Hotmail spam faking UAE minister
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 05 Sep 2022 10:21:08 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))
(envelope-from)
id 1oVEmu-0009J4-TV
for dave@doctor.nl2k.ab.ca;
Mon, 05 Sep 2022 10:17:28 -0600
Resent-From: The Doctor
Resent-Date: Mon, 5 Sep 2022 10:17:28 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-tyzapc01rlhn2171.outbound.protection.outlook.com ([40.95.110.171]:17894 helo=APC01-TYZ-obe.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.95 (FreeBSD))
(envelope-from)
id 1oV7Os-0002b4-92
for mailer-daemon@nl2k.ab.ca;
Mon, 05 Sep 2022 02:24:15 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=mU7wARXwPeSwtzqI6XJBdB/LEd4sp7TquFfikEXMg0HTO6Q2GBhSCJQ8HCmo2ML4UDgDdBlBcSQOnxNwHbYLzt+n2LQpuGqYqITcDrtXd7oSauMh/Z8ZAvHIzY2ny2ciXVD67lf1wwk65ewy6pamvcVGn3Pz1o7Xrtbp3QZxgqcgzA5zO8dgIjdOKliLSQCTtLBesdDGH6gVRmGmqxg6T/0wQHdWLxaHft4wsAkXYCS6TUdAWqvgXRzEZLEhE8PRNVXfGTxAhn7+utvhl68bHXS+ojsmghz+wNKPlcY8DoekWbPIPIfPJLrAufIdTBKJxZFXC3ufTLsFaziGfng8dw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=zhjSLwdK445sPHO/q1NSpdCkTIAvL+N4zhMGTXiUhFc=;
b=geZYXwU93tw7Og1HPHTEu21XxSk4dAWFNbNIn/rftXOm+81D9H+cCGkugkNiyj8sYXj5oXjdPjMNabA5PxZfb4sHhM4t24s8bH4IjFrz9CDIb1pWnYxNrNo6Ex6EzQaAmcwmRZ4YeogZUTdRFJGani0tcLqIIn+vgwknifaHwizVy4BUNv1jvcs3DGk/ziQeeLt+rNaDb7QocwSUXJMkgfxEJWoXrvgosZkRE1G1cF2wnHLm49vdw1WSXjTITe8mLjgmqXEWWGYqMHmYLNbtF1SkKzUH49JpM5tZbs8P4djfqkwlTqJu1imJh1rbBo11YOyZU3TvHYsgATK1Cd9HTA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none (sender ip is
172.107.174.74) smtp.rcpttodomain=trademe.co.nz smtp.mailfrom=uaegov.ae;
dmarc=none action=none header.from=uaegov.ae; dkim=none (message not signed);
arc=none (0)
Received: from SG2PR02CA0096.apcprd02.prod.outlook.com (2603:1096:4:90::36) by
PSBPR04MB4053.apcprd04.prod.outlook.com (2603:1096:301:10::12) with Microsoft
SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.5588.10; Mon, 5 Sep 2022 08:23:44 +0000
Received: from SG2APC01FT0040.eop-APC01.prod.protection.outlook.com
(2603:1096:4:90:cafe::fc) by SG2PR02CA0096.outlook.office365.com
(2603:1096:4:90::36) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5588.18 via Frontend
Transport; Mon, 5 Sep 2022 08:23:44 +0000
X-MS-Exchange-Authentication-Results: spf=none (sender IP is 172.107.174.74)
smtp.mailfrom=uaegov.ae; dkim=none (message not signed)
header.d=none;dmarc=none action=none header.from=uaegov.ae;
Received-SPF: None (protection.outlook.com: uaegov.ae does not designate
permitted sender hosts)
Received: from mail.prasarana.com.my (58.26.8.158) by
SG2APC01FT0040.mail.protection.outlook.com (10.13.36.122) with Microsoft SMTP
Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id
15.20.5588.10 via Frontend Transport; Mon, 5 Sep 2022 08:23:44 +0000
Received: from MRL-EXH-02.prasarana.com.my (10.128.66.101) by
MRL-EXH-01.prasarana.com.my (10.128.66.100) with Microsoft SMTP Server
(version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id
15.1.2176.14; Mon, 5 Sep 2022 16:23:26 +0800
Received: from User (172.107.174.74) by MRL-EXH-02.prasarana.com.my
(10.128.66.101) with Microsoft SMTP Server id 15.1.2176.14 via Frontend
Transport; Mon, 5 Sep 2022 16:23:13 +0800
Reply-To:
From: Reem A.
Subject: Hello
Date: Mon, 5 Sep 2022 03:23:26 -0500
MIME-Version: 1.0
Content-Type: text/plain; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-ID: <65125a98-1599-4f6e-b433-4e8caaa777b0@MRL-EXH-02.prasarana.com.my>
To: Undisclosed recipients:;
X-EOPAttributedMessage: 0
X-MS-Exchange-SkipListedInternetSender: ip=[172.107.174.74];domain=User
X-MS-Exchange-ExternalOriginalInternetSender: ip=[172.107.174.74];domain=User
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 7e83d274-3e4b-44ca-965e-08da8f17f2c1
X-MS-TrafficTypeDiagnostic: PSBPR04MB4053:EE_
X-MS-Exchange-AtpMessageProperties: SA|SL
X-MS-Exchange-SenderADCheck: 2
X-MS-Exchange-AntiSpam-Relay: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
=?windows-1251?Q?HGwkbjFVtgWUg86DfFJ/WHKgY5fAcDCNBjEv/QVD0H0qqe8BWQPui7dF?=
=?windows-1251?Q?MXU6BM1zR8e4KYus1ZgfM5+XKqpKE7lRQwlG8GUkpD4/UXENcuMXN4WB?=
=?windows-1251?Q?i8qTi55tXkP+l6OQCgerlf1Pi1B+Y4jqJwJI/mlKMy9vOpS9CxR/f5P/?=
=?windows-1251?Q?8kwTRh3AsCW8aFVFykl/C5t7r9l4a2+Ppa4ugbAVs9aXkHIL6OXdaYw1?=
=?windows-1251?Q?pc8h4NbG2bd+aMiMij/ebgSC0mDfei2W8ayKQHmmqfEKLA0mNCpDWo/M?=
=?windows-1251?Q?1POkH8Xrd8vi+X9WwrSB9wDM3bdtyCs2NXeCMHrZPJ/RDDFhXC9LQHPZ?=
=?windows-1251?Q?R0r1N0/rWDw4VEvppjeAcOE51aaIKQ3t09SNcAPk1mZDeVvoD/9vJ8uT?=
=?windows-1251?Q?xVEB+Nq4Kzlrlsbe25Mlh8dng1NsmeYHyiAbyX77d95HTlKvRO1ACnrK?=
=?windows-1251?Q?9Bj51dDP5YRBC/ntKTeZdzv1n5VYhBTk/mKaIr9DoxyUowiNk+BUyaJV?=
=?windows-1251?Q?eJLO0SHpG9lSL8vmw7Aem9iTPAr1UjSbnmKQxN0UZhkYJ5zarinyukAd?=
=?windows-1251?Q?54BRzKIgrkDNzhnZBz1j9jSfJzob8vhpS3Hw/YxSgmQhYc3C7vXMoUNY?=
=?windows-1251?Q?3CIxLDthgo0kMnk67QWz6Dy37d0u13HYnDvbL4wUf4O8zT4RSmbzhD/r?=
=?windows-1251?Q?hg6vLH19cB5QzsX+14VLdkMD8cpnO1wUeo5Jzez9c7g2KULKx5XevIGB?=
=?windows-1251?Q?0U4XgVJuJxvsR+SI1BFUgAl0GmAP7fjQaEM8YjluZTBAmuP7dZGvTW9/?=
=?windows-1251?Q?KxVm7YXVYcMSmnBQQYKNrd40Qj3qaFBq3/ew4P7gPfU/jIUMSSHdQ+nv?=
=?windows-1251?Q?G5A4fHP7kXzzSEjShybVfKrBeowiGbqFnBdUfj7bTIYkn1ycOQaejvZh?=
=?windows-1251?Q?26H1ekBglVfHo0dun/Gz1wWFikWcJ9JaRVlrUJguF7gnnKvoiyNvxzt0?=
=?windows-1251?Q?07arqKHIUsOoBoVuAtwJVUi/Cinwo5U+JBnvCCfyEk6QGnYyC2zwaluH?=
=?windows-1251?Q?Sf8EyVp3AnLHf2AUxJMbbxKl1JC3605EyImCcUHI+r96skN6IwQzoUeZ?=
=?windows-1251?Q?XBZ6gvU7SPAvEFdWTTatG6rYPNtec9n1Ln4ddD5IchgAr3x42cDpujgz?=
=?windows-1251?Q?G5vWFVleCkTzmbyDKDzOAr3WNLUFFiIuRh0H5lZRMp3j6DaBnP6thI23?=
=?windows-1251?Q?pAu3epCgsvOhfU56my9kuE5fUNlf5eGpaEgk6vrhbWmvZSqP7AH9sP7+?=
=?windows-1251?Q?90JLrIAd9HpNwuC/czxl3rqcbnh9tkjrINWN8I9z/+pcW/iz?=
X-Forefront-Antispam-Report:
CIP:58.26.8.158;CTRY:US;LANG:en;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:User;PTR:InfoNoRecords;CAT:OSPM;SFS:(13230016)(4636009)(346002)(396003)(376002)(136003)(39860400002)(40470700004)(46966006)(32850700003)(31686004)(40460700003)(316002)(36906005)(9686003)(86362001)(40480700001)(82310400005)(31696002)(7416002)(156005)(82740400003)(81166007)(2906002)(7406005)(7366002)(8936002)(3480700007)(5660300002)(7116003)(83380400001)(8676002)(336012)(47076005)(35950700001)(70206006)(70586007)(6666004)(41300700001)(956004)(109986005)(498600001)(26005)(2700400008);DIR:OUT;SFP:1023;
X-OriginatorOrg: myprasarana.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Sep 2022 08:23:44.5358
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 7e83d274-3e4b-44ca-965e-08da8f17f2c1
X-MS-Exchange-CrossTenant-Id: 3cbb2ff2-27fb-4993-aecf-bf16995e64c0
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3cbb2ff2-27fb-4993-aecf-bf16995e64c0;Ip=[58.26.8.158];Helo=[mail.prasarana.com.my]
X-MS-Exchange-CrossTenant-AuthSource:
SG2APC01FT0040.eop-APC01.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PSBPR04MB4053
X-Spam_score: 27.6
X-Spam_score_int: 276
X-Spam_bar: +++++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Friend, Good day to you. Apparently this email will be
coming to you as a surprise since we have not met before now. My name is
Reem E. Al-Hashimi, the Emirates Minister of State for international cooperation
[...]
Content analysis details: (27.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.4 NO_DNS_FOR_FROM DNS: Envelope sender has no MX or A DNS records
0.0 REPTO_419_FRAUD Reply-To is known advance fee fraud collector
mailbox
0.0 AXB_X_FF_SEZ_S Forefront sez this is spam
0.0 NSL_RCVD_FROM_USER Received from User
0.0 FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in
digit
[reem2018[at]daum.net]
1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,
https://senderscore.org/blocklistlookup/
[40.95.110.171 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[40.95.110.171 listed in psbl.surriel.com]
1.5 NIX_SPAM RBL: Listed in NIX_SPAM DNSBL (thanks to heise.de)
[40.95.110.171 listed in ix.dnsbl.manitu.net]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[40.95.110.171 listed in wl.mailspike.net]
0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=APC01-TYZ-obe.outbound.protection.outlook.com;ip=40.95.110.171;r=doctor.nl2k.ab.ca]
2.6 DEAR_FRIEND BODY: Dear Friend? That's not very dear!
-0.0 T_SCC_BODY_TEXT_LINE No description available.
0.0 AXB_XMAILER_MIMEOLE_OL_024C2 Yet another X header trait
0.0 LOTS_OF_MONEY Huge... sums of money
0.6 FSL_NEW_HELO_USER Spam's using Helo and User
2.0 PDS_HELO_SPF_FAIL High profile HELO that fails SPF
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain
different freemails
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
3.2 UNDISC_FREEM Undisclosed recipients + freemail reply-to
0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
2.0 MONEY_FREEMAIL_REPTO Lots of money from someone using free
email?
2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
0.0 XFER_LOTSA_MONEY Transfer a lot of money
1.5 UNDISC_MONEY Undisclosed recipients + money/fraud signs
1.8 ADVANCE_FEE_4_NEW_MONEY Advance Fee fraud and lots of money
0.0 MONEY_FRAUD_5 Lots of money and many fraud phrases
Subject: {SPAM?} Hello
Dear Friend,
Good day to you. Apparently this email will be coming to you as a surprise since we have not met before now. My name is Reem E. Al-Hashimi, the Emirates Minister of State for international cooperation and Managing Director of United Arab Emirates (Dubai) World Expo 2020 Committee. I am writing you to know if your would be willing to receive and invest a huge sum on my behalf. This fund is my share of gratification from foreign companies whom I helped during the bidding exercise towards the Dubai World Expo 2020.
As an Arab women serving as a minister, there is a limit to my personal income and investment level and For this reason, I cannot receive such a huge sum back to my country or in my personal account, so an agreement was reached with the foreign companies to direct the gratifications to an open beneficiary account with a financial institution where it will be possible for me to instruct further transfer of the fund to a third party account for investment purpose which is the reason i contacted you to receive the fund as my partner for investment in your country.
The amount is however, valued at Euro ?47,745,533.00 Million Euro and the financial institution is waiting for my instruction to transfer the funds to any designated account. I have decided to compensate you with 30% of the total amount and you will also get benefit from the investment.
REPLY ONLY TO reem.alhashimi@yandex.com
kind Regards,
Reem B. Al Hashimi
PO Box 899
AbuDhabi, United Arab Emirates
I1.17KL0LD670In/aRank6.73Mln/awhoissourceRank28.2MAdv Disp Ads1Pub Disp Ads1PIN0Summary reportDiagnosisDensity00n/a
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 05 Sep 2022 10:21:08 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))
(envelope-from
id 1oVEmu-0009J4-TV
for dave@doctor.nl2k.ab.ca;
Mon, 05 Sep 2022 10:17:28 -0600
Resent-From: The Doctor
Resent-Date: Mon, 5 Sep 2022 10:17:28 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-tyzapc01rlhn2171.outbound.protection.outlook.com ([40.95.110.171]:17894 helo=APC01-TYZ-obe.outbound.protection.outlook.com)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.95 (FreeBSD))
(envelope-from
id 1oV7Os-0002b4-92
for mailer-daemon@nl2k.ab.ca;
Mon, 05 Sep 2022 02:24:15 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=mU7wARXwPeSwtzqI6XJBdB/LEd4sp7TquFfikEXMg0HTO6Q2GBhSCJQ8HCmo2ML4UDgDdBlBcSQOnxNwHbYLzt+n2LQpuGqYqITcDrtXd7oSauMh/Z8ZAvHIzY2ny2ciXVD67lf1wwk65ewy6pamvcVGn3Pz1o7Xrtbp3QZxgqcgzA5zO8dgIjdOKliLSQCTtLBesdDGH6gVRmGmqxg6T/0wQHdWLxaHft4wsAkXYCS6TUdAWqvgXRzEZLEhE8PRNVXfGTxAhn7+utvhl68bHXS+ojsmghz+wNKPlcY8DoekWbPIPIfPJLrAufIdTBKJxZFXC3ufTLsFaziGfng8dw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=zhjSLwdK445sPHO/q1NSpdCkTIAvL+N4zhMGTXiUhFc=;
b=geZYXwU93tw7Og1HPHTEu21XxSk4dAWFNbNIn/rftXOm+81D9H+cCGkugkNiyj8sYXj5oXjdPjMNabA5PxZfb4sHhM4t24s8bH4IjFrz9CDIb1pWnYxNrNo6Ex6EzQaAmcwmRZ4YeogZUTdRFJGani0tcLqIIn+vgwknifaHwizVy4BUNv1jvcs3DGk/ziQeeLt+rNaDb7QocwSUXJMkgfxEJWoXrvgosZkRE1G1cF2wnHLm49vdw1WSXjTITe8mLjgmqXEWWGYqMHmYLNbtF1SkKzUH49JpM5tZbs8P4djfqkwlTqJu1imJh1rbBo11YOyZU3TvHYsgATK1Cd9HTA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none (sender ip is
172.107.174.74) smtp.rcpttodomain=trademe.co.nz smtp.mailfrom=uaegov.ae;
dmarc=none action=none header.from=uaegov.ae; dkim=none (message not signed);
arc=none (0)
Received: from SG2PR02CA0096.apcprd02.prod.outlook.com (2603:1096:4:90::36) by
PSBPR04MB4053.apcprd04.prod.outlook.com (2603:1096:301:10::12) with Microsoft
SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.5588.10; Mon, 5 Sep 2022 08:23:44 +0000
Received: from SG2APC01FT0040.eop-APC01.prod.protection.outlook.com
(2603:1096:4:90:cafe::fc) by SG2PR02CA0096.outlook.office365.com
(2603:1096:4:90::36) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5588.18 via Frontend
Transport; Mon, 5 Sep 2022 08:23:44 +0000
X-MS-Exchange-Authentication-Results: spf=none (sender IP is 172.107.174.74)
smtp.mailfrom=uaegov.ae; dkim=none (message not signed)
header.d=none;dmarc=none action=none header.from=uaegov.ae;
Received-SPF: None (protection.outlook.com: uaegov.ae does not designate
permitted sender hosts)
Received: from mail.prasarana.com.my (58.26.8.158) by
SG2APC01FT0040.mail.protection.outlook.com (10.13.36.122) with Microsoft SMTP
Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id
15.20.5588.10 via Frontend Transport; Mon, 5 Sep 2022 08:23:44 +0000
Received: from MRL-EXH-02.prasarana.com.my (10.128.66.101) by
MRL-EXH-01.prasarana.com.my (10.128.66.100) with Microsoft SMTP Server
(version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id
15.1.2176.14; Mon, 5 Sep 2022 16:23:26 +0800
Received: from User (172.107.174.74) by MRL-EXH-02.prasarana.com.my
(10.128.66.101) with Microsoft SMTP Server id 15.1.2176.14 via Frontend
Transport; Mon, 5 Sep 2022 16:23:13 +0800
Reply-To:
From: Reem A.
Subject: Hello
Date: Mon, 5 Sep 2022 03:23:26 -0500
MIME-Version: 1.0
Content-Type: text/plain; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-ID: <65125a98-1599-4f6e-b433-4e8caaa777b0@MRL-EXH-02.prasarana.com.my>
To: Undisclosed recipients:;
X-EOPAttributedMessage: 0
X-MS-Exchange-SkipListedInternetSender: ip=[172.107.174.74];domain=User
X-MS-Exchange-ExternalOriginalInternetSender: ip=[172.107.174.74];domain=User
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 7e83d274-3e4b-44ca-965e-08da8f17f2c1
X-MS-TrafficTypeDiagnostic: PSBPR04MB4053:EE_
X-MS-Exchange-AtpMessageProperties: SA|SL
X-MS-Exchange-SenderADCheck: 2
X-MS-Exchange-AntiSpam-Relay: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info:
=?windows-1251?Q?HGwkbjFVtgWUg86DfFJ/WHKgY5fAcDCNBjEv/QVD0H0qqe8BWQPui7dF?=
=?windows-1251?Q?MXU6BM1zR8e4KYus1ZgfM5+XKqpKE7lRQwlG8GUkpD4/UXENcuMXN4WB?=
