Co-operative Bank p.l.c phish

From - Tue May 21 10:17:02 2013

X-Account-Key: account1

X-UIDL: 00001a6f4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Sun, 19 May 2013 06:33:10 -0600

From: Co-operative Bank p.l.c

Subject: SPAM Fix The Error On Your Account

Date: Sun, 19 May 2013 13:58:20 +0100

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: *****

X-Spam-Status: Yes, score=5.2 required=5.0 tests=FORGED_MUA_OUTLOOK,

FORGED_OUTLOOK_TAGS,RCVD_IN_BACKSCATTER autolearn=no version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_5198C686.AF4F5121"

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5841]

X-AVG-ID: ID1F0D0BA1-470FA90B

X-Brightmail-Tracker: AAAAAh3E6AodxOgB

X-Brightmail-Tracker: AAAAAA==



This is a multi-part message in MIME format.



------------=_5198C686.AF4F5121

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Dear customer, We have created a new dedicated security server

to keep all our online banking customers account safe and secure. This server

has been tested in most of our bank branches. Now we are asking all our online

banking customers to register for the new security server to keep them safe.

[...]



Content analysis details: (5.2 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 RCVD_IN_BACKSCATTER RBL: Received via a relay in Backscatter.org

[159.134.118.28 listed in ips.backscatterer.org]

0.0 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format

4.2 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_5198C686.AF4F5121

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: from mail12.svc.cra.dublin.eircom.net (mail12.svc.cra.dublin.eircom.net [159.134.118.28])

by doctor.nl2k.ab.ca (Postfix) with SMTP id 42D7C12CFA81

for ; Sun, 19 May 2013 06:33:03 -0600 (MDT)

Received: (qmail 24163 messnum 1892601 invoked from network[213.94.190.12/avas01.vendorsvc.cra.dublin.eircom.net]); 19 May 2013 12:32:54 -0000

Received: from avas01.vendorsvc.cra.dublin.eircom.net (213.94.190.12)

by mail12.svc.cra.dublin.eircom.net (qp 24163) with SMTP; 19 May 2013 12:32:54 -0000

Received: from User ([86.41.153.244])

by avas01.vendorsvc.cra.dublin.eircom.net with Cloudmark Gateway

id doYR1l00Y5GeWeE01oYVi9; Sun, 19 May 2013 13:32:54 +0100

Reply-To: hybqwx@co-operative.co.uk

From: Co-operative Bank p.l.c

Subject: Fix The Error On Your Account

Date: Sun, 19 May 2013 13:58:20 +0100

MIME-Version: 1.0

Content-Type: text/html;

charset="_iso-2022-jp$ESC"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2800.1081

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean



Dear customer,

We have created a new dedicated security server to keep all
our online banking customers account safe and secure.

This server has been tested in most of our bank branches.
Now we are asking all our online banking customers to register for the
new security server to keep them safe.








In order to ensure you are properly updated and your account is fully protected.

Click here for privacy and policy update









Best wishes,

Security Team
Co-operative Bank p.l.c






------------=_5198C686.AF4F5121

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-74352D00======="



--=======AVGMAIL-74352D00=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5841 - Release Date: 05/20/13=



--=======AVGMAIL-74352D00=======--



------------=_5198C686.AF4F5121

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-79238202======="



--=======AVGMAIL-79238202=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5841 - Release Date: 05/20/13=



--=======AVGMAIL-79238202=======--



------------=_5198C686.AF4F5121--







Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA