Paypal phish from Microsoft Outlook Part 2
Posted by Dave Yadallee onpts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
[40.93.23.1 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[40.93.23.1 listed in dnsbl.ahbl.org]
[40.93.23.1 listed in dnsbl.ahbl.org]
[40.93.23.1 listed in dnsbl.ahbl.org]
[40.93.23.1 listed in dnsbl.ahbl.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[dnsbl.ahbl.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[dnsbl.ahbl.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[dnsbl.ahbl.org]
[2603:10b6:806:34d:0:0:0:12 listed in]
[dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[40.93.23.1 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[40.93.23.1 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[40.93.23.1 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[40.93.23.1 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[40.93.23.1 listed in list.dnswl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[40.93.23.1 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.0 AXB_X_FF_SEZ_S Forefront sez this is spam
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
1.5 TVD_PH_BODY_ACCOUNTS_PRE The body matches phrases such as "accounts
suspended", "account credited", "account
verification"
1.2 TVD_PH_SUBJ_META1 Email has a Phishy looking subject line
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} Payment from Pay Pal LLC for USD 789.96 has been confirmed. If you
believe this to be inaccurate, contact 18102930409. account email
verification code
=09
Payment from Pay Pal LLC for USD 789.96 has been confirmed. If you beli=
eve this to be inaccurate, contact 18102930409. account email verification =
code
dir=3D"ltr" lang=3D"en">
=20
der=3D"0" dir=3D"ltr" lang=3D"en" style=3D"border-left:1px solid #e3e3e3;bo=
rder-right: 1px solid #e3e3e3;">
:1px solid #e3e3e3;">
border-bottom:1px solid #e3e3e3;">
:1px solid #e3e3e3; border-bottom:1px solid #e3e3e3;padding:12px 0;">
Light; font-size:18pt; color:#ffffff; font-weight:normal;">
=20
"#FFFFFF">Verify your email address
;border-bottom: 1px solid #e3e3e3;">