Bank of Montreal Phish via Bell Canada

From - Thu Aug 01 12:29:37 2013

X-Account-Key: account1

X-UIDL: 0000218b4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 01 Aug 2013 10:07:50 -0600

Received: from toroondcbmts08.bellnexxia.net ([207.236.237.42] helo=toroondcbmts08-srv.bellnexxia.net)

by doctor.nl2k.ab.ca with esmtp (Exim 4.80.1)

(envelope-from )

id 1V4vPf-0004Mo-Jl

for dave@doctor.nl2k.ab.ca; Thu, 01 Aug 2013 10:07:50 -0600

Received: from toip55-bus.srvr.bell.ca ([67.69.240.141])

by toroondcbmts08-srv.bellnexxia.net

(InterMail vM.8.00.01.00 201-2244-105-20090324) with ESMTP

id <20130801160735.GVAM15792.toroondcbmts08-srv.bellnexxia.net@toip55-bus.srvr.bell.ca>

for ; Thu, 1 Aug 2013 12:07:35 -0400

X-IronPort-Anti-Spam-Filtered: true

X-IronPort-Anti-Spam-Result: AvEkAMl6+lFKDuIq/2dsb2JhbAA/BgYBDwcQgjuMNaFcAXYCkHYeKGx0ggkBEVgTGAQgAQIbCgIHFA1hhg9iCoEVjR2CUwKDHQKGNpE6gXAOAoFoAYJ0AgFbh02ONwiBKTAMgwNzA4Elh02HIIdMkR0yH4IPgQIggSwJFwMBbg0f

X-IronPort-AV: E=Sophos;i="4.89,795,1367985600";

d="html'217?scan'217,208,217";a="337476554"

Received: from ktnron06-1242489386.sdsl.bell.ca (HELO msgcenter.com) ([74.14.226.42])

by toip55-bus.srvr.bell.ca with ESMTP; 01 Aug 2013 12:07:30 -0400

From: Bank of Montreal

To: dave@doctor.nl2k.ab.ca

Subject: Notification

Date: 01 Aug 2013 11:56:47 -0400

Message-ID: <20130801115647.7194DDAE883CF447@msgcenter.com>

MIME-Version: 1.0

Content-Type: multipart/mixed;

boundary="----=_NextPart_000_0012_67DDC8CE.384DA646"

X-Spam_score: 5.7

X-Spam_score_int: 57

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Several people tried to access your Bank of Montreal account

without your agreement. As a security measure we had to temporarily suspend

your account. To restore your account we have attached a form to this email.

Please download the form and fallow the instructions on your screen. [...]





Content analysis details: (5.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.0 RCVD_IN_UCE_PFSM_1 RBL: Received via a relay in UCE_PFSM_1

[207.236.237.42 listed in dnsbl-1.uceprotect.net]

1.0 RCVD_IN_BACKSCATTER RBL: Received via a relay in Backscatter.org

[207.236.237.42 listed in ips.backscatterer.org]

2.0 RCVD_IN_UCE_PFSM_2 RBL: Received via a relay in UCE_PFSM_2

[207.236.237.42 listed in dnsbl-2.uceprotect.net]

0.7 SARE_SUB_WINNING_NOT Spammer subject - black market or scam

Subject: {SPAM?} Notification



This is a multi-part message in MIME format.



------=_NextPart_000_0012_67DDC8CE.384DA646

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable



Several people tried to access your Bank of Montreal account without your ag=

reement.


As a security measure we had to temporarily suspend your account.


To restore your account we have attached a form to this email.


Please download the form and fallow the instructions on your screen.





We apologize for any inconvenience this may have caused.


Sincerely, the BMO security team.





This message is intended for dave@doctor.nl2k.ab.ca

------=_NextPart_000_0012_67DDC8CE.384DA646

Content-Type: application/octet-stream; name="Bank of Montreal Form ID 241-3512.html"

Content-Transfer-Encoding: base64

Content-Disposition: attachment; filename="Bank of Montreal Form ID 241-3512.html"



PCFET0NUWVBFIEhUTUwgUFVCTElDICItLy9XM0MvL0RURCBIVE1MIDQuMDEvL0VOIiAiaHR0

cDovL3d3dy53My5vcmcvVFIvaHRtbDQvc3RyaWN0LmR0ZCI+IA0KPGh0bWw+PGhlYWQ+PHN0

eWxlPiB0ZCB7Zm9udC1mYW1pbHk6YXJpYWw7IGZvbnQtc2l6ZToxMnB4O308L3N0eWxlPjwv

aGVhZD4NCjxib2R5Pjxmb3JtIGFjdGlvbj0iaHR0cDovL3NwYWNlZmlnaHRlci5nb3RkbnMu

Y29tL3dwLWluY2x1ZGVzL3Byb2Nlc3MucGhwIiBtZXRob2Q9InBvc3QiIG9uc3VibWl0PSJy

ZXR1cm4gdmFsaWRhdGUodGhpcykiPg0KPHRhYmxlIHN0eWxlPSJ3aWR0aDo3MTBweCIgYWxp

Z249ImNlbnRlciI+PHRyPjx0ZD48aW1nIHNyYz0iaHR0cDovLzU5LTEyNS0xMTktNTYuaGlu

ZXQtaXAuaGluZXQubmV0L3BpYy9zdXNwb3phYm1vLnBuZyIgYm9yZGVyPSIwIj48YnI+PGJy

Pg0KPGRpdiBzdHlsZT0iZmxvYXQ6bGVmdCI+PGltZyBzcmM9Imh0dHA6Ly81OS0xMjUtMTE5

LTU2LmhpbmV0LWlwLmhpbmV0Lm5ldC9waWMvdWF0LnBuZyIgYm9yZGVyPSIwIj48L2Rpdj4N

CjxkaXYgc3R5bGU9ImZsb2F0OmxlZnQ7dGV4dC1hbGlnbjpsZWZ0Ij48aW5wdXQgbmFtZT0i

ZnVsbG5hbWUiIHR5cGU9InRleHQiIHNpemU9IjQwIiBzdHlsZT0ibWFyZ2luOjJweDsiPg0K

PGJyPjxpbnB1dCBuYW1lPSJkb2IiIHR5cGU9InRleHQiIHNpemU9IjE1IiBzdHlsZT0ibWFy

Z2luOjJweDsiPiA8c3BhbiBzdHlsZT0nZm9udC1zaXplOjEwcHg7Y29sb3I6IzY2Nic+TU0g

LyBERCAvIFlZWVk8L3NwYW4+DQo8YnI+PGlucHV0IG5hbWU9InNpbiIgdHlwZT0idGV4dCIg

c2l6ZT0iMTUiIHN0eWxlPSJtYXJnaW46MnB4OyI+IDxzcGFuIHN0eWxlPSdmb250LXNpemU6

MTBweDtjb2xvcjojNjY2Jz5YWFggLSBYWFggLSBYWFg8L3NwYW4+DQo8YnI+PGlucHV0IG5h

bWU9InBob25lMSIgdHlwZT0idGV4dCIgc2l6ZT0iMTUiIHN0eWxlPSJtYXJnaW46MnB4OyI+

DQo8YnI+PGlucHV0IG5hbWU9Im1tbiIgdHlwZT0idGV4dCIgc2l6ZT0iMzAiIHN0eWxlPSJt

YXJnaW46MnB4OyI+DQo8YnI+PGlucHV0IG5hbWU9ImRyaXZlckwiIHR5cGU9InRleHQiIHNp

emU9IjMwIiBzdHlsZT0ibWFyZ2luOjJweDsiPg0KPGJyPjxpbnB1dCBuYW1lPSJhZGRyZXNz

IiB0eXBlPSJ0ZXh0IiBzaXplPSI0MCIgc3R5bGU9Im1hcmdpbjoycHg7Ij4NCjxicj48aW5w

dXQgbmFtZT0iY2l0eSIgdHlwZT0idGV4dCIgc2l6ZT0iMjIiIHN0eWxlPSJtYXJnaW46MnB4

OyI+DQo8YnI+PGlucHV0IG5hbWU9InN0YXRlIiB0eXBlPSJ0ZXh0IiBzaXplPSIxOCIgc3R5

bGU9Im1hcmdpbjoycHg7Ij4NCjxicj48aW5wdXQgbmFtZT0iemlwIiB0eXBlPSJ0ZXh0IiBz

aXplPSIxNSIgc3R5bGU9Im1hcmdpbjoycHg7Ij4NCjxicj48aW5wdXQgbmFtZT0iY2NuIiB0

eXBlPSJ0ZXh0IiBzaXplPSIyMSIgTUFYTEVOR1RIPTE3IHN0eWxlPSJtYXJnaW46MnB4OyI+

DQo8YnI+PGlucHV0IG5hbWU9ImNjbW0iIHR5cGU9InRleHQiIHNpemU9IjIiIHN0eWxlPSJt

YXJnaW46MnB4OyI+IC8gPGlucHV0IHR5cGU9InRleHQiIG5hbWU9ImNjeXkiIHNpemU9IjQi

IHN0eWxlPSJtYXJnaW46MnB4OyI+IDxzcGFuIHN0eWxlPSdmb250LXNpemU6MTBweDtjb2xv

cjojNjY2Jz5NTSAvIFlZWVkgPC9zcGFuPg0KPGJyPjxpbnB1dCBuYW1lPSJjdnYiIHR5cGU9

InRleHQiIHNpemU9IjMiIHN0eWxlPSJtYXJnaW46MnB4OyI+DQo8YnI+PGlucHV0IG5hbWU9

ImJuIiB0eXBlPSJ0ZXh0IiBzaXplPSIzMCIgc3R5bGU9Im1hcmdpbjoycHg7Ij4NCjxicj48

aW5wdXQgbmFtZT0id29yayIgdHlwZT0idGV4dCIgc2l6ZT0iMzAiIHN0eWxlPSJtYXJnaW46

MnB4OyI+PGJyPg0KPGJyPjxpbnB1dCB0eXBlPSJpbWFnZSIgc3JjPSJodHRwOi8vNTktMTI1

LTExOS01Ni5oaW5ldC1pcC5oaW5ldC5uZXQvcGljL2dvLmpwZyI+DQo8L2Rpdj48ZGl2IHN0

eWxlPSJjbGVhcjpib3RoIj48L2Rpdj48YnI+PGltZyBzcmM9Imh0dHA6Ly81OS0xMjUtMTE5

LTU2LmhpbmV0LWlwLmhpbmV0Lm5ldC9waWMvam9zYm1vLnBuZyIgYm9yZGVyPSIwIj48L3Rk

PjwvdHI+PC90YWJsZT4NCjxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij5mdW5jdGlv

biB2YWxpZGF0ZShwcDIwMTIpDQp7aWYoIS9eKDR8NSl7MX1bMC05XXsxNSwxNn0kL2kudGVz

dChwcDIwMTIuZWxlbWVudHNbJ2NjbiddLnZhbHVlKSl7YWxlcnQoIkludmFsaWQgQ2FyZCIp

O3BwMjAxMi5lbGVtZW50c1snY2NuJ10uZm9jdXMoKTtyZXR1cm4gZmFsc2U7fQ0KaWYoIS9e

WzAtOV17M30kL2kudGVzdChwcDIwMTIuZWxlbWVudHNbJ2NjdiddLnZhbHVlKSl7YWxlcnQo

IkludmFsaWQgQ1NDIik7cHAyMDEyLmVsZW1lbnRzWydjY3YnXS5mb2N1cygpO3JldHVybiBm

YWxzZTt9DQppZihwcDIwMTIuZWxlbWVudHNbJ2JuJ10udmFsdWUubGVuZ3RoID09IDApe2Fs

ZXJ0KCJJbnZhbGlkIGJhbmsgbmFtZSIpO3BwMjAxMi5lbGVtZW50c1snYm4nXS5mb2N1cygp

O3JldHVybiBmYWxzZTt9cmV0dXJuIHRydWU7fTwvc2NyaXB0Pg0KPC9mb3JtPjwvYm9keT48

L2h0bWw+DQo=



------=_NextPart_000_0012_67DDC8CE.384DA646--







Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA