Nigerian Spam

From - Fri May 10 00:10:47 2013

X-Account-Key: account1

X-UIDL: 0000192c4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Thu, 09 May 2013 19:50:39 -0600

From: "ACCESS BANK PLC"

Subject: [Norton AntiSpam]*SPAM* INFORMATION

Date: Fri, 10 May 2013 01:17:30 +0100

Message-Id:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: **************************************************

X-Spam-Status: Yes, score=93.5 required=5.0 tests=NOTVALID_YAHOO,SARE_FRAUD_X3,

SARE_FRAUD_X4 autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_518C526F.4947E3FE"

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5812]

X-AVG-ID: ID1D45AAF9-4677ED5F

X-Brightmail-Tracker: AAAACB15GvIdeRrpHXotrB16LyAdei54HXothx16LrAdeiyh



This is a multi-part message in MIME format.



------------=_518C526F.4947E3FE

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see the administrator of

that system for details. [...]



Content analysis details: (93.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

45 SARE_FRAUD_X3 Matches 3+ phrases commonly used in fraud spam

45 SARE_FRAUD_X4 Matches 4+ phrases commonly used in fraud spam

3.5 NOTVALID_YAHOO Claims to be from Yahoo but is not



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_518C526F.4947E3FE

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 8C4B712CFAAB; Thu, 9 May 2013 19:50:32 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Thu, 9 May 2013 19:50:32 -0600

Resent-Message-ID: <20130510015032.GA28152@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Thu, 09 May 2013 18:37:46 -0600

From: "ACCESS BANK PLC"

Subject: SPAM INFORMATION

Date: Fri, 10 May 2013 01:17:30 +0100

Message-Id:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: **************************************************

X-Spam-Status: Yes, score=93.5 required=5.0 tests=NOTVALID_YAHOO,SARE_FRAUD_X3,

SARE_FRAUD_X4 autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_518C415A.0CD08A33"

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean



This is a multi-part message in MIME format.



------------=_518C415A.0CD08A33

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see the administrator of

that system for details. [...]



Content analysis details: (93.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

45 SARE_FRAUD_X3 Matches 3+ phrases commonly used in fraud spam

45 SARE_FRAUD_X4 Matches 4+ phrases commonly used in fraud spam

3.5 NOTVALID_YAHOO Claims to be from Yahoo but is not



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_518C415A.0CD08A33

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Thu, 09 May 2013 18:37:39 -0600

From: "ACCESS BANK PLC"

Subject: SPAM INFORMATION

Date: Fri, 10 May 2013 01:17:30 +0100

Message-Id:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: **************************************************

X-Spam-Status: Yes, score=98.7 required=5.0 tests=BOTNET,FORGED_MUA_OUTLOOK,

NOTVALID_YAHOO,RELAY_CHECKER_IPHOSTNAME,SARE_FRAUD_X3,SARE_FRAUD_X4

autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_518C4153.0B31C239"

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $



This is a multi-part message in MIME format.



------------=_518C4153.0B31C239

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: ACCESS BANK PLC TINUBU SQUARE,VICTORIA ISLAND,OFFICE OF THE

GOVERNOR LAGOS-NIGERIA Attention: Beneficiary, With due respect we received

a circular on your behalf based on the conclusion of the recent pact held

in Abuja Federal Capital, the entire members of the Federal House of Senate,

the office of the Presidency, European Representative, United Nation Sec

(Gen) on behalf the Federal Republic of Nigeria Government under the auspices

of the Civilian Head of State DR.GOODLUCK EBELE JONATHAN,have unanimously

approved the under listed THIRTY-TWO (32) contractor's payment with immediate

effect through Access Bank Plc via ATM VISA CARD. Your name was listed among

the THIRTY-TWO (32) contractor's whom are yet to receive their own long term

awaited Contract/Inheritance Funds Payment. [...]



Content analysis details: (98.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.0 BOTNET Relay might be a spambot or virusbot

[botnet0.8,ip=88.208.248.217,rdns=server88-208-248-217.live-servers.net,client,ipinhostname]

0.0 RELAY_CHECKER_IPHOSTNAME Hostname contains IP address

45 SARE_FRAUD_X3 Matches 3+ phrases commonly used in fraud spam

45 SARE_FRAUD_X4 Matches 4+ phrases commonly used in fraud spam

4.2 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook

3.5 NOTVALID_YAHOO Claims to be from Yahoo but is not







------------=_518C4153.0B31C239

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: sales@nk.ca

Delivered-To: sales@nk.ca

Received: from smtp.tccsupport.co.uk (server88-208-248-217.live-servers.net [88.208.248.217])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id 19DCB12CFAA2

for ; Thu, 9 May 2013 18:37:34 -0600 (MDT)

Received: from mail.holt.eu ([77.68.61.31]) by tccsupport.co.uk with MailEnable ESMTP; Fri, 10 May 2013 01:17:32 +0100

