Cryptocurrency phish from Microsoft Part 3
Posted by Dave Yadallee on1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.101.61.104 listed in dnsbl.ahbl.org]
[52.101.61.104 listed in dnsbl.ahbl.org]
[52.101.61.104 listed in dnsbl.ahbl.org]
[52.101.61.104 listed in dnsbl.ahbl.org]
[2603:10b6:510:2cf:0:0:0:17 listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:0:0:0:17 listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:0:0:0:17 listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:0:0:0:17 listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:cafe:0:0:ed listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:cafe:0:0:ed listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:cafe:0:0:ed listed in]
[dnsbl.ahbl.org]
[2603:10b6:510:2cf:cafe:0:0:ed listed in]
[dnsbl.ahbl.org]
[50.31.156.124 listed in dnsbl.ahbl.org]
[50.31.156.124 listed in dnsbl.ahbl.org]
[50.31.156.124 listed in dnsbl.ahbl.org]
[50.31.156.124 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.101.61.104 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.101.61.104 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.101.61.104 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.101.61.104 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.101.61.104 listed in list.dnswl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.101.61.104 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
2.5 SUSPICIOUS_RECIPS Similar addresses in recipient list
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_IMAGE_RATIO_06 BODY: HTML has a low ratio of text to image area
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_OBFU_PDF_ATTACH PDF attachment with generic MIME type
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
2.0 VOWEL_URI_6 URI hostname with 6 consecutive vowels
Subject: {SPAM?} Reminder: Robert Tech Digit LLC sent you a payment request
Robert Tech Digit LLC
sent you an invoice reminder
$550.00
Due Wed, February 25, 2026
Pay invoice
Invoice details
Bill to
Dear 1
For invoice #
INV-000002C2
Due date
Wed, February 25, 2026
Message
24 X 7 Support Helpline Call +1 (803)-384-7451 πΏπππ²π·π°ππ΄ π±ππ΄π°πΊπ³πΎππ½ πΈπππ π³ππππππππππ | πππ’ | πΏππππ | π°πππππ Bitcoin (BTC) Purchase | 1 | CA$ 500.00 | CA$ 500.00 PayPal Digital Asset Service Fee | 1 | CAD 50.00 |CA$ 50.00 ππΎππ°π» π²π·π°ππΆπ΄π³: CA$ 550.ππ πΈπΌπΏπΎπππ°π½π π½πΎππΈπ²π΄ ππππ ππ ππ πππππππππ πππππππ ππππππππππππ. πΏπππππ ππ πππ πππππ’. π·πππ π²πππππ: +1 (803)-384-7451
Got questions?
For any concerns regarding the invoice, contact Abesse.Songne2123@outlook.com
β
Melio is a payments solution designed to serve small businesses in the United States, including sole proprietorships. Therefore, virtually any business looking to pay other businesses for bills can use Melio.
Trusted by our industry-leading financial partners
Trusted by our industry-leading financial partners.
This email was sent to you by Melio Payments Inc.
124 East 14th St., New York, NY, 10003, USA
Privacy Policy | Terms of Service