Nigerian Spam from Google Gmail
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 28 Oct 2024 13:45:00 -0600
Received: from mail-wm1-f49.google.com ([209.85.128.49]:44162)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98 (FreeBSD))
(envelope-from
id 1t5VfI-00000000Gpz-2Af5
for dave@doctor.nl2k.ab.ca;
Mon, 28 Oct 2024 13:44:40 -0600
Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-43169902057so45581045e9.0
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1730144668; x=1730749468; darn=doctor.nl2k.ab.ca;
h=to:subject:message-id:date:from:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=jYgkOP54oSoULEcsuQEi6gsJiq2fhyAJnNodYsDmRyE=;
b=cLTRLX5IuYXYS4SaPYSD5PZPSGBrhXb4NV41VmvtMgcMqEsHagffNm2yM3RGuI6VTV
kATljks2FE4TWS6TCMMyEsQo1EDl1uUf724LNFmXWkM+6D3ZHL8Dj091I5CmMq45UhfX
ozaUE4ut4bBXfseTZw82ObV+AW2Sc/oXZmCPLHCFR6EB5pjpBrBxsBQUDlEDRUtGf4gO
rB1yTH+wRpDWG3Ah4mk38+hji34UDkRqUt2vAE81RwI+/STMctWfbG0yLkg5KpJ18rjk
/q0Eh5dQTt+Djih4paAupEVBIHqIyaPtd5Xat8Oxu/P88NvhJx0mAUwAH8UO7I2FmgVw
s2ag==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1730144668; x=1730749468;
h=to:subject:message-id:date:from:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=jYgkOP54oSoULEcsuQEi6gsJiq2fhyAJnNodYsDmRyE=;
b=Y1C6oweMDFyJusshkMMcRxkExCI3mQBFXtzHv/0XrUMFtGroXri19UsJdKiH0fQjPU
VxnA5JjmGCxrbgzjyztGHImvtnPUu3slKyiESmsGjUAZy80BpHzmtLOH4MxtcEM9rt5o
8MfOhj4J1MHjcVBSEpWRAPFem0QJT7l2hU/4cDdFRdH8cSP19peO5tGZYSxFF3pfaCd/
j39p6gu9wru7zF/m+bRAGAeXOFCMbdmJfJGK37HKkREWikuQsKGlOjI14CTGmYcMWd0N
PSCgaPriZ/qEMB79PkXlkkBdO/ixcQ2niTrTEm7a7V+EidX9oZHQVncPaNao+m2cw8DN
OhsQ==
X-Forwarded-Encrypted: i=1; AJvYcCVZxZ8YxY5e6ulEMc5NyDTIydpNBJzxnMf9ffMXEzH4IwdA0YQ5GJFrTT0vTOq3nNHyeHdI@doctor.nl2k.ab.ca
X-Gm-Message-State: AOJu0YxsJuBzWEVHMkANe9yZPNNokTk31NINBPFeEMa7JssbxPAFXpzY
xABmSqZTrHXvPK/+O9WXMk9YYnGVv2zx/JWFFDxKGNpY8Q+2PuMboU9A6mWm8/6tafhzE0wawMs
Xy+uPfdoQdWHwmynhCJ9JhasQUPmmyB5iLt2o8Wcc
X-Google-Smtp-Source: AGHT+IGAZaohUrKzHC8NRmFGirk62DUhNiJ2ypsqy8fuw9WsPcccxr2GpPCyGUNw7E86T8J5OW6g1wgFUIYXX86bXoQ=
X-Received: by 2002:a05:6402:5186:b0:5c2:439d:90d4 with SMTP id
4fb4d7f45d1cf-5cbbfa919ecmr6903127a12.30.1730141113236; Mon, 28 Oct 2024
11:45:13 -0700 (PDT)
MIME-Version: 1.0
From: Mrs Aisha Gaddafi
Date: Mon, 28 Oct 2024 18:45:00 +0000
Message-ID:
Subject: Good evening dear, investment project
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary="000000000000774bc206258ddef3"
Bcc: dave@doctor.nl2k.ab.ca
X-Spam_score: 21.1
X-Spam_score_int: 211
X-Spam_bar: +++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: My Dear Friend Greetings to you and your family; I came across
your contact during my private search, Mrs Aisha Al-Qaddafi is my name, the
only daughter of late Libyan president, I have funds the sum [...]
Content analysis details: (21.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[209.85.128.49 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.128.49 listed in dnsbl.ahbl.org]
[209.85.128.49 listed in dnsbl.ahbl.org]
[209.85.128.49 listed in dnsbl.ahbl.org]
[209.85.128.49 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.128.49 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.128.49 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.128.49 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.128.49 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
[209.85.128.49 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Error: open resolver;
-0.0 SPF_PASS SPF: sender matches SPF record
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.128.49 listed in wl.mailspike.net]
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
1.5 GR_DOMAIN_UNDISC1 To contains undisclosed recipient (undisc)
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[mrs.gaddadi01(at)gmail.com]
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit
[mrs.gaddadi01(at)gmail.com]
2.7 HK_SCAM_N1 BODY: No description available.
2.5 MILLION_USD BODY: Talks about millions of dollars
0.0 MILLION_HUNDRED BODY: Million "One to Nine" Hundred
0.0 HTML_MESSAGE BODY: HTML included in message
1.5 HK_NAME_FM_MR_MRS No description available.
0.0 LOTS_OF_MONEY Huge... sums of money
3.1 MONEY_FRAUD_3 Lots of money and several fraud phrases
0.0 UNDISC_MONEY Undisclosed recipients + money/fraud signs
2.0 ADVANCE_FEE_2_NEW_MONEY Advance Fee fraud and lots of money
Subject: {SPAM?} Good evening dear, investment project
--000000000000774bc206258ddef3
Content-Type: text/plain; charset="UTF-8"
My Dear Friend
Greetings to you and your family; I came across your contact during my
private search, Mrs Aisha Al-Qaddafi is my name, the only daughter of late
Libyan president, I have funds the sum of Twenty Seven Million Five Hundred
Thousand United State Dollar 27.500.000.00 for investment, I am interested
in you for investment project assistance in your country, i need a trusted
investment Manager or Partner because of my current refugee status, we can
build business relationship in the nearest future.
Reply me urgent for more details
Mrs Aisha Al-Qaddafi
--000000000000774bc206258ddef3
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Greetings to you and your family; I came=
across your contact during my private search, Mrs Aisha Al-Qaddafi is my n=
ame, the only daughter of late Libyan president, I have funds the sum of Tw=
enty Seven Million Five Hundred Thousand United State Dollar 27.500.000.00 =
=C2=A0for investment, I am interested in you for investment project assista=
nce in your country, i need a trusted investment Manager or Partner because=
of my current refugee status, we can build business relationship in the ne=
arest future.
Reply me urgent for more details
Mrs Aisha Al-Qaddafi=
div>
--000000000000774bc206258ddef3--
Domain for sale spam from Google Gmail
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 28 Oct 2024 12:58:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98 (FreeBSD))
(envelope-from
id 1t5Uvd-000000007vx-1Pc5
for dave@doctor.nl2k.ab.ca;
Mon, 28 Oct 2024 12:57:25 -0600
Resent-From: The Doctor
Resent-Date: Mon, 28 Oct 2024 12:57:25 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-ej1-f47.google.com ([209.85.218.47]:59666)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98 (FreeBSD))
(envelope-from
id 1t5Tck-000000004nm-04Ym
for sales@nk.ca;
Mon, 28 Oct 2024 11:33:57 -0600
Received: by mail-ej1-f47.google.com with SMTP id a640c23a62f3a-a9a68480164so635722066b.3
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1730136822; x=1730741622; darn=nk.ca;
h=to:subject:message-id:date:from:in-reply-to:references:mime-version
:from:to:cc:subject:date:message-id:reply-to;
bh=bVzWJONKszJkrZ2AcX1FGtsRXnA+yvcsy4sH2U8ADlk=;
b=AphsikShWazBaxM+C+hYJ1+3Um1kuCcHEkSUGZ4yTcGZ1vzS/IZ/wAsx8gWoG9NVfN
GZJ2pnTvdprRlrLHZDVUVU0aLSQEVJXPeTKvWhXHPgkDOI9vOqEgaDv78NFpmuQfcUjw
ya0t0Q0c4LPZ351Vck8DxRwdYWu99qph0c6nI0AB5d+B5wptQ/QwCtP5IIYp0Gii2sYR
Ffy5Z7ZT3Vb3ipKQQ04WDMNU1W512QcVSIPLPbB8h5BxF6oDhSsFTF2yvVS+nzXWXxii
Ec1y5iENC0Pglu3gcQVq9Bw2HsmMSqxW4tCOqd1A/i2NwLxT2hi7lj9+6+wkow3avPJt
pqEg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1730136822; x=1730741622;
h=to:subject:message-id:date:from:in-reply-to:references:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=bVzWJONKszJkrZ2AcX1FGtsRXnA+yvcsy4sH2U8ADlk=;
b=h8xj0KxiFG66X1aiDNBMMN2MOQh9jtdY3JxW/figXI/sqD5wRW66kxo468jpTaHhSO
1xoENUJtGvjg7QnLwRb6BzJ4fwG/poqA96frd3xc3BGErj6CMTw0wGmb0X9WDbSD+Ic8
KCcFFOy/8jQXq4bVbEXaWstOvKCQvHcEhU6hlYeGuP0ADcguUQj5sTxjMSisRb65LleC
snUEKaJWDR0p5OM2FQXxCDeAfc32Y+vlip2V0Cbo/jqu2ECvC/uI3B+9w4qUqlLVxQFM
UzzkVhMhnjnTOZPAn0hqXhJXygRZfKp0DTd812tCJFdOnMhAk4+Y4iT1gsyyKh1lIkY2
ZDCg==
X-Gm-Message-State: AOJu0YxlE7BvUzmXp9r/dWGWZKe9EwQRs4kBzN10YrUmpBXyIM+FX7U/
ZNd9OugvGX0CIhH1dtxnlSjB8Vz2zQFgNEywCf6zz9OHXCD0GSL9ZCoqma1jsw4JR6oaYewatGZ
paKNL4b3UWMnIkw+c2U+BcF7BZAbbbWuN
X-Google-Smtp-Source: AGHT+IF/rtVvtkAQQNf9zlbH+BdhNYnoLLFm3atZdvLExXR9P144pxVSOr6takfNM7yp+geHsr/QSV1p/knunsFzAZ8=
X-Received: by 2002:a17:907:7f13:b0:a99:5f2a:444d with SMTP id
a640c23a62f3a-a9de61a0feemr829084966b.56.1730136821871; Mon, 28 Oct 2024
10:33:41 -0700 (PDT)
MIME-Version: 1.0
References:
In-Reply-To:
From: David Samuel
Date: Mon, 28 Oct 2024 18:33:29 +0100
Message-ID:
Subject: Re: Premium Domain for sale: BroadbandCA.com
To: sales@nk.ca
Content-Type: multipart/alternative; boundary="000000000000ae39f006258cde59"
X-Spam_score: 8.8
X-Spam_score_int: 88
X-Spam_bar: ++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hello, Have you had a chance to consider this offer? How can
I make this purchase work for you? We're open to reasonable offers and negotiations
so let me know.
Content analysis details: (8.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[209.85.218.47 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.218.47 listed in dnsbl.ahbl.org]
[209.85.218.47 listed in dnsbl.ahbl.org]
[209.85.218.47 listed in dnsbl.ahbl.org]
[209.85.218.47 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.218.47 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.218.47 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.218.47 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.218.47 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
[209.85.218.47 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Error: open resolver;
0.0 URIBL_DBL_BLOCKED_OPENDNS ADMINISTRATOR NOTICE: The query to
dbl.spamhaus.org was blocked due to usage of an
open resolver. See
https://www.spamhaus.org/returnc/pub/
[URI: mailfoogae.appspot.com]
[URI: broadbandca.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.218.47 listed in wl.mailspike.net]
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: mailfoogae.appspot.com/142.250.69.212]
[URI: broadbandca.com/13.248.169.48]
[URI: broadbandca.com/76.223.54.146]
[URI: ns1.namefind.com/97.74.99.64]
[URI: ns2.namefind.com/173.201.67.64]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[davidaberton(at)gmail.com]
1.0 HTML_IMAGE_ONLY_16 BODY: HTML: images with 1200-1600 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or identical to
background
0.0 T_REMOTE_IMAGE Message contains an external image
Subject: {SPAM?} Re: Premium Domain for sale: BroadbandCA.com
--000000000000ae39f006258cde59
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Hello,
Have you had a chance to consider this offer?
How can I make this purchase work for you?
We're open to reasonable offers and negotiations so let me know.
On Wed, Oct 16, 2024, 20:20 David Samuel
> Hey there,
>
> BroadbandCA.com is a premium domain recently put up for sale on GoDaddy
> domain marketplace.
>
> We are offering this domain to you for a discount price of 199 USD only a=
s
> our research has shown that this domain could serve a wide range of
> purposes for your business.
>
> To complete all transactions regarding acquisition and purchase, go to
> BroadbandCA.com.
>
> You can also make direct purchase available on GoDaddy.com, depending on
> your preference.
>
> Best Regards,
> David.
> =E1=90=A7
>
--000000000000ae39f006258cde59
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
>
>
=3D"auto">
nd negotiations so let me know.
div dir=3D"ltr" class=3D"gmail_attr">On Wed, Oct 16, 2024, 20:20 David Samu=
el <davidaberton@gmail.com=
> wrote:
0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
ere,
=C2=A0
BroadbandCA.com is a premium domain recently put up for s=
ale on GoDaddy domain marketplace.
We are offering this domain to yo=
u for a discount price of 199 USD only as our research has shown that this =
domain could serve a wide range of purposes for your business.
To co=
mplete all transactions regarding acquisition and purchase, go to Broadband=
CA.com.
You can also make direct purchase available on GoDaddy.com, =
depending on your preference.
Best Regards,
David.
=3D"width:0px;max-height:0px;overflow:hidden" src=3D"https://mailfoogae.app=
spot.com/t?sender=3DaZGF2aWRhYmVydG9uQGdtYWlsLmNvbQ%3D%3D&type=3Dzeroco=
ntent&guid=3D42c1b875-79c8-44e2-870f-04b659143433">
ff" size=3D"1">=E1=90=A7
--000000000000ae39f006258cde59--