Datefinder Phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Tue, 20 Feb 2024 14:50:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rcXzV-000000001rw-1I8u

for dave@doctor.nl2k.ab.ca;

Tue, 20 Feb 2024 14:49:29 -0700

Resent-From: The Doctor

Resent-Date: Tue, 20 Feb 2024 14:49:29 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-vi1eur05olkn2086.outbound.protection.outlook.com ([40.92.90.86]:36033 helo=EUR05-VI1-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rcWj3-00000000JrC-0MtN

for doctor@doctor.nl2k.ab.ca;

Tue, 20 Feb 2024 13:28:30 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=mrAp3oQW2gqGC7bgtx95PIodSf35uKCJz8oVyxuTo3syIqclg6iRr1zfreipM58h22f2vyo6EdzEiEXV5w/9xMGYzhwDK2PGmaqE+mpWQFH59Zke1hwJIVahaadB1ozge46xOxDpXDW4gNdaWZRPACm9F96XySwEb58UtlSVvlnsRWZ0lqiJZsknN4de4v9G7f6IQKMxVBNB+1pSBoFMYzZ9o68kYYMhE2Wc+mcitVPym17mt8MqAfo5m0alV7kAdmu5WFch3wP7B/znQMYZ90Y9AvZdlr3L4Z0cvBDBYHSX/Y2E0R+4bnXyJSjDujn18ryH621BR95X1vTYXFKqOw==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=+Qh4T8mlLkg7qAlGouhH+nVVPeZE662feHb4eWthtVU=;

b=ghcz5Pu0a8DVZdZ20bb2X+oV0H5vxMtJ4Q7TjATvInURMU6ryt59NiBB9TRaM4wMyI55HdtfLzyyqUmAVgm7SSjuHL0J6XNXHnHl6euFHB59ly5bKd9R0TvHMCSUTZaoJjsKvRBrVljSx/CItRqGxXd6HkCIL9sf5CDbQL5EKVUMPJMmo+uhR1BPMsM2BxK4rik0Asc8wVEMyajL8pDVvcohIvaXWwIi9yLZRKuNmtP/AC6TrOa2dFyxB/26KSC1nEJeHfbLl0FTeFvQgs9SFl1DWJC/tTZbzhTRW1Clnl/sSBtBKoS49pQYxdFzgeXDvy+a1zPvWc6KSX1lTfDmvA==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none;

dkim=none; arc=none

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=outlook.com;

s=selector1;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=+Qh4T8mlLkg7qAlGouhH+nVVPeZE662feHb4eWthtVU=;

b=TLjE4RnRlybdU78HkA7A+gsMqthd2iuX3GH9+uFat06SkDwqYrJJb/tU7/4onwv33Z0wELdGFXKLkpo/iKKgIQbBt0f+ZJsGCrEmw5Gu9wqBDtSxypXtN9870MJ4guIK26TKUsuvSWSwzCKzxX85gkyP+oEzbYyIGz4D2x7l3BQ4hopnopUJosnYfklAKehnSYr8U5Q8t/ew9U0qQXcHe4tt57kW5ZLHdBwWdW7041295iywr7P0R0HAex2SO2MoHXVkT68hfsdfE7OhsKphLuknFdyqroPqHCVsFdp2Un6932nJBdYkNOAiez9swhMITJD0A5mvvigbmAQCaSAi9Q==

Received: from AS4P251MB0413.EURP251.PROD.OUTLOOK.COM (2603:10a6:20b:4bd::8)

by DU0P251MB0435.EURP251.PROD.OUTLOOK.COM (2603:10a6:10:347::8) with

Microsoft SMTP Server (version=TLS1_2,

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7292.39; Tue, 20 Feb

2024 20:26:11 +0000

Received: from AS4P251MB0413.EURP251.PROD.OUTLOOK.COM

([fe80::1c76:b763:1524:3011]) by AS4P251MB0413.EURP251.PROD.OUTLOOK.COM

([fe80::1c76:b763:1524:3011%7]) with mapi id 15.20.7270.036; Tue, 20 Feb 2024

20:26:11 +0000

Content-Type: multipart/alternative; boundary="===============3325682761253975343=="

Subject: Profile visit from match

From: MariaBW

CC: MariaBW

Date: Tue, 20 Feb 2024 20:25:58 +0000

X-TMN: [QZtcVJ9sjjeRRCupIXMod9N181Xc1SJS]

X-ClientProxiedBy: FR2P281CA0010.DEUP281.PROD.OUTLOOK.COM

(2603:10a6:d10:a::20) To AS4P251MB0413.EURP251.PROD.OUTLOOK.COM

(2603:10a6:20b:4bd::8)

Message-ID:



MIME-Version: 1.0

X-MS-Exchange-MessageSentRepresentingType: 1

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: AS4P251MB0413:EE_|DU0P251MB0435:EE_

X-MS-Office365-Filtering-Correlation-Id: b1f1a3de-259e-4ea8-c0ff-08dc32522d0f

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

=?utf-8?B?SFZteTAxWGVDK0VJRVpmWnU1cXN2RlpITEZ4TE1ISXIwQTN2dnh2MGlGSk9B?=

=?utf-8?B?cmRuNlIvRTlFTjZBelVySVpKY3lGeWVuaXpEUWl0bFo2bmFONnNDdkJnVmZk?=

=?utf-8?B?YkVHOHVtRXVqazBaTXJTc3lGYWZkUnZmeFR1LzRwd2RXSW9OdmZ0a0t6U2x1?=

=?utf-8?B?Vi83Rm90WGR2YzVNUVhja2w2NEUwMFV1WjlqNFVIUDZLQXNjRElvVVowQjZj?=

=?utf-8?B?ajhIQWU4YnBhWnV6cHB4WFdXaVZZSmptOHNWeW5OVkFIbTRsNXhkRXpmRm9T?=

=?utf-8?B?T3hVZEVsa3JHTXA0ajBmdFgwQ3BTL1EyeTJ2TFB0bmlaSk1KR2RGaFllRXIz?=

=?utf-8?B?WW83YlRRRmthU2I3WHZueTg5WjVYaVVwdXJ2WlRFUU8wOGh3SWt6VnVRclk2?=

=?utf-8?B?UXFaQ0MwbFNKb0VUMmpFMEREMUZhK1Z5YVBMZDZUMTlSU2lrYnBScmcyV2d5?=

=?utf-8?B?cHhqWmJmTFFjVjEyd0p0VmlrU3VwR21RU1FlYURNaGxQdkkvQWluMDFMT0J3?=

=?utf-8?B?S0ZyaGlac2hDYVhMQ29PV1o3MXdZdWdiT0FZY1RBYmN3QkJieitJU1VaL0tw?=

=?utf-8?B?VFpJRm1wL0pRREpnQTRUTzZYckhGTWhzNU9ocEtaQWdZWld2clVBc0o4VURX?=

=?utf-8?B?SVBORHk2RnVCYzVmU2xkOXI4Uk1YdjlkMk9STm8zSGczZWU1VGZhRU1nZHdt?=

=?utf-8?B?SEFBblVHYklBaitwMnFQYk5BVExSbVRYa3FZRTBPcWJLczI1N2RlL2tlWFdD?=

=?utf-8?B?UXVRNTMxRDhPSWU0OFdMdktiS2pBd0duanFtRE5MTTNyYjFseTBkOGI4dlNn?=

=?utf-8?B?c3JTTmVKMEhqZ0prV1ZMWWVlU3NJRGxHdTJnUExVZVAxTXdxblRKZEpPUm9q?=

=?utf-8?B?SWFqTktQK1NMelIwNWNGblU1b2dMZDMwbkFvNi95REVMRjJIbUFZRkRLNHJh?=

=?utf-8?B?dyt1cUx1TGd3UlpqdlIvSnhPNFVyZU10QlgrVVlNUEhRTUE1K1Y4UzZoL0hz?=

=?utf-8?B?MDdEUU5vRCsyQ1RVRE9VWWYyVlExRUdiS2NXaENUcEpNbVRLeUEzYit1Wkhr?=

=?utf-8?B?azJLK242Z3dMZzJwaHhTbnQ0RTlxSXhKT21ucFRsRmpiMjY0TFUzK2JERDI2?=

=?utf-8?B?cXBhbWdJNTFnejVyeHFpaHV2ejVFdlY4Yzl2M1RLWFJJazNZWlJwanlpdWZo?=

=?utf-8?B?OFNMcVM0Y2Uzay9kUmpFbXU2ZVpUWmhRMWZGVHZpRWRuVHNhdlpoOVZtUStU?=

=?utf-8?B?RTY1M25qNzBQMWdOOGQ5bFBIeGl3UTFjdXhmd2dFc3hETGVtQm16UElhVmR0?=

=?utf-8?B?V0lRMWZ1SUc0KzIwdlFQUEVPSERRWUYxTjBUcU0xbzJIcy9NTWw2Tkh6YmNl?=

=?utf-8?B?dG90bjhEQ3hrWkoxck53V3NnZ1FWUE5QZm11UEt1TzNMNmh0WUx4TnFOSDI0?=

=?utf-8?B?bFV1VUgyMVM1K1l2cjMxeThwbG92dFF0bTBQK3dZMmNZWkFETDNsNmJSaVRi?=

=?utf-8?B?dkNObTJqc0FoYnFmM2xmTml2MiswL2tGdEl3NXVaTkJOcXRXcTFOcVhMVkhE?=

=?utf-8?B?VGMrakwrMFV0ZEV0N2liTnRzT01xcEpxZDRIRjdVMlRNYnAvNzAzMUJhM0hP?=

=?utf-8?B?QU5rMUdzVG9VRVhzQ3RsRVpLMHZXeWFXUHMrRnVqbWhldE96bDBnZ0dGZ01D?=

=?utf-8?Q?E0xeSg2rFNBveHQk8z45?=

X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1

X-MS-Exchange-AntiSpam-MessageData-0:

=?utf-8?B?YkhFWStOb3RscTJTeUZHZ1FBU0orY3BnSmlqaHVQVzlhY0w0WnFwejhVY1Rm?=

=?utf-8?B?U1NyT1JMRloxY3dGNGVuM3FvcmFKZmNJN1dYL2ZKRWhIdWVWclNtMzdYVzI1?=

=?utf-8?B?OFhJd2l4cUQ5L3IxbjFmTklhcDdWSHZ5dHd2Vm54VzdNUGMxUmIwUDdPanZI?=

=?utf-8?B?ZjdUUFdUcGpaK3NFZDBVdTliOEYwU3V6Vkg1ODBFNEJQcTVrSkg1ODExMkhk?=

=?utf-8?B?emFkSGxFeldqN0xWN2JUNk81NXZTQW5pb3F1UlREKzVucEdzMDNMUFFHSHpP?=

=?utf-8?B?NkxRam9TL0Q3NHdZUzlyalo0SklxVXlFeTQrNHFMSjNRYWNWWmYreUUxSFVY?=

=?utf-8?B?RzhiQ1BpVG40bnVoSGpUaWtYMHJuQkdGMTdYNU5lRERPNlQrdGQvUjMrUm5n?=

=?utf-8?B?OVV3SmlVWHo3dUJPUUtHK0FXeDJsVG1SNzgxbnFYbXZ4UTlCL2lLazhucEZM?=

=?utf-8?B?amxUZmJXejU1ZzI0ZEhWYm1ZemxWS2tlWG11b3R1dnovK25jNzhWcU9HTVh5?=

=?utf-8?B?VmdTRDFRRVcwMGgrZG01WGtUSlJEZ2lBSEtNQThpWmdCazVXZVRRV1dJVjVF?=

=?utf-8?B?WDUzWU1KZ2FuMmtOOGxaWU9jUGdLQzZoRVVFSy8vTFhUVU1GQTdNRTVMT1dB?=

=?utf-8?B?VlNzeXFYNkdHcWxNcHM0Q2lCMk83SG53ZWpseCs4bFk5dWI0MG5jTU5qcE8v?=

=?utf-8?B?bzEvU1U4bzJzNjhxbkNxd1VwVU1oK2dneEphZDJYVFQ4Q3NCOGJXM0Ywd0Fv?=

=?utf-8?B?cTRyU3FBeUhiRFZqQ1Z0NHpXSFQ5VWFuVkxGVyttaVZoQWhGTGcvd0g1RzFt?=

=?utf-8?B?YmpzVG8wd1R6MGExcnZyNlpzeGUwREdrZmdSYUJGVHhpOUNrUlBIbnh6UGtV?=

=?utf-8?B?M0hKdnNVVi80bkErTlByUzF2aWMrd0wrS3VJMXRkU1RkODhWY3dsY1pxNjk1?=

=?utf-8?B?YXQrblhwM2JuTWdXd0M4WVBtUDM1NUd3cHltZTJpdkFaT0JoeGJQYUd0MlBp?=

=?utf-8?B?QUxzYTg3Q1B6dFhXY1M2VzZXMU0rUk5ra0VFMWFnbmVwMjZUZTV1WE5VYkNw?=

=?utf-8?B?c3RRSGdEWEZQSWZhRXYrbEdaMGFuQytMT1dUN3J2c1JWNmcydFAyajVSQUJT?=

=?utf-8?B?dnNnRitOZFVVdjdJSTVZVS9SMHU3enREcFZuaWh4OXBkRTFiT3loVkpSQlZw?=

=?utf-8?B?SkUzeDJuZVJnTkZvZUFibVk1NnBXRzh5RWxMTlVHbythUHJCYlk5bmx0VG85?=

=?utf-8?B?THp3Mmo2dVFHN1dOS1FTSElmVzZyZ0oxSm1Vb0RWamJISGlpM1RvdWkydzl5?=

=?utf-8?B?Ynk5bHp0bERtWTZIT1M4LzNYQ0h3TGFhWEZVd25ZcFc5cWlUZGxYcXFpTFZs?=

=?utf-8?B?a0l4VVhJWnlVWGFlRVhVZm8rcytoSkZzQjR2RGp3L2o1azd0MmxBQjMweUlB?=

=?utf-8?B?OTNJN2hUM3pMRXNNWGJwYWZIZ3U3OWdsaHpaYU9ZM0hQeDgrL3FDeGVFeER6?=

=?utf-8?B?T1JwdWIwRnFscHZGbnIyV0txN3AwdlVhaVRjOVpwaXhaMEs0UEI5THFOOU9y?=

=?utf-8?B?WEhzbnBlOHVxZ3RjdmhWWUNDRHgxM05Qbi9lNEQzbkNEM0lJQWZ5UjFPZ0Z1?=

=?utf-8?Q?kDeoDqOs8RwalkJ1ZGG2NoKEpga9L8Nq0REE8iZyhPCk=3D?=

X-OriginatorOrg: outlook.com

X-MS-Exchange-CrossTenant-Network-Message-Id: b1f1a3de-259e-4ea8-c0ff-08dc32522d0f

X-MS-Exchange-CrossTenant-AuthSource: AS4P251MB0413.EURP251.PROD.OUTLOOK.COM

X-MS-Exchange-CrossTenant-AuthAs: Internal

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Feb 2024 20:26:10.8543

(UTC)

X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted

X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa

X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg:

00000000-0000-0000-0000-000000000000

X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU0P251MB0435

X-Spam_score: 6.4

X-Spam_score_int: 64

X-Spam_bar: ++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Take advantage of the holiday offer and create your account

today by clicking this link - completely free! Below, you can find the best

recommendation for you, based on your location. Browse profiles and choose

your best match. Check her profile for more photos!



Content analysis details: (6.4 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[40.92.90.86 listed in list.dnswl.org]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[40.92.90.86 listed in wl.mailspike.net]

1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist

[URI: shorturl.ac]

-0.0 SPF_PASS SPF: sender matches SPF record

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

0.0 ARC_VALID Message has a valid ARC signature

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's

domain

-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from

envelope-from domain

0.0 ARC_SIGNED Message has a ARC signature

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

1.2 MISSING_HEADERS Missing To: header

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[lonna_ko(at)outlook.com]

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.0 HTML_MESSAGE BODY: HTML included in message

0.7 MPART_ALT_DIFF BODY: HTML and text parts are different

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag

1.4 MALFORMED_FREEMAIL Bad headers on message from free email service

0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts

Subject: {SPAM?} Profile visit from match



--===============3325682761253975343==

Content-Type: text/html; charset="utf-8"

Content-Transfer-Encoding: base64



PG1ldGEgaHR0cC1lcXVpdj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJz

ZXQ9dXRmLTgiPjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNlbnRlciI+Jm5ic3A7PC9wPgoKPHAgc3R5

bGU9InRleHQtYWxpZ246Y2VudGVyIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjIwcHgiPjxzcGFu

IHN0eWxlPSJmb250LWZhbWlseTpBcmlhbCxzYW5zLXNlcmlmIj48c3BhbiBzdHlsZT0iY29sb3I6

IzAwMDAwMCI+PHN0cm9uZz5UYWtlIGFkdmFudGFnZSBvZiB0aGUgaG9saWRheSBvZmZlciBhbmQg

Y3JlYXRlIHlvdXIgYWNjb3VudCB0b2RheSBieSBjbGlja2luZyB0aGlzIDxhIGhyZWY9Imh0dHBz

Oi8vdC5seS9ZZEJhbyI+bGluazwvYT4gLSBjb21wbGV0ZWx5IGZyZWUhPC9zdHJvbmc+PC9zcGFu

Pjwvc3Bhbj48L3NwYW4+PC9wPgoKPHAgc3R5bGU9InRleHQtYWxpZ246Y2VudGVyIj4mbmJzcDs8

L3A+Cgo8cCBzdHlsZT0idGV4dC1hbGlnbjpjZW50ZXIiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6

MTRweCI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OkFyaWFsLHNhbnMtc2VyaWYiPjxzcGFuIHN0

eWxlPSJjb2xvcjojMDAwMDAwIj48ZW0+QmVsb3csIHlvdSBjYW4gZmluZCB0aGUgYmVzdCByZWNv

bW1lbmRhdGlvbiBmb3IgeW91LCBiYXNlZCBvbiB5b3VyIGxvY2F0aW9uLjxicj4KQnJvd3NlIHBy

b2ZpbGVzIGFuZCBjaG9vc2UgeW91ciBiZXN0IG1hdGNoLiBDaGVjayBoZXIgcHJvZmlsZSBmb3Ig

bW9yZSBwaG90b3MhPC9lbT48L3NwYW4+PC9zcGFuPjwvc3Bhbj48L3A+Cgo8cCBzdHlsZT0idGV4

dC1hbGlnbjpjZW50ZXIiPiZuYnNwOzwvcD4KCjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNlbnRlciI+

Jm5ic3A7PC9wPgoKPHAgc3R5bGU9InRleHQtYWxpZ246Y2VudGVyIj48c3BhbiBzdHlsZT0iZm9u

dC1zaXplOjE4cHgiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTpBcmlhbCxzYW5zLXNlcmlmIj48

c3BhbiBzdHlsZT0iY29sb3I6IzAwMDAwMCI+QmVsb3cgeW91IGNhbiBzZWUgb25lIG9mIG91ciBt

ZW1iZXJzLjwvc3Bhbj48L3NwYW4+PC9zcGFuPjwvcD4KCjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNl

bnRlciI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMy45OTk5OTk5OTk5OTk5OThwdCI+PHNwYW4g

c3R5bGU9ImZvbnQtZmFtaWx5OkFyaWFsLHNhbnMtc2VyaWYiPjxzcGFuIHN0eWxlPSJjb2xvcjoj

MDAwMDAwIj48c3Ryb25nPjxpbWcgc3JjPSJodHRwczovL2xoNy11cy5nb29nbGV1c2VyY29udGVu

dC5jb20vaUpPX1QzWHBNZTdJbW5wc3FJZ2VqdEhybm9DYUZ5d1p5NGJ5eWZRaTVmVjZqV0FyT2RC

NDJ6eG03NnJhaXFjSFUzSmkxU3BlN3pqRl9mLVlsbDFaSW5aQ1FJZTBIemJ0cEpUN0poVGwzZjA5

Z2JwQ2dJUDlBX202cW5MVzlHcHk2T2xWSGZzRmphZThHdVZ3XzVjWHExSSIgc3R5bGU9ImhlaWdo

dDo3NzlweDsgd2lkdGg6NjI0cHgiPjwvc3Ryb25nPjwvc3Bhbj48L3NwYW4+PC9zcGFuPjwvcD4K

CjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNlbnRlciI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMy45

OTk5OTk5OTk5OTk5OThwdCI+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OkFyaWFsLHNhbnMtc2Vy

aWYiPjxzcGFuIHN0eWxlPSJjb2xvcjojMDAwMDAwIj48c3Ryb25nPk9ubGluZSBub3cg8J+MuTwv

c3Ryb25nPjwvc3Bhbj48L3NwYW4+PC9zcGFuPjwvcD4KCjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNl

bnRlciI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxMy45OTk5OTk5OTk5OTk5OThwdCI+PHNwYW4g

c3R5bGU9ImZvbnQtZmFtaWx5OkFyaWFsLHNhbnMtc2VyaWYiPjxzcGFuIHN0eWxlPSJjb2xvcjoj

MDAwMDAwIj48c3Ryb25nPkZpbmQgb24gZGF0ZWZpbmRlcjwvc3Ryb25nPjwvc3Bhbj48L3NwYW4+

PC9zcGFuPjwvcD4KCjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNlbnRlciI+PGJyPgo8YnI+CjxhIGhy

ZWY9Imh0dHA6Ly9zaG9ydHVybC5hYy83Y2dsMCIgc3R5bGU9InRleHQtZGVjb3JhdGlvbjpub25l

Ij48c3BhbiBzdHlsZT0iZm9udC1zaXplOjE4cHQiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTpB

cmlhbCxzYW5zLXNlcmlmIj48c3BhbiBzdHlsZT0iY29sb3I6IzExNTVjYyI+PHU+TWFyaWFCVzwv

dT48L3NwYW4+PC9zcGFuPjwvc3Bhbj48L2E+PGJyPgo8YnI+CjxzcGFuIHN0eWxlPSJmb250LXNp

emU6MThweCI+RGF0ZUZpbmRlciAtIFlvdXIgR2F0ZXdheSB0byBNZWFuaW5nZnVsIENvbm5lY3Rp

b25zISBEaXNjb3ZlciB0aGUgd29ybGQgb2Ygcm9tYW5jZSBhbmQgY29tcGFuaW9uc2hpcCBvbiBE

YXRlRmluZGVyLCB3aGVyZSBnZW51aW5lIGNvbm5lY3Rpb25zIGhhcHBlbi48L3NwYW4+PC9wPgoK

PHAgc3R5bGU9InRleHQtYWxpZ246Y2VudGVyIj48YnI+CjxzcGFuIHN0eWxlPSJmb250LXNpemU6

MThweCI+VW5sZWFzaCB0aGUgcG90ZW50aWFsIG9mIG9ubGluZSBkYXRpbmcgd2l0aCBvdXIgZGl2

ZXJzZSBwcm9maWxlcyBhbmQgcGVyc29uYWxpemVkIGFsZ29yaXRobXMsIGNyZWF0aW5nIGEgdW5p

cXVlIGFuZCBmdWxmaWxsaW5nIGV4cGVyaWVuY2UuPC9zcGFuPjwvcD4KCjxwIHN0eWxlPSJ0ZXh0

LWFsaWduOmNlbnRlciI+PGJyPgo8c3BhbiBzdHlsZT0iZm9udC1zaXplOjE4cHgiPkpvaW4gdXMg

bm93IHRvIGVtYmFyayBvbiBhIGpvdXJuZXkgb2YgZXhjaXRpbmcgcG9zc2liaWxpdGllcyBhbmQg

ZmluZCBtb3JlIHRoYW4ganVzdCBhIG1hdGNoLjwvc3Bhbj48L3A+Cgo8cCBzdHlsZT0idGV4dC1h

bGlnbjpjZW50ZXIiPjxicj4KPHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToyMHB4Ij48c3Ryb25nPkNy

ZWF0ZSB5b3VyIHByb2ZpbGUgYW5kIHN0YXJ0IHlvdXIgYWR2ZW50dXJlIG9uIERhdGVGaW5kZXIg

dG9kYXkhPC9zdHJvbmc+PC9zcGFuPjwvcD4KCjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNlbnRlciI+

Jm5ic3A7PC9wPgoKPHAgc3R5bGU9InRleHQtYWxpZ246Y2VudGVyIj4mbmJzcDs8L3A+Cgo8cCBz

dHlsZT0idGV4dC1hbGlnbjpjZW50ZXIiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6MThweCI+PGVt

PllvdXIgbG9uZWx5IGRheXMgbWF5IGJlIG92ZXIgc29vbi4gVGFrZSB0aGlzIGNoYW5jZSBhbmQg

c3RhcnQgdGhlIGFkdmVudHVyZSBvZiBtZWV0aW5nIGEgbmV3IHBlcnNvbiwgeW91IG5ldmVyIGtu

b3cgd2hlcmUgaXQgd2lsbCB0YWtlIHlvdSE8L2VtPjwvc3Bhbj48L3A+Cgo8cCBzdHlsZT0idGV4

dC1hbGlnbjpjZW50ZXIiPiZuYnNwOzwvcD4KCjxwIHN0eWxlPSJ0ZXh0LWFsaWduOmNlbnRlciI+

PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZToxOHB4Ij5Zb3Ugb25seSBsaXZlIG9uY2UsIHNvIGRvbid0

IG92ZXJ0aGluayBpdCE8L3NwYW4+PC9wPgoKPHAgc3R5bGU9InRleHQtYWxpZ246Y2VudGVyIj4m

bmJzcDs8L3A+Cgo8cCBzdHlsZT0idGV4dC1hbGlnbjpjZW50ZXIiPjxicj4KPHNwYW4gc3R5bGU9

ImZvbnQtc2l6ZToxNHB4Ij48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6QXJpYWwsc2Fucy1zZXJp

ZiI+PHNwYW4gc3R5bGU9ImNvbG9yOiMwMDAwMDAiPkRvbuKAmXQgd2FudCB0byByZWNlaXZlIGFu

eSBtb3JlIGVtYWlscz88L3NwYW4+PC9zcGFuPjxicj4KPGJyPgo8YSBocmVmPSJodHRwOi8vdC5s

eS9HVnJCSSIgc3R5bGU9InRleHQtZGVjb3JhdGlvbjpub25lIj48c3BhbiBzdHlsZT0iZm9udC1m

YW1pbHk6QXJpYWwsc2Fucy1zZXJpZiI+PHNwYW4gc3R5bGU9ImNvbG9yOiMxMTU1Y2MiPjx1PlVu

c3Vic2NyaWJlIGhlcmU8L3U+PC9zcGFuPjwvc3Bhbj48L2E+PHNwYW4gc3R5bGU9ImZvbnQtZmFt

aWx5OkFyaWFsLHNhbnMtc2VyaWYiPjxzcGFuIHN0eWxlPSJjb2xvcjojMDAwMDAwIj4uPC9zcGFu

Pjwvc3Bhbj48L3NwYW4+PC9wPgoKPHAgc3R5bGU9InRleHQtYWxpZ246Y2VudGVyIj48YnI+CiZu

YnNwOzwvcD4K



--===============3325682761253975343==--

Ryobi one phish from Microsoft Outlook

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 19 Feb 2024 18:28:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rcEuy-00000000MDd-3NoN

for dave@doctor.nl2k.ab.ca;

Mon, 19 Feb 2024 18:27:32 -0700

Resent-From: The Doctor

Resent-Date: Mon, 19 Feb 2024 18:27:32 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-be0deu01on2105.outbound.protection.outlook.com ([40.107.127.105]:44352 helo=DEU01-BE0-obe.outbound.protection.outlook.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rcEK4-00000000Dcl-0zXw

for doctor@doctor.nl2k.ab.ca;

Mon, 19 Feb 2024 17:49:28 -0700

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=hg++3TQNEw+LMYhHThwVPD6s95dFRfzox20JpMx4YxaFpqTnsbszg7ltGztHWo8ROeDl5pxZYngOpHrxNliOo863G4NWguZP2PcFYTewoJtrAYvOX1pWNwEP64xE0s+VnNLZH9tjEE1ZkJLjjaG1um9vODDE3B8oL7dcX7xjLEwptL6FayXSGuQEHD1gcK5ykwp1VyuflUNIx0mIDHjZ3umiZsbhZl4sSUEhYvd+vnQWvW8xxClVdXGveOC7FhNgKxjpCSjI6oOdxX6pTDcaxyIvzaAdDjYc6iy86dyW8JMOwjAAygspGC3PzLxufrXJLNVZuvgMYunPmtPgH/IBPg==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;

bh=WSk4pCwCayg+HpRuGcOvi91kXE1rTbj6c4t5tgWQTyo=;

b=WxJWt9YxJxersxtniHW8Ii9h8Jx/eEJN5ztd1UcexwshLMP+WaMYH6L2GqizcrECUhWDKC/6cGI2Oj9j7kkwqpcRkSgr5fcXubxllr/OREeJcUrr4YNG8wftYUBfKsxr+RbTHCka7R0HatbJ4LedNdERC4d1bVhV29MWhwmXrG2fIdVEe0fimsyudxk13wafJ2yyRjBz8Xe74Tr4l0aFKakSUZ6rNOwG77yhh2g+nTJGrN2rc8YLL+AFWPjE7DSRs65M3f4ze7q9q/pezLYNBZoAEfzN/OJR2UJkIi9uKHCeq1oA+Q84VsH2PbQNju0K8t/ZiW83znaf7Hix8InwGw==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=fail (sender ip is

141.8.194.43) smtp.rcpttodomain=doctor.nl2k.ab.ca

smtp.mailfrom=hbdokmwt.onmicrosoft.com; dmarc=none action=none

header.from=hbdokmwt.onmicrosoft.com; dkim=none (message not signed);

arc=none (0)

X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 141.8.194.43)

smtp.mailfrom=hbdokmwt.onmicrosoft.com; dkim=none (message not signed)

header.d=none;dmarc=none action=none header.from=hbdokmwt.onmicrosoft.com;

MIME-Version: 1.0

From: Deals

To: doctor

Subject: Shipment Pending - Ryobi One Chainsaw

Date: Tue, 20 Feb 2024 01:45:42 +0100

x-priority: 1

Content-Type: multipart/alternative; charset="UTF-8";boundary="d4uTz0QPnKHYKXK.xlfejnpkgu.43619"

Delivered-To: doctor

Reply-To: Deals

X-Sender: admin@hbdokmwt.onmicrosoft.com

Message-ID:

<364d1790-052e-4fec-96ec-4b3aa6c1beea@BE0DEU01FT003.eop-deu01.prod.protection.outlook.com>

X-EOPAttributedMessage: 0

X-MS-PublicTrafficType: Email

X-MS-TrafficTypeDiagnostic: BE0DEU01FT003:EE_|FR2P281MB2687:EE_

X-MS-Office365-Filtering-Correlation-Id: 37ba9a88-0944-4428-e426-08dc31ad7d1a

X-MS-Exchange-SenderADCheck: 1

X-MS-Exchange-AntiSpam-Relay: 0

X-Microsoft-Antispam: BCL:0;

X-Microsoft-Antispam-Message-Info:

gTt/A1xh/FqR4AvurGUqjFgue4LKqJE1oXYBD1tgqUnSmR1gcSSuTOmC7kY+IkA9sHnr/pNpRFpzx5e7Q6GS6QbNbh+aW16w2HIoPwkfOwqVE6Ga+umqWcMymTCYYMn1ogrtTN9hFAd0msT1woOhTSY2/bE3OtbiSjHmoPZs+Gc813DY4mWRes7CmvUvLsM1fEU95qDTF5b2duBXQDe/ChvGMe4PJdKMOBzTTrIwcXb4j+gqMu3UMrG1FYEps8HsEJ0ir1Aar0Gr1/xso2IsUxHg5IKyuIxYkMSiVe+9gOh8IE0gli8Ww8wDjiE4csGvui5vsX3mT9r0/dzXjCESFS7Vx3iatpEaA0CfCklPvU6XcrkB6diKr1UdQSWXhoXH

X-Forefront-Antispam-Report:

CIP:141.8.194.43;CTRY:RU;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.vizio.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230031)(36860700004)(7200799017)(46966006)(40470700004);DIR:OUT;SFP:1102;

X-OriginatorOrg: hbdokmwt.onmicrosoft.com

X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Feb 2024 00:47:17.6379

(UTC)

X-MS-Exchange-CrossTenant-Network-Message-Id: 37ba9a88-0944-4428-e426-08dc31ad7d1a

X-MS-Exchange-CrossTenant-Id: 51342385-4adc-4e08-bc54-ffeb5ae20642

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=51342385-4adc-4e08-bc54-ffeb5ae20642;Ip=[141.8.194.43];Helo=[mail.vizio.com]

X-MS-Exchange-CrossTenant-AuthSource:

BE0DEU01FT003.eop-deu01.prod.protection.outlook.com

X-MS-Exchange-CrossTenant-AuthAs: Anonymous

X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem

X-MS-Exchange-Transport-CrossTenantHeadersStamped: FR2P281MB2687

X-Spam_score: 19.7

X-Spam_score_int: 197

X-Spam_bar: +++++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: doctor(371045762904643567694237871994)



Content analysis details: (19.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[40.107.127.105 listed in list.dnswl.org]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[40.107.127.105 listed in wl.mailspike.net]

0.0 T_SPF_TEMPERROR SPF: test of record failed (temperror)

-0.0 SPF_HELO_PASS SPF: HELO matches SPF record

0.0 ARC_VALID Message has a valid ARC signature

0.0 ARC_SIGNED Message has a ARC signature

0.6 HK_RANDOM_ENVFROM Envelope sender username looks random

1.0 HK_RANDOM_REPLYTO Reply-To username looks random

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[lwvmofeh.dffcyozo(at)hbdokmwt.onmicrosoft.com]

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words

0.0 HTML_MESSAGE BODY: HTML included in message

0.7 MPART_ALT_DIFF BODY: HTML and text parts are different

1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different

freemails

0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts

0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image

1.5 URI_IMG_CWINDOWSNET Non-MSFT image hosted by Microsoft Azure infra,

possible phishing

1.0 FORGED_SPF_HELO No description available.

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 SCC_BODY_SINGLE_WORD Message body seems like one word

0.7 BODY_URI_ONLY Message body is only a URI in one line of text or for

an image

1.0 HOSTED_IMG_FREEM Image hosted at large ecomm, CDN or hosting site or

redirected, freemail from or reply-to

3.5 HOSTED_IMG_DIRECT_MX Image hosted at large ecomm, CDN or hosting

site, message direct-to-mx

1.0 XPRIO Has X-Priority header

2.7 SCC_BODY_URI_ONLY Very short body with something maybe clickable

0.0 BODY_SINGLE_WORD Message body is only one word (no spaces)

1.2 BODY_SINGLE_URI Message body is only a URI

0.0 T_REMOTE_IMAGE Message contains an external image

1.8 SPOOFED_FREEM_REPTO Forged freemail sender with freemail reply-to

Subject: {SPAM?} Shipment Pending - Ryobi One Chainsaw



--d4uTz0QPnKHYKXK.xlfejnpkgu.43619

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset="UTF-8"







doctor(371045762904643567694237871994)





























































































--d4uTz0QPnKHYKXK.xlfejnpkgu.43619--