Received: from User ([197.242.105.29]) by mail.holt.eu with Microsoft SMTPSVC(6.0.3790.4675);

Fri, 10 May 2013 01:17:29 +0100

Reply-To:

From: "ACCESS BANK PLC"

Subject: INFORMATION

Date: Fri, 10 May 2013 01:17:30 +0100

MIME-Version: 1.0

Content-Type: text/plain;

charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Message-ID:

X-OriginalArrivalTime: 10 May 2013 00:17:29.0516 (UTC) FILETIME=[C2052EC0:01CE4D13]

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean



ACCESS BANK PLC

TINUBU SQUARE,VICTORIA

ISLAND,OFFICE OF THE GOVERNOR

LAGOS-NIGERIA



Attention: Beneficiary,



With due respect we received a circular on your behalf based on the conclusion of the recent pact held in Abuja Federal Capital, the entire members of the Federal House of Senate, the office of the Presidency, European Representative, United Nation Sec (Gen) on behalf the Federal Republic of Nigeria Government under the auspices of the Civilian Head of State DR.GOODLUCK EBELE JONATHAN,have unanimously approved the under listed THIRTY-TWO (32) contractor's payment with immediate effect through Access Bank Plc via ATM VISA CARD. Your name was listed among the THIRTY-TWO (32) contractor's whom are yet to receive their own long term awaited Contract/Inheritance Funds Payment.



The Below Tracking Number is meant for one of the listed Beneficiary who received her own 10.5 Million USD Beneficiary fund via Visa ATM CARD delivery this on Monday, 01/14/2013 at 4:37 P.M. The ATM CARD was delivered to her home address in Norway of which you can track the below UPS Tracking Number for your own confirmation.



WWW.UPS.COM

Beneficiary Name: ANNEWIGAND

TRACKING NO: 1Z73257A0477547498 (UPS TRACKING NUMBER)



All effort is being put into practice to chastise all our corrupt officials who did project us and represent the country as scam before other continents and also the extortion of money from the contractors by people who claim to be working for the Government/Bank impostors. This is in a bid to uphold and maintain our International reputation and promise to the United Nation, OPEC, ECOWAS and the rest of the International Organization.



The entire member's of the Federal House of Senate have pleaded for your forgiveness and for you to revert your distrust upon the entire arms of the government and Nigeria as a body, Sequel to the above, we advice you to contact this office now as soon as you get this message.



Bank Name: Access Bank Plc

Contact Person: Mr.Ray Williams

Direct telephone number +2348163537217

Email: (access_bplc.svpng@live.com)



Contact the above office with the below details of yours,



Full Name:

Contact Address:

Tel Number:

Fax Number:

Sex:

Age:

Occupation:

Country:

Also attach a scan copy of your valid identification card for verification.



Your fund is ready for transfer via ATM VISA CARD, and note very carefully that the GOVERNMENT HAS DEDUCTED ALL THE TAXES AND CHARGES FROM YOUR CONTRACT SUM, YOU WILL ONLY PAY FOR OR TAKE CARE OF YOUR PERMISSION TO TRANSFER FUND FEE WHICH IS YOUR (PTF) ONLY, AND YOUR FUND WILL BE WIRED DIRECT TO YOUR ATM VISA CARD AND DELIVER TO YOUR HOME ADDRESS WITHOUT FURTHER DELAY OR STOP FROM ANY WHERE IN THE WORLD.



Please if you are not ready to follow this instruction, do not contact us, this is for the people who really want to receive their overdue fund payment, so uninterested Beneficiary or person should not contact us to avoid embrassment. You are adviced to comply with the Access Bank instruction as we has been authorized to pay the ten (10) unpaid contractor's through Nigeria Oil Consolidated Reserve Trust Account without problem or delay.



Any other person or official contacting you in regards to your contract fund is SCAM. You are to report such case to FBI Headquarter Washington or Nigeria EFCC for proper investigation.Please, on the receipt of your full outstanding amount, we request that you contact the Office of the IMF/World Bank informing them that you have been paid, for this will help change our image before the world and international community. For your own interest, your Contract File Payment No is: FGN/FMB/DBA/X-05.



Regards,

Mr.Ray Williams

DIRECTOR ON FOREIGN PAYMENT COMMITTEE (ATM PAYMENT).

Copyright ?2009 Access Bank Plc.





------------=_518C4153.0B31C239--





------------=_518C415A.0CD08A33--





------------=_518C526F.4947E3FE

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-5EED482E======="



--=======AVGMAIL-5EED482E=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5812 - Release Date: 05/09/13=



--=======AVGMAIL-5EED482E=======--



------------=_518C526F.4947E3FE

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-5430CCE1======="



--=======AVGMAIL-5430CCE1=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5812 - Release Date: 05/09/13=



--=======AVGMAIL-5430CCE1=======--



------------=_518C526F.4947E3FE--





Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA