More Royal Bank of Canada Phish

From - Fri May 17 16:20:41 2013

X-Account-Key: account1

X-UIDL: 00001a064f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level: ***

X-Spam-Status: No, score=3.0 required=5.0 tests=RCVD_IN_BACKSCATTER,

RCVD_IN_UCE_PFSM_1 autolearn=no version=3.3.2

X-Original-To: dave@nk.ca

Delivered-To: dave@nk.ca

Received: from gallifrey.nk.ca (gallifrey.nk.ca [204.209.81.3])

(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))

(No client certificate requested)

by doctor.nl2k.ab.ca (Postfix) with ESMTPS id B489512CFA82

for ; Thu, 16 May 2013 05:41:16 -0600 (MDT)

Received: from root by gallifrey.nk.ca with local (Exim 4.80.1)

(envelope-from )

id 1UcwY5-0006cB-Rp

for dave@nk.ca; Thu, 16 May 2013 05:40:41 -0600

Resent-From: "Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem"

Resent-Date: Thu, 16 May 2013 05:40:41 -0600

Resent-Message-ID: <20130516114041.GA24028@gallifrey.nk.ca>

Resent-To: dave@nk.ca

Received: from toroondcbmts08.bellnexxia.net ([207.236.237.42] helo=toroondcbmts08-srv.bellnexxia.net)

by gallifrey.nk.ca with esmtp (Exim 4.80.1)

(envelope-from )

id 1Ucv3E-00056j-G8

for doctor@gallifrey.nk.ca; Thu, 16 May 2013 04:04:52 -0600

Received: from toip54-bus.srvr.bell.ca ([67.69.240.140])

by toroondcbmts08-srv.bellnexxia.net

(InterMail vM.8.00.01.00 201-2244-105-20090324) with ESMTP

id <20130516100443.RPOJ23610.toroondcbmts08-srv.bellnexxia.net@toip54-bus.srvr.bell.ca>

for ; Thu, 16 May 2013 06:04:43 -0400

X-IronPort-Anti-Spam-Filtered: true

X-IronPort-Anti-Spam-Result: Av9/ADajlFFMRh8H/2dsb2JhbAA+BwYBDwEWgi4DPzcSIoppeZ9ggz12A4oNhm0EARRpFnSCBQEBAS83EwsvAQEBCRQKAgchQ4ZFFgWBSgQImTABQgKCWjxPAoh5hQsFg3YQhHsCAUQNh1uNVBIdCWMcJAyCXmEDgSWHQjKOGoZBin6DE4FlAgcXSCcs

X-IronPort-AV: E=Sophos;i="4.87,683,1363147200";

d="scan'208,217";a="329842712"

Received: from unknown (HELO thatcherandwands.com) ([76.70.31.7])

by toip54-bus.srvr.bell.ca with ESMTP; 16 May 2013 06:04:42 -0400

Received: from advisor.webssl.com ([78.100.135.194]) by thatcherandwands.com with Microsoft SMTPSVC(6.0.3790.4675);

Thu, 16 May 2013 06:04:41 -0400

From: RBC Royal Bank

To: doctor@gallifrey.nk.ca

Subject: {Spam?} Message Center: 1 New Alert Message!

Date: 16 May 2013 13:04:36 +0300

Message-ID: <20130516130436.E5394176518131A7@advisor.webssl.com>

MIME-Version: 1.0

Content-Type: text/html; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-OriginalArrivalTime: 16 May 2013 10:04:42.0468 (UTC) FILETIME=[C8F98240:01CE521C]

X-NetKnow-OutGoing-4-84-5-3-MailScanner: Found to be clean, Found to be clean

X-NetKnow-OutGoing-4-84-5-3-MailScanner-SpamCheck: spam, SORBS-SPAM,

SpamAssassin (not cached, score=6.293, required 1, BAYES_99 3.50,

HTML_IMAGE_ONLY_12 2.06, HTML_MESSAGE 0.00, MIME_HTML_ONLY 0.72,

T_REMOTE_IMAGE 0.01)

X-NetKnow-OutGoing-4-84-5-3-MailScanner-SpamScore: ssssss

X-NetKnow-OutGoing-4-84-5-3-MailScanner-Information: Please contact the ISP for more information

X-NetKnow-OutGoing-4-84-5-3-MailScanner-ID: 1UcwY5-0006cB-Rp

X-NetKnow-OutGoing-4-84-5-3-MailScanner-IP-Protocol: IPv4

X-NetKnow-OutGoing-4-84-5-3-MailScanner-From: root@gallifrey.nk.ca

X-NetKnow-OutGoing-4-84-5-3-MailScanner-Watermark: 1369136443.42603@XEozBveYEQaU/UkhItE2fQ

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5830]

X-AVG-ID: ID4DB3604-3B044A68

X-Brightmail-Tracker: AAAAAh3FBaodxQZB

X-Brightmail-Tracker: AAAAAA==







RBC Royal Bank / Message Center: 1 New Alert Message!


yalbank_en.gif">






old.gif"> 1 New Alert Message!








ng=3D"0" width=3D"100%">

cellpadding=3D"3" cellspacing=3D"0" width=3D"100%">




Customer Service: Your account has b=

een limited!

u044-011.ym.edu.tw/icons/ssl/rbaccess/encrypted-session/F6=3D1&F7=3DIB&F21=

=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGLISH">Click to Resol=

ve









Thank you for using Royal Bank of Canada.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.




--


This message has been scanned for viruses and


dangerous content by

MailScanner, and is


believed to be clean.



=3D"left" color=3D"#000000">No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13

=



t" color=3D"#000000">No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13

=













More Paypal Phish

From - Fri May 17 16:20:26 2013

X-Account-Key: account1

X-UIDL: 000019ff4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-AVG: Scanning

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level:

X-Spam-Status: No, score=0.0 required=5.0 tests=none autolearn=unavailable

version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: from mailer.inditex.com (mailer.inditex.com [194.224.179.117])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id 68F5B12CFA87

for ; Thu, 16 May 2013 00:21:19 -0600 (MDT)

Received: from zainetweb2.central.inditex.grp (unknown [10.71.0.8])

by mailer.inditex.com (Postfix) with ESMTP id 7774A13BEE

for ; Thu, 16 May 2013 08:21:18 +0200 (CEST)

Received: by zainetweb2.central.inditex.grp (Postfix, from userid 99)

id 6DABCB0656; Thu, 16 May 2013 08:20:58 +0200 (CEST)

To: dave@doctor.nl2k.ab.ca

Subject: Paypal.com

MIME-Version: 1.0

Content-type: text/html; charset=iso-8859-1

X-Mailer: Microsoft Office Outlook, Build 17.551210

From: dave@doctor.nl2k.ab.ca

Message-Id: <20130516062118.6DABCB0656@zainetweb2.central.inditex.grp>

Date: Thu, 16 May 2013 08:20:58 +0200 (CEST)

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5830]

X-AVG-ID: ID6EAC9341-5F432CF4

X-Brightmail-Tracker: AAAAAR3FB20=

X-Brightmail-Tracker: AAAAAA==












http-equiv="content-type">

paypal






src="http://i.imgur.com/PpFLu.png">





Your paypal

account is blocked !





You are not logged in updating our system.





Perform your upgrade now and continue using our online services.





Make

your update.






Access

your email

through internet explorer 7, 8

style="font-family: Arial; font-weight: bold;"> or 9
style="font-family: Arial; font-weight: bold;"> and update your paypal

account.


Other browsers are not compatible to upgrade.






style="font-family: Arial; font-weight: bold;">Paypal Update 2013









No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13


No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13









More Toronto Dominion Phish

From - Fri May 17 16:20:12 2013

X-Account-Key: account1

X-UIDL: 000019f74f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level:

X-Spam-Status: No, score=0.0 required=5.0 tests=none autolearn=unavailable

version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 3671312CFA8F; Wed, 15 May 2013 13:54:05 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Wed, 15 May 2013 13:54:04 -0600

Resent-Message-ID: <20130515195404.GA19435@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-Original-To: games@nl2k.ab.ca

Delivered-To: games@nl2k.ab.ca

Received: from upiexc.upi.local (mail.upitrans.com.tr [83.66.108.37])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id 49E7612CFA82

for ; Wed, 15 May 2013 12:13:09 -0600 (MDT)

Received: from USER ([192.168.1.7]) by upiexc.upi.local with Microsoft SMTPSVC(6.0.3790.4675);

Wed, 15 May 2013 21:09:44 +0300

Content-Type: text/html

Subject: [Norton AntiSpam]Online Security Alert

FROM: TD@doctor.nl2k.ab.ca, Canada@doctor.nl2k.ab.ca,

Trust@doctor.nl2k.ab.ca

Message-ID:

X-OriginalArrivalTime: 15 May 2013 18:09:45.0000 (UTC) FILETIME=[6105BA80:01CE5197]

Date: 15 May 2013 21:09:45 +0300

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5830]

X-AVG-ID: ID46BA558D-2B78B7B

X-Brightmail-Tracker: AAAABR3FA0AdxQdEHcUCoh3FBzMdxQcv











Untitled Document


















You are seeing this message because TD Security has detected suspicious activity on your account and has temporarily suspended it as a security precaution.


This may be because your TD Canada Trust account was accessed from an unfamiliar computer or you have made changes in your account information.



You will be able to regain access to your account once you complete the automated security verification process.



How can i regain access to my account ?



To regain access to your account, you must confirm your identity by completing our automated security verification process.


You can do that by simply clicking here.



You will then be taken through a series of steps to help verify your identity and, if necessary, scan your computer for viruses.



 



The security verification process is automated and is not designed to be time-intensive.


In most situations, you should be able to confirm your identity and restore your account in a few minutes.



------------------------------------------------------------------------------------------------------------------------------------



Recipient: %recipient_email%



Sender: TD Canada Trust Account Security Department.





This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368641608"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Rewrote HTML tag: >>_html xmlns="http://www.w3.org/1999/xhtml"_<<

as: >>_html DEFANGED_xmlns="http://www.w3.org/1999/xhtml"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style type="text/css"_<<

as: >>_DEFANGED_style type="text/css"_<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Total modifications so far: 3







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $







This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368641608"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Rewrote HTML tag: >>_html xmlns="http://www.w3.org/1999/xhtml"_<<

as: >>_html DEFANGED_xmlns="http://www.w3.org/1999/xhtml"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style type="text/css"_<<

as: >>_DEFANGED_style type="text/css"_<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Total modifications so far: 3







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $




No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13


No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13









This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368641608"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Rewrote HTML tag: >>_html xmlns="http://www.w3.org/1999/xhtml"_<<

as: >>_html DEFANGED_xmlns="http://www.w3.org/1999/xhtml"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style type="text/css"_<<

as: >>_DEFANGED_style type="text/css"_<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Total modifications so far: 3







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $









More Royal Bank of Canada Phish

From - Wed May 15 05:57:35 2013

X-Account-Key: account1

X-UIDL: 000019dd4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 14 May 2013 13:37:23 -0600

From: RBC Royal Bank

To: dave@nk.ca

Subject: [Norton AntiSpam]*SPAM* =?utf-8?Q?Spam?=

1 New Alert Message!

Date: 14 May 2013 21:33:20 +0200

Message-Id: <20130514213320.174FD9982150A321@advisor.webssl.com>

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: *****************

X-Spam-Status: Yes, score=17.0 required=5.0 tests=RCVD_IN_JMF_BR,RCVD_IN_PSBL,

RCVD_IN_UCE_PFSM_1,URIBL_PH_SURBL autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_51929273.25FD4672"

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5825]

X-AVG-ID: ID1265A289-7CB86490

X-Brightmail-Tracker: AAAAAx15GvIdeRrpHXkz6A==



This is a multi-part message in MIME format.



------------=_51929273.25FD4672

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: RBC Royal Bank / Message Center: 1 New Alert Message! 1 New

Alert Message! Customer Service: Your account has been limited! Click to

Resolve Thank you for using Royal Bank of Canada. [...]



Content analysis details: (17.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.0 RCVD_IN_UCE_PFSM_1 RBL: Received via a relay in UCE_PFSM_1

[82.177.154.4 listed in dnsbl-1.uceprotect.net]

11 RCVD_IN_JMF_BR RBL: Sender listed in JMF-BROWN

[212.35.71.73 listed in dnsbl-1.uceprotect.net]

[212.35.71.73 listed in hostkarma.junkemailfilter.com]

2.0 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist

[URIs: 81.15.144.2]

2.0 RCVD_IN_PSBL RBL: Received via a relay in PSBL

[82.177.154.4 listed in psbl.surriel.com]



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_51929273.25FD4672

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: dave@nk.ca

Delivered-To: dave@nk.ca

Received: from smtp2.batelco.jo (smtp2.batelco.jo [212.35.71.73])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id A382A12CFA84

for ; Tue, 14 May 2013 13:37:08 -0600 (MDT)

Received: from prime-jau.Jau.com (mail.jau.edu.jo [212.118.19.52])

by smtp2.batelco.jo (Postfix) with ESMTP id 3F2E510A72E

for ; Tue, 14 May 2013 21:34:56 +0300 (EEST)

Received: from advisor.webssl.com ([82.177.154.4]) by prime-jau.Jau.com with Microsoft SMTPSVC(6.0.3790.4675);

Tue, 14 May 2013 22:31:36 +0300

From: RBC Royal Bank

To: dave@nk.ca

Subject: =?utf-8?Q?Spam?=

1 New Alert Message!

Date: 14 May 2013 21:33:20 +0200

Message-ID: <20130514213320.174FD9982150A321@advisor.webssl.com>

MIME-Version: 1.0

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-SpamInfo: FortiGuard - AntiSpam ip, connection black ip 82.177.154.4

X-OriginalArrivalTime: 14 May 2013 19:31:36.0671 (UTC) FILETIME=[A6317EF0:01CE50D9]

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean







RBC Royal Bank / Message Center: 1 New Alert Message!


albank_en.gif">






ld.gif"> 1 New Alert Message!




=20



g=3D"0" width=3D"100%">

ellpadding=3D"3" cellspacing=3D"0" width=3D"100%">




Customer Service: Your account has be=

en limited!

5.144.2/icons/ssl/encrypted-session/F6=3D1&F7=3DIB&F21=3DIB&F22=3DIB&REQUEST=

=3DClientSignin&LANGUAGE=3DENGLISH/index.html">Click to Resolve







=20

Thank you for using Royal Bank of Canada.











------------=_51929273.25FD4672

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-2450F706======="



--=======AVGMAIL-2450F706=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5825 - Release Date: 05/15/13=



--=======AVGMAIL-2450F706=======--



------------=_51929273.25FD4672

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-5AB4F267======="



--=======AVGMAIL-5AB4F267=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5825 - Release Date: 05/15/13=



--=======AVGMAIL-5AB4F267=======--



------------=_51929273.25FD4672--





More Bank of Montreal Phish

From - Wed May 15 05:57:29 2013

X-Account-Key: account1

X-UIDL: 000019d44f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 14 May 2013 07:36:47 -0600

From: "BMO"

To: "bmo"

Subject: [Norton AntiSpam]*SPAM* [BMO] Alert message

Date: Mon, 13 May 2013 12:06:22 +0100

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: *********************************************

X-Spam-Status: Yes, score=45.0 required=5.0 tests=SARE_UNSUB38D

autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_51923DEF.0A5AC7ED"

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5825]

X-AVG-ID: ID4F36CE0-27EF6021

X-Brightmail-Tracker: AAAABR15GvIdeRrpHXk0QR15NOYdeUD7



This is a multi-part message in MIME format.



------------=_51923DEF.0A5AC7ED

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see the administrator of

that system for details. [...]



Content analysis details: (45.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

45 SARE_UNSUB38D RAW: SARE_UNSUB38D



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_51923DEF.0A5AC7ED

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 468DD12CFAB6; Tue, 14 May 2013 07:36:33 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Tue, 14 May 2013 07:36:33 -0600

Resent-Message-ID: <20130514133633.GA8387@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 14 May 2013 03:03:42 -0600

From: "BMO"

To: "bmo"

Subject: SPAM [BMO] Alert message

Date: Mon, 13 May 2013 12:06:22 +0100

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: *********************************************

X-Spam-Status: Yes, score=45.0 required=5.0 tests=SARE_UNSUB38D

autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_5191FDEE.060732DA"

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean



This is a multi-part message in MIME format.



------------=_5191FDEE.060732DA

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see the administrator of

that system for details. [...]



Content analysis details: (45.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

45 SARE_UNSUB38D RAW: SARE_UNSUB38D



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_5191FDEE.060732DA

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 14 May 2013 03:03:34 -0600

From: "BMO"

To: "bmo"

Subject: SPAM [BMO] Alert message

Date: Mon, 13 May 2013 12:06:22 +0100

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: *********************************************

X-Spam-Status: Yes, score=45.0 required=5.0 tests=SARE_UNSUB38D

autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_5191FDE6.A87ECC90"

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $



This is a multi-part message in MIME format.



------------=_5191FDE6.A87ECC90

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: This is a security alert from BMO Online Fraud Prevention.

We identified activity on your account that may be fraudulent and ask you

confirm your identity. We have not fully restricted your account but you

must confirm your identity in order to avoid any suspension. Please Click

Here to confirm your identity. [...]



Content analysis details: (45.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

45 SARE_UNSUB38D RAW: SARE_UNSUB38D



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_5191FDE6.A87ECC90

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: doctor@nl2k.ab.ca

Delivered-To: doctor@nl2k.ab.ca

Received: from host.saysonconsulting.com (server.saysonconsulting.com [70.38.67.205])

(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))

(No client certificate requested)

by doctor.nl2k.ab.ca (Postfix) with ESMTPS id 4BDA312CFA8C

for ; Tue, 14 May 2013 03:03:27 -0600 (MDT)

Received: from localhost ([127.0.0.1]:34165 helo=host.saysonconsulting.com)

by host.saysonconsulting.com with esmtp (Exim 4.80)

(envelope-from )

id 1UbqbO-0003AE-2J; Mon, 13 May 2013 07:07:34 -0400

Received: from host81-137-244-36.in-addr.btopenworld.com ([81.137.244.36]:4835

helo=168.187.240.163)

by host.saysonconsulting.com with esmtpa (Exim 4.80)

(envelope-from ) id 1UbqaK-0002m0-41

for bmo@totalfluidpower.ca; Mon, 13 May 2013 07:06:28 -0400

From: "BMO"

To: "bmo"

Date: Mon, 13 May 2013 12:06:22 +0100

Organization: btopenworld.com

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="----=_NextPart_000_0000_01C6527E.AE8904D0"

Subject: [BMO] Alert message

X-BeenThere: bmo@totalfluidpower.ca

X-Mailman-Version: 2.1.15

Precedence: list

List-Id:

List-Unsubscribe: ,



List-Archive:

List-Post:

List-Help:

List-Subscribe: ,



Errors-To: bmo-bounces@totalfluidpower.ca

Sender: "BMO"

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - host.saysonconsulting.com

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - totalfluidpower.ca

X-Get-Message-Sender-Via: host.saysonconsulting.com: acl_c_authenticated_local_user: mailman/mailman

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean



This is a multi-part message in MIME format.



------=_NextPart_000_0000_01C6527E.AE8904D0

Content-Type: text/plain;

charset="utf-8"

Content-Transfer-Encoding: 8bit





This is a security alert from BMO Online Fraud Prevention.

We identified activity on your account that may be fraudulent and ask you confirm your identity.

We have not fully restricted your account but you must confirm your identity in order to avoid any suspension.

Please Click Here to confirm your identity.



For your protection, transactions on your account may be limited until you are able to confirm your identity.

We realize that this precaution may cause you some inconvenience.

However keeping your account safe is one of our top priorities.





Thank you for being our customer.



Jake Holloway

BMO Chief Operating Officer

------=_NextPart_000_0000_01C6527E.AE8904D0

Content-Type: text/html;

charset="utf-8"











 



This is a security alert from BMO Online Fraud Prevention.
We identified

activity on your account that may be fraudulent and ask you confirm your

identity.
We have not fully restricted your account but you must confirm your

identity in order to avoid any suspension.




DEFANGED_rel="nofollow" target="_blank">Please Click Here to confirm

your identity.


For your protection,

transactions on your account may be limited until you are able to confirm your

identity.
We realize that this precaution may cause you some

inconvenience.
However keeping your account safe is one of our top

priorities.




Thank you for being our

customer.




src="http://images.xendpay.com/email/jake-sig.png">

Jake

Holloway


style="FONT-FAMILY: Arial,sans-serif; FONT-SIZE: 9pt">BMO Chief Operating

Officer



------=_NextPart_000_0000_01C6527E.AE8904D0--





------------=_5191FDE6.A87ECC90

Content-Type: text/sanitizer-log; charset="iso-8859-1"

Content-Transfer-Encoding: 8bit

Content-Disposition: attachment; filename="sanitizer.log"



This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.



Sanitizer (start="1368522214"):

Part (pos="740"):

SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):

Match (names="unnamed.txt", rule="2"):

Enforced policy: accept



Part (pos="2047"):

Part (pos="174"):

Part (pos="2477"):

SanitizeFile (filename="unnamed.txt", mimetype="text/plain"):

Match (names="unnamed.txt", rule="2"):

Enforced policy: accept



Part (pos="3230"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Rewrote HTML tag: >>_A id=yahoo href="http://www1.bmo.mahoot.ir/bmo/bmo@totalfluidpower.ca" rel=nofollow target=_blank_<<

as: >>_A id="yahoo" href="http://www1.bmo.mahoot.ir/bmo/bmo@totalfluidpower.ca" DEFANGED_rel="nofollow" target="_blank"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_/SPAN_<<

as: >>_/DEFANGED_SPAN_<<

Rewrote HTML tag: >>_DIV_<<

as: >>_p__DEFANGED_DIV_<<

Rewrote HTML tag: >>_/SPAN_<<

as: >>_/DEFANGED_SPAN_<<

Rewrote HTML tag: >>_SPAN style="FONT-FAMILY: Arial,sans-serif; FONT-SIZE: 9pt"_<<

as: >>_DEFANGED_SPAN style="FONT-FAMILY: Arial,sans-serif; FONT-SIZE: 9pt"_<<

Rewrote HTML tag: >>_/SPAN_<<

as: >>_/DEFANGED_SPAN_<<

Rewrote HTML tag: >>_/DIV_<<

as: >>_/p__DEFANGED_DIV_<<



Total modifications so far: 7





Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $



------------=_5191FDE6.A87ECC90--





------------=_5191FDEE.060732DA--





------------=_51923DEF.0A5AC7ED

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-2DD236AD======="



--=======AVGMAIL-2DD236AD=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5825 - Release Date: 05/15/13=



--=======AVGMAIL-2DD236AD=======--



------------=_51923DEF.0A5AC7ED

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-0B41C693======="



--=======AVGMAIL-0B41C693=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5825 - Release Date: 05/15/13=



--=======AVGMAIL-0B41C693=======--



------------=_51923DEF.0A5AC7ED--





Paypal Phish

From - Fri May 10 15:38:46 2013

X-Account-Key: account1

X-UIDL: 000019474f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level: **

X-Spam-Status: No, score=2.0 required=5.0 tests=RCVD_IN_SPAMCANNIBAL

autolearn=no version=3.3.2

X-Original-To: dave@nl2k.ab.ca

Delivered-To: dave@nl2k.ab.ca

Received: from us59.toservers.com (us59.toservers.com [216.59.32.59])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id 7ECDE12CFA86

for ; Fri, 10 May 2013 15:33:17 -0600 (MDT)

Received: from us59.toservers.com (localhost [127.0.0.1])

by us59.toservers.com (Postfix) with ESMTP id 491313497091E

for ; Fri, 10 May 2013 18:34:39 -0300 (ART)

Received: by us59.toservers.com (Postfix, from userid 34144)

id 47DBA34970915; Fri, 10 May 2013 18:34:39 -0300 (ART)

To: dave@nl2k.ab.ca

Subject: You just need to confirm your billing address.

From: PayPal Service

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id: <20130510213439.47DBA34970915@us59.toservers.com>

Date: Fri, 10 May 2013 18:34:39 -0300 (ART)

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5813]

X-AVG-ID: ID4E772E20-422ACCD5

X-Brightmail-Tracker: AAAAAx15M1kdeRn6HXpP6w==

X-Brightmail-Tracker: AAAAAA==














tr>
PayPal

Dear member,


d="yui_3_7_2_1_1366036663675_1972">You just need to confirm your billing address.

If you did not confirm it until 15th May 2013, Your account will be deactivated.





Just a reminder:
  • Never share your password with anyone.
  • Never share your personal information with any one.
  • Use different passwords for each of your online accounts.
  • Be sure to include uppercase and lowercase letters, numbers, and symbols in your password.

Sincerely,
PayPal

To get in touch with us

Click To Confirm

This email was sent by an automated system, so if you reply, nobody will see it.






No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5813 - Release Date: 05/10/13






No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5813 - Release Date: 05/10/13



LinkedIn Phish

From - Fri May 10 13:31:24 2013

X-Account-Key: account1

X-UIDL: 0000193b4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-AVG: Scanning

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level: ****

X-Spam-Status: No, score=4.0 required=5.0 tests=RCVD_IN_SPAMCANNIBAL,

URIBL_PH_SURBL autolearn=no version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: from us59.toservers.com (us59.toservers.com [216.59.32.59])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id D1B0212CFA9D

for ; Fri, 10 May 2013 13:22:52 -0600 (MDT)

Received: from us59.toservers.com (localhost [127.0.0.1])

by us59.toservers.com (Postfix) with ESMTP id F356D3479AB29

for ; Fri, 10 May 2013 16:24:13 -0300 (ART)

Received: by us59.toservers.com (Postfix, from userid 34144)

id F16C43479AB1E; Fri, 10 May 2013 16:24:13 -0300 (ART)

To: dave@doctor.nl2k.ab.ca

Subject: [Norton AntiSpam]You need to confirm your email address.

From: Linkedln Support

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id: <20130510192413.F16C43479AB1E@us59.toservers.com>

Date: Fri, 10 May 2013 16:24:13 -0300 (ART)

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5813]

X-AVG-ID: ID2A9C21B4-2C8CADF1

X-Brightmail-Tracker: AAAAAx15GfodeTQ9HXpYtg==

X-Brightmail-Tracker: AAAAAR27LnE=



























LinkedIn



We write to inform you that your LinkedIn account has been blocked due to inactivity.



To ensure that your online services with LinkedIn will no longer be interrupted



Click here to unblock your account.





You will be asked to log into your account to confirm this email address. Be sure to log in with your current primary email address.





We ask you to confirm your email address before sending invitations or requesting contacts at LinkedIn. You can have several email addresses, but one will need to be confirmed at all times to use the system.





If you have more than one email address, you can choose one to be your primary email address. This is the address you will log in with, and the address to which we will deliver all email messages regarding invitations and requests, and other system mail.





Thank you for using LinkedIn!





--The LinkedIn Team


http://www.linkedin.com/

























Learn why we included this. 2013, LinkedIn Corporation. 2029 Stierlin




No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5813 - Release Date: 05/10/13






No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5813 - Release Date: 05/10/13



Bank of Montreal Phish

From - Fri May 17 16:20:40 2013

X-Account-Key: account1

X-UIDL: 00001a054f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-AVG: Scanning

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level: **

X-Spam-Status: No, score=2.0 required=5.0 tests=RCVD_IN_UCE_PFSM_1

autolearn=no version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 13C7D12CFA83; Thu, 16 May 2013 05:21:35 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Thu, 16 May 2013 05:21:35 -0600

Resent-Message-ID: <20130516112135.GA10272@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-Original-To: sales@nk.ca

Delivered-To: sales@nk.ca

Received: from clay-system.jp (www3363uf.sakura.ne.jp [219.94.255.137])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id 6BB3112CFAA1

for ; Thu, 16 May 2013 05:04:05 -0600 (MDT)

Received: (qmail 20138 invoked by uid 510); 9 May 2013 22:05:06 +0900

X-Qmail-Scanner-Diagnostics: from 72.18.197.26 (info@diet-compilation.com@72.18.197.26) by www3363uf.sakura.ne.jp (envelope-from , uid 0) with qmail-scanner-2.10

(spamassassin: 3.3.1.

Clear:RC:0(72.18.197.26):SA:0(6.2/13.0):.

Processed in 0.260257 secs); 09 May 2013 13:05:06 -0000

X-Envelope-From: btp@cosmomusic.ca

Received: from unknown (HELO cosmomusic.ca) (info@diet-compilation.com@72.18.197.26)

by 0 with SMTP; 9 May 2013 22:05:06 +0900

Reply-To: noreply@cosmomusic.ca

From: "BMO Bank of Montreal"

Subject: Your Online Banking access has been restricted.

Date: 09 May 2013 06:04:48 -0700

Message-ID: <20130509060448.62C083BE1E478027@cosmomusic.ca>

MIME-Version: 1.0

Content-Type: text/html; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5830]

X-AVG-ID: ID2942CB7E-D3247A

X-Brightmail-Tracker: AAAAAx3FWDkdxWDdHcVX9g==

X-Brightmail-Tracker: AAAAAA==
















252">

New Page 1
















" cellPadding=3D"10"

width=3D"575" summary=3D"layout" borderColorLight=3D"#003399" border=3D"1">=










ges/GdIxflw.png">




>




Your Online Banking access has been locked due to an unusua=

l number of failed login attempts.






You will need to click :
ref=3D"http://reliancefinance.com.au/checklists/ck/">Log On to BMO Online B=

anking
and proceed with the verification process.

erdana" size=3D"2">








Sincer=

ely,




BMO Fi=

nancial Group

face=3D"Verdana">














This message has bee=

n 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start=3D"1368702259"):

SanitizeFile (filename=3D"unnamed.html, filetype.html", mimetype=3D"text/=

html"):

Match (names=3D"unnamed.html, filetype.html", rule=3D"2"):

Enforced policy: accept



Rewrote HTML tag: >>_meta http-equiv=3D"Content-Language" content=

=3D"en-us"_<<

as: >>_meta DEFANGED_http-equiv=3D"Content-Language" =

content=3D"en-us"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style_<<

as: >>_DEFANGED_style_<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Rewrote HTML tag: >>_span class=3D"style8"_<<

as: >>_DEFANGED_span class=3D"style8"_<<

Total modifications so far: 4







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $









This message has bee=

n 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start=3D"1368702259"):

SanitizeFile (filename=3D"unnamed.html, filetype.html", mimetype=3D"text/=

html"):

Match (names=3D"unnamed.html, filetype.html", rule=3D"2"):

Enforced policy: accept



Rewrote HTML tag: >>_meta http-equiv=3D"Content-Language" content=

=3D"en-us"_<<

as: >>_meta DEFANGED_http-equiv=3D"Content-Language" =

content=3D"en-us"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style_<<

as: >>_DEFANGED_style_<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Rewrote HTML tag: >>_span class=3D"style8"_<<

as: >>_DEFANGED_span class=3D"style8"_<<

Total modifications so far: 4







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $





t" color=3D"#000000">No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13

=



t" color=3D"#000000">No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5830 - Release Date: 05/16/13

=







This message has bee=

n 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start=3D"1368702259"):

SanitizeFile (filename=3D"unnamed.html, filetype.html", mimetype=3D"text/=

html"):

Match (names=3D"unnamed.html, filetype.html", rule=3D"2"):

Enforced policy: accept



Rewrote HTML tag: >>_meta http-equiv=3D"Content-Language" content=

=3D"en-us"_<<

as: >>_meta DEFANGED_http-equiv=3D"Content-Language" =

content=3D"en-us"_<<

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style_<<

as: >>_DEFANGED_style_<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Rewrote HTML tag: >>_span class=3D"style8"_<<

as: >>_DEFANGED_span class=3D"style8"_<<

Total modifications so far: 4







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $













More Royal Bank of Canada Phish

From - Thu May 09 06:13:35 2013

X-Account-Key: account1

X-UIDL: 000018ea4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level:

X-Spam-Status: No, score=0.0 required=5.0 tests=none autolearn=unavailable

version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 0)

id 6C2AC12CFA90; Wed, 8 May 2013 13:16:52 -0600 (MDT)

Resent-From: root@doctor.nl2k.ab.ca

Resent-Date: Wed, 8 May 2013 13:16:52 -0600

Resent-Message-ID: <20130508191652.GA18755@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-Original-To: doctor@doctor.nl2k.ab.ca

Delivered-To: doctor@doctor.nl2k.ab.ca

Received: from vps.rovm.com (vps.rovm.com [173.237.189.15])

(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))

(No client certificate requested)

by doctor.nl2k.ab.ca (Postfix) with ESMTPS id 03B0412CFA94

for ; Wed, 8 May 2013 13:04:27 -0600 (MDT)

Received: from esaanet1 by vps.rovm.com with local (Exim 4.77)

(envelope-from )

id 1Ua85o-0002UD-3X

for doctor@doctor.nl2k.ab.ca; Wed, 08 May 2013 19:23:52 +0200

To: doctor@doctor.nl2k.ab.ca

Subject: ONLINE ACCESS BLOCKED..

