Bitcoin Phish from Microsoft Outlook Part 3
Posted by Dave Yadallee on
[2603:10a6:10:3c2:0:0:0:20 listed in]
[dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[103.230.209.8 listed in sbl-xbl.spamhaus.org]
[103.230.209.8 listed in sbl-xbl.spamhaus.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[103.230.209.8 listed in zen.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[40.93.6.34 listed in list.dnswl.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[40.93.6.34 listed in bl.score.senderscore.com]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
1.0 HK_RANDOM_FROM From username looks random
0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters
3.5 VOWEL_FROM_7 Impronouncable from header (7+ consecutive vowels)
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[haressaznzxrrsxaxz321(at)gmail.com]
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.2 FREEMAIL_FORGED_FROMDOMAIN 2nd level domains in From and EnvelopeFrom
freemail headers are different
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} =?utf-8?q?Subject=3A_Pa=E2=80=8Byment_Received_TRX43050953_=E2=80=93_BTC_Ord?=
=?utf-8?q?er_Processing?=
--===============3131275277521598797==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Dear Customer,
Your PayPal payment has been received successfully and your Bitcoin (BTC) o=
rder is now under processing. Our system has securely logged your transacti=
on and it is currently waiting for confirmation.
Transaction ID: TRX43050953
Date: 04/28/2026
Amount: $841
Payment Method: PayPal
Order Status: Pending Confirmation
Please note that Bitcoin transactions depend on blockchain confirmations, w=
hich may take some time based on network activity. You will be notified onc=
e your transaction is completed.
For any questions or further assistance, please contact our support team us=
ing the number below:
Customer Support: +1 804 315 0219
Thank you for your trust in our service.
Best Regards,
Billing Department
--===============3131275277521598797==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
--===============3131275277521598797==--
[dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[209.85.216.41 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
[103.230.209.8 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[40.93.6.34 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[103.230.209.8 listed in sbl-xbl.spamhaus.org]
[103.230.209.8 listed in sbl-xbl.spamhaus.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[103.230.209.8 listed in zen.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[40.93.6.34 listed in list.dnswl.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[40.93.6.34 listed in bl.score.senderscore.com]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
1.0 HK_RANDOM_FROM From username looks random
0.5 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters
3.5 VOWEL_FROM_7 Impronouncable from header (7+ consecutive vowels)
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[haressaznzxrrsxaxz321(at)gmail.com]
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.2 FREEMAIL_FORGED_FROMDOMAIN 2nd level domains in From and EnvelopeFrom
freemail headers are different
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} =?utf-8?q?Subject=3A_Pa=E2=80=8Byment_Received_TRX43050953_=E2=80=93_BTC_Ord?=
=?utf-8?q?er_Processing?=
--===============3131275277521598797==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Dear Customer,
Your PayPal payment has been received successfully and your Bitcoin (BTC) o=
rder is now under processing. Our system has securely logged your transacti=
on and it is currently waiting for confirmation.
Transaction ID: TRX43050953
Date: 04/28/2026
Amount: $841
Payment Method: PayPal
Order Status: Pending Confirmation
Please note that Bitcoin transactions depend on blockchain confirmations, w=
hich may take some time based on network activity. You will be notified onc=
e your transaction is completed.
For any questions or further assistance, please contact our support team us=
ing the number below:
Customer Support: +1 804 315 0219
Thank you for your trust in our service.
Best Regards,
Billing Department
--===============3131275277521598797==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Dear Customer,
Your PayPal payment has been received successfully and your Bitcoin (BTC) o=
rder is now under processing. Our system has securely logged your transacti=
on and it is currently waiting for confirmation.
Transaction ID: TRX43050953
Date: 04/28/2026
Amount: $841
Payment Method: PayPal
Order Status: Pending Confirmation
Please note that Bitcoin transactions depend on blockchain confirmations, w=
hich may take some time based on network activity. You will be notified onc=
e your transaction is completed.
For any questions or further assistance, please contact our support team us=
ing the number below:
Customer Support: +1 804 315 0219
Thank you for your trust in our service.
Best Regards,
Billing Department
Your PayPal payment has been received successfully and your Bitcoin (BTC) o=
rder is now under processing. Our system has securely logged your transacti=
on and it is currently waiting for confirmation.
Transaction ID: TRX43050953
Date: 04/28/2026
Amount: $841
Payment Method: PayPal
Order Status: Pending Confirmation
Please note that Bitcoin transactions depend on blockchain confirmations, w=
hich may take some time based on network activity. You will be notified onc=
e your transaction is completed.
For any questions or further assistance, please contact our support team us=
ing the number below:
Customer Support: +1 804 315 0219
Thank you for your trust in our service.
Best Regards,
Billing Department
--===============3131275277521598797==--