Dating phish from Microsoft Outlook Part 2
Posted by Dave Yadallee onContent-Type: multipart/alternative;
boundary="_000_PU4P216MB22811844F3349C10D44CFA43F261APU4P216MB2281KORP_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-9412-4-msonline-outlook-4829b.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PU4P216MB2281.KORP216.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: e004b6b5-ae46-417d-f713-08de6b4870d8
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Feb 2026 21:40:00.8244
(UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PUVP216MB3225
X-Spam_score: 13.9
X-Spam_score_int: 139
X-Spam_bar: +++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hi, I randomly stumbled onto a new dating site recently and
ended up spending more time there than I expected. Not because it was flashy,
but because it actually felt quite normal. You can browse prof [...]
Content analysis details: (13.9 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.103.74.33 listed in dnsbl.ahbl.org]
[52.103.74.33 listed in dnsbl.ahbl.org]
[52.103.74.33 listed in dnsbl.ahbl.org]
[52.103.74.33 listed in dnsbl.ahbl.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[dnsbl.ahbl.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[dnsbl.ahbl.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[dnsbl.ahbl.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.103.74.33 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.103.74.33 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.103.74.33 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.103.74.33 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:1096:301:12b:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
[52.103.74.33 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.103.74.33 listed in list.dnswl.org]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: quoraq.pro]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: quoraq.pro]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: quoraq.pro]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
1.2 MISSING_HEADERS Missing To: header
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[blairalt1kj(at)hotmail.com]
0.0 T_PDS_PRO_TLD .pro TLD
[URI: quoraq.pro (pro)]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.103.74.33 listed in wl.mailspike.net]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
1.4 MALFORMED_FREEMAIL Bad headers on message from free email service
Subject: {SPAM?} No stress, no obligation, just fun
--_000_PU4P216MB22811844F3349C10D44CFA43F261APU4P216MB2281KORP_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
Hi,
I randomly stumbled onto a new dating site recently and ended up spending m=
ore time there than I expected. Not because it was flashy, but because it a=
ctually felt quite normal.
You can browse profiles, read about people=92s interests, see what they enj=
oy doing, and get a sense of someone before even starting a conversation. T=
hat alone already makes things feel a lot less awkward.
If you want to explore it a bit, you can check it out here.
pro/Mbhbqk>
Some people are clearly just chatting, some are flirting, some are hoping t=
o meet someone for real. It doesn=92t feel like anyone is being pushed in o=
ne direction, which I found quite nice.
Anyway, just sharing in case you ever feel like trying something different.
--_000_PU4P216MB22811844F3349C10D44CFA43F261APU4P216MB2281KORP_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
252">
ottom: 12pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
Hi,
ottom: 12pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
I randomly stumb=
led onto a new dating site recently and ended up spending more time there t=
han I expected. Not because it was flashy, but because it actually felt qui=
te normal.
ottom: 12pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
You can browse p=
rofiles, read about people=92s interests, see what they enjoy doing, and ge=
t a sense of someone before even starting a conversation. That alone alread=
y makes things feel a lot less awkward.
ottom: 12pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
If you want to e=
xplore it a bit, you can
9d779-02b6-30b7-6d32-e51c20fd95c1" href=3D"https://quoraq.pro/Mbhbqk">check=
it out here.
ottom: 12pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
Some people are =
clearly just chatting, some are flirting, some are hoping to meet someone f=
or real. It doesn=92t feel like anyone is being pushed in one direction, wh=
ich I found quite nice.
ottom: 12pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class=
=3D"elementToProof">
Anyway, just sha=
ring in case you ever feel like trying something different.
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
--_000_PU4P216MB22811844F3349C10D44CFA43F261APU4P216MB2281KORP_--