Outlook scam/hacking email or legit?

Soldato
Joined
6 May 2009
Posts
20,230
I usually move on and delete this type of mail but from what I can see this looks legit. What do you think, i'll delete it anyway but might aswel post here for a warning...


The email is from 'HotmailOutlookCheck'

It contains in the body
----------------------------------------------------------------------------------
1 new message.
To read your message(s), just click on the link below and login.

It then links to a login https://faiman.us/?k=[my email address]@hotmail.co.uk
----------------------------------------------------------------------------------
Part of the message source shows

Received: from VE1EUR01HT098.eop-EUR01.prod.protection.outlook.com
(2603:10a6:600:bb::16) by LO2P265MB0733.GBRP265.PROD.OUTLOOK.COM with HTTPS
via LO3P265CA0011.GBRP265.PROD.OUTLOOK.COM; Wed, 13 May 2020 04:46:36 +0000

ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=pass (sender ip is 40.92.71.90) smtp.rcpttodomain=hotmail.co.uk smtp.mailfrom=live.co.uk; dmarc=fail (p=none sp=none pct=100) action=none header.from=hotmail.co.uk;
dkim=none (message not signed); arc=pass (0 oda=1 ltdi=1
dkim=[1,1,header.d=hotmail.co.uk] dmarc=[1,1,header.from=hotmail.co.uk])
Received: from VE1EUR01FT020.eop-EUR01.prod.protection.outlook.com
(2a01:111:e400:7e19::49) by
VE1EUR01HT098.eop-EUR01.prod.protection.outlook.com (2a01:111:e400:7e19::308)
with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2979.27; Wed, 13 May
2020 04:46:36 +0000

X-Sender-IP: 40.92.71.90 - http://www.ipaddress-finder.com/?ip=40.92.71.90 -
Hostname -mail-oln040092071090.outbound.protection.outlook.com X-OriginatorOrg: outlook.com


Further down

MIME-Version: 1.0
----_com.samsung.android.email_7245314043292262

Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: base64

DQogDQoNCg0KMSBuZXcgbWVzc2FnZS4NCg0KVG8gcmVhZCB5b3VyIG1lc3NhZ2UocyksIGp1c3Qg
Y2xpY2sgb24gdGhlIGxpbmsgYmVsb3cgYW5kIGxvZ2luLg0KDQoNCiANCg0KaHR0cHM6Ly9mYWlt
YW4udXMvP2s9YWxleGxlYXJveWRAaG90bWFpbC5jby51aw0KDQoNCiANCg==

----_com.samsung.android.email_7245314043292262
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: base64
 
Back
Top Bottom