=?windows-1251?Q?i8qTi55tXkP+l6OQCgerlf1Pi1B+Y4jqJwJI/mlKMy9vOpS9CxR/f5P/?=
=?windows-1251?Q?8kwTRh3AsCW8aFVFykl/C5t7r9l4a2+Ppa4ugbAVs9aXkHIL6OXdaYw1?=
=?windows-1251?Q?pc8h4NbG2bd+aMiMij/ebgSC0mDfei2W8ayKQHmmqfEKLA0mNCpDWo/M?=
=?windows-1251?Q?1POkH8Xrd8vi+X9WwrSB9wDM3bdtyCs2NXeCMHrZPJ/RDDFhXC9LQHPZ?=
=?windows-1251?Q?R0r1N0/rWDw4VEvppjeAcOE51aaIKQ3t09SNcAPk1mZDeVvoD/9vJ8uT?=
=?windows-1251?Q?xVEB+Nq4Kzlrlsbe25Mlh8dng1NsmeYHyiAbyX77d95HTlKvRO1ACnrK?=
=?windows-1251?Q?9Bj51dDP5YRBC/ntKTeZdzv1n5VYhBTk/mKaIr9DoxyUowiNk+BUyaJV?=
=?windows-1251?Q?eJLO0SHpG9lSL8vmw7Aem9iTPAr1UjSbnmKQxN0UZhkYJ5zarinyukAd?=
=?windows-1251?Q?54BRzKIgrkDNzhnZBz1j9jSfJzob8vhpS3Hw/YxSgmQhYc3C7vXMoUNY?=
=?windows-1251?Q?3CIxLDthgo0kMnk67QWz6Dy37d0u13HYnDvbL4wUf4O8zT4RSmbzhD/r?=
=?windows-1251?Q?hg6vLH19cB5QzsX+14VLdkMD8cpnO1wUeo5Jzez9c7g2KULKx5XevIGB?=
=?windows-1251?Q?0U4XgVJuJxvsR+SI1BFUgAl0GmAP7fjQaEM8YjluZTBAmuP7dZGvTW9/?=
=?windows-1251?Q?KxVm7YXVYcMSmnBQQYKNrd40Qj3qaFBq3/ew4P7gPfU/jIUMSSHdQ+nv?=
=?windows-1251?Q?G5A4fHP7kXzzSEjShybVfKrBeowiGbqFnBdUfj7bTIYkn1ycOQaejvZh?=
=?windows-1251?Q?26H1ekBglVfHo0dun/Gz1wWFikWcJ9JaRVlrUJguF7gnnKvoiyNvxzt0?=
=?windows-1251?Q?07arqKHIUsOoBoVuAtwJVUi/Cinwo5U+JBnvCCfyEk6QGnYyC2zwaluH?=
=?windows-1251?Q?Sf8EyVp3AnLHf2AUxJMbbxKl1JC3605EyImCcUHI+r96skN6IwQzoUeZ?=
=?windows-1251?Q?XBZ6gvU7SPAvEFdWTTatG6rYPNtec9n1Ln4ddD5IchgAr3x42cDpujgz?=
=?windows-1251?Q?G5vWFVleCkTzmbyDKDzOAr3WNLUFFiIuRh0H5lZRMp3j6DaBnP6thI23?=
=?windows-1251?Q?pAu3epCgsvOhfU56my9kuE5fUNlf5eGpaEgk6vrhbWmvZSqP7AH9sP7+?=
=?windows-1251?Q?90JLrIAd9HpNwuC/czxl3rqcbnh9tkjrINWN8I9z/+pcW/iz?=
X-Forefront-Antispam-Report:
CIP:58.26.8.158;CTRY:US;LANG:en;SCL:5;SRV:;IPV:NLI;SFV:SPM;H:User;PTR:InfoNoRecords;CAT:OSPM;SFS:(13230016)(4636009)(346002)(396003)(376002)(136003)(39860400002)(40470700004)(46966006)(32850700003)(31686004)(40460700003)(316002)(36906005)(9686003)(86362001)(40480700001)(82310400005)(31696002)(7416002)(156005)(82740400003)(81166007)(2906002)(7406005)(7366002)(8936002)(3480700007)(5660300002)(7116003)(83380400001)(8676002)(336012)(47076005)(35950700001)(70206006)(70586007)(6666004)(41300700001)(956004)(109986005)(498600001)(26005)(2700400008);DIR:OUT;SFP:1023;
X-OriginatorOrg: myprasarana.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 05 Sep 2022 08:23:44.5358
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 7e83d274-3e4b-44ca-965e-08da8f17f2c1
X-MS-Exchange-CrossTenant-Id: 3cbb2ff2-27fb-4993-aecf-bf16995e64c0
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3cbb2ff2-27fb-4993-aecf-bf16995e64c0;Ip=[58.26.8.158];Helo=[mail.prasarana.com.my]
X-MS-Exchange-CrossTenant-AuthSource:
SG2APC01FT0040.eop-APC01.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PSBPR04MB4053
X-Spam_score: 27.6
X-Spam_score_int: 276
X-Spam_bar: +++++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Dear Friend, Good day to you. Apparently this email will be
coming to you as a surprise since we have not met before now. My name is
Reem E. Al-Hashimi, the Emirates Minister of State for international cooperation
[...]
Content analysis details: (27.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.4 NO_DNS_FOR_FROM DNS: Envelope sender has no MX or A DNS records
0.0 REPTO_419_FRAUD Reply-To is known advance fee fraud collector
mailbox
0.0 AXB_X_FF_SEZ_S Forefront sez this is spam
0.0 NSL_RCVD_FROM_USER Received from User
0.0 FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in
digit
[reem2018[at]daum.net]
1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,
https://senderscore.org/blocklistlookup/
[40.95.110.171 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[40.95.110.171 listed in psbl.surriel.com]
1.5 NIX_SPAM RBL: Listed in NIX_SPAM DNSBL (thanks to heise.de)
[40.95.110.171 listed in ix.dnsbl.manitu.net]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[40.95.110.171 listed in wl.mailspike.net]
0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.org/Why?s=helo;id=APC01-TYZ-obe.outbound.protection.outlook.com;ip=40.95.110.171;r=doctor.nl2k.ab.ca]
2.6 DEAR_FRIEND BODY: Dear Friend? That's not very dear!
-0.0 T_SCC_BODY_TEXT_LINE No description available.
0.0 AXB_XMAILER_MIMEOLE_OL_024C2 Yet another X header trait
0.0 LOTS_OF_MONEY Huge... sums of money
0.6 FSL_NEW_HELO_USER Spam's using Helo and User
2.0 PDS_HELO_SPF_FAIL High profile HELO that fails SPF
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain
different freemails
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
3.2 UNDISC_FREEM Undisclosed recipients + freemail reply-to
0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
2.0 MONEY_FREEMAIL_REPTO Lots of money from someone using free
email?
2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
0.0 XFER_LOTSA_MONEY Transfer a lot of money
1.5 UNDISC_MONEY Undisclosed recipients + money/fraud signs
1.8 ADVANCE_FEE_4_NEW_MONEY Advance Fee fraud and lots of money
0.0 MONEY_FRAUD_5 Lots of money and many fraud phrases
Subject: {SPAM?} Hello
Dear Friend,
Good day to you. Apparently this email will be coming to you as a surprise since we have not met before now. My name is Reem E. Al-Hashimi, the Emirates Minister of State for international cooperation and Managing Director of United Arab Emirates (Dubai) World Expo 2020 Committee. I am writing you to know if your would be willing to receive and invest a huge sum on my behalf. This fund is my share of gratification from foreign companies whom I helped during the bidding exercise towards the Dubai World Expo 2020.
As an Arab women serving as a minister, there is a limit to my personal income and investment level and For this reason, I cannot receive such a huge sum back to my country or in my personal account, so an agreement was reached with the foreign companies to direct the gratifications to an open beneficiary account with a financial institution where it will be possible for me to instruct further transfer of the fund to a third party account for investment purpose which is the reason i contacted you to receive the fund as my partner for investment in your country.
The amount is however, valued at Euro ?47,745,533.00 Million Euro and the financial institution is waiting for my instruction to transfer the funds to any designated account. I have decided to compensate you with 30% of the total amount and you will also get benefit from the investment.
REPLY ONLY TO reem.alhashimi@yandex.com
kind Regards,
Reem B. Al Hashimi
PO Box 899
AbuDhabi, United Arab Emirates
I1.17KL0LD670In/aRank6.73Mln/awhoissourceRank28.2MAdv Disp Ads1Pub Disp Ads1PIN0Summary reportDiagnosisDensity00n/a
Trackbacks
Trackback specific URI for this entryThis link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.
No Trackbacks
Comments
Display comments as Linear | ThreadedNo comments