More Alberta Treasury Branch Phish from Australia

From - Sat May 25 07:48:04 2013

X-Account-Key: account1

X-UIDL: 00001b304f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level:

X-Spam-Status: No, score=1.0 required=5.0 tests=BOTNET,RELAY_CHECKER_BADDNS

autolearn=no version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 87AFA12CFAE8; Fri, 24 May 2013 07:59:16 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Fri, 24 May 2013 07:59:16 -0600

Resent-Message-ID: <20130524135916.GA21880@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-Original-To: games@nl2k.ab.ca

Delivered-To: games@nl2k.ab.ca

Received: from host.gapajob.com.au (unknown [173.199.190.140])

(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))

(No client certificate requested)

by doctor.nl2k.ab.ca (Postfix) with ESMTPS id A2FB712CFAE5

for ; Fri, 24 May 2013 07:53:40 -0600 (MDT)

Received: from [185.7.214.35] (port=51063 helo=fb.mail.gandi.net)

by host.gapajob.com.au with esmtpsa (SSLv3:EDH-RSA-DES-CBC3-SHA:168)

(Exim 4.80)

(envelope-from )

id 1Uf9WO-0001Et-U3

for games@nl2k.ab.ca; Wed, 22 May 2013 23:56:06 +1000

From: "ATBONLINE - Financial Services"

Subject: ATB ONLINE BUSINESS - Your Account Statement Notice is Ready

22/05/2013

To: games@nl2k.ab.ca

Content-Type: multipart/mixed; boundary="d07KQL=_5kqkQXOKfT51sG1RpvUNyFolpG"

MIME-Version: 1.0

Reply-To: sharon.lennox@atb.com.au

Date: Wed, 22 May 2013 15:56:23 +0000

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - host.gapajob.com.au

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - atb.com.au

X-Get-Message-Sender-Via: host.gapajob.com.au: authenticated_id: sharon.lennox@thoughtsonbox.com.au

X-Source:

X-Source-Args:

X-Source-Dir:

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3184/5854]

X-AVG-ID: IDB47135B-6EBD3454

X-Brightmail-Tracker: AAAABh3FYAQdxV+rHcVgzh3FYN0dxWDYHcVf+g==

X-Brightmail-Tracker: AAAAAA==



This is a multi-part message in MIME format



--d07KQL=_5kqkQXOKfT51sG1RpvUNyFolpG

Content-Type: text/plain_; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable



DEAR ALBERTA TREASURY BRANCH CUSTOMER



Your most recent monthly statement is ready and is available for download (=

see attachement). The statement includes all ATB Financial transactions and=

your starting and ending balances.



We email you to let you know your account statement is ready. You can view =

or print a copy of your statement from the same page. kindly download the a=

ttached file to view your most recent statement.



ATB Financial Online Services

Customer Relations Services





As this e-mail is an automated message, do not reply to this email.





--------------------------------------------------



No virus found in this message.

Checked by AVG - www.avg.com

Version: 2013.0.1901 / Virus Database: 4108/8641 - Release Date...





--d07KQL=_5kqkQXOKfT51sG1RpvUNyFolpG

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-041BAE89======="



--=======AVGMAIL-041BAE89=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

Viruses found in the attached files.

ATB Financial Statement May 2013.html: Virus found JS/Phish. The attac=

hment was moved to the Virus Vault.

* sanitizer.log: Virus found JS/Phish. The attachment was moved to the V=

irus Vault.



Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3184/5854 - Release Date: 05/24/13=



--=======AVGMAIL-041BAE89=======--



--d07KQL=_5kqkQXOKfT51sG1RpvUNyFolpG

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-0A5A1042======="



--=======AVGMAIL-0A5A1042=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3184/5854 - Release Date: 05/24/13=



--=======AVGMAIL-0A5A1042=======--



--d07KQL=_5kqkQXOKfT51sG1RpvUNyFolpG--





.



Trackbacks

Trackback specific URI for this entry

This link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.

No Trackbacks

Comments

Display comments as Linear | Threaded

No comments

Add Comment

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
Standard emoticons like :-) and ;-) are converted to images.

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA