BTC Paypal phish from Microsoft Outlook Part 1
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 23 Jun 2026 15:24:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from)
id 1wc8aI-00000000Gun-2sq2
for dave@doctor.nl2k.ab.ca;
Tue, 23 Jun 2026 15:23:06 -0600
Resent-From: The Doctor
Resent-Date: Tue, 23 Jun 2026 15:23:06 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-westus2azlp17010074.outbound.protection.outlook.com ([40.93.10.74]:51376 helo=CO1PR03CU002.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.3 (FreeBSD))
(envelope-from)
id 1wc4wh-00000000EbU-0COc
for doctor@doctor.nl2k.ab.ca;
Tue, 23 Jun 2026 11:30:10 -0600
Received: from SN7PR04CA0228.namprd04.prod.outlook.com (2603:10b6:806:127::23)
by SA1PR18MB5995.namprd18.prod.outlook.com (2603:10b6:806:3e5::9) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.139.20; Tue, 23 Jun
2026 17:28:59 +0000
Received: from SN1PEPF000252A4.namprd05.prod.outlook.com
(2603:10b6:806:127:cafe::28) by SN7PR04CA0228.outlook.office365.com
(2603:10b6:806:127::23) with Microsoft SMTP Server (version=TLS1_3,
cipher=TLS_AES_256_GCM_SHA384) id 15.21.159.12 via Frontend Transport; Tue,
23 Jun 2026 17:28:57 +0000
Authentication-Results: spf=pass (sender IP is 209.85.128.71)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=google.com;dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;compauth=pass
reason=100
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.128.71 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.128.71; helo=mail-wm1-f71.google.com; pr=C
Received: from mail-wm1-f71.google.com (209.85.128.71) by
SN1PEPF000252A4.mail.protection.outlook.com (10.167.242.11) with Microsoft
SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.159.10
via Frontend Transport; Tue, 23 Jun 2026 17:28:56 +0000
X-IncomingTopHeaderMarker:
OriginalChecksum:69E94EDDCCC317A7382B233001AE1493E7625ECBB4989501371E2DC435462D50;UpperCasedChecksum:2D96D2652777FAC9142D897AF6051B1C2E124A8BDAC2D2896E84B0CBB4776FCE;SizeAsReceived:3431;Count:15
Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-490c840efe6so10915295e9.1
for; Tue, 23 Jun 2026 10:28:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=google.com; s=20251104; t=1782235736; x=1782840536; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=tgTEoFK5t+QZF3palIbNTYfnShlYs/6yP4lrg7uKrlg=;
b=NUPONEAXVmj4BnOlGQkGLGxqUM/w7921jyiSG2dTPn1YgToaoAMrEfekBJRtzgGsCX
WZYS2MMM3KyYAGIOlVzyb0mgE7cYHXPdERjj+zfvz4vECaohv+o8DU4nn6Nf2P2v/D8p
+dP15JoH5U2vCwdEu8vIs6h7nO2zbwaGsDsHO3W/Li85I/z3KCx8Nut91NYnLLHWZMKx
XElOMqc0cjT+LCKHDbydy+d8INefXnykhvL7AnE/YL4LB1BZBLnokMGvJ9/cgeIt00qa
r1o9O32l4GZFTWeMHOfzKxIkvfmQikKgAT8kfa6JGY69ai5Q85KSUlBlI3dPh2llEdya
46rA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20251104; t=1782235736; x=1782840536; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=tgTEoFK5t+QZF3palIbNTYfnShlYs/6yP4lrg7uKrlg=;
b=a2tCllOyZvw87fE3yAFEy43cKftUmFXD5b9fbqGmC7CPHGCIv5/597PiZMwzUcm3gj
X+dC6a/ft/0DcaJnr1n+3hgbG1YIsy1QbYdcZsk4ugGNiGc2ptRZn0gnRfCa3y2BQgqQ
zFOFBw9stU8bPA/p/fRqnEgoxOplCN1SMXJbVQTER4swhM5pokdGxcadaa7/p3twqxzN
7dF8qpFMojdCHm1DcowoKVtbwGeWeR7zZGdgbfOTId3gPuuRB5pxmJ2dHF7ZOxUSCxr2
Jfm2ppe5Az69nGd8JQI1oD3kMbGmNyB+uHoo8rcsMWhk3W6r/IeGRTr6uLj04dXchTK1
fxrg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1782235736; x=1782840536;
h=to:from:subject:date:message-id:sender:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=tgTEoFK5t+QZF3palIbNTYfnShlYs/6yP4lrg7uKrlg=;
b=n2A00AuB7qJLN/2BBHImEJj6l//U7xQ4tKWjMWc5Xe5L89jM/N+1AypyRgl75ITTGZ
lsxVqFBP0mgnjrNaJuf8uA9F2kWYniS6wc66msmgp4aT/nTj05YLpNr9fLTNTHXgeNdY
AVNASHNrNHXgJcBIyumZqPedDxqv3vfjJ565tsGr8hVF3KABXZfF7tewh8LQUBueqyV9
AIvHl9CQ8e8/ktanPOJ2nNCLZS+pt+0SU+gZInBeT/ryXW+hj3FIXdd9XRX/+dwyK9QL
a6WKyAZ20ySZntqSe3mRNUv16bsR7zK6yO+XSbxGzau+AMRjbTTzokGweN88JhomNYN8
09Xg==
X-Gm-Message-State: AOJu0YxE+XRhNNxrJRP3KhvG1dTSsW/nFF+SKf8MGtD31t/67nRTqCO9
llsvODePH23wgCOE0Kvir2waawn88tpxZHWPAiNhjI2Spu3k4SXyS2XoX6NqQ9apo6fMORxnGPi
SAshixPBQvcPz4pP5LNWCz8xkjR7YWlxI4SA=
MIME-Version: 1.0
X-Received: by 2002:a05:600c:4e8f:b0:48a:53cb:8604 with SMTP id
5b1f17b1804b1-4925a0c4ec8mr68780115e9.14.1782235735045; Tue, 23 Jun 2026
10:28:55 -0700 (PDT)
Reply-To: Haresasz Nxysarwsa
Sender: =?UTF-8?Q?Kalend=C3=A1r_Google?=
Message-ID:
Date: Tue, 23 Jun 2026 17:28:55 +0000
Subject: =?UTF-8?Q?Pozv=C3=A1nky=3A_Important_Transaction_Alert_=2D_BTC_Order_S?=
=?UTF-8?Q?ubmitted_=40_ut_23=2E_j=C3=BAn_=2D_st_24=2E_j=C3=BAn_2026_=28cynthiaperez38990?=
=?UTF-8?Q?3=40groups=2Eoutlook=2Ecom=29?=
From: Haresasz Nxysarwsa
To: cynthiaperez389903@groups.outlook.com
Content-Type: multipart/mixed; boundary="000000000000e4baa50654ef17cc"
X-IncomingHeaderCount: 15
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SN1PEPF000252A4:EE_|SA1PR18MB5995:EE_
X-MS-Office365-Filtering-Correlation-Id: 7777c2d4-fd54-42ab-75ff-08ded14ce7d1
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 209.85.128.71
X-SID-PRA: HARESSAZNZXRRSXAXZ321@GMAIL.COM
X-SID-Result: PASS
X-MS-Consumer-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-MS-Exchange-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 23 Jun 2026 15:24:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wc8aI-00000000Gun-2sq2
for dave@doctor.nl2k.ab.ca;
Tue, 23 Jun 2026 15:23:06 -0600
Resent-From: The Doctor
Resent-Date: Tue, 23 Jun 2026 15:23:06 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-westus2azlp17010074.outbound.protection.outlook.com ([40.93.10.74]:51376 helo=CO1PR03CU002.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wc4wh-00000000EbU-0COc
for doctor@doctor.nl2k.ab.ca;
Tue, 23 Jun 2026 11:30:10 -0600
Received: from SN7PR04CA0228.namprd04.prod.outlook.com (2603:10b6:806:127::23)
by SA1PR18MB5995.namprd18.prod.outlook.com (2603:10b6:806:3e5::9) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.139.20; Tue, 23 Jun
2026 17:28:59 +0000
Received: from SN1PEPF000252A4.namprd05.prod.outlook.com
(2603:10b6:806:127:cafe::28) by SN7PR04CA0228.outlook.office365.com
(2603:10b6:806:127::23) with Microsoft SMTP Server (version=TLS1_3,
cipher=TLS_AES_256_GCM_SHA384) id 15.21.159.12 via Frontend Transport; Tue,
23 Jun 2026 17:28:57 +0000
Authentication-Results: spf=pass (sender IP is 209.85.128.71)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=google.com;dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;compauth=pass
reason=100
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.128.71 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.128.71; helo=mail-wm1-f71.google.com; pr=C
Received: from mail-wm1-f71.google.com (209.85.128.71) by
SN1PEPF000252A4.mail.protection.outlook.com (10.167.242.11) with Microsoft
SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.159.10
via Frontend Transport; Tue, 23 Jun 2026 17:28:56 +0000
X-IncomingTopHeaderMarker:
OriginalChecksum:69E94EDDCCC317A7382B233001AE1493E7625ECBB4989501371E2DC435462D50;UpperCasedChecksum:2D96D2652777FAC9142D897AF6051B1C2E124A8BDAC2D2896E84B0CBB4776FCE;SizeAsReceived:3431;Count:15
Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-490c840efe6so10915295e9.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=google.com; s=20251104; t=1782235736; x=1782840536; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=tgTEoFK5t+QZF3palIbNTYfnShlYs/6yP4lrg7uKrlg=;
b=NUPONEAXVmj4BnOlGQkGLGxqUM/w7921jyiSG2dTPn1YgToaoAMrEfekBJRtzgGsCX
WZYS2MMM3KyYAGIOlVzyb0mgE7cYHXPdERjj+zfvz4vECaohv+o8DU4nn6Nf2P2v/D8p
+dP15JoH5U2vCwdEu8vIs6h7nO2zbwaGsDsHO3W/Li85I/z3KCx8Nut91NYnLLHWZMKx
XElOMqc0cjT+LCKHDbydy+d8INefXnykhvL7AnE/YL4LB1BZBLnokMGvJ9/cgeIt00qa
r1o9O32l4GZFTWeMHOfzKxIkvfmQikKgAT8kfa6JGY69ai5Q85KSUlBlI3dPh2llEdya
46rA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20251104; t=1782235736; x=1782840536; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=tgTEoFK5t+QZF3palIbNTYfnShlYs/6yP4lrg7uKrlg=;
b=a2tCllOyZvw87fE3yAFEy43cKftUmFXD5b9fbqGmC7CPHGCIv5/597PiZMwzUcm3gj
X+dC6a/ft/0DcaJnr1n+3hgbG1YIsy1QbYdcZsk4ugGNiGc2ptRZn0gnRfCa3y2BQgqQ
zFOFBw9stU8bPA/p/fRqnEgoxOplCN1SMXJbVQTER4swhM5pokdGxcadaa7/p3twqxzN
7dF8qpFMojdCHm1DcowoKVtbwGeWeR7zZGdgbfOTId3gPuuRB5pxmJ2dHF7ZOxUSCxr2
Jfm2ppe5Az69nGd8JQI1oD3kMbGmNyB+uHoo8rcsMWhk3W6r/IeGRTr6uLj04dXchTK1
fxrg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1782235736; x=1782840536;
h=to:from:subject:date:message-id:sender:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=tgTEoFK5t+QZF3palIbNTYfnShlYs/6yP4lrg7uKrlg=;
b=n2A00AuB7qJLN/2BBHImEJj6l//U7xQ4tKWjMWc5Xe5L89jM/N+1AypyRgl75ITTGZ
lsxVqFBP0mgnjrNaJuf8uA9F2kWYniS6wc66msmgp4aT/nTj05YLpNr9fLTNTHXgeNdY
AVNASHNrNHXgJcBIyumZqPedDxqv3vfjJ565tsGr8hVF3KABXZfF7tewh8LQUBueqyV9
AIvHl9CQ8e8/ktanPOJ2nNCLZS+pt+0SU+gZInBeT/ryXW+hj3FIXdd9XRX/+dwyK9QL
a6WKyAZ20ySZntqSe3mRNUv16bsR7zK6yO+XSbxGzau+AMRjbTTzokGweN88JhomNYN8
09Xg==
X-Gm-Message-State: AOJu0YxE+XRhNNxrJRP3KhvG1dTSsW/nFF+SKf8MGtD31t/67nRTqCO9
llsvODePH23wgCOE0Kvir2waawn88tpxZHWPAiNhjI2Spu3k4SXyS2XoX6NqQ9apo6fMORxnGPi
SAshixPBQvcPz4pP5LNWCz8xkjR7YWlxI4SA=
MIME-Version: 1.0
X-Received: by 2002:a05:600c:4e8f:b0:48a:53cb:8604 with SMTP id
5b1f17b1804b1-4925a0c4ec8mr68780115e9.14.1782235735045; Tue, 23 Jun 2026
10:28:55 -0700 (PDT)
Reply-To: Haresasz Nxysarwsa
Sender: =?UTF-8?Q?Kalend=C3=A1r_Google?=
Message-ID:
Date: Tue, 23 Jun 2026 17:28:55 +0000
Subject: =?UTF-8?Q?Pozv=C3=A1nky=3A_Important_Transaction_Alert_=2D_BTC_Order_S?=
=?UTF-8?Q?ubmitted_=40_ut_23=2E_j=C3=BAn_=2D_st_24=2E_j=C3=BAn_2026_=28cynthiaperez38990?=
=?UTF-8?Q?3=40groups=2Eoutlook=2Ecom=29?=
From: Haresasz Nxysarwsa
To: cynthiaperez389903@groups.outlook.com
Content-Type: multipart/mixed; boundary="000000000000e4baa50654ef17cc"
X-IncomingHeaderCount: 15
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SN1PEPF000252A4:EE_|SA1PR18MB5995:EE_
X-MS-Office365-Filtering-Correlation-Id: 7777c2d4-fd54-42ab-75ff-08ded14ce7d1
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 209.85.128.71
X-SID-PRA: HARESSAZNZXRRSXAXZ321@GMAIL.COM
X-SID-Result: PASS
X-MS-Consumer-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-MS-Exchange-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com