Bitcoin phish from Microsoft Outlook Part 3
Posted by Dave Yadallee on-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[40.93.10.75 listed in list.dnswl.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[40.93.10.75 listed in bl.score.senderscore.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[40.93.10.75 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters
3.5 VOWEL_FROM_7 Impronouncable from header (7+ consecutive vowels)
1.0 HK_RANDOM_REPLYTO Reply-To username looks random
1.0 HK_RANDOM_FROM From username looks random
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[haressaznzxrrsxaxz321(at)gmail.com]
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[haressaznzxrrsxaxz321(at)gmail.com]
0.3 LONGWORD BODY: Uses overlong words
0.1 TW_RW BODY: Odd Letter Triples with RW
0.6 MEGALONGWORD BODY: Uses really overlong words
0.1 TW_DJ BODY: Odd Letter Triples with DJ
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.2 FREEMAIL_FORGED_FROMDOMAIN 2nd level domains in From and EnvelopeFrom
freemail headers are different
0.6 LONG_INVISIBLE_TEXT Long block of hidden text - bayes poison?
0.1 TO_IN_SUBJ To address is in Subject
Subject: {SPAM?} =?UTF-8?Q?Pozv=C3=A1nky=3A_Transaction_Alert_=2D_Bitcoin_Purchase_Requ?=
=?UTF-8?Q?est_Received_=40_po_18=2E_m=C3=A1j_2026_=28cynthiaperez389903=40groups=2Eo?=
=?UTF-8?Q?utlook=2Ecom=29?=
Haresasz Nxysarwsa has invited you to Transaction Alert – Bitcoin Purchase Request Received
Transaction Alert – Bitcoin Purchase Request Received
Pripojiť sa cez Google Meet – Dear Customer, Your PayPal payment for Bitcoin has been received and securely logged in our system. Transaction Summary: Purchase Type: Bitcoin (BTC) Payment Method: PayPal Amount Charged: $750.00
Pripojiť sa cez Google Meet
Odkaz na stretnutie
meet.google.com/hnf-cmsp-djr
Dear Customer,
Your PayPal payment for Bitcoin has been received and securely logged in our system.
Transaction Summary:
Purchase Type: Bitcoin (BTC)
Payment Method: PayPal
Amount Charged: $750.00
Status: Under Review
Our verification team is currently processing your order. Once approved, the transaction will be finalized automatically.
If this activity was not authorized by you, please call +1 801 614 4470 immediately.
Best Regards,
Accounts & Billing Team
Kedy
pondelok 18. máj 2026
Organizátor
Haresasz Nxysarwsa
haressaznzxrrsxaxz321@gmail.com
Hostia
(Zoznam hostí bol na žiadosť organizátora skrytý)
Odpoveď na cynthiaperez389903@groups.outlook.com
Áno
Nie
Možno
Ďalšie možnosti
Pozvánka z Kalendára Google
Túto správu ste dostali, pretože ste účastníkom danej udalosti.
Ak túto pozvánku prepošlete, ktorýkoľvek jej príjemca bude môcť odoslať odpoveď organizátorovi, byť pridaný do zoznamu hostí, pozývať iných bez ohľadu na ich vlastný stav pozvánky alebo meniť vaše potvrdenie účasti. Ďalšie informácie