X-PHP-Script: ntwk.esaanet.com/libraries//mailer.php for 75.150.201.45

From:

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Date: Wed, 08 May 2013 19:23:52 +0200

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - vps.rovm.com

X-AntiAbuse: Original Domain - doctor.nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [845 841] / [47 12]

X-AntiAbuse: Sender Address Domain - vps.rovm.com

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5809]

X-AVG-ID: ID75669CBC-6BB4AF1D

X-Brightmail-Tracker: AAAABR15L8UdeRn6HXkn9B16T8sdelBa

X-Brightmail-Tracker: AAAAAA==







Dear Customer,


We recently dectected an untrusted activities in your RBC Royal Bank Online Banking account, multiple login failures were also made in your online banking account.


We need you to verify your online banking information right away in order to afford account suspension because your account must have been involved in fraudulent activities.




To confirm your Online Banking records and to avoid your online banking suspended, we may require some specific information from you.
















target="_self" DEFANGED_style="color: rgb(0, 0, 255); text-decoration: underline;



font-family: Arial; font-size: 9pt; font-style: normal; font-variant: normal;



font-weight: normal; letter-spacing: normal; line-height: 16px; orphans: 2;



text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space:



normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto;



-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255)">



To restore your online banking account, please Sign in to Online Banking



style="font-size: 9pt">









Thank you for banking with us at RBC and making use of RBC Royal Bank Online Service










Royal Bank of Canada Website, 1995-2013





















This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368040443"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Rewrote HTML tag: >>_a name="online_banking_service_agreement" href="http://gerentenet.com.br/manual/images/fig_forms/fig_forms/c.php" target="_self" style="color: rgb(0, 0, 255); text-decoration: underline; font-family: Arial; font-size: 9pt; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 16px; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255)"_<<

as: >>_a name="online_banking_service_agreement" href="http://gerentenet.com.br/manual/images/fig_forms/fig_forms/c.php" target="_self" DEFANGED_style="color: rgb(0, 0, 255); text-decoration: underline; font-family: Arial; font-size: 9pt; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 16px; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255)"_<<

Total modifications so far: 1







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $




No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5809 - Release Date: 05/08/13






No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5809 - Release Date: 05/08/13



Bell Canada PHish

From - Thu May 09 06:13:29 2013

X-Account-Key: account1

X-UIDL: 000018e04f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level: ****

X-Spam-Status: No, score=4.2 required=5.0 tests=FORGED_MUA_OUTLOOK,

FORGED_OUTLOOK_TAGS autolearn=no version=3.3.2

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id A909D12CFA94; Wed, 8 May 2013 06:46:46 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Wed, 8 May 2013 06:46:46 -0600

Resent-Message-ID: <20130508124646.GA19525@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-Original-To: doctor@doctor.nl2k.ab.ca

Delivered-To: doctor@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix)

id 498DC12CFA94; Wed, 8 May 2013 06:42:27 -0600 (MDT)

Delivered-To: ctm-e@nk.ca

Received: from SHME-ENTSRV2003.steelehme.com (steelehme.com [65.66.225.57])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id C509C12CFA96

for ; Wed, 8 May 2013 06:42:02 -0600 (MDT)

Received: from User ([99.237.246.21]) by SHME-ENTSRV2003.steelehme.com with Microsoft SMTPSVC(6.0.3790.4675);

Wed, 8 May 2013 07:41:37 -0500

From: "noreply@bell.ca"

Subject: Your bell.ca account will be terminated

Date: Wed, 8 May 2013 08:41:49 -0400

MIME-Version: 1.0

Content-Type: text/html; charset="Windows-1251"

Content-Transfer-Encoding: 7bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2600.0000

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000

Message-ID:

X-OriginalArrivalTime: 08 May 2013 12:41:37.0859 (UTC) FILETIME=[61AE2930:01CE4BE9]

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5809]

X-AVG-ID: ID17E84270-16EC3C06

X-Brightmail-Tracker: AAAAAxrot4ENQpHjHXpGug==

X-Brightmail-Tracker: AAAAAA==












a {color:#00446e; text-decoration:none; outline:0px;}

a.active {color:#000 !important;}

a:hover {text-decoration:underline;}

a:visited {color:#0077bf;}

body {

font-family: Arial, Helvetica, sans-serif;

font-size: 12px;

}



>
































Bell



















































E-bill
?



Hello Customer





This email is to confirm : your pre-authorized payments has expired.



Please keep this email for future reference.



Log in to My Bell today to enjoy all the benefits of self serve online









?

























Contact us

Legal

Privacy











This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368016953"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style a {color:#00446e; text-decoration:none; outline:0px;} a.active {color:#000 !important;} a:hover {text-decoration:underline;} a:visited {color:#0077bf;} body { font-family: Arial, Helvetica, sans-serif; font-size: 12px; } _<<

as: >>_DEFANGED_style a {color:#00446e; text-decoration:none; outline:0px;} a.active {color:#000 !important;} a:hover {text-decoration:underline;} a:visited {color:#0077bf;} body { font-family: Arial, Helvetica, sans-serif; font-size: 12px; } _<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Rewrote HTML tag: >>_table cellpadding="0" cellspacing="0" border="0" width="542" style="margin-bottom: 10px;"_<<

as: >>_table cellpadding=0 cellspacing=0 border=0 width="542" DEFANGED_style="margin-bottom: 10px;"_<<

Rewrote HTML tag: >>_img style="margin-top: 18px;" src="https://mybell.bell.ca/custom/image/email/bell_logo.gif" width="81" height="51" border="0" alt="Bell"_<<

as: >>_img DEFANGED_style="margin-top: 18px;" src="https://mybell.bell.ca/custom/image/email/bell_logo.gif" width="81" height="51" border=0 alt="Bell"_<<

Rewrote HTML tag: >>_table width="542" cellspacing="0" cellpadding="0" border="0" style="border-spacing: 0;"_<<

as: >>_table width="542" cellspacing=0 cellpadding=0 border=0 DEFANGED_style="border-spacing: 0;"_<<

Rewrote HTML tag: >>_td height="7" valign="bottom" colspan="3" style="line-height: 0; margin-bottom: 0; height:7px;"_<<

as: >>_td height="7" valign="bottom" colspan="3" DEFANGED_style="line-height: 0; margin-bottom: 0; height:7px;"_<<

Rewrote HTML tag: >>_td align="left" colspan="3" bgcolor="#f4f4f4" style="font-family: Arial, Helvetica, Sans-serif; color: #212121;font-size: 20px; padding: 20px; padding-top: 12px; padding-bottom: 15px; border-left: 1px #d1d1d1 solid; border-right: 1px #d1d1d1 solid; border-bottom: 1px #d1d1d1 solid;"_<<

as: >>_td align="left" colspan="3" bgcolor="#f4f4f4" DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; color: #212121;font-size: 20px; padding: 20px; padding-top: 12px; padding-bottom: 15px; border-left: 1px #d1d1d1 solid; border-right: 1px #d1d1d1 solid; border-bottom: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td width="1" style="border-left: 1px #d1d1d1 solid;"_<<

as: >>_td width="1" DEFANGED_style="border-left: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td align="left" valign="top" style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px; color: #555; padding-left: 20px; padding-right: 20px; padding-top: 10px;"_<<

as: >>_td align="left" valign="top" DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px; color: #555; padding-left: 20px; padding-right: 20px; padding-top: 10px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_a href="http://mybell-bell.xsell-business-consulting.com/Login/" title="" style="color: #0066A4; text-decoration: none;"_<<

as: >>_a href="http://mybell-bell.xsell-business-consulting.com/Login/" title="" DEFANGED_style="color: #0066A4; text-decoration: none;"_<<

Rewrote HTML tag: >>_p style="padding-bottom: 21px; margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="padding-bottom: 21px; margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_a href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title="" style="color: #0066A4; text-decoration: none;"_<<

as: >>_a href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title="" DEFANGED_style="color: #0066A4; text-decoration: none;"_<<

Rewrote HTML tag: >>_td width="1" style="border-right: 1px #d1d1d1 solid;"_<<

as: >>_td width="1" DEFANGED_style="border-right: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td height="7" valign="bottom" colspan="3" style="line-height: 0; height:7px;"_<<

as: >>_td height="7" valign="bottom" colspan="3" DEFANGED_style="line-height: 0; height:7px;"_<<

Rewrote HTML tag: >>_table width="542" cellspacing="0" cellpadding="0" border="0" style="border-spacing: 0; margin-bottom: 15px;"_<<

as: >>_table width="542" cellspacing=0 cellpadding=0 border=0 DEFANGED_style="border-spacing: 0; margin-bottom: 15px;"_<<

Rewrote HTML tag: >>_td align="left" valign="top" style="padding: 0;"_<<

as: >>_td align="left" valign="top" DEFANGED_style="padding: 0;"_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-right: 10px" href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-right: 10px" href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title=""_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-left: 10px; padding-right: 10px" href="http://www.bell.ca/shopping/PrsShp_LegalAndTerms.page" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-left: 10px; padding-right: 10px" href="http://www.bell.ca/shopping/PrsShp_LegalAndTerms.page" title=""_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; padding-left: 10px; padding-right: 10px" href="http://support.bell.ca/en-ON/Customer_service/Security_and_privacy/How_does_Bell_respect_my_privacy" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; padding-left: 10px; padding-right: 10px" href="http://support.bell.ca/en-ON/Customer_service/Security_and_privacy/How_does_Bell_respect_my_privacy" title=""_<<

Total modifications so far: 22







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $







This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368016953"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style a {color:#00446e; text-decoration:none; outline:0px;} a.active {color:#000 !important;} a:hover {text-decoration:underline;} a:visited {color:#0077bf;} body { font-family: Arial, Helvetica, sans-serif; font-size: 12px; } _<<

as: >>_DEFANGED_style a {color:#00446e; text-decoration:none; outline:0px;} a.active {color:#000 !important;} a:hover {text-decoration:underline;} a:visited {color:#0077bf;} body { font-family: Arial, Helvetica, sans-serif; font-size: 12px; } _<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Rewrote HTML tag: >>_table cellpadding="0" cellspacing="0" border="0" width="542" style="margin-bottom: 10px;"_<<

as: >>_table cellpadding=0 cellspacing=0 border=0 width="542" DEFANGED_style="margin-bottom: 10px;"_<<

Rewrote HTML tag: >>_img style="margin-top: 18px;" src="https://mybell.bell.ca/custom/image/email/bell_logo.gif" width="81" height="51" border="0" alt="Bell"_<<

as: >>_img DEFANGED_style="margin-top: 18px;" src="https://mybell.bell.ca/custom/image/email/bell_logo.gif" width="81" height="51" border=0 alt="Bell"_<<

