Cryptocurrency phish from microsoft outlook
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 09 Oct 2024 09:58:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98 (FreeBSD))
(envelope-from
id 1syZ3g-00000000FZh-45nG
for dave@doctor.nl2k.ab.ca;
Wed, 09 Oct 2024 09:57:04 -0600
Resent-From: The Doctor
Resent-Date: Wed, 9 Oct 2024 09:57:04 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail.ramly.com.my ([219.93.101.253]:52878 helo=zimbra.ramly.com.my)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.98 (FreeBSD))
(envelope-from
id 1syYe3-00000000Bj8-12lL
for doctor@nl2k.ab.ca;
Wed, 09 Oct 2024 09:30:43 -0600
Received: from localhost (localhost [127.0.0.1])
by zimbra.ramly.com.my (Postfix) with ESMTP id B31D3FFDD7B3
for
Received: from zimbra.ramly.com.my ([127.0.0.1])
by localhost (zimbra.ramly.com.my [127.0.0.1]) (amavisd-new, port 10032)
with ESMTP id fNN4Tx1DA97S for
Wed, 9 Oct 2024 23:14:24 +0800 (+08)
Received: from localhost (localhost [127.0.0.1])
by zimbra.ramly.com.my (Postfix) with ESMTP id 6BEF7FFDD7A3
for
X-Virus-Scanned: amavisd-new at ramly.com.my
Received: from zimbra.ramly.com.my ([127.0.0.1])
by localhost (zimbra.ramly.com.my [127.0.0.1]) (amavisd-new, port 10026)
with ESMTP id TefWzGvnbMU5 for
Wed, 9 Oct 2024 23:14:23 +0800 (+08)
Received: from YankyHQ (unknown [20.55.110.231])
by zimbra.ramly.com.my (Postfix) with ESMTPSA id 9C0FBFFCF01D
for
From: "Kathryn Dalli"
Subject: Secure: Your Ethereum DeFi Login Details
To:
Content-Type: multipart/alternative; boundary="3LmG3GUepHLOQtLYsAnizbwf=_bZsdzeoL"
MIME-Version: 1.0
Date: Wed, 9 Oct 2024 15:14:20 +0000
Message-Id: <09192024101415B28B84C6BA$084D6DBF61@ramly.com.my>
X-Spam_score: 13.6
X-Spam_score_int: 136
X-Spam_bar: +++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hi Mike Morlock, As per your request, $300,000 has been successfully
invested into a DeFi Layer project through Ethereum (ETH). Below are the
details you’ll need to access your account: Username: mmorlock Password:
Password1 (Change it) Website URL: www.defixlayer.com
Content analysis details: (13.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[20.55.110.231 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
[219.93.101.253 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[219.93.101.253 listed in dnsbl.ahbl.org]
[219.93.101.253 listed in dnsbl.ahbl.org]
[219.93.101.253 listed in dnsbl.ahbl.org]
[219.93.101.253 listed in dnsbl.ahbl.org]
[20.55.110.231 listed in dnsbl.ahbl.org]
[20.55.110.231 listed in dnsbl.ahbl.org]
[20.55.110.231 listed in dnsbl.ahbl.org]
[20.55.110.231 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[219.93.101.253 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[219.93.101.253 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[219.93.101.253 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[219.93.101.253 listed in dnsbl.ahbl.org]
2.5 URIBL_DBL_PHISH Contains a Phishing URL listed in the DBL blocklist
[URI: defixlayer.com]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: defixlayer.com]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: www.defixlayer.com]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: defixlayer.com]
-0.0 SPF_PASS SPF: sender matches SPF record
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 LOTS_OF_MONEY Huge... sums of money
0.0 NO_RDNS2 Sending MTA has no reverse DNS
Subject: {SPAM?} Secure: Your Ethereum DeFi Login Details
This is a multi-part message in MIME format
--3LmG3GUepHLOQtLYsAnizbwf=_bZsdzeoL
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Hi Mike Morlock,
As per your request, $300,000 has been successfully invested into a De=
Fi Layer project through Ethereum (ETH). Below are the details you=E2=80=
=99ll need to access your account:
Username: mmorlock
Password: Password1 (Change it)
Website URL: www.defixlayer.com
Please visit the provided website and connect your wallet to begin tra=
cking or withdrawing your funds as they grow in the DeFi project.
For security, delete this email after saving your login details
Best regards,
Kathryn Dalli, Esq.
Portfolio Manager
Twomey, Latham, Shea, Kelley, Dubin & Quartararo LLP
33 West Second Street, P.O. Box 9398, Riverhead, NY 11901
O: (631) 727-2108 Ext. 228
--3LmG3GUepHLOQtLYsAnizbwf=_bZsdzeoL
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
8">
le=3D1"> <=
title>Secure: Your Ethereum DeFi Login Details
Hi Mi=
ke Morlock,
As per your request, $300,000 has been successfully =
invested into a DeFi Layer project through Ethereum (ETH). Below are t=
he details you=E2=80=99ll need to access your account:
Username:=
mmorlock
Password: Password1<=
/STRONG> (Change it)
Website URL: www.defixlayer=
=2Ecom
Please visit the provided website and connec=
t your wallet to begin tracking or withdrawing your funds as they grow=
in the DeFi project.
#ff0000>For security, delete this email after saving your login detail=
s
Best regards,
Kathryn Dalli, Esq.
>Portfolio Manager
Twomey, Latham, Shea, Kelley, Dubin & Quarta=
raro LLP
33 West Second Street, P.O. Box 9398, Riverhead, NY 11901<=
BR>O: (631) 727-2108 Ext. 228
--3LmG3GUepHLOQtLYsAnizbwf=_bZsdzeoL--