 09 Jul 2025 21:18:38 +0100
Message-ID: <20250709211838.8E16E74A953DA460@belgicastore.com>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable
X-Spam_score: 8.1
X-Spam_score_int: 81
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Security Alert â ď¸ Security Alert: Unusual Login Attempt
Detected
Content analysis details: (8.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[98.142.254.53 listed in dnsbl.ahbl.org]
[98.142.254.53 listed in dnsbl.ahbl.org]
[98.142.254.53 listed in dnsbl.ahbl.org]
[98.142.254.53 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[98.142.254.53 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[98.142.254.53 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[98.142.254.53 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[98.142.254.53 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
[98.142.254.53 listed in will-spam-for-food.eu.org]
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.1 DKIM_INVALID DKIM or DK signature exists, but is not valid
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.3 PDS_FROM_NAME_TO_DOMAIN From:name looks like To:domain
0.0 PDS_FRNOM_TODOM_NAKED_TO Naked to From name equals to Domain
Subject: {SPAM?} Did you login your email root@nk.ca now?
background-color: #f4f6f8;
color: #333;
padding: 20px">
margin: auto;
background-color: #fff;
border-radius: 8px;
padding: 30px;
box-shadow: 0 0 10px rgba(0,0,0,0.05)" class=3D"email-container">
⚠️ Security Alert: Unusual Login Attempt Detected
Dear User,
We detected an attempt to access your email account from the following l=
ocation:
- IP Address: 198.342.99.2=20
- Country: Unknown=20
- Time: July 9, 2025 — 11:23 AM UTC
As a precaution, we have temporarily locked your account until you verif=
y and enable our new login protection features.
Please click the secure link below to continue and enable phishing prote=
ction:
padding: 12px 24px;
margin-top: 20px;
background-color: #0073aa;
color: #fff;
text-decoration: none;
border-radius: 5px;
font-weight: bold" class=3D"button" href=3D"https://qrto.org/4yHwt7">=
Enable Security Protection=20
If you do not log in now, you are liable for any malicious activity on y=
ou.
Thank you for helping keep your account safe.
font-size: 12px;
color: #777;
text-align: center" class=3D"footer">© 2025 cPanel, Inc. | .
IV>