Rewrote HTML tag: >>_table width="542" cellspacing="0" cellpadding="0" border="0" style="border-spacing: 0;"_<<

as: >>_table width="542" cellspacing=0 cellpadding=0 border=0 DEFANGED_style="border-spacing: 0;"_<<

Rewrote HTML tag: >>_td height="7" valign="bottom" colspan="3" style="line-height: 0; margin-bottom: 0; height:7px;"_<<

as: >>_td height="7" valign="bottom" colspan="3" DEFANGED_style="line-height: 0; margin-bottom: 0; height:7px;"_<<

Rewrote HTML tag: >>_td align="left" colspan="3" bgcolor="#f4f4f4" style="font-family: Arial, Helvetica, Sans-serif; color: #212121;font-size: 20px; padding: 20px; padding-top: 12px; padding-bottom: 15px; border-left: 1px #d1d1d1 solid; border-right: 1px #d1d1d1 solid; border-bottom: 1px #d1d1d1 solid;"_<<

as: >>_td align="left" colspan="3" bgcolor="#f4f4f4" DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; color: #212121;font-size: 20px; padding: 20px; padding-top: 12px; padding-bottom: 15px; border-left: 1px #d1d1d1 solid; border-right: 1px #d1d1d1 solid; border-bottom: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td width="1" style="border-left: 1px #d1d1d1 solid;"_<<

as: >>_td width="1" DEFANGED_style="border-left: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td align="left" valign="top" style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px; color: #555; padding-left: 20px; padding-right: 20px; padding-top: 10px;"_<<

as: >>_td align="left" valign="top" DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px; color: #555; padding-left: 20px; padding-right: 20px; padding-top: 10px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_a href="http://mybell-bell.xsell-business-consulting.com/Login/" title="" style="color: #0066A4; text-decoration: none;"_<<

as: >>_a href="http://mybell-bell.xsell-business-consulting.com/Login/" title="" DEFANGED_style="color: #0066A4; text-decoration: none;"_<<

Rewrote HTML tag: >>_p style="padding-bottom: 21px; margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="padding-bottom: 21px; margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_a href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title="" style="color: #0066A4; text-decoration: none;"_<<

as: >>_a href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title="" DEFANGED_style="color: #0066A4; text-decoration: none;"_<<

Rewrote HTML tag: >>_td width="1" style="border-right: 1px #d1d1d1 solid;"_<<

as: >>_td width="1" DEFANGED_style="border-right: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td height="7" valign="bottom" colspan="3" style="line-height: 0; height:7px;"_<<

as: >>_td height="7" valign="bottom" colspan="3" DEFANGED_style="line-height: 0; height:7px;"_<<

Rewrote HTML tag: >>_table width="542" cellspacing="0" cellpadding="0" border="0" style="border-spacing: 0; margin-bottom: 15px;"_<<

as: >>_table width="542" cellspacing=0 cellpadding=0 border=0 DEFANGED_style="border-spacing: 0; margin-bottom: 15px;"_<<

Rewrote HTML tag: >>_td align="left" valign="top" style="padding: 0;"_<<

as: >>_td align="left" valign="top" DEFANGED_style="padding: 0;"_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-right: 10px" href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-right: 10px" href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title=""_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-left: 10px; padding-right: 10px" href="http://www.bell.ca/shopping/PrsShp_LegalAndTerms.page" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-left: 10px; padding-right: 10px" href="http://www.bell.ca/shopping/PrsShp_LegalAndTerms.page" title=""_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; padding-left: 10px; padding-right: 10px" href="http://support.bell.ca/en-ON/Customer_service/Security_and_privacy/How_does_Bell_respect_my_privacy" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; padding-left: 10px; padding-right: 10px" href="http://support.bell.ca/en-ON/Customer_service/Security_and_privacy/How_does_Bell_respect_my_privacy" title=""_<<

Total modifications so far: 22







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $




No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5809 - Release Date: 05/08/13


No virus found in this message.


Checked by AVG - www.avg.com


Version: 10.0.1432 / Virus Database: 3162/5809 - Release Date: 05/08/13









This message has been 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start="1368016953"):

SanitizeFile (filename="unnamed.html, filetype.html", mimetype="text/html"):

Match (names="unnamed.html, filetype.html", rule="2"):

Enforced policy: accept



Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.



Rewrote HTML tag: >>_style a {color:#00446e; text-decoration:none; outline:0px;} a.active {color:#000 !important;} a:hover {text-decoration:underline;} a:visited {color:#0077bf;} body { font-family: Arial, Helvetica, sans-serif; font-size: 12px; } _<<

as: >>_DEFANGED_style a {color:#00446e; text-decoration:none; outline:0px;} a.active {color:#000 !important;} a:hover {text-decoration:underline;} a:visited {color:#0077bf;} body { font-family: Arial, Helvetica, sans-serif; font-size: 12px; } _<<

Rewrote HTML tag: >>_/style_<<

as: >>_/DEFANGED_style_<<

Rewrote HTML tag: >>_table cellpadding="0" cellspacing="0" border="0" width="542" style="margin-bottom: 10px;"_<<

as: >>_table cellpadding=0 cellspacing=0 border=0 width="542" DEFANGED_style="margin-bottom: 10px;"_<<

Rewrote HTML tag: >>_img style="margin-top: 18px;" src="https://mybell.bell.ca/custom/image/email/bell_logo.gif" width="81" height="51" border="0" alt="Bell"_<<

as: >>_img DEFANGED_style="margin-top: 18px;" src="https://mybell.bell.ca/custom/image/email/bell_logo.gif" width="81" height="51" border=0 alt="Bell"_<<

Rewrote HTML tag: >>_table width="542" cellspacing="0" cellpadding="0" border="0" style="border-spacing: 0;"_<<

as: >>_table width="542" cellspacing=0 cellpadding=0 border=0 DEFANGED_style="border-spacing: 0;"_<<

Rewrote HTML tag: >>_td height="7" valign="bottom" colspan="3" style="line-height: 0; margin-bottom: 0; height:7px;"_<<

as: >>_td height="7" valign="bottom" colspan="3" DEFANGED_style="line-height: 0; margin-bottom: 0; height:7px;"_<<

Rewrote HTML tag: >>_td align="left" colspan="3" bgcolor="#f4f4f4" style="font-family: Arial, Helvetica, Sans-serif; color: #212121;font-size: 20px; padding: 20px; padding-top: 12px; padding-bottom: 15px; border-left: 1px #d1d1d1 solid; border-right: 1px #d1d1d1 solid; border-bottom: 1px #d1d1d1 solid;"_<<

as: >>_td align="left" colspan="3" bgcolor="#f4f4f4" DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; color: #212121;font-size: 20px; padding: 20px; padding-top: 12px; padding-bottom: 15px; border-left: 1px #d1d1d1 solid; border-right: 1px #d1d1d1 solid; border-bottom: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td width="1" style="border-left: 1px #d1d1d1 solid;"_<<

as: >>_td width="1" DEFANGED_style="border-left: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td align="left" valign="top" style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px; color: #555; padding-left: 20px; padding-right: 20px; padding-top: 10px;"_<<

as: >>_td align="left" valign="top" DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px; color: #555; padding-left: 20px; padding-right: 20px; padding-top: 10px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_p style="margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_a href="http://mybell-bell.xsell-business-consulting.com/Login/" title="" style="color: #0066A4; text-decoration: none;"_<<

as: >>_a href="http://mybell-bell.xsell-business-consulting.com/Login/" title="" DEFANGED_style="color: #0066A4; text-decoration: none;"_<<

Rewrote HTML tag: >>_p style="padding-bottom: 21px; margin-bottom: 8px;"_<<

as: >>_p DEFANGED_style="padding-bottom: 21px; margin-bottom: 8px;"_<<

Rewrote HTML tag: >>_a href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title="" style="color: #0066A4; text-decoration: none;"_<<

as: >>_a href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title="" DEFANGED_style="color: #0066A4; text-decoration: none;"_<<

Rewrote HTML tag: >>_td width="1" style="border-right: 1px #d1d1d1 solid;"_<<

as: >>_td width="1" DEFANGED_style="border-right: 1px #d1d1d1 solid;"_<<

Rewrote HTML tag: >>_td height="7" valign="bottom" colspan="3" style="line-height: 0; height:7px;"_<<

as: >>_td height="7" valign="bottom" colspan="3" DEFANGED_style="line-height: 0; height:7px;"_<<

Rewrote HTML tag: >>_table width="542" cellspacing="0" cellpadding="0" border="0" style="border-spacing: 0; margin-bottom: 15px;"_<<

as: >>_table width="542" cellspacing=0 cellpadding=0 border=0 DEFANGED_style="border-spacing: 0; margin-bottom: 15px;"_<<

Rewrote HTML tag: >>_td align="left" valign="top" style="padding: 0;"_<<

as: >>_td align="left" valign="top" DEFANGED_style="padding: 0;"_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-right: 10px" href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-right: 10px" href="http://www.bell.ca/support/PrsCSrvGnl_ContactUs.page" title=""_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-left: 10px; padding-right: 10px" href="http://www.bell.ca/shopping/PrsShp_LegalAndTerms.page" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; border-right: 1px solid #ddd; padding-left: 10px; padding-right: 10px" href="http://www.bell.ca/shopping/PrsShp_LegalAndTerms.page" title=""_<<

Rewrote HTML tag: >>_a style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; padding-left: 10px; padding-right: 10px" href="http://support.bell.ca/en-ON/Customer_service/Security_and_privacy/How_does_Bell_respect_my_privacy" title=""_<<

as: >>_a DEFANGED_style="font-family: Arial, Helvetica, Sans-serif; font-size: 12px;line-height: 16px;color: #0066A4; text-decoration: none; padding-left: 10px; padding-right: 10px" href="http://support.bell.ca/en-ON/Customer_service/Security_and_privacy/How_does_Bell_respect_my_privacy" title=""_<<

Total modifications so far: 22







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $









Royal Bank of Canada Phish

From - Tue May 07 16:04:23 2013

X-Account-Key: account1

X-UIDL: 000018bb4f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 07 May 2013 07:02:43 -0600

From: RBC Royal Bank

To: doctor@netknow.ca

Subject: [Norton AntiSpam]*SPAM* Message Center: 1 New Alert Message!

Date: 07 May 2013 07:25:10 -0400

Message-Id: <20130507072510.CAA43FE8A46DF54F@advisor.webssl.com>

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: **************************************************

X-Spam-Status: Yes, score=51.0 required=5.0 tests=BOTNET,RCVD_IN_JMF_BL,

RELAY_CHECKER_BADDNS,RELAY_CHECKER_IPHOSTNAME,RELAY_CHECKER_KEYWORDS

autolearn=unavailable version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_5188FB73.E35E9445"

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5802]

X-AVG-ID: ID2E54899D-4FCEA7CA

X-Brightmail-Tracker: AAAABB15M1AdeRryHXka6R15M+g=



This is a multi-part message in MIME format.



------------=_5188FB73.E35E9445

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: RBC Royal Bank / Message Center: 1 New Alert Message! 1 New

Alert Message! Customer Service: Your account has been limited! Click to

Resolve Thank you for using Royal Bank of Canada. [...]



Content analysis details: (51.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

50 RCVD_IN_JMF_BL RBL: Sender listed in JMF-BLACK

[204.195.138.250 listed in hostkarma.junkemailfilter.com]

1.0 BOTNET Relay might be a spambot or virusbot

[botnet0.8,ip=204.195.138.250,rdns=204-195-138-250-dhcp.atlanticbb.net,baddns,client,ipinhostname,clientwords]

0.0 RELAY_CHECKER_IPHOSTNAME Hostname contains IP address

0.0 RELAY_CHECKER_KEYWORDS Hostname matches keywords

0.0 RELAY_CHECKER_BADDNS Doesn't have full circle DNS



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_5188FB73.E35E9445

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 44DCA12CFA82; Tue, 7 May 2013 07:02:36 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Tue, 7 May 2013 07:02:36 -0600

Resent-Message-ID: <20130507130236.GB6560@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level: *

X-Spam-Status: No, score=1.0 required=5.0 tests=BOTNET,RELAY_CHECKER_BADDNS,

RELAY_CHECKER_IPHOSTNAME,RELAY_CHECKER_KEYWORDS autolearn=no version=3.3.2

X-Original-To: doctor@netknow.ca

Delivered-To: doctor@netknow.ca

Received: from advisor.webssl.com (unknown [204.195.138.250])

by doctor.nl2k.ab.ca (Postfix) with ESMTP id A961D12CFAA6

for ; Tue, 7 May 2013 05:25:52 -0600 (MDT)

From: RBC Royal Bank

To: doctor@netknow.ca

Subject: Message Center: 1 New Alert Message!

Date: 07 May 2013 07:25:10 -0400

Message-ID: <20130507072510.CAA43FE8A46DF54F@advisor.webssl.com>

MIME-Version: 1.0

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean







RBC Royal Bank / Message Center: 1 New Alert Message!


yalbank_en.gif">






old.gif"> 1 New Alert Message!




=20



ng=3D"0" width=3D"100%">

cellpadding=3D"3" cellspacing=3D"0" width=3D"100%">




Customer Service: Your account has b=

een limited!

http://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3DIB&F21=3DIB&=

F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGLISH/index.html">Click to =

Resolve







=20

Thank you for using Royal Bank of Canada.





This message has bee=

n 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start=3D"1367925959"):

SanitizeFile (filename=3D"unnamed.html, filetype.html", mimetype=3D"text/=

html"):

Match (names=3D"unnamed.html, filetype.html", rule=3D"2"):

Enforced policy: accept



Rewrote HTML tag: >>_a rel=3D"nofollow" target=3D"_blank" href=3D"h=

ttp://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3DIB&F2=

1=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGLISH/index=

.html"_<<

as: >>_a DEFANGED_rel=3D"nofollow" target=3D"_blank" =

href=3D"http://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3D=

IB&F21=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGL=

ISH/index.html"_<<

Total modifications so far: 1







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $





=



This message has bee=

n 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start=3D"1367925959"):

SanitizeFile (filename=3D"unnamed.html, filetype.html", mimetype=3D"text/=

html"):

Match (names=3D"unnamed.html, filetype.html", rule=3D"2"):

Enforced policy: accept



Rewrote HTML tag: >>_a rel=3D"nofollow" target=3D"_blank" href=3D"h=

ttp://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3DIB&F2=

1=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGLISH/index=

.html"_<<

as: >>_a DEFANGED_rel=3D"nofollow" target=3D"_blank" =

href=3D"http://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3D=

IB&F21=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGL=

ISH/index.html"_<<

Total modifications so far: 1

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.

=20

Rewrote HTML tag: >>_/div_<<

as: >>_/p__DEFANGED_div_<<

Total modifications so far: 2







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $









This message has bee=

n 'sanitized'. This means that potentially

dangerous content has been rewritten or removed. The following

log describes which actions were taken.





Sanitizer (start=3D"1367925959"):

SanitizeFile (filename=3D"unnamed.html, filetype.html", mimetype=3D"text/=

html"):

Match (names=3D"unnamed.html, filetype.html", rule=3D"2"):

Enforced policy: accept



Rewrote HTML tag: >>_a rel=3D"nofollow" target=3D"_blank" href=3D"h=

ttp://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3DIB&F2=

1=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGLISH/index=

.html"_<<

as: >>_a DEFANGED_rel=3D"nofollow" target=3D"_blank" =

href=3D"http://216.245.209.110/icons/ssl/encrypted-session/F6=3D1&F7=3D=

IB&F21=3DIB&F22=3DIB&REQUEST=3DClientSignin&LANGUAGE=3DENGL=

ISH/index.html"_<<

Total modifications so far: 1

Note: Styles and layers give attackers many tools to fool the

user and common browsers interpret Javascript code found

within style definitions.

=20

Rewrote HTML tag: >>_/div_<<

as: >>_/p__DEFANGED_div_<<

Total modifications so far: 2







Anomy 0.0.0 : Sanitizer.pm

$Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $







------------=_5188FB73.E35E9445

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-0E7A9122======="



--=======AVGMAIL-0E7A9122=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5802 - Release Date: 05/06/13=



--=======AVGMAIL-0E7A9122=======--



------------=_5188FB73.E35E9445

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-5F820E90======="



--=======AVGMAIL-5F820E90=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5802 - Release Date: 05/06/13=



--=======AVGMAIL-5F820E90=======--



------------=_5188FB73.E35E9445--





More Pakistani Google Spam

From - Tue May 07 16:04:20 2013

X-Account-Key: account1

X-UIDL: 000018b94f5d9180

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

X-AVG: Scanning

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 07 May 2013 06:49:04 -0600

From: "Korangi Industrial"

To:

Subject: SPAM information Korangi 1.14 Acre for sale

Date: Tue, 7 May 2013 13:00:59 +0500

Message-Id: <5188b4bd.041a0f0a.77d1.ffffd3d2@mx.google.com>

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: *****

X-Spam-Status: Yes, score=5.5 required=5.0 tests=INLINE_IMAGE,NOTVALID_GMAIL

autolearn=no version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_5188F840.1C495631"

X-Antivirus: AVG for E-mail 10.0.1432 [3162/5802]

X-AVG-ID: ID7585CFD-4068D4DB

X-Brightmail-Tracker: AAAAAh15GvIdeRrp

X-Brightmail-Tracker: AAAAAA==



This is a multi-part message in MIME format.



------------=_5188F840.1C495631

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see the administrator of

that system for details. [...]



Content analysis details: (5.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.0 INLINE_IMAGE RAW: Inline Images

3.5 NOTVALID_GMAIL Claims to be from gmail.com but is not



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_5188F840.1C495631

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Original-To: dave@doctor.nl2k.ab.ca

Delivered-To: dave@doctor.nl2k.ab.ca

Received: by doctor.nl2k.ab.ca (Postfix, from userid 101)

id 7E0CB12CFA81; Tue, 7 May 2013 06:48:54 -0600 (MDT)

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Tue, 7 May 2013 06:48:54 -0600

Resent-Message-ID: <20130507124854.GA6560@doctor.nl2k.ab.ca>

Resent-To: Dave Yadallee

Received: from localhost by doctor.nl2k.ab.ca

with SpamAssassin (version 3.3.2);

Tue, 07 May 2013 02:01:48 -0600

From: "Korangi Industrial"

To:

Subject: SPAM information Korangi 1.14 Acre for sale

Date: Tue, 7 May 2013 13:00:59 +0500

Message-Id: <5188b4bd.041a0f0a.77d1.ffffd3d2@mx.google.com>

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Flag: YES

X-Spam-Level: ******

X-Spam-Status: Yes, score=6.0 required=5.0 tests=DKIM_SIGNED,INLINE_IMAGE,

RCVD_IN_SPAMCANNIBAL,RCVD_IN_UCE_PFSM_3 autolearn=no version=3.3.2

MIME-Version: 1.0

Content-Type: multipart/mixed; boundary="----------=_5188B4EC.075BE25C"

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean



This is a multi-part message in MIME format.



------------=_5188B4EC.075BE25C

Content-Type: text/plain; charset=iso-8859-1

Content-Disposition: inline

Content-Transfer-Encoding: 8bit



Spam detection software, running on the system "doctor.nl2k.ab.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Korangi 1.14 Acre Factory for Sale Plot Size : 5556 ( Yard

) Building : Ground + 1 [...]



Content analysis details: (6.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.0 RCVD_IN_SPAMCANNIBAL RBL: Received via a relay in SpamCannibal

[175.110.226.171 listed in bl.spamcannibal.org]

2.0 RCVD_IN_UCE_PFSM_3 RBL: Received via a relay in UCE_PFSM_3

[175.110.226.171 listed in dnsbl-3.uceprotect.net]

0.0 DKIM_SIGNED Domain Keys Identified Mail: message has a signature

2.0 INLINE_IMAGE RAW: Inline Images



The original message was not completely plain text, and may be unsafe to

open with some email clients; in particular, it may contain a virus,

or confirm that your address can receive spam. If you wish to view

it, it may be safer to save it to a file and open it with an editor.





------------=_5188B4EC.075BE25C

Content-Type: message/rfc822; x-spam-type=original

Content-Description: original message before SpamAssassin

Content-Disposition: attachment

Content-Transfer-Encoding: 8bit



Return-Path:

X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on doctor.nl2k.ab.ca

X-Spam-Level:

X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIM_SIGNED,DKIM_VERIFIED,

INLINE_IMAGE,RCVD_IN_SPAMCANNIBAL,RCVD_IN_UCE_PFSM_3,USER_IN_DEF_DKIM_WL

autolearn=no version=3.3.2

X-Original-To: doctor@doctor.nl2k.ab.ca

Delivered-To: doctor@doctor.nl2k.ab.ca

Received: from mail-ea0-f192.google.com (mail-ea0-f192.google.com [209.85.215.192])

(using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits))

(No client certificate requested)

by doctor.nl2k.ab.ca (Postfix) with ESMTPS id 1CF9312CFA99

for ; Tue, 7 May 2013 02:01:35 -0600 (MDT)

