More TD Phish

From - Mon Mar 17 10:16:19 2014

X-Account-Key: account2

X-UIDL: 000572d4501fb806

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-path:

Envelope-to: aboo@doctor.nl2k.ab.ca

Delivery-date: Mon, 17 Mar 2014 10:15:48 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.82)

(envelope-from )

id 1WPZH4-0007lh-9w

for aboo@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 09:16:22 -0600

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Mon, 17 Mar 2014 09:16:21 -0600

Resent-Message-ID: <20140317151621.GA29432@doctor.nl2k.ab.ca>

Resent-To: See root

Received: from server.socialdesignmedia.com ([67.23.247.177])

by doctor.nl2k.ab.ca with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)

(Exim 4.82)

(envelope-from )

id 1WPYzk-0006l8-9k

for archive@nl2k.ab.ca; Mon, 17 Mar 2014 08:59:02 -0600

Received: from 227-4.clcom.cgocable.ca ([24.226.227.4]:8549 helo=td.com)

by server.socialdesignmedia.com with esmtpa (Exim 4.80.1)

(envelope-from )

id 1WPYzX-0007WM-7i

for archive@nl2k.ab.ca; Mon, 17 Mar 2014 10:58:15 -0400

From: TD Canada Trust

To: archive@nl2k.ab.ca

Subject: EasyWeb Online Security

Date: 17 Mar 2014 10:57:41 -0400

Message-ID: <20140317105741.6EE002C6CA8C2D6E@td.com>

MIME-Version: 1.0

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - server.socialdesignmedia.com

X-AntiAbuse: Original Domain - nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - td.com

X-Get-Message-Sender-Via: server.socialdesignmedia.com: authenticated_id: mhuerta@conalepnl.edu.mx

X-Source:

X-Source-Args:

X-Source-Dir:






3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">=20















=09=09



=09

=20


">



 



Dear Customer,



=09=09=09

Your TD Canada Trust EasyWeb Internet Banking account has been lock=

ed=20

temporarily due to many unsuccessful login attempts.



=09=09=09

You are kindly advised to
ystem/css/style.htm">Login
to EasyWeb=20

Internet Banking and follow the instructions on your screen.








TD Canada Trust Online Security



 


=09=09=09

The data submitted will be =

transmitted=20

over an SSL encrypted connection (128 bit Secure Socket Layer).
=








(Server ID: SW2A : c2e97b55-=

8a40-4212-be3a-36d94820eb0c=20

)













Canada Revenue Agency Phish

From - Mon Mar 17 09:15:17 2014

X-Account-Key: account2

X-UIDL: 000572ce501fb806

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-path:

Envelope-to: aboo@doctor.nl2k.ab.ca

Delivery-date: Mon, 17 Mar 2014 09:15:14 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.82)

(envelope-from )

id 1WPYRw-0004TS-Py

for aboo@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 08:23:33 -0600

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Mon, 17 Mar 2014 08:23:32 -0600

Resent-Message-ID: <20140317142332.GE12542@doctor.nl2k.ab.ca>

Resent-To: See root

Received: from [198.87.129.12] (helo=www.miselu.com)

by doctor.nl2k.ab.ca with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)

(Exim 4.82)

(envelope-from )

id 1WPXzS-0002XC-E0

for root@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 07:54:39 -0600

Received: from www.miselu.com (www.miselu.com [127.0.0.1])

by www.miselu.com (8.13.8/8.13.8-) with ESMTP id s2HCxuMm024175

for ; Mon, 17 Mar 2014 05:59:56 -0700

Received: (from root@localhost)

by www.miselu.com (8.13.8/8.13.8/Submit) id s2HCxu7c024172;

Mon, 17 Mar 2014 05:59:56 -0700

Date: Mon, 17 Mar 2014 05:59:56 -0700

Message-Id: <201403171259.s2HCxu7c024172@www.miselu.com>

To: root@doctor.nl2k.ab.ca

Subject: Your tax refund online

From: Canada Revenue Agency

Content-Type: text/html

X-Spam_score: 7.0

X-Spam_score_int: 70

X-Spam_bar: +++++++

X-Spam_report: Spam detection software, running on the system "gallifrey.nk.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Claim Your Tax Refund Online We identified an error in the

calculation of your tax from the last payment, amounting to a 733,17$. In

order for us to return the excess payment, you need to create a Tax Gateway

account after which the funds will be credited to your specified bank account.

[...]



Content analysis details: (7.0 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.5 TVD_PH_BODY_ACCOUNTS_PRE BODY: TVD_PH_BODY_ACCOUNTS_PRE

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

2.0 MIME_HEADER_CTYPE_ONLY 'Content-Type' found without required MIME

headers

1.1 TO_NO_BRKTS_NORDNS_HTML To: misformatted and no rDNS and HTML only

Subject: {SPAM?} Your tax refund online
































cellPadding="10"

width="575" summary="layout" borderColorLight="#307D7E" border="1">












color="#307D7E">


Claim Your Tax Refund Online





We identified an error in the calculation of your tax from the

last payment, amounting
to a 733,17$. In order for us to return the

excess payment, you need to create a Tax Gateway account after which the

funds will be credited to your specified bank account.

Please

click "Get Started" below to claim your refund:




size="2" color="#307D7E">





Get

Started





We are here to ensure

the correct tax is paid at the right time, whether this relates to

payment of taxes received by the department or entitlement to benefits

paid.

























More TD Phish

From - Mon Mar 17 09:16:18 2014

X-Account-Key: account2

X-UIDL: 000572d1501fb806

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-path:

Envelope-to: aboo@doctor.nl2k.ab.ca

Delivery-date: Mon, 17 Mar 2014 09:15:32 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.82)

(envelope-from )

id 1WPYQo-0004Oz-62

for aboo@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 08:22:22 -0600

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Mon, 17 Mar 2014 08:22:22 -0600

Resent-Message-ID: <20140317142222.GC12542@doctor.nl2k.ab.ca>

Resent-To: See root

Received: from smtp43.singnet.com.sg ([165.21.103.151])

by doctor.nl2k.ab.ca with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)

(Exim 4.82)

(envelope-from )

id 1WPWGy-0003k5-HB

for doctor@nl2k.ab.ca; Mon, 17 Mar 2014 06:04:42 -0600

Received: from [192.168.1.100] ([124.66.142.42])

by smtp43.singnet.com.sg (8.13.8/8.14.1) with ESMTP id s2HC1dtw010843;

Mon, 17 Mar 2014 20:01:45 +0800

Message-Id: <201403171201.s2HC1dtw010843@smtp43.singnet.com.sg>

Content-Type: multipart/alternative; boundary="===============2134173274=="

MIME-Version: 1.0

Subject: Dear Td Canada Trust Member

To: Recipients

From: "TD Canada"

Date: Mon, 17 Mar 2014 20:01:50 +0800

X-PMX-Version: 5.5.2.363555, Antispam-Engine: 2.6.1.350677, Antispam-Data: 2013.8.24.225128

X-PMX-AS: AS-Check

X-PMX-Score: Probability=9%



You will not see this in a MIME-aware mail reader.

--===============2134173274==

Content-Type: text/plain; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body



TD Canada Trust Survey Department selected you to take part in our quic=

k survey. =



To earn your 150$ reward, please Login .



=20

--===============2134173274==

Content-Type: text/html; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body




=3Diso-8859-1"/>






-SPACING: 0px; FONT: medium 'Times New Roman'; TEXT-TRANSFORM: none; COLOR:=

rgb(0,0,0); TEXT-INDENT: 0px; WHITE-SPACE: normal; LETTER-SPACING: normal;=

BORDER-COLLAPSE: separate; orphans: 2; widows: 2; webkit-border-horizontal=

-spacing: 0px; webkit-border-vertical-spacing: 0px; webkit-text-decorations=

-in-effect: none; webkit-text-size-adjust: auto; webkit-text-stroke-width: =

0px">


l">TD Canada Trust Survey Department selected you to take part in our =

quick survey.




-SPACING: 0px; FONT: medium 'Times New Roman'; TEXT-TRANSFORM: none; COLOR:=

rgb(0,0,0); TEXT-INDENT: 0px; WHITE-SPACE: normal; LETTER-SPACING: normal;=

BORDER-COLLAPSE: separate; orphans: 2; widows: 2; webkit-border-horizontal=

-spacing: 0px; webkit-border-vertical-spacing: 0px; webkit-text-decorations=

-in-effect: none; webkit-text-size-adjust: auto; webkit-text-stroke-width: =

0px">


l">To earn your 150$ reward, please
rg/TdCaTrust.html">Login
.





--===============2134173274==--



More TD Phish

From - Mon Mar 17 09:16:17 2014

X-Account-Key: account2

X-UIDL: 000572d0501fb806

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

X-Mozilla-Keys:

Return-path:

Envelope-to: aboo@doctor.nl2k.ab.ca

Delivery-date: Mon, 17 Mar 2014 09:15:32 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.82)

(envelope-from )

id 1WPYPm-0004Lq-Ij

for aboo@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 08:21:18 -0600

Resent-From: doctor@doctor.nl2k.ab.ca

Resent-Date: Mon, 17 Mar 2014 08:21:18 -0600

Resent-Message-ID: <20140317142118.GA12542@doctor.nl2k.ab.ca>

Resent-To: See root

Received: from gator3273.hostgator.com ([198.57.247.237])

by doctor.nl2k.ab.ca with esmtps (TLSv1.2:DHE-RSA-AES256-GCM-SHA384:256)

(Exim 4.82)

(envelope-from )

id 1WPVY1-0001M3-EJ

for root@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 05:18:10 -0600

Received: from saber770 by gator3273.hostgator.com with local (Exim 4.80.1)

(envelope-from )

id 1WPVXu-0001s4-1O

for root@doctor.nl2k.ab.ca; Mon, 17 Mar 2014 06:17:30 -0500

To: root@doctor.nl2k.ab.ca

Subject: You have (1 unread) secure message

X-PHP-Script: cherishedwife.com/s98.php for 95.97.133.154

From: TD Canada Trust

Reply-To:

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Date: Mon, 17 Mar 2014 06:17:30 -0500

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - gator3273.hostgator.com

X-AntiAbuse: Original Domain - doctor.nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [33141 500] / [47 12]

X-AntiAbuse: Sender Address Domain - gator3273.hostgator.com

X-BWhitelist: no

X-Source-IP:

X-Source: /usr/bin/php

X-Source-Args: /usr/bin/php /home3/saber770/public_html/cherishedwife.com/s98.php

X-Source-Dir: lostinch.com:/public_html/cherishedwife.com

X-Source-Sender:

X-Source-Auth: saber770

X-Email-Count: 219

X-Source-Cap: c2FiZXI3NzA7c2FiZXI3NzA7Z2F0b3IzMjczLmhvc3RnYXRvci5jb20=













Your EasyWeb account has 1 new m









 









 







Your 
EasyWeb account

has 1 new secure message.



 









 







TD Canada Trust | Customer Service Centre

















More Apple Phish

Return-path:

Envelope-to: sales@nk.ca

Delivery-date: Mon, 17 Mar 2014 05:43:05 -0600

Received: from fra.fraternityadv.com ([142.4.19.198])

by doctor.nl2k.ab.ca with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)

(Exim 4.82)

(envelope-from )

id 1WPVw7-0002cO-Rg

for sales@nk.ca; Mon, 17 Mar 2014 05:43:05 -0600

Received: from adacocac by fra.fraternityadv.com with local (Exim 4.82)

(envelope-from )

id 1WPVw3-0006Fk-Pp

for sales@nk.ca; Mon, 17 Mar 2014 06:42:27 -0500

To: sales@nk.ca

Subject: Please update your account details on iTunes.

X-PHP-Script: adacocacola.com/wp-content/plugins/11.php for 77.79.107.130

From: Apple

Reply-To: app@apple.ca

MIME-Version: 1.0

Content-Type: text/html

Content-Transfer-Encoding: 8bit

Message-Id:

Date: Mon, 17 Mar 2014 06:42:27 -0500

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - fra.fraternityadv.com

X-AntiAbuse: Original Domain - nk.ca

X-AntiAbuse: Originator/Caller UID/GID - [530 32007] / [47 12]

X-AntiAbuse: Sender Address Domain - fra.fraternityadv.com

X-Get-Message-Sender-Via: fra.fraternityadv.com: authenticated_id: adacocac/only user confirmed/virtual account not confirmed

X-Source: /usr/bin/php

X-Source-Args: /usr/bin/php /home/adacocac/public_html/wp-content/plugins/11.php

X-Source-Dir: adacocacola.com:/public_html/wp-content/plugins

X-Spam_score: 5.8

X-Spam_score_int: 58

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "gallifrey.nk.ca", has

identified this incoming email as possible spam. The original message

has been attached to this so you can view it (if it isn't spam) or label

similar future email. If you have any questions, see

the administrator of that system for details.



