PAedophile accusation phish from Microsoft Outlook Part 2
Posted by Dave Yadallee on
Content analysis details: (7.9 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
[52.101.201.86 listed in dnsbl.ahbl.org]
[52.101.201.86 listed in dnsbl.ahbl.org]
[52.101.201.86 listed in dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.101.201.86 listed in list.dnswl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.101.201.86 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
1.2 MISSING_HEADERS Missing To: header
1.7 DEAR_SOMETHING BODY: Contains 'Dear (something)'
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} RV: TR: Complaint
--_004_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_
Content-Type: multipart/alternative;
boundary="_000_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_"
--_000_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
________________________________
Dear Sir or Madam,
Please find attached a document intended for you.
This email is neither spam nor a mistake.
We look forward to hearing from you.
Best regards,
--_000_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
1">
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
[52.101.201.86 listed in dnsbl.ahbl.org]
[52.101.201.86 listed in dnsbl.ahbl.org]
[52.101.201.86 listed in dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.101.201.86 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:208:5c:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
[52.101.201.86 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.101.201.86 listed in list.dnswl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.101.201.86 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
1.2 MISSING_HEADERS Missing To: header
1.7 DEAR_SOMETHING BODY: Contains 'Dear (something)'
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} RV: TR: Complaint
--_004_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_
Content-Type: multipart/alternative;
boundary="_000_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_"
--_000_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
________________________________
Dear Sir or Madam,
Please find attached a document intended for you.
This email is neither spam nor a mistake.
We look forward to hearing from you.
Best regards,
--_000_BL0PR02MB46607BC21D6630660034495F93582BL0PR02MB4660namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
1">
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
quot;, "Aptos_MSFontService", Calibri, Helvetica, sans-serif; fon=
t-size: 12pt; color: rgb(0, 0, 0);">
Dear Sir or Madam,
quot;, "Aptos_MSFontService", Calibri, Helvetica, sans-serif; fon=
t-size: 12pt; color: rgb(0, 0, 0);">
Please find attached a document intended for you.
quot;, "Aptos_MSFontService", Calibri, Helvetica, sans-serif; fon=
t-size: 12pt; color: rgb(0, 0, 0);">
This email is neither spam nor a mistake.
quot;, "Aptos_MSFontService", Calibri, Helvetica, sans-serif; fon=
t-size: 12pt; color: rgb(0, 0, 0);">
We look forward to hearing from you.
quot;, "Aptos_MSFontService", Calibri, Helvetica, sans-serif; fon=
t-size: 12pt; color: rgb(0, 0, 0);">
Best regards,
{False jpeg attachment}