← Back to writing
Field report · Inbox forensics

The Candy House Email

A message that opened with a summary of Hansel and Gretel, signed off as a French insurer, and pointed at a university admissions page — and somehow still walked straight past the spam filter.

It arrived in Spanish, addressed to a name that wasn't quite mine, and told me — at some length — about two children who escape a witch's candy house. There was no ask, no invoice, no urgent warning. Just a fairy tale, two university links, and a signature from someone claiming to work for a Paris insurance company. It read like nothing at all, which is exactly why I couldn't leave it alone.

§1What actually arrived

Translated from the original Spanish, the body read like this:

Message body, translated

Hola anthonypriest,

Abandoned in the thick of the forest, two ingenious brothers discovered a mysterious candy house. weber.edu/admissions/whatsnext.html They soon realized that it was the trap of an evil witch.

Thanks to their cunning to escape danger portalapps.weber.edu/advisors/ they found their way back home safely with their family.

Regards,
Pierre
AXA S.A.
25 Avenue Matignon, Paris 75008, France
+33 1 40 75 57 00

Nothing in that message connects to anything else in it. A retelling of a Brothers Grimm story links to a state university's admissions page and an academic-advisor directory, then gets signed by "Pierre" from a French insurer whose name never appears anywhere else in the email. The greeting doesn't use a real name — it uses the string before the @ in my address. And underneath a visible link that reads contacto@axa.fr, the actual mailto: target in the raw HTML points to admissions@weber.edu. None of it was asking me for anything. That's what made it worth pulling apart.

§2Verdict

Assessment

Malicious or abusive spam — most likely a spam-filter evasion test, a compromised-account campaign, or preparation for a later push. It is not a conventional credential-phishing attempt in the form it arrived in.

Payload risk in this specimen: Low Confidence it's deceptive: High Sender attribution: Unresolved

§3What the headers say

The header block is the part of this email that's telling the truth — as far as it goes. It confirms who actually sent the mail, but not why, and not on whose authority.

Message metadata
FromGaya Erlandson <gayaerlandsonizj@arseya.org>
Return-Pathgayaerlandsonizj@arseya.org
Toanthonypriest@outlook.com
SubjectAndrés vivió feliz, sabiendo que cada logro había sido construido con paciencia, esfuerzo y perseverancia.
DateTue, 25 Aug 2026 12:00:56 +0000
Message-ID<PH7PR16MB616717983FAC9243116ECC11B6AF2@PH7PR16MB6167.namprd16.prod.outlook.com>
Raw email SHA-25605863f91118beb00ea3bcb12929085a1c51a75aa03cebc76ecff125754f8513f

The message passed SPF and DKIM for arseya.org, and Outlook logged DMARC / compound authentication as passing or best-guess passing. It came from 40.107.200.124 — an outbound Microsoft-protection host — and Outlook's own spam confidence score landed it at SCL 1: not flagged as junk.

That establishes only one thing with confidence: infrastructure authorized to send as arseya.org sent this. It does not establish that AXA sent it, or that it's benign. A compromised Microsoft 365 tenant, an abused mailbox, or a domain built for spam are all consistent with what the headers show — the headers alone can't tell those apart. The clumsy construction of the message reads like it was built specifically to slide under simple filters without tripping content-based detection.

§4Seven things that don't add up

  1. Identity mismatch. The authenticated sender is at arseya.org; the signature claims to be Pierre from AXA S.A.
  2. Misleading link. Visible text reads contacto@axa.fr; the underlying mailto: target is admissions@weber.edu.
  3. Unrelated content. Sender, AXA signature, Spanish fairy tale, and Weber State University URLs share no coherent thread.
  4. Generic personalization. The greeting uses my mailbox name, not a verified real name.
  5. Unexplained attachment. A file named CLIENTE23915.bin arrived with no reason given for it.
  6. Likely hash-busting content. That attachment is 32 random-looking hex strings — the kind of inert filler used to change a message's hash and dodge signature-based spam detection.
  7. No business purpose stated. The email never says why AXA, Weber State, or the sender is contacting me at all.

§5Where the links actually go

Both HTTPS links in the body resolved, on inspection, to ordinary Weber State University pages — one an admissions "what's next" page, the other an academic-advisor directory. No redirect chain, no credential form, no drive-by download.

Links present in the body
Link 1https://weber.edu/admissions/whatsnext.html
Link 2https://portalapps.weber.edu/advisors/

A legitimate destination doesn't launder the rest of the email — it just means these two links, in this specimen, on this day, were decoys rather than the attack itself. Page behavior can change after the fact, so that's a snapshot, not a guarantee.

§6The 1,055 bytes that don't do anything

The attachment is where the message stops pretending to make sense and starts looking like tooling.

Attachment: CLIENTE23915.bin
Declared MIME typeapplication/macbinary
Detected typeASCII text
Size1,055 bytes
SHA-2560ad4da25a3c51d8ec87a96106505c5ddf12d6be26bf7093b9355242688290518
Contents32 newline-separated hex strings, 32 characters each
Executable codeNone found
Embedded URLsNone found
Public hash matchNone found

The .bin extension and the MacBinary MIME label both suggest a binary payload; what's actually inside is inert plain text with no code and no links. That mismatch, and the fact that nothing in the message explains why the attachment exists, is why it still shouldn't be opened — its only apparent job is to make every copy of this email hash differently.

§7So what is this, actually?

This isn't a conventional phishing attempt — it never asks for a login, a payment, or a reply. But false identity cues, mismatched link destinations, unrelated legitimate URLs, and randomized attachment filler don't happen by accident together. That combination is deliberate.

The most likely explanation is spam-filter testing or reputation conditioning: whoever sent this may be probing mailbox delivery, using benign university links to build deliverability history, or staging infrastructure for a later, sharper campaign. A compromised account blasting out malformed test mail is equally plausible. Nothing in a single specimen is enough to identify the operator or predict the next stage.

§8What I did about it

  • Reported the message in Outlook as phishing / junk.
  • Deleted it after preserving the raw .eml and its hashes.
  • Did not reply, call the listed number, or open the attachment.
  • No credential reset or device remediation was warranted — there was no interaction beyond saving the file for analysis.

If you ever open a link, enter credentials, or run an attachment from a message like this, that's a different situation — treat it as an active incident, not a research exercise.

Scope & limitations. This was a static examination of the saved .eml — headers, decoded body, links, and attachment — with the linked pages retrieved noninteractively. The sample was not uploaded to any third-party analysis service and nothing was executed. Public searches turned up no match for either hash; absence of a match is not proof of safety.

raw-email-sha256 · 05863f91118beb00ea3bcb12929085a1c51a75aa03cebc76ecff125754f8513f attachment-sha256 · 0ad4da25a3c51d8ec87a96106505c5ddf12d6be26bf7093b9355242688290518