Content preview: Our security check detected multiple unwanted login attepmts

on your account. You need to update your iTunes account details for better

security. Click the link below to update your account details: Click Here

to Update [...]



Content analysis details: (5.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.6 TVD_PH_SUBJ_ACCOUNTS_POST TVD_PH_SUBJ_ACCOUNTS_POST

-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay

domain

1.5 TVD_PH_SEC BODY: Message has a phrase standard for phishing mails

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag

Subject: {SPAM?} Please update your account details on iTunes.



Our security check detected multiple unwanted login attepmts on your

account.



You need to update your iTunes account details for better security.


Click the link below to update your account details:


Click Here to Update






We are sorry for any problems caused by our security check.



iTunes team.







More TD Phish

Return-path:

Envelope-to: sales@nk.ca

Delivery-date: Mon, 17 Mar 2014 06:03:46 -0600

Received: from smtp41.singnet.com.sg ([165.21.103.142])

by doctor.nl2k.ab.ca with esmtp (Exim 4.82)

(envelope-from )

id 1WPWG6-0003iA-6F; Mon, 17 Mar 2014 06:03:45 -0600

Received: from sg-apps02.gillcapital.local ([116.12.226.222])

by smtp41.singnet.com.sg (8.14.3/8.14.1) with ESMTP id s2HC2S5C002864;

Mon, 17 Mar 2014 20:02:33 +0800

Message-Id: <201403171202.s2HC2S5C002864@smtp41.singnet.com.sg>

Content-Type: multipart/alternative; boundary="===============0372507373=="

MIME-Version: 1.0

Subject: Dear Td Canada Trust Member

To: Recipients

From: "TD Canada"

Date: Mon, 17 Mar 2014 20:09:44 +0800

X-PMX-Version: 5.5.2.363555, Antispam-Engine: 2.6.1.350677, Antispam-Data: 2014.3.17.115115

X-PMX-AS: AS-Check

X-PMX-Score: Probability=9%



You will not see this in a MIME-aware mail reader.

--===============0372507373==

Content-Type: text/plain; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body



TD Canada Trust Survey Department selected you to take part in our quic=

k survey. =



To earn your 150$ reward, please Login .



=20

--===============0372507373==

Content-Type: text/html; charset="iso-8859-1"

MIME-Version: 1.0

Content-Transfer-Encoding: quoted-printable

Content-Description: Mail message body




=3Diso-8859-1"/>






-SPACING: 0px; FONT: medium 'Times New Roman'; TEXT-TRANSFORM: none; COLOR:=

rgb(0,0,0); TEXT-INDENT: 0px; WHITE-SPACE: normal; LETTER-SPACING: normal;=

BORDER-COLLAPSE: separate; orphans: 2; widows: 2; webkit-border-horizontal=

-spacing: 0px; webkit-border-vertical-spacing: 0px; webkit-text-decorations=

-in-effect: none; webkit-text-size-adjust: auto; webkit-text-stroke-width: =

0px">


l">TD Canada Trust Survey Department selected you to take part in our =

quick survey.




-SPACING: 0px; FONT: medium 'Times New Roman'; TEXT-TRANSFORM: none; COLOR:=

rgb(0,0,0); TEXT-INDENT: 0px; WHITE-SPACE: normal; LETTER-SPACING: normal;=

BORDER-COLLAPSE: separate; orphans: 2; widows: 2; webkit-border-horizontal=

-spacing: 0px; webkit-border-vertical-spacing: 0px; webkit-text-decorations=

-in-effect: none; webkit-text-size-adjust: auto; webkit-text-stroke-width: =

0px">


l">To earn your 150$ reward, please
Trust.html">Login
.





--===============0372507373==--