Paypal Bitcoin Phishing from Microsoft Outlook Part 1
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 09 Jun 2026 14:14:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from)
id 1wX2pM-000000008Jz-3ZZB
for dave@doctor.nl2k.ab.ca;
Tue, 09 Jun 2026 14:13:36 -0600
Resent-From: The Doctor
Resent-Date: Tue, 9 Jun 2026 14:13:36 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-northcentralusazlp17013059.outbound.protection.outlook.com ([40.93.20.59]:36351 helo=CH4PR04CU002.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.3 (FreeBSD))
(envelope-from)
id 1wWz2L-00000000Mzm-1z9q
for doctor@doctor.nl2k.ab.ca;
Tue, 09 Jun 2026 10:10:57 -0600
Received: from SJ0PR03CA0161.namprd03.prod.outlook.com (2603:10b6:a03:338::16)
by LV9PR18MB927589.namprd18.prod.outlook.com (2603:10b6:408:376::24) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.92.10; Tue, 9 Jun 2026
16:09:43 +0000
Received: from SJ5PEPF00000205.namprd05.prod.outlook.com
(2603:10b6:a03:338::4) by SJ0PR03CA0161.outlook.office365.com
(2603:10b6:a03:338::16) with Microsoft SMTP Server (version=TLS1_3,
cipher=TLS_AES_256_GCM_SHA384) id 15.21.92.13 via Frontend Transport; Tue, 9
Jun 2026 16:09:43 +0000
Authentication-Results: spf=pass (sender IP is 209.85.128.69)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=google.com;dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;compauth=pass
reason=100
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.128.69 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.128.69; helo=mail-wm1-f69.google.com; pr=C
Received: from mail-wm1-f69.google.com (209.85.128.69) by
SJ5PEPF00000205.mail.protection.outlook.com (10.167.244.38) with Microsoft
SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.113.7
via Frontend Transport; Tue, 9 Jun 2026 16:09:43 +0000
X-IncomingTopHeaderMarker:
OriginalChecksum:25E206E7EFFC06789889CF8D86B6964DFEE09EA908D2C89631F8CA767E6F9F15;UpperCasedChecksum:BD9ADE5EE704C0427FE424ECDF6BE331E32665AF02722F5BC1C8778369E2571B;SizeAsReceived:3419;Count:15
Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-490c4f61a34so26033535e9.2
for; Tue, 09 Jun 2026 09:09:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=google.com; s=20251104; t=1781021382; x=1781626182; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=3gsPOXFxVkVry+97oF/DtoS3xmb1+/434RuDnz6KWwU=;
b=qHKWfW6ZXpSimhCwbftv4xr/rqGg098TGoNW3GNKhTY6qLkiGn8Uqk9cepSh8ZMLX0
52KVgfLKwHMTk+Tv5lK3xlFN1DtqieGG2sX7g7ASOQ2z97wyy4h2keI8j8hbWKWr4CtH
40BLeYHFQy5fwWzLVmttgnRua7FmDbTK275U5J9oo6MVXujlQy4hcWsPkAajgGk9rMPD
vi696C4q6fQ/b5kjR5VQvoWBlj4OV13c1aAIokCEdNvZtvutW3R47uhTYNh5XQQmVfef
61VkXqQL3zn1WsNiUzZX8Q3Fw1laGTYNQD33rFP6gWx6nRg+9+0VJruFBnB+E9bIYi+3
5LmA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20251104; t=1781021382; x=1781626182; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=3gsPOXFxVkVry+97oF/DtoS3xmb1+/434RuDnz6KWwU=;
b=dItvbUxLcD9s9giosS0mgrmC50efZ164QIyIAOVSn99uoHu8oFpaaUwXDUkD1egJ6K
kFxsTfA/FfrxVi0/48vm2Un1Ba2RaYxWWPGY2e6Gxh2+9jKQtJWJTyCemWM26ekcJ6KF
iZFxQGy031BdO1NsK9pw6UgqxzQVHUirYH4f9lgDD6BcyQn9Ccqivmxxb5uKcfSQbgX/
COIL6FfzAPjcaKJl4Vkvg3aqgy7WOsIBdADPgZgCr2SBd1/M+Mf+bKmLUq+zxUf1h4ZJ
909KyIKJFQirXeLYImL4MjKbEJN7SX6HZpKKNvggkEWOTHk0cO5/JUhEGkYpin/25Stz
2AZg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1781021382; x=1781626182;
h=to:from:subject:date:message-id:sender:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=3gsPOXFxVkVry+97oF/DtoS3xmb1+/434RuDnz6KWwU=;
b=rhNR/7SMCSo9kH+hhSRcNqZaXKSM0PFaJ0HckxNGRDAG5ycBo0Rxf9IQZ0qzisj96w
F8PFJQwTkmuBMv1E3BpNS4R6a2sk1N3LMCaFIxuDND+/IqFI4h6w5rAD5+q7SKTctzDo
OhA3ifMViHavXDpbMZD3ikepRk1+fShPRLz2PLQ/MK/1irjM1KVj8zVorLo5sdLTB27H
e/pZBJ4q77Vr2vtcnfqwY/uLay+aRid3iAyGMeunFrErcvE2nOfTmvkTCPcX612J4FUw
bBjYdJqJD+JLNbBRKIIUsizOCy9fJvGuFx7JP7KwSD6aKcupzhovSAIgwA60o8DG8xIe
a78w==
X-Gm-Message-State: AOJu0YzrTVfivXnWWlGg+DGIWB2nHkj/rHLwbyR1HnrW0sEqKxmHMR+q
WfKNZpOiWbvtell7zswSZbifzD/5vym2vRbDJGMkci1CjsI9mHHGR+9PQ+ooK9Qs52U4qlUKKjY
w1Ps37DUV4rPwvLOtQPAUhSTabQZqyJf7mU8=
MIME-Version: 1.0
X-Received: by 2002:a05:600c:c491:b0:490:bb44:3f8b with SMTP id
5b1f17b1804b1-490c2605385mr349204085e9.17.1781021381628; Tue, 09 Jun 2026
09:09:41 -0700 (PDT)
Reply-To: Haresasz Nxysarwsa
Sender: =?UTF-8?Q?Kalend=C3=A1r_Google?=
Message-ID:
Date: Tue, 09 Jun 2026 16:09:41 +0000
Subject: =?UTF-8?Q?Pozv=C3=A1nky=3A_Payment_Confirmation_=2D_Your_Bitcoin_Order?=
=?UTF-8?Q?_Is_Being_Verified_=40_ut_9=2E_j=C3=BAn_2026_=28cynthiaperez389903=40gro?=
=?UTF-8?Q?ups=2Eoutlook=2Ecom=29?=
From: Haresasz Nxysarwsa
To: cynthiaperez389903@groups.outlook.com
Content-Type: multipart/mixed; boundary="000000000000ca1c610653d45a01"
X-IncomingHeaderCount: 15
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SJ5PEPF00000205:EE_|LV9PR18MB927589:EE_
X-MS-Office365-Filtering-Correlation-Id: f5632051-3a3f-486b-14ef-08dec64184c9
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 209.85.128.69
X-SID-PRA: HARESSAZNZXRRSXAXZ321@GMAIL.COM
X-SID-Result: PASS
X-MS-Consumer-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-MS-Exchange-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-Microsoft-Antispam:
BCL:0;ARA:1444111002|9020799019|9000799056|29080799009|16200799027|9400799043|4040799016|970799063|34130799006|32020799003|3151999006|26000799027|6149299003|26130799012|22000799015|24102599021|5139299004|1680799066|6092099016|26104999009|21002599022;
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 09 Jun 2026 14:14:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wX2pM-000000008Jz-3ZZB
for dave@doctor.nl2k.ab.ca;
Tue, 09 Jun 2026 14:13:36 -0600
Resent-From: The Doctor
Resent-Date: Tue, 9 Jun 2026 14:13:36 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-northcentralusazlp17013059.outbound.protection.outlook.com ([40.93.20.59]:36351 helo=CH4PR04CU002.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wWz2L-00000000Mzm-1z9q
for doctor@doctor.nl2k.ab.ca;
Tue, 09 Jun 2026 10:10:57 -0600
Received: from SJ0PR03CA0161.namprd03.prod.outlook.com (2603:10b6:a03:338::16)
by LV9PR18MB927589.namprd18.prod.outlook.com (2603:10b6:408:376::24) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.92.10; Tue, 9 Jun 2026
16:09:43 +0000
Received: from SJ5PEPF00000205.namprd05.prod.outlook.com
(2603:10b6:a03:338::4) by SJ0PR03CA0161.outlook.office365.com
(2603:10b6:a03:338::16) with Microsoft SMTP Server (version=TLS1_3,
cipher=TLS_AES_256_GCM_SHA384) id 15.21.92.13 via Frontend Transport; Tue, 9
Jun 2026 16:09:43 +0000
Authentication-Results: spf=pass (sender IP is 209.85.128.69)
smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
header.d=google.com;dkim=pass (signature was verified)
header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;compauth=pass
reason=100
Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
209.85.128.69 as permitted sender) receiver=protection.outlook.com;
client-ip=209.85.128.69; helo=mail-wm1-f69.google.com; pr=C
Received: from mail-wm1-f69.google.com (209.85.128.69) by
SJ5PEPF00000205.mail.protection.outlook.com (10.167.244.38) with Microsoft
SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.113.7
via Frontend Transport; Tue, 9 Jun 2026 16:09:43 +0000
X-IncomingTopHeaderMarker:
OriginalChecksum:25E206E7EFFC06789889CF8D86B6964DFEE09EA908D2C89631F8CA767E6F9F15;UpperCasedChecksum:BD9ADE5EE704C0427FE424ECDF6BE331E32665AF02722F5BC1C8778369E2571B;SizeAsReceived:3419;Count:15
Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-490c4f61a34so26033535e9.2
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=google.com; s=20251104; t=1781021382; x=1781626182; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=3gsPOXFxVkVry+97oF/DtoS3xmb1+/434RuDnz6KWwU=;
b=qHKWfW6ZXpSimhCwbftv4xr/rqGg098TGoNW3GNKhTY6qLkiGn8Uqk9cepSh8ZMLX0
52KVgfLKwHMTk+Tv5lK3xlFN1DtqieGG2sX7g7ASOQ2z97wyy4h2keI8j8hbWKWr4CtH
40BLeYHFQy5fwWzLVmttgnRua7FmDbTK275U5J9oo6MVXujlQy4hcWsPkAajgGk9rMPD
vi696C4q6fQ/b5kjR5VQvoWBlj4OV13c1aAIokCEdNvZtvutW3R47uhTYNh5XQQmVfef
61VkXqQL3zn1WsNiUzZX8Q3Fw1laGTYNQD33rFP6gWx6nRg+9+0VJruFBnB+E9bIYi+3
5LmA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20251104; t=1781021382; x=1781626182; darn=groups.outlook.com;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=3gsPOXFxVkVry+97oF/DtoS3xmb1+/434RuDnz6KWwU=;
b=dItvbUxLcD9s9giosS0mgrmC50efZ164QIyIAOVSn99uoHu8oFpaaUwXDUkD1egJ6K
kFxsTfA/FfrxVi0/48vm2Un1Ba2RaYxWWPGY2e6Gxh2+9jKQtJWJTyCemWM26ekcJ6KF
iZFxQGy031BdO1NsK9pw6UgqxzQVHUirYH4f9lgDD6BcyQn9Ccqivmxxb5uKcfSQbgX/
COIL6FfzAPjcaKJl4Vkvg3aqgy7WOsIBdADPgZgCr2SBd1/M+Mf+bKmLUq+zxUf1h4ZJ
909KyIKJFQirXeLYImL4MjKbEJN7SX6HZpKKNvggkEWOTHk0cO5/JUhEGkYpin/25Stz
2AZg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1781021382; x=1781626182;
h=to:from:subject:date:message-id:sender:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=3gsPOXFxVkVry+97oF/DtoS3xmb1+/434RuDnz6KWwU=;
b=rhNR/7SMCSo9kH+hhSRcNqZaXKSM0PFaJ0HckxNGRDAG5ycBo0Rxf9IQZ0qzisj96w
F8PFJQwTkmuBMv1E3BpNS4R6a2sk1N3LMCaFIxuDND+/IqFI4h6w5rAD5+q7SKTctzDo
OhA3ifMViHavXDpbMZD3ikepRk1+fShPRLz2PLQ/MK/1irjM1KVj8zVorLo5sdLTB27H
e/pZBJ4q77Vr2vtcnfqwY/uLay+aRid3iAyGMeunFrErcvE2nOfTmvkTCPcX612J4FUw
bBjYdJqJD+JLNbBRKIIUsizOCy9fJvGuFx7JP7KwSD6aKcupzhovSAIgwA60o8DG8xIe
a78w==
X-Gm-Message-State: AOJu0YzrTVfivXnWWlGg+DGIWB2nHkj/rHLwbyR1HnrW0sEqKxmHMR+q
WfKNZpOiWbvtell7zswSZbifzD/5vym2vRbDJGMkci1CjsI9mHHGR+9PQ+ooK9Qs52U4qlUKKjY
w1Ps37DUV4rPwvLOtQPAUhSTabQZqyJf7mU8=
MIME-Version: 1.0
X-Received: by 2002:a05:600c:c491:b0:490:bb44:3f8b with SMTP id
5b1f17b1804b1-490c2605385mr349204085e9.17.1781021381628; Tue, 09 Jun 2026
09:09:41 -0700 (PDT)
Reply-To: Haresasz Nxysarwsa
Sender: =?UTF-8?Q?Kalend=C3=A1r_Google?=
Message-ID:
Date: Tue, 09 Jun 2026 16:09:41 +0000
Subject: =?UTF-8?Q?Pozv=C3=A1nky=3A_Payment_Confirmation_=2D_Your_Bitcoin_Order?=
=?UTF-8?Q?_Is_Being_Verified_=40_ut_9=2E_j=C3=BAn_2026_=28cynthiaperez389903=40gro?=
=?UTF-8?Q?ups=2Eoutlook=2Ecom=29?=
From: Haresasz Nxysarwsa
To: cynthiaperez389903@groups.outlook.com
Content-Type: multipart/mixed; boundary="000000000000ca1c610653d45a01"
X-IncomingHeaderCount: 15
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SJ5PEPF00000205:EE_|LV9PR18MB927589:EE_
X-MS-Office365-Filtering-Correlation-Id: f5632051-3a3f-486b-14ef-08dec64184c9
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 209.85.128.69
X-SID-PRA: HARESSAZNZXRRSXAXZ321@GMAIL.COM
X-SID-Result: PASS
X-MS-Consumer-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-MS-Exchange-Group-Expansion-Loop: cynthiaperez389903@groups.outlook.com
X-Microsoft-Antispam:
BCL:0;ARA:1444111002|9020799019|9000799056|29080799009|16200799027|9400799043|4040799016|970799063|34130799006|32020799003|3151999006|26000799027|6149299003|26130799012|22000799015|24102599021|5139299004|1680799066|6092099016|26104999009|21002599022;