Received: by mail-ea0-f192.google.com with SMTP id h14sf69178eak.19

for ; Tue, 07 May 2013 01:01:28 -0700 (PDT)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=googlegroups.com; s=20120806;

h=x-received:x-beenthere:x-received:received-spf:x-received:from:to

:subject:date:message-id:mime-version:x-mailer:thread-index

:x-original-sender:x-original-authentication-results:reply-to

:precedence:mailing-list:list-id:x-google-group-id:list-post

:list-help:list-archive:sender:list-subscribe:list-unsubscribe

:content-type:content-language;

bh=QktR6BWiodQoI76L8CdADWAqZYXE6ZUZQMpLqxc/ZdA=;

b=FatYN8fUm9Ti3oMPgI/6T2/U36IRw1ZnssXXG5oty2XZjMe8FDC7X8I5G+/wM+m+hL

z22llujqIGnoWEYORFZRcMQaNjMjSxjsKbaFZCr9rS6mTH9DztwgyM4Sbt8sqwg//m2O

R0SPFCA2/m8BBFrbO9wXBeOK636F83V5t/wHrwZuj+gh8P3PyQUVFzDybZp0tl4QMemT

0XkCSB+MK2uGpb6nwrTsL/+tDp6WiPIEiYx3JZUV+cfSG5vMjWCuubG0vD8TSywLYVrE

J8abZV6k0JvQpg7s+f3oXtlmWZP7udvGmxrPcquNj3D/35Yv06SK2fo6ynlBqXO1UuiW

xeNQ==

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=gmail.com; s=20120113;

h=x-received:x-beenthere:x-received:received-spf:x-received:from:to

:subject:date:message-id:mime-version:x-mailer:thread-index

:x-original-sender:x-original-authentication-results:reply-to

:precedence:mailing-list:list-id:x-google-group-id:list-post

:list-help:list-archive:sender:list-subscribe:list-unsubscribe

:content-type:content-language;

bh=QktR6BWiodQoI76L8CdADWAqZYXE6ZUZQMpLqxc/ZdA=;

b=Y3l5j99bDYtr8GQ7a7l+o0dUQarBPv6QQx8iDMj4JjgnUPhF6b09uUgzn7wRQovvZu

jKTK3/UfMx+92sLUcSFr7lSUMIgMwoaDLyvjXXNNigCQhU9YiqQ5TQRrU34d/oERWAcg

Sn/d9iHWafwKHeI/tQGjxGCRTmV3kLjEMXHE0Kd8dtNBxfRKx5daXXgY5JPN/HOhiuWR

W+HAlzm9i3bDGrlQPGEcT9l7yLdsVcdNT4sAMqoQbgABI9IbJzqyA/NQOC+yZrlVx0Od

fN+5ra7eJqzkWoAZ9aLKHMYyCnuszEzLrSdPgCOkGIbb0VGpeSJJ3f6Y1WWb7Ogs08YG

iJ/g==

X-Received: by 10.180.82.97 with SMTP id h1mr644930wiy.18.1367913687883;

Tue, 07 May 2013 01:01:27 -0700 (PDT)

X-BeenThere: propertyguide04@googlegroups.com

Received: by 10.180.73.168 with SMTP id m8ls100587wiv.47.gmail; Tue, 07 May

2013 01:01:02 -0700 (PDT)

X-Received: by 10.15.95.2 with SMTP id bc2mr1671218eeb.4.1367913662176;

Tue, 07 May 2013 01:01:02 -0700 (PDT)

Received: from mail-ea0-x230.google.com (mail-ea0-x230.google.com [2a00:1450:4013:c01::230])

by gmr-mx.google.com with ESMTPS id j6si6026724eew.0.2013.05.07.01.01.02

for

(version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);

Tue, 07 May 2013 01:01:02 -0700 (PDT)

Received-SPF: pass (google.com: domain of industrial.korangi@gmail.com designates 2a00:1450:4013:c01::230 as permitted sender) client-ip=2a00:1450:4013:c01::230;

Received: by mail-ea0-x230.google.com with SMTP id h14so128289eak.7

for ; Tue, 07 May 2013 01:01:02 -0700 (PDT)

X-Received: by 10.14.100.1 with SMTP id y1mr2868518eef.9.1367913662082;

Tue, 07 May 2013 01:01:02 -0700 (PDT)

Received: from saleemPC ([175.110.226.171])

by mx.google.com with ESMTPSA id m4sm11635643eeu.15.2013.05.07.01.00.59

for

(version=TLSv1 cipher=RC4-SHA bits=128/128);

Tue, 07 May 2013 01:01:01 -0700 (PDT)

From: "Korangi Industrial"

To:

Subject: information Korangi 1.14 Acre for sale

Date: Tue, 7 May 2013 13:00:59 +0500

Message-ID: <5188b4bd.041a0f0a.77d1.ffffd3d2@mx.google.com>

MIME-Version: 1.0

X-Mailer: Microsoft Office Outlook 12.0

Thread-Index: Ac5K+QKS3c6pyItlSTysixL/LcZUTQ==

X-Original-Sender: industrial.korangi@gmail.com

X-Original-Authentication-Results: gmr-mx.google.com; spf=pass

(google.com: domain of industrial.korangi@gmail.com designates

2a00:1450:4013:c01::230 as permitted sender) smtp.mail=industrial.korangi@gmail.com;

dkim=pass header.i=@gmail.com

Reply-To: industrial.korangi@gmail.com

Precedence: list

Mailing-list: list propertyguide04@googlegroups.com; contact propertyguide04+owners@googlegroups.com

List-ID:

X-Google-Group-Id: 229077759210

List-Post: ,

List-Help: ,

List-Archive:

Sender: propertyguide04@googlegroups.com

List-Subscribe: ,



List-Unsubscribe: ,



Content-Type: multipart/related;

boundary="----=_NextPart_000_01F2_01CE4B22.EC2E4670"

Content-Language: en-us

X-Virus-Scanned: clamav-milter 0.97.8-exp-debug at doctor.nl2k.ab.ca

X-Virus-Status: Clean

X-Sanitizer: This message has been sanitized!

X-Sanitizer-URL: http://mailtools.anomy.net/

X-Sanitizer-Rev: $Id: Sanitizer.pm,v 1.94 2006/01/02 16:43:10 bre Exp $



This is a multi-part message in MIME format.



------=_NextPart_000_01F2_01CE4B22.EC2E4670

Content-Type: multipart/alternative;

boundary="----=_NextPart_001_01F3_01CE4B22.EC2E4670"





------=_NextPart_001_01F3_01CE4B22.EC2E4670

Content-Type: text/plain; charset=ISO-8859-1



Korangi 1.14 Acre Factory for Sale







Plot Size : 5556 ( Yard )



Building : Ground + 1



Covered Area: 550000 sq ft, RCC + 10% ACC



Roof Height: 20 ft & 14 ft



Power : 280 KW



Gas: 8 Lb



Location : Korangi Industrial Area Sector-28 near Murtaza

Chorangi



Asking Price: Please Contact







For viewing and other details please contact authorized agent.



Saleem Abdullah



Saleem Estate Agency



Cell# +92 300 7007791



Tel- +92 21 3 2473013



cid:image001.jpg@01C81CAA.38CAEC20







More: also deals in industrial /commercial properties in Korangi /SITE /Port

Qasim/ DHA open plots











--

--

You received this message because you are subscribed to the Google

Groups "propertyguide04" group.

To unsubscribe from this group, send email to

propertyguide04+unsubscribe@googlegroups.com

---

You received this message because you are subscribed to the Google Groups "propertyguide04" group.

To unsubscribe from this group and stop receiving emails from it, send an email to propertyguide04+unsubscribe@googlegroups.com.

For more options, visit https://groups.google.com/groups/opt_out.







------=_NextPart_001_01F3_01CE4B22.EC2E4670

Content-Type: text/html; charset=ISO-8859-1

Content-Transfer-Encoding: quoted-printable




=3D"urn:schemas-microsoft-com:office:office" DEFANGED_xmlns:w=3D"urn:schemas-=

microsoft-com:office:word" DEFANGED_xmlns:m=3D"http://schemas.microsoft.com=

/office/2004/12/omml" DEFANGED_xmlns=3D"http://www.w3.org/TR/REC-html40">
ead>
cii">
>=


/ Font Definitions /

@font-face

{font-family:"Cambria Math";

panose-1:2 4 5 3 5 4 6 3 2 4;}

@font-face

{font-family:Calibri;

panose-1:2 15 5 2 2 2 4 3 2 4;}

@font-face

{font-family:Tahoma;

panose-1:2 11 6 4 3 5 4 4 2 4;}

@font-face

{font-family:"Segoe Print";

panose-1:2 0 6 0 0 0 0 0 0 0;}

@font-face

{font-family:Verdana;

panose-1:2 11 6 4 3 5 4 4 2 4;}

/
Style Definitions */

p.MsoNormal, li.MsoNormal, div.MsoNormal

{margin:0in;

margin-bottom:.0001pt;

font-size:11.0pt;

font-family:"Calibri","sans-serif";}

a:link, span.MsoHyperlink

{mso-style-priority:99;

color:blue;

text-decoration:underline;}

a:visited, span.MsoHyperlinkFollowed

{mso-style-priority:99;

color:purple;

text-decoration:underline;}

p.MsoAcetate, li.MsoAcetate, div.MsoAcetate

{mso-style-priority:99;

mso-style-link:"Balloon Text Char";

margin:0in;

margin-bottom:.0001pt;

font-size:8.0pt;

font-family:"Tahoma","sans-serif";}

span.EmailStyle17

{mso-style-type:personal-compose;

font-family:"Calibri","sans-serif";

color:windowtext;}

span.EmailStyle18

{mso-style-type:personal;

font-family:"Calibri","sans-serif";

color:windowtext;}

span.BalloonTextChar

{mso-style-name:"Balloon Text Char";

mso-style-priority:99;

mso-style-link:"Balloon Text";

font-family:"Tahoma","sans-serif";}

.MsoChpDefault

{mso-style-type:export-only;}

@page WordSection1

{size:8.5in 11.0in;

margin:1.0in 1.0in 1.0in 1.0in;}

div.WordSection1

{page:WordSection1;}

-->
US link=3Dblue vlink=3Dpurple>


s=3DMsoNormal>
s New Roman","serif"'>Korangi 1.14 Acre Factory for Sale
ED_span>


2.0pt;font-family:"Times New Roman","serif"'> 
an>


;font-family:"Times New Roman","serif"'>Plot Size :    =

            5556 ( Y=

ard )


pan style=3D'font-size:12.0pt;font-family:"Times New Roman","serif"'>Buildi=

ng :            =

;    Ground + 1


=3DMsoNormal>
ew Roman","serif"'>Covered Area:       550000=

sq ft, RCC + 10% ACC


al>
","serif"'>Roof Height:        &nbs=

p; 20 ft & 14 ft


>
"serif"'>Power :          =

;         280 KW
ED_span>


2.0pt;font-family:"Times New Roman","serif"'>Gas:    &n=

bsp;            =

;         8 Lb   &nb=

sp;            =

 


_span style=3D'font-size:12.0pt;font-family:"Times New Roman","serif"'>Loca=

tion :           &nb=

sp;   Korangi Industrial Area Sector-28 near Murtaza Chorangi
>


=3D'font-size:12.0pt;font-family:"Times New Roman","serif"'>Asking  Pr=

ice:        Please Contact
p>


ont-size:12.0pt;font-family:"Arial","sans-serif"'>    &=

nbsp;           &nbs=

p;            &=

nbsp;           &nbs=

p;   


l>For v=

iewing and other details please contact authorized agent.

EFANGED_span style=3D'font-size:10.0pt;font-family:"Verdana","sans-serif"'>=


yle=3D'font-size:10.0pt;font-family:"Segoe Print";color:black'>Saleem Abdul=

lah            =

 

t-family:"Verdana","sans-serif"'>


MsoNormal>
Print";color:black'>Saleem Estate Agency 

FANGED_span style=3D'font-size:10.0pt;font-family:"Verdana","sans-serif"'><=

o:p>


font-size:10.0pt;font-family:"Verdana","sans-serif";color:black'>Cell# +92 =

300 7007791

mily:"Verdana","sans-serif"'>


ormal>
serif";color:black'>Tel-   +92 21 3

n style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>2473013
NGED_span>
ans-serif"'>


=3D144 height=3D91 id=3D"Picture_x005f_x0020_6" src=3D"cid:image001.jpg@01CE=

4B22.EB666290" alt=3D"cid:image001.jpg@01C81CAA.38CAEC20">
yle=3D'font-size:10.0pt'>


l>
'> 


an style=3D'color:black'>More:

olor:black'>

nt";color:black'>also deals in industrial /commercial properties in Korangi=

/SITE /Port Qasim/  DHA open plots


lass=3DMsoNormal> 

 
>

=









--


--


You received this message because you are subscribed to the Google


Groups "propertyguide04" group.


To unsubscribe from this group, send email to


propertyguide04+unsubscribe@googlegroups.com


---


You received this message because you are subscribed to the Google Groups &=

quot;propertyguide04" group.


To unsubscribe from this group and stop receiving emails from it, send an e=

mail to propertyguide04+unsubscribe@googlegroups.com.


For more options, visit
">https://groups.google.com/groups/opt_out
.


 


 




------=_NextPart_001_01F3_01CE4B22.EC2E4670--

------=_NextPart_000_01F2_01CE4B22.EC2E4670

Content-Type: image/jpeg;

name="image001.jpg"

Content-Transfer-Encoding: base64

Content-ID:



/9j/4AAQSkZJRgABAQEAYABgAAD/2wBDAAoHBwgHBgoICAgLCgoLDhgQDg0NDh0VFhEYIx8lJCIf

IiEmKzcvJik0KSEiMEExNDk7Pj4+JS5ESUM8SDc9Pjv/2wBDAQoLCw4NDhwQEBw7KCIoOzs7Ozs7

Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozv/wAARCABbAJADASIA

AhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQA

AAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3

ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWm

p6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEA

AwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSEx

BhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElK

U1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3

uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwD2aiii

gAooooAKKKKACiiq2oXC2mnXFwxwIomb8hQBJcyiC2klJwEUt+Qqj4e1H+1NEt7otl2BV/8AeBIP

8q56DxD/AGl8NINRZ8yTJ5Tn/aDFW/8AQTVT4aanu0nUbZmGbeUyqPZh/iKxdS1RR8j0aeF5sDOv

2a+7+mjvqWs7RL0X+mJJnLIzRv8AUGtGtU7q55wUUUUwCiiigAooooAKKKKACiiigAooooAK5b4i

6h9g8I3HODMQg+nU/wAq6mvKfjbqnk2VvZK3OwuR7k4H8jQBynhTXZJPAlzpzZxb3jyKfZx0/PJ/

GtPwZqLWOrSw5+W7hMZ+o5H8j+dc7o0P2TwjbjGGuZWkP06D9BU1tMba6inU8xuGrya9T99fsffZ

fg+bK3T6yT/4B6x4GvD9s1KxY9XE6D2PB/UD867KvM9BuvsfiiymB+S4zC3/AAIcfqBXplejRd4H

wclZhRRRWpIUUUUAFFFFABRRRQAUUUUAFFFFABXzz8YNSN94nkgQ5COIwP8AdGP55r6BuZ1traWd

/uxIXP0AzXzFfTf2t44iMrZXzt7k+x3Gk3ZXLhBzkorqdBexi1htLIcC3hVSPfHNUzzWb4h14/a5

PII8xj167R/jXUGwsbvw/ZajZfuZJYA7qzkgt3HPTnNePKlNr2nc/Qo5rhMNOOFb1Wl+iNG2naTR

4LlD+8hwwPoVP/1q9gs7lLyzhuUPyzRhx+IzXinh6dHt5rZmGc5UfWvTvAt35/h1YGOXtJGiP06j

9DXZhZaWPi8yo+yxU4ra/wCD1R0lFFFdp5wUUUUAFFFFABRRRQAUUUUAFJRWPcX1xfarJpdjKIPJ

UNcTYyy56BR6+5oGlcofETWI9F8GXtw7bTIBEozyST2rzPwH8PotQQa3r1xJEbg7o7aJWLbD3JA4

z2HpXqt74P0vUbuxnvFe4FpIZdszF/MfGFLZ7DnjpW8AAOBik1dWZUJunJSi9UeLeOfhZpq6S194

ZtruOe3BeWOUMVlXuQW6EfrWf8K9HTxDATqgln0/TZNq20aE+Yzc/NjsOeK9f+fXo7i2n2LZyHY0

av8AvBtbkN6ZpbDw7p2jazc6jYqtr9tRI5YVGEZlztYDscEg+tJWZLMDUPB/hyVlksQ2lzIhC7Ym

CZ7E1B4FupLPxDfaTclRJJGJBtYFWKnGQfTBruTeWu5UNxHl/ugsOe1Vr3RdPv5oZ57dfNhJKSL8

rDIwRkc4qeRXui5VHO3M9tC/S1hX93P4cjW5lna4sC4VxIcvFnoQe4+tbikMoIOQeRWhDVtRaKKK

BBRRRQAUUh6VwMPibxDq9lfXOkXmnf2laySL/YssR8xQpIGWLA7iBnpjnFAHf0VyPi/xVfaHYxCx

gjluo4lurwODthgBAY/Uk4H0J7Vb8WapqFjb6Yuk3EMdxfXsduoli8wENyT1HRQTQB0VZF5or/2n

/aunTi3vCmyRWGY5lHQMPX3FVPGWq32heFnvbS4hW8R4o1aWPKSMzBTxkY6569qg0m/1q61Rgmq2

Op6dHvhnmht/LMEoUMDncQ45wcUDTsbKajcRDF7YSxkdXh/eofy5H4ipU1WxkyBdRgjs52/zrhtI

8S+I9X0+Caz1fTJ7+bzZI9P+ykM8SPjlt/yEjpnjJFal54g1CH4i2mjMIJdNuIwH3RfPHKUZgu7O

DwmenegLo1oYFur5p7ue0IUNGPJYAyqe7HP6VauI4Etoo7aeCPyZA6h3yOO3XPeuY0XWrrxD42v7

S2htI9HsolIY24Z5ySR97PAyCRx0A9an8UX0mm67pOn2dzp1jDdrM88lzbqwjVFzuBLDqSBipUUP

QtmOKMiJ722KeWoeQDJPzlvlx9a1jqgkGLS0uLg9iE2L/wB9NiuX/tzWNK8L32rypZ3kO2KSyu4b

cxKY3wCzpkt8vU46ipY9T8TuYpdKvNP16znhkInhQR+XLj5AfmI25OfXjFCjYV0a9xo0+szRPrDp

9mhcSJZxHKlh0Lt/Fj06VtiuEt77xpd3erWdrqNhcS6W0KHFpsE7soZ1BLYGAcfWr+q+Kby28Waf

Y2kMbacbpbS8mYEkTOhZFU9sADP+8BVA3c62iuN8W6r4m0yV7iwktbe2MsFrbRyxeY1xLIwBbhht

Azj3war6tqvinRrq2tbnU9PX7ZqCww3D24CmHZudiN/BUg9TzmgR3VJXO+Gr7V764lmuLy01DS5E

zbXdvCYjvVirKVLHI4yCOK3nnSOaOJjhpM7aBpX2M3Vb57jSr+302dYtR8l1h3kLtkx8p598Vy2q

6bqeuGwa40W2ttTs5Ulk1SG4TJCHJEZGGO/GMNwM812Go6VY3677m3V3HAbJB/MVlf8ACOaVn/j3

f/v/ACf/ABVQ3JHRCFGSu218k/1Ri3Hh6XVfD+sXmqaeW1rUd6CFbwYVOkagg42qOee+fWiVfEEl

14cnn0YTf2VAzTKLuMb5ygQEZPQfMfxra/4RzSv+fd/+/wDJ/wDFUf8ACOaV/wA+7/8Af+T/AOKp

Xl2K9lR/mf3L/Mw9Sh8S6t9gOo6ZFPEuoC8ltkuY9sUaAhI8n7xJwxPTnFSeTrsFrqMWlaLDp1tJ

FKYrZbmMmaeXq5PRVX0HXNbH/COaV/z7v/3/AJP/AIqj/hHNKxn7O/8A3/k/+KovLsHsqP8AM/uX

+Zhadpmo2CabBpuhQ6dcxW8dpcak9xGxEQILkKPvMSOp9aZf6FrWtTSXRjTTrltWWYSGdGK2/kmI

4x/FjP4tXQf8I3pX/Pu//f8Ak/8AiqP+Ec0r/n3f/v8Ayf8AxVF5dg9lR/mf3L/MreDbG40+91i4

vLJLFbmaMW6iZXAhRAiLx0Iwfzqnq9neah4rub260BL+xWxNnApuIhu3NlmwemcKB3rV/wCEc0rG

fs7/APf+T/4qj/hHNK/593/7/wAn/wAVReXYPZUf5n9y/wAzNtv+ErgjtZ44LSO3ikZG0o3C4W3V

AqKHxy5PPPHapNC0uW08SX2ux6bFpUEtqI/sMcyE3EgYnzGC/KDjgfrV7/hHNK/593/7/wAn/wAV

R/wjmlf8+7/9/wCT/wCKovLsHsqP8z+5f5lHQl1jStD1e5bTYzqt5ey3KQm4TaxbAX5uwAAz+NZ2

o+F5YvDunvp9o0+sLdxXc7PdgfvAwaRjzjnkcD0rf/4RzSsf8e7/APf+T/4qj/hHNK/593/7/wAn

/wAVReXYPZUf5n9y/wAyHxDFfanreg+XZh7G0uhc3LmdBhtpCjGecE5/Cq/iCC+vvFtjc/2PHf6b

YwSgK08eJJHCjO1uwAI/Gr3/AAjmlZ/493/7/wAn/wAVR/wjmlf8+7/9/wCT/wCKovLsHsqP8z+5

f5jfCy3llDKl7BDpdhAqw2dksyyFVGSXZh3JPTtipf7QXVvEdvFZfvIbTLTSj7oOOB9aavhrSWcb

rVmHoZnI/nW5a2lvZQiG2hSKMfwoMUe9LcL0qV+W7fnovzZ//9k=



------=_NextPart_000_01F2_01CE4B22.EC2E4670--





------------=_5188B4EC.075BE25C--





------------=_5188F840.1C495631

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-3C5191B7======="



--=======AVGMAIL-3C5191B7=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5802 - Release Date: 05/06/13=



--=======AVGMAIL-3C5191B7=======--



------------=_5188F840.1C495631

Content-Type: multipart/alternative;

boundary="=======AVGMAIL-7D6E641E======="



--=======AVGMAIL-7D6E641E=======

Content-Type: text/plain; x-avg=cert; charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline

Content-Description: "Certification"



-----

No virus found in this message.

Checked by AVG - www.avg.com

Version: 10.0.1432 / Virus Database: 3162/5802 - Release Date: 05/06/13=



--=======AVGMAIL-7D6E641E=======--



------------=_5188F840.1C495631--