<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Phish] Telephone phishing thread in Spam, Scam and Phishbusters</title>
<link>http://www.dslreports.com/forum/r20059853</link>
<description></description>
<language>en</language>
<pubDate>Wed, 25 Nov 2009 12:40:25 EDT</pubDate>
<lastBuildDate>Wed, 25 Nov 2009 12:40:25 EDT</lastBuildDate>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,23033992</link>
<description><![CDATA[<A HREF="/useremail/u/334792"><b>SYNACK</b></A> : Here's an interesting followup to this after checking my online bill in more details. We have 4 lines on that account and not all numbers are adjacent. Still, all phones received the <b>same</b> text message <b>literally within seconds of each other</b>.<br><br>I called t-mobile to see if there are any security measures in place to possibly prevent such things in the future, similar to e.g. spam filters for e-mail.<br><br>I am curious if the target numbers were skimmed from the <A HREF="http://www.itworld.com/security/69017/t-mobile-confirms-stolen-data-genuine">stolen t-mobile data</b>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23033992</guid>
<pubDate>Wed, 16 Sep 2009 14:42:46 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22939038</link>
<description><![CDATA[<A HREF="/useremail/u/334792"><b>SYNACK</b></A> : phishing MMS received on cell (t-mobile):<br><br><b>310@tmomail.net</b>: We found a problem in your California account. Call urgently at <b>(888) 666-9128</b><br><br>(Googling that number show numerous similar messages)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22939038</guid>
<pubDate>Fri, 28 Aug 2009 13:55:55 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22805242</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : Your number must have been one of the first batches called. It has now shown up on several of the phone number websites:<br><br>&raquo;<A HREF="http://800notes.com/Phone.aspx/1-877-245-1472" >800notes.com/Phone.aspx/1-877-245-1472</A><br><br>&raquo;<A HREF="http://whocallsme.com/Phone-Number.aspx/8772451472" >whocallsme.com/Phone-Number.aspx/8772451472</A><br><br>&raquo;<A HREF="http://www.callercomplaints.com/SearchResult.aspx?Phone=877-245-1472" >www.callercomplaints.com/SearchR&middot;&middot;&middot;245-1472</A><br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22805242</guid>
<pubDate>Mon, 03 Aug 2009 01:21:25 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22804912</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : That's funny, I got the same text today. I noticed that it said receive instead of received after looking at it a couple of times. I didn't even bother calling, especially after that grammatical error. So then I googled (hah it's a verb) the 3878 text number and nothing showed up. Then I searched the message through google and found that people actually gave up their account information lol.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22804912</guid>
<pubDate>Sun, 02 Aug 2009 23:36:49 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22804668</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><small>said by  NightVisor <A HREF="/useremail/u/329504"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><small>*deadpan*</small> Define "special". <small>*deadpan:end*</small><br><br></div>"rare, uncommon, unique..."<br><small>in a complimentary way</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22804668</guid>
<pubDate>Sun, 02 Aug 2009 22:19:26 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22804458</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Good thinking.  And thanks for posting.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22804458</guid>
<pubDate>Sun, 02 Aug 2009 21:25:37 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22804403</link>
<description><![CDATA[<A HREF="/useremail/u/329504"><b>NightVisor</b></A> : <small>*deadpan*</small> Define "special". <small>*deadpan:end*</small><br><br>I wanted to see what the message hook was. I already knew it was a scam, but the number didn't show up in any search engines. Since this thread (the whole forum, actually) is regularly monitored by Google et al., might as well drop in the number and the message so if someone else searches, they'll find the info.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22804403</guid>
<pubDate>Sun, 02 Aug 2009 21:15:42 EDT</pubDate>
</item>

<item>
<title>Re: SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22804215</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><small>said by  NightVisor <A HREF="/useremail/u/329504"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>At that point, I hung up.<br> </div>Wow! You're in a special class of people.<br>Off the top of my head I'll say less than 1 in a half million people who receive these respond to them.<br>Did you call out of irritation or were you initially unsure about the message?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22804215</guid>
<pubDate>Sun, 02 Aug 2009 20:29:59 EDT</pubDate>
</item>

<item>
<title>SMS sent to cell phone</title>
<link>http://www.dslreports.com/forum/remark,22803510</link>
<description><![CDATA[<A HREF="/useremail/u/329504"><b>NightVisor</b></A> : From: 3736<br><br>Message:<br>customer.notification@visa.com / "Card Block Alert". To find out why you receive this alert call 1-877-245-1472. Thank you. /<br><br>What happens when I call that number?<br>"Your credit union has identified your account as having fraudulent entries and your credit card has been blocked. Please stay on the and a credit union security specialist will assist you."<br><br>*sounds of call being transfered*<br><br>"To assist you with your account, please enter your credit card number"<br><br>At that point, I hung up.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22803510</guid>
<pubDate>Sun, 02 Aug 2009 17:04:22 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Paypal vish</title>
<link>http://www.dslreports.com/forum/remark,22619731</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : Here's where he was routing the calls to<br>sip:cacat0099@proxy01.sipphone.com]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22619731</guid>
<pubDate>Sat, 27 Jun 2009 09:15:20 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,22605753</link>
<description><![CDATA[<A HREF="/useremail/u/1589236"><b>Rowan</b></A> : My SO has a new cell phone -- TWO DAYS OLD -- and has received 6 calls today (one per hour or so).  The first few were "caller unknown", but the most recent call showed up as 877-648-0958.  I've called that no. from another phone and I get 'invalid number'.  They've left no messages, so not sure what they're up to, but Goog sez lots of other ppls are having this recent prob with this same no.<br><br>Just thought I'd report in.<br><br>~Rowan]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22605753</guid>
<pubDate>Wed, 24 Jun 2009 20:53:33 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Paypal vish</title>
<link>http://www.dslreports.com/forum/remark,22593873</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : I thought it was Italy, then I wondered how low the IQ of a Phisher would have to be in order to think that a victim would make an international call to Italy to contact PayPal support.<br><br>I guess that must be the downside of dropping out of Phishing 101.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22593873</guid>
<pubDate>Mon, 22 Jun 2009 21:34:40 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Paypal vish</title>
<link>http://www.dslreports.com/forum/remark,22593403</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Yes, I assume foreign.<br><br>If I am reading it correctly, the "00" is a prefix for US callers, then the 39 is the international code for Italy.<br><small>--<br>AT&T dsl; Speedstream 5100b modem; openSuSE 11.0; firefox 3.0.11</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22593403</guid>
<pubDate>Mon, 22 Jun 2009 19:57:45 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Paypal vish</title>
<link>http://www.dslreports.com/forum/remark,22593255</link>
<description><![CDATA[<A HREF="/useremail/u/666842"><b>MGD</b></A> : <div class="bquote"><small>said by  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Excerpt from vish:<br><br>Restore your account .<br> Please Call our Card Department at 0039-069-165-7836<br><br> </div>A foreign number perhaps ?, there are too many digits for it to be a US number<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22593255</guid>
<pubDate>Mon, 22 Jun 2009 19:26:00 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Paypal vish</title>
<link>http://www.dslreports.com/forum/remark,22568195</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Excerpt from vish:<br><br>Restore your account .<br> Please Call our Card Department at 0039-069-165-7836<br><textarea name="code" class="text" cols=50 rows=10>Received: from mail.bccnews.us (mail.bccnews.us &#91;208.70.72.115&#93;)&#012;        by mp.cs.niu.edu (8.14.3/8.14.3) with ESMTP id n5HGYf0e029439&#012;        for &lt;munged@cs.niu.edu&gt;; Wed, 17 Jun 2009 11:34:46 -0500 (CDT)&#012;Received: from User &#91;207.178.222.51&#93; by mail.bccnews.us with ESMTP&#012;  (SMTPD32-7.07) id A04A3D70040; Wed, 17 Jun 2009 07:40:10 -0700&#012;From: "PayPal"&lt;contact@ppas.com&gt;&#012;Subject: Notice.&#012;Date: Wed, 17 Jun 2009 07:35:48 -0700&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.11</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22568195</guid>
<pubDate>Wed, 17 Jun 2009 17:43:10 EDT</pubDate>
</item>

<item>
<title>F &#x26; M Bank Express Online - vish at (641) 410 2293</title>
<link>http://www.dslreports.com/forum/remark,21692848</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> :  <blockquote><small>said by vish body :</small><hr>Dear F&M Bank customer,<br><br>We are hereby notifying you that we've recently suffered a phishing-Attack. Beca<br>use we have registered too many frauds we suspended your account. For security r<br>easons you must call us and provide the requested information so we can verify t<br>he integrity of your F&M ExpressOnline Banking account. If you fail to complete<br>the verification in the next 24 hours your account will be blocked.<br><br>***************************************************<br><br>Call us at: +1 (641) 410 2293 and confirm your identity.<br><br>***************************************************<br><br>Note: The call is free of charge for you!<br><br>Please comply and thanks for understanding.<br><br>\251 2009 F&M Bank<br><hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;billing@myfmbank.com&gt;&#012;Received: from mail.tekonet.de (mail.tekonet.de &#91;194.39.185.4&#93;)&#012;        by mp.cs.niu.edu (8.14.3/8.14.3) with ESMTP id n070egAR027175&#012;        for &lt;munged@cs.niu.edu&gt;; Tue, 6 Jan 2009 18:40:51 -0600 (CST)&#012;Received: by mail.tekonet.de with MERCUR Mailserver (v5.00.19 MTA1LTI1NjQtNjQxNA&#012;==) for &lt;munged@cs.niu.edu&gt;; Tue, 6 Jan 2009 22:28:57 +0100&#012;From: "F&amp;M Bank"&lt;billing@myfmbank.com&gt;&#012;Subject: &#91;URGENT NOTICE&#93; We've recently suffered a phishing-Attack&#012;Date: Tue, 6 Jan 2009 16:56:25 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;To: &lt;munged@cs.niu.edu&gt;&#012;Message-Id: &lt;0901062228579700@mail.tekonet.de&gt;&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.5</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21692848</guid>
<pubDate>Tue, 06 Jan 2009 20:13:52 EDT</pubDate>
</item>

<item>
<title>Capital One vish</title>
<link>http://www.dslreports.com/forum/remark,21667710</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : A vish for Capital One, at +1(315-235-1392)<br><br> <blockquote><small>said by mail body :</small><hr>In our terms and contidions you have agreed to state that your<br>account must always be under your control or those you designate<br>at all times. We have noticed some activity related to your account that<br>indicates that order parties may have tried gaining access or control of your<br>information in your account.<br><br>Therefore, to prevent unauthorized access to your Capital One Bank<br>Internet Banking account,you are limited to five failed login attempts in <br>a 24-hour period. You have exceeded this number of attempts.*<br><br>To reactivate your debit card , please call: +1(315-235-1392)<br><br>Copyright Capital One Bank, All Rights Reserved.<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;service@capitalone.com&gt;&#012;Received: from southeasterngeothermal.com (mail.southeasterngeothermal.com &#91;208.103.1.222&#93;)&#012;        by mp.cs.niu.edu (8.14.3/8.14.3) with ESMTP id n022CGfj008721&#012;        for &lt;*munged*&gt;; Thu, 1 Jan 2009 20:12:22 -0600 (CST)&#012;Received: from User (&#91;207.181.121.72&#93;) by southeasterngeothermal.com with Microsoft SMTPSVC(6.0.3790.3959);&#012;         Sun, 14 Dec 2008 10:08:29 -0500&#012;Reply-To: &lt;no-reply@capitalone.com&gt;&#012;From: "Capital One Services, Inc."&lt;service@capitalone.com&gt;&#012;Subject: Important Member Service Information&#012;Date: Sun, 14 Dec 2008 10:09:12 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;SOUTHEASTERNchAHrey000006c0@southeasterngeothermal.com&gt;&#012;X-OriginalArrivalTime: 14 Dec 2008 15:08:29.0486 (UTC) FILETIME=&#91;D2673CE0:01C95DFD&#93;&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.5</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21667710</guid>
<pubDate>Thu, 01 Jan 2009 21:19:36 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21589795</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Credit Union Access:<br><br><textarea name="code" class="text" cols=50 rows=10> Return-Path:     &lt;card@creditunionaccess.com&gt;&#012;Authentication-Results: mta170.mail.re4.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received: from 68.99.120.49 (EHLO dukecmmtar02.coxmail.com) (68.99.120.49) by mta170.mail.re4.yahoo.com with SMTP; Mon, 15 Dec 2008 21:15:46 -0800&#012;Received: from creditunionaccess.com (&#91;98.191.101.166&#93;) by dukecmmtar02.coxmail.com (InterMail vM.6.01.06.05 201-2131-130-106-20070212) with ESMTP id &lt;20081216051546.XOJQ18528.dukecmmtar02.coxmail.com@creditunionaccess.com&gt; for &lt;x@yahoo.com&gt;; Tue, 16 Dec 2008 00:15:46 -0500&#012;Reply-To: card@creditunionaccess.com&#012;From: &#012;"Credit Union Access" &lt;card@creditunionaccess.com&gt; &lt;card@creditunionaccess.com&gt;  &#012;To: x@yahoo.com&#012;Subject: Account Status Alert&#012;Date: 15 Dec 2008 22:15:45 -0700&#012;Message-ID: &lt;20081215221545.860840C6428CA82A@creditunionaccess.com&gt;&#012;MIME-Version: 1.0&#012;Content-Type: text/html; charset="iso-8859-1"&#012;Content-Transfer-Encoding: quoted-printable&#012;Content-Length: 788&#012;</textarea><!--end code block--><br>Dear CU Member:<br><br>This is not a promotional e-mail. Please call us immediately at (877) 898-7930 regarding recent restriction placed on your account. We're available 24/7 to take your call.<br><br>Please disregard this e-mail if you've already call us since the date this e-mail was sent.<br><br>We appreciate your prompt attention to this matter.<br><br>Thank you<br>CU Fraud Prevention Security Department <br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21589795</guid>
<pubDate>Tue, 16 Dec 2008 10:16:29 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21556277</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : U.S. Bank telephone phish (there were two of these, with the same image and telephone number):<br><br>#1:<br><textarea name="code" class="text" cols=50 rows=10>  Return-Path:     &lt;rtkxxo@yahoo.com&gt;&#012;Authentication-Results: mta569.mail.mud.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received: from 68.230.240.9 (EHLO eastrmmtao103.cox.net) (68.230.240.9) by mta569.mail.mud.yahoo.com with SMTP; Tue, 09 Dec 2008 16:10:50 -0800&#012;Received: from eastrmimpo03.cox.net (&#91;68.1.16.126&#93;) by eastrmmtao103.cox.net (InterMail vM.7.08.02.01 201-2186-121-102-20070209) with ESMTP id &lt;20081210001049.DUTA18445.eastrmmtao103.cox.net@eastrmimpo03.cox.net&gt;; Tue, 9 Dec 2008 19:10:49 -0500&#012;Received: from User (&#91;70.187.22.254&#93;) by eastrmimpo03.cox.net with bizsmtp id pCAj1a0085Uvfce02CAkUW; Tue, 09 Dec 2008 19:10:48 -0500 a=gMMwTlpgCVsA:10 a=nDDMXIyUaCkA:10 a=oJL9TIRMo0YA:10 a=HWowFZCwAAAA:8 a=6VBaUAmcAAAA:8 a=vzUeNKtdRj-0HKc1hJIA:9&#012;Reply-To: rtkxxo@yahoo.com&#012;From: &#012;U.S. Bank&lt;rtkxxo@yahoo.com&gt;  &#012;Subject: Multiple password failures ! Please call our 24-hours Security Department&#012;Date: Wed, 10 Dec 2008 01:14:07 +0100&#012;MIME-Version: 1.0&#012;Content-Type: text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Message-Id: &lt;20081210001049.DUTA18445.eastrmmtao103.cox.net@eastrmimpo03.cox.net&gt;&#012;Content-Length: 173&#012;</textarea><!--end code block--><br>#2<br><textarea name="code" class="text" cols=50 rows=10> Return-Path:     &lt;dsmxzu@yahoo.com&gt;&#012;Authentication-Results: mta149.mail.re1.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received: from 68.230.240.13 (EHLO eastrmmtai106.cox.net) (68.230.240.13) by mta149.mail.re1.yahoo.com with SMTP; Tue, 09 Dec 2008 15:16:23 -0800&#012;Received: from eastrmimpo03.cox.net (&#91;68.1.16.126&#93;) by eastrmmtao107.cox.net (InterMail vM.7.08.02.01 201-2186-121-102-20070209) with ESMTP id &lt;20081209231458.FIYS4842.eastrmmtao107.cox.net@eastrmimpo03.cox.net&gt;; Tue, 9 Dec 2008 18:14:58 -0500&#012;Received: from User (&#91;70.188.140.60&#93;) by eastrmimpo03.cox.net with bizsmtp id pBEt1a00K1JP2Ge02BEuhr; Tue, 09 Dec 2008 18:14:58 -0500 a=gMMwTlpgCVsA:10 a=5a7zk8gS10wA:10 a=oJL9TIRMo0YA:10 a=HWowFZCwAAAA:8 a=6VBaUAmcAAAA:8 a=vzUeNKtdRj-0HKc1hJIA:9&#012;Reply-To: dsmxzu@yahoo.com&#012;From: &#012;U.S. Bank&lt;dsmxzu@yahoo.com&gt;  &#012;Subject: Multiple password failures ! Please call our 24-hours Security Department&#012;Date: Wed, 10 Dec 2008 00:18:17 +0100&#012;MIME-Version: 1.0&#012;Content-Type: text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Message-Id: &lt;20081209231458.FIYS4842.eastrmmtao107.cox.net@eastrmimpo03.cox.net&gt;&#012;Content-Length: 173&#012;</textarea><!--end code block--><br>The body of the email is an image only (the screenshot above). It is clickable, but appears to lead to the real U.S. Bank website.<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21556277?c=1378241&ret=L2ZvcnVtL3IyMDA1OTg1My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="154315 bytes" WIDTH=600 HEIGHT=386 SRC="/r0/download/1378241.thumb600~c79c3600a13464196401ec282d842496/us_bank_phish.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21556277</guid>
<pubDate>Tue, 09 Dec 2008 23:03:39 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21495743</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <b>800-523-8103 Capital One</b><br><br>Sent to my mother's Yahoo email. Only thing changed is the first part of the To: address<br><br><textarea name="code" class="text" cols=50 rows=10> &#012; Return-Path:     &lt;mailout04@westnotificationsgroup.com&gt;&#012;Authentication-Results: mta198.mail.ac4.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received: from 208.34.106.236 (EHLO vocal-net.net) (208.34.106.236) by mta198.mail.ac4.yahoo.com with SMTP; Thu, 27 Nov 2008 23:35:42 -0800&#012;Received: from westnotificationsgroup.com (unverified &#91;72.54.106.166&#93;) by ntvop4.netaccnt.net (Vircom SMTPRS 4.5.654.13) with ESMTP id &lt;B0142103054@ntvop4.netaccnt.net&gt; for &lt;nataleemorse@yahoo.com&gt;; Fri, 28 Nov 2008 02:10:33 -0500&#012;From: &#012;"Capital One" &lt;service@capitaone.com&gt; &lt;216.57.96.8 (HELO mailout04.westnotificationsgroup.com)&gt;  &#012; &#012;To: x@yahoo.com&#012;Subject: Capital One Alert: Irregular Credit Card Activity&#012;Date: 28 Nov 2008 00:13:11 -0700&#012;Message-ID: &lt;20081128001311.B0F742BDBB2F8318@capitaone.com&gt;&#012;MIME-Version: 1.0&#012;Content-Type: text/html; charset="iso-8859-1"&#012;Content-Transfer-Encoding: quoted-printable&#012;Content-Length: 3634&#012; &#012;Irregular Credit Card Activity&#012; &#012;Account:  Capital One&reg; credit card&#012;Date:  11/28/2008&#012; &#012;We detected irregular activity on your Capital One&reg; credit card on 11/28/2008. For your protection, you must verify this activity before you can continue using your card.&#012; &#012;Please call us immediately at 1-800-523-8103 or collect using the number listed on the back of your card. We will review the activity on your account with you and upon verification, we will remove any restrictions placed on your account.&#012; &#012; &#012; &#012;Important Information from Capital One&#012; &#012;Contact Us | Privacy&#012; &#012;This e-mail was sent to you and contains information directly related to your account with us, other services to which you have subscribed, and/or any application you may have submitted.&#012; &#012;The site may be unavailable during normal weekly maintenance or due to unforeseen circumstances.&#012; &#012;Capital One and its service providers are committed to protecting your privacy and ask you not to send sensitive account information through e-mail. If you are not a Capital One customer and believe you received this message in error, please notify us by responding to this e-mail.&#012; &#012;&copy;2008 Capital One. Capital One is a federally registered service mark. All rights reserved. 15000 Capital One Drive, Attn: 12038-0111, Richmond, Virginia 23238. To contact us by mail, please use the following address: Capital One, PO Box 30285, Salt Lake City, Utah 84130-0285.&#012; &#012;09860 023 001&#012;</textarea><!--end code block--><br>The attached logo is the one the phisher used. They left off "what's in your wallet?", which normally is positioned beginning right below the 'One' part of the name.<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21495743?c=1374431&ret=L2ZvcnVtL3IyMDA1OTg1My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="31549 bytes" WIDTH=600 HEIGHT=108 SRC="/r0/download/1374431.thumb600~3ac4f4080738c579fb0de91bfac59ca5/capital_one_logo.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21495743</guid>
<pubDate>Fri, 28 Nov 2008 04:36:53 EDT</pubDate>
</item>

<item>
<title>877-214-0565 - Community Financial Members Federal Credit Union</title>
<link>http://www.dslreports.com/forum/remark,21450377</link>
<description><![CDATA[<A HREF="/useremail/u/178056"><b>DC DSL</b></A> : The message:  <div class="bquote">ADVISORY:</span>&nbsp;Some members and non-members of Community Financial Members Federal Credit Union have received fraudulent emails. This email was NOT issued by Community Financial Members Federal Credit Union, and should be deleted.  Do not follow the instructions in the email. Do not click the link. </b><b> For security reasons we have deactivated your debit card.  Please call our toll-free hotline at (877) 214-0565 to activate your debit card</a>.<br></div></b><br><br>Headers:<br><br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;support@cfcu.org&gt;&#012;Received: from dukecmfep05.coxmail.com &#91;68.99.120.40&#93; by mail.rueckgauer.com with SMTP;&#012;   Tue, 18 Nov 2008 15:46:44 -0500&#012;Received: from User (&#91;24.248.209.212&#93;) by dukecmmtar02.coxmail.com&#012;          (InterMail vM.6.01.06.05 201-2131-130-106-20070212) with SMTP&#012;          id &lt;20081118194108.LMXS4924.dukecmmtar02.coxmail.com@User&gt;;&#012;          Tue, 18 Nov 2008 14:41:08 -0500&#012;From: "Community Financial Members Federal Credit Union"&lt;support@cfcu.org&gt;&#012;Subject: Contact Us!&#012;Date: Tue, 18 Nov 2008 13:40:56 -0600&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Message-Id: &lt;20081118194108.LMXS4924.dukecmmtar02.coxmail.com@User&gt;&#012;X-Rcpt-To: &lt;xxxx@rueckgauer.com&gt;&#012;X-SmarterMail-Spam: SPF_None&#012;</textarea><!--end code block--><br>It's so touching how much they care for "members and non-members" alike, and have deactivated my debit card for me! <br><br>Frickin morons...they couldn't even send well-formed HTML!<br><br><small>--<br><i>There is no giant fur-bearing trout.</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21450377</guid>
<pubDate>Wed, 19 Nov 2008 07:03:47 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21374827</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Resource bank.  Phone number is 815-981-4765<br><br><textarea name="code" class="text" cols=50 rows=10>Return-Path: accounts@resourcebank.com&#012;Delivery-Date: Tue, 04 Nov 2008 07:57:29 -0600&#012;Received: from mail.nelsonmazda.com (mail.nelsonmazda.com &#91;68.99.76.194&#93;)&#012;        by mp.cs.niu.edu (8.14.3/8.14.3) with ESMTP id mA4DvN65018274&#012;        for &lt;munged@cs.niu.edu&gt;; Tue, 4 Nov 2008 07:57:28 -0600 (CST)&#012;Received: from User (&#91;142.176.87.114&#93;) by mail.nelsonmazda.com with Microsoft SMTPSVC(6.0.3790.3959);&#012;         Tue, 4 Nov 2008 08:01:57 -0600&#012;Reply-To: &lt;do-not-reply@resourcebank.com&gt;&#012;From: "Resource Bank"&lt;accounts@resourcebank.com&gt;&#012;Subject: Notice&#012;Date: Tue, 4 Nov 2008 09:56:07 -0400&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;NAGMAILZkfzDskqC5Et000000cd@mail.nelsonmazda.com&gt;&#012;X-OriginalArrivalTime: 04 Nov 2008 14:01:57.0348 (UTC) FILETIME=&#91;E6615240:01C93E85&#93;&#012; &#012;&lt;html&gt;&#012; &#012;&lt;head&gt;&#012;&lt;meta http-equiv="Content-Language" content="en-gb"&gt;&#012;&lt;meta http-equiv="Content-Type" content="text/html; charset=windows-1252"&gt;&#012;&lt;title&gt;Resource Bank&lt;/title&gt;&#012;&lt;/head&gt;&#012; &#012;&lt;body&gt;&#012; &#012;&lt;font size="2" face="Arial, Helvetica, sans-serif"&gt;&#012;&lt;p&gt;&amp;nbsp; Dear Customer, &lt;/p&gt;&#012;&lt;p&gt;&lt;b&gt;&lt;font color="#000000"&gt;&amp;nbsp; Resource Bank &lt;/font&gt;&lt;/b&gt;&#012;temporarily suspended your account.&lt;br&gt;&#012;&lt;b&gt;&lt;font color="#000000"&gt;&amp;nbsp;&amp;nbsp;Reason:&lt;/font&gt;&lt;/b&gt; Security Issues.&lt;br&gt;&#012;&amp;nbsp;&amp;nbsp;We need you to complete an account update so we can unlock your account.&lt;br&gt;&#012;&amp;nbsp;&lt;/p&gt;&#012;&lt;p&gt;&amp;nbsp; &lt;b&gt;To start the update &#012;process &lt;/b&gt;&#012;&lt;/font&gt;&lt;b&gt;&lt;font face="Arial, Helvetica, sans-serif" size="2"&gt;call at the &#012;following number : 815-981-4765&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;b&gt;&lt;font face="Arial, Helvetica, sans-serif" size="2"&gt;&amp;nbsp; &lt;/font&gt;&lt;/b&gt;&#012;&lt;font size="2" face="Arial, Helvetica, sans-serif"&gt;&#012;&lt;br&gt;&#012;&amp;nbsp;&amp;nbsp;The information provided will be treated in confidence and stored in our &#012;secure database.&lt;br&gt;&#012;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&#012;&lt;div class="copyright" align="left"&gt;&#012;        &lt;font size="1" color="#000000" face="Arial, Helvetica, sans-serif"&gt;&amp;nbsp;&amp;nbsp; Copyright &lt;A9&gt; Resource Bank. All Rights Reserved&lt;/font&gt;&lt;/div&gt;&#012; &#012;&lt;/body&gt;&#012; &#012;&lt;/html&gt;&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.3</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21374827</guid>
<pubDate>Tue, 04 Nov 2008 13:55:27 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21269464</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : One from Uniter Heritage Credit Union:<br><br><textarea name="code" class="text" cols=50 rows=10> Return-Path:     &lt;service@uhcu.org&gt;&#012;Authentication-Results: mta435.mail.mud.yahoo.com from=uhcu.org; domainkeys=neutral (no sig)&#012;Received: from 194.116.199.143 (EHLO thb-mta-05.emailfiltering.com) (194.116.199.143) by mta435.mail.mud.yahoo.com with SMTP; Wed, 15 Oct 2008 03:34:41 -0700&#012;Received: from host217-41-113-124.in-addr.btopenworld.com (&#91;217.41.113.124&#93;) by thb-mta-05.emailfiltering.com with emfmta (version 3.6.5.44.1.r-3.2.3-libc2.3.2) vanilla id 3044468324 ; Wed, 15 Oct 2008 11:34:40 +0100&#012;Received: from User (&#91;68.191.184.90&#93;) by mail.bbs.eu.com with Microsoft SMTPSVC(6.0.3790.3959); Wed, 15 Oct 2008 11:33:10 +0100&#012;Reply-To: &lt;no-reply@uhcu.org&gt;&#012;From: &#012;"United Heritage C.U"&lt;service@uhcu.org&gt;  &#012; &#012;Subject: Important Member Service Information !&#012;Date: Wed, 15 Oct 2008 05:34:39 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Bcc: &#012;Return-Path: service@uhcu.org&#012;Message-ID: &lt;BBS-SVR01R4T3XJVVfA00001c3e@mail.bbs.eu.com&gt;&#012;Content-Length: 735&#012; &#012;Dear Member:&#012; &#012;According to our clients needs United Heritage Credit Union is currently launching a new&#012;security system that will improve the level of member service we can provide.&#012; &#012;We strongly urge that all our members need to update their credit card within&#012;the next 48 hours, so we can add them to our new database.&#012; &#012;To start the update process call us now on our service number : +1(818) 824 4009&#012; &#012;Sorry for any inconvenience this may cause!&#012; &#012;Sincerely,&#012;Jenny Laudadio&#012;Marketing director, United Heritage Credit Union.&#012; &#012;---------------------------------------------------------------------------------- --&#012;Scanned by BBS MessageAngel for viruses and unwanted content.&#012;Powered by emailsystems. Visit www.bbs.eu.com/messageangel&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21269464</guid>
<pubDate>Wed, 15 Oct 2008 07:12:24 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21267657</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Two more from ANB Texas, with a different phone number:<br><br><textarea name="code" class="text" cols=50 rows=10>  Return-Path:     &lt;suspended@anbtx.com&gt;&#012;Authentication-Results: mta244.mail.re2.yahoo.com from=anbtx.com; domainkeys=neutral (no sig)&#012;Received: from 216.126.204.132 (EHLO mail.acninc.net) (216.126.204.132) by mta244.mail.re2.yahoo.com with SMTP; Tue, 14 Oct 2008 15:02:07 -0700&#012;Received: from User &#91;208.69.57.85&#93; by mail.acninc.net with ESMTP (SMTPD32-8.15) id A4F9581009C; Tue, 14 Oct 2008 14:45:45 -0600&#012;Reply-To: &lt;suspended@anbtx.com&gt;&#012;From: &#012;"American National Bank of Texas"&lt;suspended@anbtx.com&gt;  &#012; &#012;Subject: Important Member Service Information !&#012;Date: Tue, 14 Oct 2008 16:45:43 -0400&#012;MIME-Version: 1.0&#012;Content-Type: text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Message-Id: &lt;200810141445360.SM01716@User&gt;&#012;Content-Length: 688&#012; &#012;Dear Customer,&#012; &#012;In our terms and contidions you have agreed to state that your&#012;account must always be under your control or those you designate&#012;at all times. We have noticed some activity related to your account that&#012;indicates that order parties may have tried gaining access or control of your&#012;information in your account.&#012; &#012;Therefore, to prevent unauthorized access to your American National Bank of Texas&#012;Internet Banking account,you are limited to five failed login attempts in&#012;a 24-hour period. You have exceeded this number of attempts.*&#012; &#012;To reactivate your debit card , please call: +1(804-684-8586)&#012; &#012;Copyright &copy; 2008 American National Bank of Texas. All Rights Reserved.&#012;</textarea><!--end code block--><br>Second message has the same phone number and message body, <br>but different headers:<br><br><textarea name="code" class="text" cols=50 rows=10> Return-Path:     &lt;memberservice@anbtx.com&gt;&#012;Authentication-Results: mta119.mail.re1.yahoo.com from=anbtx.com; domainkeys=neutral (no sig)&#012;Received: from 67.58.160.20 (HELO mail.zitomedia.net) (67.58.160.20) by mta119.mail.re1.yahoo.com with SMTP; Tue, 14 Oct 2008 15:24:52 -0700&#012;Received: (qmail 24961 invoked from network); 14 Oct 2008 22:24:51 -0000&#012;Received: from unknown (HELO User) (lucas@68.191.184.90) by mail.zitomedia.com with SMTP; Tue, 14 Oct 2008 18:24:51 -0400&#012;Reply-To: &lt;no-reply@anbtx.com&gt;&#012;From: &#012;"American National Bank of Texas"&lt;memberservice@anbtx.com&gt;  &#012; &#012;Subject: Important Member Service Information !&#012;Date: Tue, 14 Oct 2008 17:24:51 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Content-Length: 667&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21267657</guid>
<pubDate>Tue, 14 Oct 2008 21:07:26 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21266302</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : American National Bank Of Texas:<br><br><textarea name="code" class="text" cols=50 rows=10> &#012; Return-Path:     &lt;memberservice@anbtx.com&gt;&#012;Authentication-Results: mta230.mail.re4.yahoo.com from=anbtx.com; domainkeys=neutral (no sig)&#012;Received: from 67.79.177.26 (EHLO wsrv1.wiringtech.local) (67.79.177.26) by mta230.mail.re4.yahoo.com with SMTP; Tue, 14 Oct 2008 04:10:11 -0700&#012;Received: from User (&#91;68.191.184.90&#93;) by wsrv1.wiringtech.local with Microsoft SMTPSVC(6.0.3790.3959); Tue, 14 Oct 2008 07:04:42 -0400&#012;Reply-To: &lt;no-reply@anbtx.com&gt;&#012;From: &#012;"American National Bank of Texas"&lt;memberservice@anbtx.com&gt;  &#012; &#012;Subject: Important Notification&#012;Date: Tue, 14 Oct 2008 06:06:31 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Bcc: &#012;Return-Path: memberservice@anbtx.com&#012;Message-ID: &lt;WSRV1zmtlefFc8gc4aR00004b9c@wsrv1.wiringtech.local&gt;&#012;Content-Length: 670&#012; &#012;In our terms and contidions you have agreed to state that your&#012;account must always be under your control or those you designate&#012;at all times. We have noticed some activity related to your account that&#012;indicates that order parties may have tried gaining access or control of your&#012;information in your account.&#012; &#012;Therefore, to prevent unauthorized access to your American National Bank of Texas&#012;Internet Banking account,you are limited to five failed login attempts in&#012;a 24-hour period. You have exceeded this number of attempts.*&#012; &#012;To reactivate your debit card , please call: +1(805-617-4170)&#012; &#012;Copyright &copy; 2008  American National Bank of Texas. All rights reserved.&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21266302</guid>
<pubDate>Tue, 14 Oct 2008 17:31:47 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,21224005</link>
<description><![CDATA[<A HREF="/useremail/u/708743"><b>Lizz</b></A> : <textarea name="code" class="text" cols=50 rows=10>From Merchants National Bank Mon Oct 6 11:00:37 2008&#012;Return-Path: &lt;info@merchantsnat.com&gt;&#012;Authentication-Results: mta102.sbc.mail.mud.yahoo.com from=merchantsnat.com; domainkeys=neutral (no sig)&#012;Received: from 72.242.21.146 (EHLO flpi119.prodigy.net) (207.115.20.159) by mta102.sbc.mail.mud.yahoo.com with SMTP; Mon, 06 Oct 2008 11:13:20 -0700&#012;Received: from russellmassey.com (server.russellmassey.com &#91;72.242.21.146&#93;) by flpi119.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m96IDFL3030348 for &lt;xxxxx@pacbell.net&gt;; Mon, 6 Oct 2008 11:13:19 -0700&#012;Received: from User (&#91;68.213.58.58&#93;) by russellmassey.com with Microsoft SMTPSVC(6.0.3790.1830); Mon, 6 Oct 2008 14:00:37 -0400&#012;From: &#012;"Merchants National Bank"&lt;info@merchantsnat.com&gt;  &#012;Add sender to Contacts&#012;Subject: MNB - Fraud Alert&#012;Date: Mon, 6 Oct 2008 13:00:37 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Bcc: &#012;Message-ID: &lt;SERVERYYclEohn9Nhkr00005660@russellmassey.com&gt;&#012;Content-Length: 876&#012;Compact Headers&#012; &#012;ADVISORY: Some members and non-members of Merchants National Bank have received fraudulent emails.&#012; &#012;This email was NOT issued by Merchants National Bank, and should be deleted.&#012; &#012;Do not follow the instructions in the email. Do not click the link.&#012; &#012;For security reasons we have deactivated your debit card.&#012; &#012;Please contact us at (888) 425-2294 to activate your debit card.&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21224005</guid>
<pubDate>Mon, 06 Oct 2008 15:41:31 EDT</pubDate>
</item>

<item>
<title>Salin Bank</title>
<link>http://www.dslreports.com/forum/remark,21163981</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : The Salin Bank <A HREF="http://www.dslreports.com/phishtrack?pid=31431&urls=1">phish #31431</a> is really a voice/telephone vish for 1-800-681-2713.<br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21163981</guid>
<pubDate>Wed, 24 Sep 2008 21:28:53 EDT</pubDate>
</item>

<item>
<title>Farmers State Bank</title>
<link>http://www.dslreports.com/forum/remark,21083973</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Submitted <A HREF="http://www.dslreports.com/phishtrack?pid=31133&urls=1">phish #31133</a> is really a voice/telephone vish for phone number (888) 687-5642.<br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21083973</guid>
<pubDate>Tue, 09 Sep 2008 18:08:45 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20961257</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Not a problem.<br><br>This thread is mainly for reporting specific instances.  So discussing the phenomenon in a different thread is fine.<br><br>I'll add a link to your other thread:<br>&raquo;<A HREF="/forum/r20960677-Criminals-have-now-gone-vishing">Criminals have now gone 'vishing'</A><br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20961257</guid>
<pubDate>Sat, 16 Aug 2008 18:31:16 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20960694</link>
<description><![CDATA[<A HREF="/useremail/u/151802"><b>jaykaykay</b></A> : Ooops.  I guess I am a bit late!  I just posted a thread about this in the Security Forum.   :(  Oh well.  The more that hear about it, the better.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20960694</guid>
<pubDate>Sat, 16 Aug 2008 15:53:51 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20807798</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : One from WAMU:<br><textarea name="code" class="text" cols=50 rows=10>From: "WAMU" &lt;office@wamu.com&gt;&#012; &#012;To: undisclosed-recipients&#012; &#012; Return-Path:     &lt;office@wamu.com&gt;&#012;Authentication-Results: mta289.mail.re2.yahoo.com from=wamu.com; domainkeys=neutral (no sig)&#012;Received: from 70.158.128.6 (EHLO POP.brmemc.net) (70.158.128.6) by mta289.mail.re2.yahoo.com with SMTP; Wed, 16 Jul 2008 22:48:25 -0700&#012;Received: from User (unverified &#91;141.164.8.38&#93;) by POP.brmemc.net (Vircom SMTPRS 4.5.654.13) with ESMTP id &lt;B0187023259@POP.brmemc.net&gt;; Wed, 16 Jul 2008 13:51:49 -0400&#012;Reply-To: &lt;do-not-reply@wamu.com&gt;&#012;From: &#012;"WAMU"&lt;office@wamu.com&gt;  &#012;Add sender to Contacts&#012;Subject: Urgent Notification&#012;Date: Wed, 16 Jul 2008 12:50:52 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Content-Length: 385&#012;</textarea><!--end code block--><br>This part of the message is invisible. I found it by<br>checking the page source:<br><br>"To activate your account please call urgent at 713-481-1635."<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20807798</guid>
<pubDate>Thu, 17 Jul 2008 17:48:02 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20565840</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : A Point Bank vish that arrived today:<br><br><textarea name="code" class="text" cols=50 rows=10> Return-Path:     &lt;info@pointbank.com&gt;&#012;Authentication-Results: mta156.mail.re1.yahoo.com from=pointbank.com; domainkeys=neutral (no sig)&#012;Received: from 99.129.23.5 (EHLO web.mavcomp.com) (99.129.23.5) by mta156.mail.re1.yahoo.com with SMTP; Fri, 30 May 2008 05:51:48 -0700&#012;Received: from User (&#91;68.213.182.38&#93;) by web.mavcomp.com with Microsoft SMTPSVC(6.0.3790.3959); Fri, 30 May 2008 07:51:04 -0500&#012;From: &#012;"PointBank"&lt;info@pointbank.com&gt;  &#012;Add sender to Contacts&#012;Subject: Contact Us&#012;Date: Fri, 30 May 2008 08:03:10 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;Bcc: &#012;Return-Path: info@pointbank.com&#012;Message-ID: &lt;WEBNXGjjuH9z7frxNkm00000121@web.mavcomp.com&gt;&#012;Content-Length: 833&#012;</textarea><!--end code block--><br>Dear CardHolder,<br>Your debit card has open issues<br>Contact us immediately for assistance.<br>Toll Free Line: 1-(877)- &#9;596-6749<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20565840</guid>
<pubDate>Fri, 30 May 2008 19:31:55 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20559745</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : AA/Citibank Vish (<strike>also submitted to Phishtracker</strike> - see below) - posted<br> here because there's also a telephone number.<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.133; Thu, 29 May 2008 15:13:17 -0700&#012;X-YahooFilteredBulk:71.165.227.158&#012;X-Originating-IP:&#91;71.165.227.158&#93;&#012;Return-Path:&lt;american.airlines@aa.com&gt;&#012;Authentication-Results:mta361.mail.mud.yahoo.com from=aa.com; domainkeys=neutral (no sig)&#012;Received:from 71.165.227.158 (EHLO rlmurawski.com) (71.165.227.158) by mta361.mail.mud.yahoo.com with SMTP; Thu, 29 May 2008 15:13:17 -0700&#012;Received:from aa.com (&#91;71.170.119.34&#93;) by rlmurawski.com with Microsoft SMTPSVC(6.0.3790.211); Thu, 29 May 2008 15:05:34 -0700&#012;Reply-to:American.Airlines@aas.com&#012;From:American.Airlines@aa.com  &#012;To:x@yahoo.com&#012;Subject:Citi / AAdvantage MasterCard (Alerting Service)&#012;Date:29 May 2008 16:55:03 -0500&#012;Message-ID:&lt;20080529165503.DE8515CF9B566BEF@aa.com&gt;&#012;MIME-Version:1.0&#012;Content-Type:text/html; charset="iso-8859-1"&#012;Content-Transfer-Encoding:quoted-printable&#012;Return-Path:American.Airlines@aa.com&#012;X-OriginalArrivalTime:29 May 2008 22:05:34.0265 (UTC) FILETIME=&#91;1E213A90:01C8C1D8&#93;&#012;Content-Length:2060&#012;</textarea><!--end code block--><br>Edit: This did not successfully get parsed by Phishtracker. The<br>link first leads to hxxp://mail.mrfood.com/logo_servis.gif, but then<br>redirects to hxxp://mail.opt-al.com/www.citicards.com/cards/wv/copy.doscreenID1214.htm<br><br>(The second link has already been reported to Google as a<br>web forgery, and is still active as of the time of this post.)<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small><br><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20559745?c=1312357&ret=L2ZvcnVtL3IyMDA1OTg1My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="93419 bytes" WIDTH=600 HEIGHT=183 SRC="/r0/download/1312357.thumb600~e104541381ed6db68b3a82c396672207/citibak_AA_Vish-Phish.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20559745</guid>
<pubDate>Thu, 29 May 2008 18:33:38 EDT</pubDate>
</item>

<item>
<title>EPPIcard vish 772-924-0104</title>
<link>http://www.dslreports.com/forum/remark,20517200</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Email message text:<br><pre><br>Dear EPPICard member,<br> <br>We recently reviewed your account, and suspect that your EPPICard account may<br>have been accessed from an unauthorized computer. This may be due to changes<br>in your IP address or location. Protecting the security of your account and <br>the EPPICard network is our primary concern. Therefor, we have temporarily<br>blocked your banking account.<br> <br>To unlock your account call our toll free number: 772-924-0104<br> <br>To protect your account please follow the instructions below:<br>    - NEVER SHARE YOUR PASSWORD with other persons<br>    - ALWAYS LOG OFF after using your online account<br>    - NEVER access EPPICard`s website by clicking on a link provided in an e-mail<br> <br>We apologize for any inconvenience this may cause, and appreciate your<br>assistance in helping us maintaining the integrity of the entire EPPICard System.<br> <br>Thank you,<br>EPPICard Security Advisor.<br> <br>Copyright 2008 EPPICard - The safe and secure way to acces your payments.<br></pre><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;notice@eppicard.com&gt;&#012;Received: from NYSWEB.COM (&#91;64.65.53.19&#93;)&#012;        by mp.cs.niu.edu (8.14.3/8.14.3) with ESMTP id m4LFYOsj010468&#012;        (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT)&#012;        for &lt;x@x&gt;; Wed, 21 May 2008 10:34:29 -0500 (CDT)&#012;Message-Id: &lt;200805211534.m4LFYOsj010468@mp.cs.niu.edu&gt;&#012;Received: (qmail 19262 invoked from network); 21 May 2008 10:52:33 -0400&#012;Received: from tutlani.com (HELO User) (207.210.93.11)&#012;  by nacentertainment.com with SMTP; 21 May 2008 10:52:33 -0400&#012;Reply-To: &lt;do-not-reply@eppicard.com&gt;&#012;From: "EPPICard"&lt;notice@eppicard.com&gt;&#012;To: x@x, x@x, x@x,&#012;        x@x, x@x, x@x,&#012;        x@x, x@x,&#012;        x@x, x@x&#012;Subject: Urgent Notification!&#012;Date: Wed, 21 May 2008 10:52:33 -0400&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.14</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20517200</guid>
<pubDate>Wed, 21 May 2008 12:07:33 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20482931</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <textarea name="code" class="text" cols=50 rows=10>Delivered-To: no.job.needed@gmail.com&#012;Received: by 10.142.155.4 with SMTP id c4cs16970wfe;&#012;        Wed, 14 May 2008 08:55:10 -0700 (PDT)&#012;Received: by 10.35.28.12 with SMTP id f12mr2105619pyj.45.1210780510055;&#012;        Wed, 14 May 2008 08:55:10 -0700 (PDT)&#012;Return-Path: &lt;test@telus.net&gt;&#012;Received: from defout.telus.net (defout.telus.net &#91;199.185.220.240&#93;)&#012;        by mx.google.com with ESMTP id f24si4254145pyh.26.2008.05.14.08.55.09;&#012;        Wed, 14 May 2008 08:55:09 -0700 (PDT)&#012;Received-SPF: pass (google.com: domain of test@telus.net designates 199.185.220.240 as permitted sender) client-ip=199.185.220.240;&#012;Authentication-Results: mx.google.com; spf=pass (google.com: domain of test@telus.net designates 199.185.220.240 as permitted sender) smtp.mail=test@telus.net&#012;Received: from priv-edtnaa16.telusplanet.net (&#91;206.116.132.29&#93;)&#012;          by priv-edtnes25.telusplanet.net&#012;          (InterMail vM.7.08.02.02 201-2186-121-104-20070414) with ESMTP&#012;          id &lt;20080514155450.QWUB16573.priv-edtnes25.telusplanet.net@priv-edtnaa16.telusplanet.net&gt;;&#012;          Wed, 14 May 2008 09:54:50 -0600&#012;Received: from User (d206-116-132-29.bchsia.telus.net &#91;206.116.132.29&#93;)&#012;by priv-edtnaa16.telusplanet.net (BorderWare MXtreme Infinity Mail Firewall) with SMTP&#012;id 83448V1ULV; Wed, 14 May 2008 09:55:09 -0600 (MDT)&#012;From: "test" &lt;test@telus.net&gt;&#012;Subject: fdfdfdfdfd55&#012;Date: Wed, 14 May 2008 08:55:10 -0700&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Message-Id: &lt;20080514155509.83448V1ULV@priv-edtnaa16.telusplanet.net&gt;&#012;To: undisclosed-recipients:;&#012; &#012;Dear MasterCard customer, &#012; &#012;We regret to inform you that we have received numerous fraudulent emails which ask for personal&#012;account information. The emails contained links to fraudulent pages that looked legit. &#012; &#012;Please remember that we will never ask for personal account information via email or web pages. &#012; &#012;Because of this we are launching a new security system to make MasterCard accounts more secure&#012;and safe. To take advatage of our new consumer Identity Theft Protection Program we had to&#012;deactivate access to your card account. &#012; &#012;To activate it please call us immediately at (615) 348-6681&#012; &#012;Activation is free of charge and will take place as soon as you finish the activation process. &#012; &#012;? 1994-2008 MasterCard. All rights reserved.&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20482931</guid>
<pubDate>Wed, 14 May 2008 18:07:01 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20421194</link>
<description><![CDATA[<A HREF="/useremail/u/708743"><b>Lizz</b></A> : So you all don't think I'm nuts, the "simply sign on" is a link to a phishing site which DOES show in phishtracker.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20421194</guid>
<pubDate>Fri, 02 May 2008 12:46:00 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20421158</link>
<description><![CDATA[<A HREF="/useremail/u/708743"><b>Lizz</b></A> : A vish AND a phish, all in one! (and with all the spamcatcher info in the header, ATT/Yahoo still left it in my inbox, not the bulk  :mad:)<br><br>From Bank of America Fri May 2 06:59:39 2008<br>X-Apparently-To:&#9;XXX@pacbell.net via 209.191.85.223; Fri, 02 May 2008 07:01:12 -0700<br>X-Originating-IP:&#9;[64.97.155.27]<br>Return-Path:&#9;<br>Authentication-Results:&#9;mta136.sbc.mail.re3.yahoo.com from=alerts.bankofamerica.com; domainkeys=neutral (no sig)<br>Received:&#9;from 207.115.20.65 (EHLO flpi096.prodigy.net) (207.115.20.65) by mta136.sbc.mail.re3.yahoo.com with SMTP; Fri, 02 May 2008 07:01:12 -0700<br>X-Originating-IP:&#9;[64.97.155.27]<br>Received:&#9;from sc2.he.tucows.com (smtpout2027.sc2.he.tucows.com [64.97.155.27]) by flpi096.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m42E1Bpw001455 for ; Fri, 2 May 2008 07:01:11 -0700<br>Received:&#9;from sc2-out04.emaildefenseservice.com (64.97.201.174) by sc2.he.tucows.com (7.3.127) id 48188F54000E71E6; Fri, 2 May 2008 13:59:46 +0000<br>Message-ID:&#9; (added by postmaster@globo.com)<br>X-SpamScore:&#9;96<br>X-Spamcatcher-Summary:&#9;96,15,0,9ea1071f6304b62f,0631c5bc6dd70dd7,alert@alerts.bankofamerica.com,-,<br>X-Spamcatcher-Explanation:&#9;(33%) BODY: mail is from Bank of America but doesn't contain any Bank of America URLS;(27%) BODY: likely phishing content;(13%) X-MAILER: mail headers not consistent with User Agent "Outlook";(13%) HTML: HTML code not consistent with User Agent "Outlook";(7%) BODY: text/html email has no html tag;(7%) BODY: content type is strictly "text/html";<br>Received:&#9;from User (unknown [41.223.251.88]) (Authenticated sender: atm05@globo.com) by sc2-out04.emaildefenseservice.com (Postfix) with ESMTP; Fri, 2 May 2008 13:59:19 +0000 (UTC)<br>From:&#9;"Bank of America"   Add to Address BookAdd to Address Book  Add Mobile Alert<br>Subject:&#9;Online Banking Verification<br>Date:&#9;Fri, 2 May 2008 14:59:39 +0100<br>MIME-Version:&#9;1.0<br>Content-Type:&#9;text/html; charset="Windows-1251"<br>Content-Transfer-Encoding:&#9;7bit<br>X-Priority:&#9;3<br>X-MSMail-Priority:&#9;Normal<br>X-Mailer:&#9;Microsoft Outlook Express 6.00.2600.0000<br>X-MimeOLE:&#9;Produced By Microsoft MimeOLE V6.00.2600.0000<br>Content-Length:&#9;2867<br><br>Dear Valued Bank of America Online Customer:<br><br>IMPORTANT: Your online account information must be confirmed and verified to ensure uninterrupted service.<br><br>To enhance the level of service you receive with Bank of America Online Services, we regularly review the online banking accounts. We have issued this warning message to inform you that we have detected a slight error in your account information. This might be due to either of the following reasons:.<br>bullet&#9;A recent change in your personal information ( i.e.change of address).<br>bullet&#9;Submiting invalid information during the initial sign up process.<br>bullet&#9;An inability to accurately verify your selected option of payment due to an internal error within our processors.<br><br>As a result, we require you to confirm and verify your account information By Clicking Here and completing the confirmation process.<br><br>Note<br>However, failure to confirm and verify your account information will result in temporarily account suspension. Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience.<br>If you have any question regarding this, please call us at 888-692-5949, 24 hours a day, seven days a week. or simply Sign In to Online Banking and click on "Help".<br><br>Thank you for banking at Bank of America. We look forward to serving your financial needs for many years to come.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20421158</guid>
<pubDate>Fri, 02 May 2008 12:40:30 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20381463</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Amarillo National Bank vish:<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.133; Thu, 24 Apr 2008 07:31:59 -0700&#012;X-Originating-IP:&#91;65.104.246.242&#93;&#012;Return-Path:&lt;customer_service@anb.com&gt;&#012;Authentication-Results:mta101.mail.re3.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received:from 65.104.246.242 (EHLO mail.kwp.org) (65.104.246.242) by mta101.mail.re3.yahoo.com with SMTP; Thu, 24 Apr 2008 07:31:57 -0700&#012;Received:from (&#91;&#93;) by mail.kwp.org (Merak 4.2.3) with SMTP id KPJ36965 for &lt;x@yahoo.com&gt;; Thu, 24 Apr 2008 09:31:56 -0500&#012;From:Amarillo@  Add Mobile Alert ,&#012;To:x@yahoo.com&#012;Subject:ANB Secure Email Notification&#012;Date:24 Apr 2008 09:29:41 -0500&#012;Message-ID:&lt;20080424092941.2195C1DDD96B4626@from.header.has.no.domain&gt;&#012;MIME-Version:1.0&#012;Content-Type:text/html; charset="iso-8859-1"&#012;Content-Transfer-Encoding:quoted-printable&#012;Content-Length:1653&#012;</textarea><!--end code block--><br>URLs for both the forged ANB and Verisign logos in the<br>body of the phish (posted as JPG as it is all html)<br><br>ANB: hxxp://jeannemcallister.com/logo.gif<br>Verisign: hxxp://jeannemcallister.com/logo-verisign.gif<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small><br><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20381463?c=1300797&ret=L2ZvcnVtL3IyMDA1OTg1My54bWw%3D"><IMG class="apic" BORDER=0 TITLE="100027 bytes" WIDTH=600 HEIGHT=495 SRC="/r0/download/1300797.thumb600~b60966253b70d4e1715ec20d8403a53a/anb_phish.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20381463</guid>
<pubDate>Thu, 24 Apr 2008 17:56:42 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20375706</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Another Franklin Bank one, same phone number as before:<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.138; Tue, 22 Apr 2008 15:07:58 -0700&#012;X-YahooFilteredBulk:74.52.162.130&#012;X-Originating-IP:&#91;74.52.162.130&#93;&#012;Return-Path:&lt;franklinbank@mesanetworks.net&gt;&#012;Authentication-Results:mta209.mail.re4.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received:from 74.52.162.130 (EHLO mx11.mesanetworks.net) (74.52.162.130) by mta209.mail.re4.yahoo.com with SMTP; Tue, 22 Apr 2008 15:07:56 -0700&#012;Received:(qmail 9582 invoked by uid 509); 22 Apr 2008 11:26:37 -0600&#012;Received:from 72.19.158.63 by mx11.mesanetworks.net (envelope-from &lt;franklinbank@mesanetworks.net&gt;, uid 508) with qmail-scanner-1.25-st-qms (clamdscan: 0.87/2133. spamassassin: 3.0.6. perlscan: 1.25-st-qms. Clear:RC:1(72.19.158.63):. Processed in 0.525889 secs); 22 Apr 2008 17:26:37 -0000&#012;X-Antivirus-MESANETWORKS-Mail-From:franklinbank@mesanetworks.net via mx11.mesanetworks.net&#012;X-Antivirus-MESANETWORKS:1.25-st-qms (Clear:RC:1(72.19.158.63):. Processed in 0.525889 secs Process 9540)&#012;Received:from 72-19-158-63.static.mesanetworks.net (HELO User) (72.19.158.63) by mx11.mesanetworks.net with SMTP; 22 Apr 2008 11:26:36 -0600&#012;Reply-to:&lt;noreply@mesanetworks.net&gt;&#012;From:"Franklin Bank" &lt;franklinbank@mesanetworks.net&gt;  Add Mobile Alert&#012;Subject:SECURITY ALERT!&#012;Date:Tue, 22 Apr 2008 11:26:31 -0600&#012;MIME-Version:1.0&#012;Content-Type:text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding:7bit&#012;X-Priority:3&#012;X-MSMail-Priority:Normal&#012;X-Mailer:Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000&#012;X-Antivirus-MESANETWORKS-Message-ID:&lt;120888519710709540@mx11.mesanetworks.net&gt;&#012;Content-Length:1584&#012; &#012;  Dear Franklin Bank Customer,&#012; &#012;  Franklin Bank is aware of new phishing e-mails that are circulating.&#012;  These e-mails request consumers to click a link due to a compromise of a &#012;  credit card account. You should not respond to this message.&#012; &#012;  Due to unusual levels of fraud we have had to suspend any future authorizations&#012;  being conducted with your Visa ATM/Check Card.&#012; &#012;  For your security we have deactivate your card.&#012; &#012;  How to activate/re-activate your card ?&#012; &#012;  Call our Card Department: (866) 797-5643&#012; &#012; &#012; &#012;  Our automated system allows you to quickly activate your card.&#012; &#012;  We apologize for any inconvenience this may cause.&#012; &#012;  Corporate Office&#012;  9800 Richmond, Suite 680&#012;  Houston, TX 77042&#012; &#012;  Copyright &copy; 2006 Franklin Bank. All Rights Reserved.&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20375706</guid>
<pubDate>Wed, 23 Apr 2008 17:36:22 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20364225</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Yet another Franklin Bank one, trying to look legitimate by<br>warning recipients of phishing scams. They're not fooling me.<br><br>The phone number's likely bogus, and the IP address 72.28.171.9 is likely a botnet zombie (it certainly<br>isn't one of Franklin's IPs). The Corporate Office<br>address is real, however.<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.140; Mon, 21 Apr 2008 12:15:14 -0700&#012;X-YahooFilteredBulk:8.10.184.138&#012;X-Originating-IP:&#91;8.10.184.138&#93;&#012;Return-Path:&lt;franklinbank@ddsadsa.com&gt;&#012;Authentication-Results:mta250.mail.re3.yahoo.com from=ddsadsa.com; domainkeys=neutral (no sig)&#012;Received:from 8.10.184.138 (EHLO mail.wghco.com) (8.10.184.138) by mta250.mail.re3.yahoo.com with SMTP; Mon, 21 Apr 2008 12:15:14 -0700&#012;Received:from User (&#91;72.28.171.9&#93;) by mail.wghco.com with Microsoft SMTPSVC(6.0.3790.3959); Mon, 21 Apr 2008 11:49:39 -0700&#012;From:"Franklin Bank" &lt;franklinbank@ddsadsa.com&gt;  Add Mobile Alert&#012;Subject:SECURITY ALERT!&#012;Date:Mon, 21 Apr 2008 14:48:37 -0400&#012;MIME-Version:1.0&#012;Content-Type:text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding:7bit&#012;X-Priority:3&#012;X-MSMail-Priority:Normal&#012;X-Mailer:Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Return-Path:franklinbank@ddsadsa.com&#012;Message-ID:&lt;HENSCHEN7n0swXX1sPt00000677@mail.wghco.com&gt;&#012;X-OriginalArrivalTime:21 Apr 2008 18:49:39.0703 (UTC) FILETIME=&#91;742AE870:01C8A3E0&#93;&#012;X-TM-AS-Product-Ver:SMEX-7.5.0.1243-5.0.1023-15864.001&#012;X-TM-AS-Result:Yes-21.877000-4.000000-31&#012;X-TM-AS-User-Approved-Sender:No&#012;X-TM-AS-User-Blocked-Sender:No&#012;Content-Length:1586&#012; &#012;  Dear Franklin Bank Customer,&#012; &#012;  Franklin Bank is aware of new phishing e-mails that are circulating.&#012;  These e-mails request consumers to click a link due to a compromise of a &#012;  credit card account. You should not respond to this message.&#012; &#012;  Due to unusual levels of fraud we have had to suspend any future authorizations&#012;  being conducted with your Visa ATM/Check Card.&#012; &#012;  For your security we have deactivate your card.&#012; &#012;  How to activate/re-activate your card ?&#012; &#012;  Call our Card Department: (866) 797-5643&#012; &#012; &#012; &#012;  Our automated system allows you to quickly activate your card.&#012; &#012;  We apologize for any inconvenience this may cause.&#012; &#012;  Corporate Office&#012;  9800 Richmond, Suite 680&#012;  Houston, TX 77042&#012; &#012;  Copyright &copy; 2006 Franklin Bank. All Rights Reserved.&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20364225</guid>
<pubDate>Mon, 21 Apr 2008 17:15:16 EDT</pubDate>
</item>

<item>
<title>Lizz_Vish_Archived</title>
<link>http://www.dslreports.com/forum/remark,20345663</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : X-Apparently-To: myemail@pacbell.net via 209.191.85.225; Tue, 15 Apr 2008 10:39:54 -0700   <br>X-Originating-IP:[212.85.249.132]   <br>Return-Path:   <br>Authentication-Results:mta121.sbc.mail.mud.yahoo.com from=franklin.com; domainkeys=neutral (no sig)   <br>Received:from 207.115.36.53 (EHLO nlpi024.prodigy.net) (207.115.36.53) by mta121.sbc.mail.mud.yahoo.com with SMTP; Tue, 15 Apr 2008 10:39:52 -0700   <br>X-Header-Overseas:Mail.from.Overseas.source.212.85.249.132   <br>X-Originating-IP:[212.85.249.132]   <br>Received:from node-2.minx.net.uk (node-2.minx.net.uk [212.85.249.132]) by nlpi024.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m3FHdoDY014536 for ; Tue, 15 Apr 2008 12:39:50 -0500   <br>Received:from [195.82.101.89] (helo=mail.QuantumFittedFurniture.co.uk) by node-2.minx.net.uk with esmtp (Exim 4.60) (envelope-from ) id 1JlpIR-0005rN-Og for myemail@pacbell.net; Tue, 15 Apr 2008 18:50:20 +0100   <br>Received:from User ([192.168.0.250] RDNS failed) by mail.QuantumFittedFurniture.co.uk with Microsoft SMTPSVC(6.0.3790.3959); Tue, 15 Apr 2008 18:29:09 +0100   <br>Reply-to:   <br>From:"Franklin Bank"   Add to Address BookAdd to Address Book  Add Mobile Alert   <br>Subject:Card Deactivation   <br>Date:Tue, 15 Apr 2008 13:39:36 -0400   <br>MIME-Version:1.0   <br>Content-Type:text/plain; charset="Windows-1251"   <br>Content-Transfer-Encoding:7bit   <br>X-Priority:3   <br>X-MSMail-Priority:Normal   <br>X-Mailer:Microsoft Outlook Express 6.00.2600.0000   <br>X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000   <br>Bcc:   <br>Message-ID:   <br>X-OriginalArrivalTime:15 Apr 2008 17:29:10.0078 (UTC) FILETIME=[37021DE0:01C89F1E]   <br>X-MINX-Orig-IP:195.82.101.89   <br>X-Spam-Score:2.9 (++)   <br>X-Spam-Level:++   <br>Content-Length:563   <br>    <br>Card Deactivation   <br>Message from: Customer Service   <br>Date: 04/15/2008   <br>    <br>We detected irregular activity on your ATM/Check Card on 04/15/2008.   <br>For your protection we have had to suspend any future authorizations    <br>being conducted with your card.   <br>    <br>For your security we have deactivate your card.   <br>    <br>How to activate/re-activate your card ?   <br>    <br>You may stop by your branch or call our Activation Center:   <br>    <br>Activation Center: (866) 797-5640   (24 Hour Line)  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20345663</guid>
<pubDate>Wed, 16 Apr 2008 19:38:51 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20340407</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Another Franklin Bank one:<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.135; Tue, 15 Apr 2008 09:09:54 -0700&#012;X-YahooFilteredBulk:64.34.200.180&#012;X-Originating-IP:&#91;64.34.200.180&#93;&#012;Return-Path:&lt;bankfranklin@franklin.com&gt;&#012;Authentication-Results:mta112.mail.re3.yahoo.com from=franklin.com; domainkeys=neutral (no sig)&#012;Received:from 64.34.200.180 (EHLO web420.linux-hosting.com) (64.34.200.180) by mta112.mail.re3.yahoo.com with SMTP; Tue, 15 Apr 2008 09:09:53 -0700&#012;Received:from User (72-28-171-009-dhcp.aik.sc.atlanticbb.net &#91;72.28.171.9&#93;) (authenticated bits=0) by web420.linux-hosting.com (8.13.1/8.13.1) with ESMTP id m3FFmMlk010716; Tue, 15 Apr 2008 21:18:22 +0530&#012;Message-Id:&lt;200804151548.m3FFmMlk010716@web420.linux-hosting.com&gt;&#012;Reply-to:&lt;noreply@franklinsecurity.com&gt;&#012;From:"Franklin Bank" &lt;bankfranklin@franklin.com&gt;  Add Mobile Alert&#012;Subject:Card Deactivation&#012;Date:Tue, 15 Apr 2008 12:01:07 -0400&#012;MIME-Version:1.0&#012;Content-Type:text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding:7bit&#012;X-Priority:3&#012;X-MSMail-Priority:Normal&#012;X-Mailer:Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Content-Length:563&#012; &#012;Card Deactivation&#012;Message from: Customer Service&#012;Date: 04/15/2008&#012; &#012;We detected irregular activity on your ATM/Check Card on 04/15/2008.&#012;For your protection we have had to suspend any future authorizations &#012;being conducted with your card.&#012; &#012;For your security we have deactivate your card.&#012; &#012;How to activate/re-activate your card ?&#012; &#012;You may stop by your branch or call our Activation Center:&#012; &#012;Activation Center: (866) 797-5640   (24 Hour Line) &#012; &#012;Our automated system allows you to quickly activate your card.&#012;We apologize for any inconvenience this may cause.. &#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20340407</guid>
<pubDate>Tue, 15 Apr 2008 21:12:05 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20321069</link>
<description><![CDATA[<A HREF="/useremail/u/178056"><b>DC DSL</b></A> : I got a Franklin.  I called the number.  There's a semi-realistic TRS on it that asks for the card number, PIN, expiration date.<br><br>I put in completely bogus info (like 1234567812345678 for the card number).  After a brief pause, it came back with "card, PIN or expiration are not valid, please reenter."  So, I made up different info.  It took it, said the card is now active and valid worldwide and ended.  <br><br>I called back a few more times.  Sometimes I gave it identical data, others not.  It took it all just the same.<br><br>It seems that it tries to make it seem legit to get someone to reenter the info to make sure they've got a live one.  However, they farkled it and it doesn't catch mismatches.<br><br>This would be great rainy-day fun wasting their time and flooding them with bogus data if it wasn't a toll-free number that captures the number you're calling from regardless of caller id blocking.  (Anyone near a pay phone wanna give it a go and see if they're stupid enough to not have blocked pay station callers?)<br><br>=====<br><br>Return-Path: <br>Received: from mail.im3.com [216.201.16.126] by mail.ultimahosts.com with SMTP;<br>   Fri, 11 Apr 2008 16:25:02 -0400<br>Received: from User (unverified [72.28.171.9]) by cartman.im3.com<br>  (Vircom SMTPRS 4.4.568.66) with ESMTP id ;<br>  Fri, 11 Apr 2008 15:53:41 -0400<br>X-Modus-BlackList: bankfranklin@franklinsecurity.com=OK<br>X-Modus-Audit: FALSE;0;0;0<br>Reply-To: <br>From: "Franklin Bank"<br>Subject: Card Deactivation<br>Date: Fri, 11 Apr 2008 15:53:36 -0400<br>MIME-Version: 1.0<br>Content-Type: text/html;<br>&#9;charset="Windows-1251"<br>Content-Transfer-Encoding: 7bit<br>X-Priority: 3<br>X-MSMail-Priority: Normal<br>X-Mailer: Microsoft Outlook Express 6.00.2600.0000<br>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000<br>X-Rcpt-To: <br>X-SmarterMail-Spam: SPF_None<br><br> <br>    Card Deactivation <br>    Message from: Customer Service<br>    Date: 04/10/2008<br>    We detected irregular activity on your ATM/Check Card on 04/10/2008.<br>    For your protection we have had to suspend any future authorizations being<br>    conducted with your card.<br>    For your security we have deactivate your card.<br>    How to activate/re-activate your card ?<br>    You may stop by your branch or call our Activation Center. <br><br>    Activation Center: (866) 578-0984 (24 Hour Line)<br> <br>    Our automated system allows you to quickly activate your card.<br>    We apologize for any inconvenience this may cause.<br>    Copyright &copy; 2006 Franklin Bank. All Rights Reserved.<br><small>--<br><i>There is no giant fur-bearing trout.</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20321069</guid>
<pubDate>Fri, 11 Apr 2008 23:16:45 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20293000</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : This one apparently from CUNA regarding the Wal-Mart data<br>breach seems to be quite suspicious. It had me fooled for<br>a minute, until I looked more closely at the headers. Nice try.<br><br>As before, the only thing changed is the name in the X-<br>Apparently-To: header:<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.135; Sun, 06 Apr 2008 10:14:58 -0700&#012;X-YahooFilteredBulk:217.40.42.57&#012;X-Originating-IP:&#91;217.40.42.57&#93;&#012;Return-Path:&lt;customerservice@cona.com&gt;&#012;Authentication-Results:mta134.mail.re3.yahoo.com from=; domainkeys=neutral (no sig)&#012;Received:from 217.40.42.57 (EHLO erissrv1.eris.org.uk) (217.40.42.57) by mta134.mail.re3.yahoo.com with SMTP; Sun, 06 Apr 2008 10:14:57 -0700&#012;Received:from cona.com (&#91;74.7.27.50&#93;) by erissrv1.eris.org.uk with Microsoft SMTPSVC(5.0.2195.6713); Sun, 6 Apr 2008 17:36:49 +0100&#012;From:CUNA@  Add Mobile Alert&#012;To:nataleemorse@yahoo.com&#012;Subject:Wal-Mart Stores, Inc. Data Breach Announcment&#012;Date:06 Apr 2008 11:36:39 -0500&#012;Message-ID:&lt;20080406113639.BCE6A283E7E711F5@from.header.has.no.domain&gt;&#012;MIME-Version:1.0&#012;Content-Type:text/html; charset="iso-8859-1"&#012;Content-Transfer-Encoding:quoted-printable&#012;Return-Path:customerservice@cona.com&#012;X-OriginalArrivalTime:06 Apr 2008 16:36:49.0531 (UTC) FILETIME=&#91;6960ECB0:01C89804&#93;&#012;Content-Length:2742&#012; &#012;WAL-MART STORES, INC. DATA BREACH ANNOUNCMENT&#012; &#012;April/06/2008&#012; &#012;CUNA is aware of the recent data breach at Wal-Mart Stores, Inc. and is taking&#012;proactive steps to address the situation. The Customer Security Team at CUNA&#012;is currently gathering information regarding the data breach and will react swiftly&#012;in the best interests of its customers, including the re-issue of compromised&#012;cards if necessary.&#012; &#012;It is important to note that CUNA has effective fraud monitoring systems in&#012;place and is constantly reviewing our accounts for fraudulent and/or suspicious&#012;activity. The security of your account is very important to us.&#012; &#012;Moving forward, we recommend that all CUNA customers review their account&#012;activity on an ongoing basis and report to us any suspicious activity. In addition,&#012;it is recommended that customers activate "Enhanced Card Security" to block &#012; &#012;Please call Customer Care at 1-800-794-9672, to activate (Enhanced Card Security)&#012;for your debit or credit card.&#012; &#012;Due to the extensive news coverage of this event, there have been reports of other&#012;scams. If you receive a phone call or email from someone claiming to be from&#012;Visa, or MasterCard DO NOT provide them with any personal or account information&#012;Please visit http://www.nophishing.org/ for further information regarding fraud.&#012; &#012;Finally, you may continue to use your debit card. Customers who have been affected&#012;by the data breach will be notified, and be given further instructions via postal mail. If&#012;you have immediate questions regarding your account, please contact Customer Care&#012;at 1-800-794-9672, option 1.&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20293000</guid>
<pubDate>Sun, 06 Apr 2008 17:49:16 EDT</pubDate>
</item>

<item>
<title>[Phish] Credit Union 1 vish (ATM card)</title>
<link>http://www.dslreports.com/forum/remark,20270939</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Card Deactivation <br>  Message from: Customer Service<br>  Date: 04/02/2008<br>  We detected irregular activity on your ATM/Check Card on 04/02/2008.<br>  For your protection we have had to suspend any future authorizations<br>  being conducted with your card.<br>  For your security we have deactivate your card.<br>  How to activate/re-activate your card ?<br>  You may stop by your branch or call our Activation Center. <br><br>  Activation Center: (866) 722-3235 (24 Hour Line)<br>  Our automated system allows you to quickly activate your card.<br>  We apologize for any inconvenience this may cause.<br>  Copyright &copy; 2008 Credit Union 1. All Rights Reserved.<br><br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;creditunion1@membersecurity.com&gt;&#012;Received: from delagarzafence.com (2003-sbs.delagarzafence.com &#91;68.91.246.105&#93;)&#012;        by mp.cs.niu.edu (8.14.2/8.14.2) with ESMTP id m32INure009129&#012;        for &lt;munged@cs.niu.edu&gt;; Wed, 2 Apr 2008 13:24:01 -0500 (CDT)&#012;Received: from User (&#91;65.66.160.78&#93;) by delagarzafence.com with Microsoft SMTPSVC(6.0.3790.3959);&#012;         Wed, 2 Apr 2008 11:52:13 -0500&#012;Reply-To: &lt;noreply@membersecurity.com&gt;&#012;From: "Credit Union 1"&lt;creditunion1@membersecurity.com&gt;&#012;Subject: Card Deactivation&#012;Date: Wed, 2 Apr 2008 11:53:00 -0500&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;2003-SBS5W3xNbMrRn00000073e@delagarzafence.com&gt;&#012;X-OriginalArrivalTime: 02 Apr 2008 16:52:13.0280 (UTC) FILETIME=&#91;E652D600:01C894E1&#93;&#012; &#012;&lt;p&gt;&lt;font face="Arial"&gt;&amp;nbsp;&amp;nbsp;&lt;img src="http://boxbownow.com/a/header.gif" width="339" height="92"&gt;&lt;/font&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font face="Arial"&gt; &lt;/font&gt;&lt;font face="Arial"&gt;&amp;nbsp;  &lt;font size="2"&gt;&lt;strong&gt;Card Deactivation &lt;br /&gt;&#012;&lt;/strong&gt;&lt;/font&gt;&lt;/font&gt;&lt;strong&gt;&lt;font size="2" face="Arial"&gt;&amp;nbsp; Message from: Customer Service&lt;br /&gt;&#012;&amp;nbsp; Date: 04/02/2008&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font face="Arial"&gt;&amp;nbsp;&lt;font size="2"&gt; We detected irregular activity on your          ATM/Check Card on 04/02/2008.&lt;br /&gt;&#012;&lt;/font&gt;&lt;/font&gt;&lt;font face="Arial"&gt;&amp;nbsp;&lt;font size="2"&gt; &lt;/font&gt;&lt;/font&gt;&lt;font size="2" face="Arial"&gt;For your protection we have had to suspend any future authorizations&lt;b&#012;r&gt;&#012;&amp;nbsp; being conducted with&#012;your         card&lt;/font&gt;&lt;font size="2"&gt;.&lt;/font&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font size="2" face="Arial"&gt;&amp;nbsp; For your security we have deactivate your card.&lt;/font&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font size="2" face="Arial"&gt;&amp;nbsp; How to activate/re-activate your card ?&lt;/font&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font size="2" face="Arial"&gt;&amp;nbsp; You may stop by your branch or call our Activation Center. &lt;br&gt;&#012;  &lt;br&gt;&#012;&amp;nbsp; &lt;strong&gt;&lt;font color="#CC0000"&gt;Activation Center:  (866) 722-3235 (24 Hour Line)&lt;/font&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font size="2" face="Arial"&gt;&amp;nbsp; Our automated system allows you to quickly activate your card.&lt;br /&gt;&#012;&amp;nbsp; We apologize for any inconvenience this may cause&lt;font size="1"&gt;.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&#012;&lt;p&gt;&lt;font size="2" face="Arial"&gt;&amp;nbsp;&amp;nbsp;Copyright &amp;copy; 2008 Credit Union 1.          All Rights Reserved.&lt;/font&gt;&lt;font face="Arial"&gt;&lt;br /&gt;&#012;  &lt;/font&gt;&lt;br&gt;&#012;&lt;/p&gt;&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20270939</guid>
<pubDate>Wed, 02 Apr 2008 15:09:16 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20244143</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : VISA - local number to me in Houston. Scary.<br><br> <blockquote><small>quote:</small><hr>> VISA Security Department temporary disabled your account. <br><br>Verified by VISA will never ask you any information via e-mail. Call this number (832)772-7857 - Toll Free<br><br>You must reactivate your account immediately, or you won't be able to use your cards again. <br><br>> Sorry for any inconvenience this may cause and thank you for your patience. <br><br>> To reactivate your account call us:  832-772-7857- Toll Free<br><br>&copy; 2001-2008 Visa. All Rights Reserved.<br><br>This message was sent to Email Id :<br> <br>WPTLLOFITJBTPCIRFUNZMICCCONJSFMEEMUDLO<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>X-Greylist: delayed 870 seconds by postgrey-1.23 at coral.dslreports.com; Fri, 28 Mar 2008 12:49:54 EDT&#012;Received: from costanzosbakery.com (mail.costanzosbakery.com &#91;72.45.146.150&#93;)&#012;by mail.dslr.net (Postfix) with ESMTP id 4CF4D4374F&#012;for &lt;removed@dslr.net&gt;; Fri, 28 Mar 2008 12:49:54 -0400 (EDT)&#012;Received: from User (&#91;209.132.209.130&#93;) by costanzosbakery.com with Microsoft SMTPSVC(6.0.3790.1830);&#012; Fri, 28 Mar 2008 12:11:22 -0400&#012;Reply-To: &lt;do-not-reply@visa.com&gt;&#012;From: "VISA"&lt;security@visa.com&gt;&#012;Subject: VISA Security Department temporary disabled your account. &#012;Date: Fri, 28 Mar 2008 09:11:21 -0700&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Message-ID: &lt;SERVER2003HrdZ6Vzvd00006939@costanzosbakery.com&gt;&#012;X-OriginalArrivalTime: 28 Mar 2008 16:11:22.0725 (UTC) FILETIME=&#91;5D9D1150:01C890EE&#93;&#012;To: undisclosed-recipients:;&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20244143</guid>
<pubDate>Fri, 28 Mar 2008 20:09:29 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20238851</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : <b>Pentagon Federal Credit Union Phish</b><br><br>As before, the only thing changed was the name in the <br>X-Apparently-To header.<br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.140; Thu, 27 Mar 2008 19:46:30 -0700&#012;X-YahooFilteredBulk:65.105.120.87&#012;X-Originating-IP:&#91;65.105.120.87&#93;&#012;Return-Path:&lt;service@penfed.org&gt;&#012;Authentication-Results:mta506.mail.mud.yahoo.com from=penfed.org; domainkeys=neutral (no sig)&#012;Received:from 65.105.120.87 (EHLO webmail.iconnectu.net) (65.105.120.87) by mta506.mail.mud.yahoo.com with SMTP; Thu, 27 Mar 2008 19:46:30 -0700&#012;Received:from User &#91;207.166.116.186&#93; by webmail.iconnectu.net with ESMTP (SMTPD32-6.06) id AC88B3DC004A; Thu, 27 Mar 2008 21:48:40 -0500&#012;Reply-to:&lt;service@penfed.org&gt;&#012;From:"service@penfed.org" &lt;service@penfed.org&gt;  Add Mobile Alert&#012;Subject:Pentagon Federal Credit Union Account Suspended&#012;Date:Fri, 28 Mar 2008 10:40:50 -0400&#012;MIME-Version:1.0&#012;Content-Type:text/plain; charset="_iso-2022-jp$ESC"&#012;Content-Transfer-Encoding:7bit&#012;X-Priority:1&#012;X-MSMail-Priority:High&#012;X-Mailer:Microsoft Outlook Express 6.00.2800.1081&#012;X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2800.1081&#012;Message-Id:&lt;200803272149182.SM02700@User&gt;&#012;Content-Length:284&#012; &#012;Dear Pentagon Federal Credit Union Customer, &#012; &#012;   ACCOUNT SUSPENDED&#012; &#012;Your account has been suspended for invalid billing information&#012; provided.&#012; &#012;To activate your account please call the security department at&#012; 856-431-1109&#012; &#012;Thank You&#012; &#012;Pentagon Federal Credit Union Security Department&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20238851</guid>
<pubDate>Thu, 27 Mar 2008 23:14:50 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20204809</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : A Franklin Bank phone phish sent to my mom's Yahoo email:<br>(I submitted a regular one of these just now to Phishtracker -<br>it too has a phone number in it as well, probably bogus.)<br>As with the last one I posted, the only thing changed was<br>in the X-Apparently-To: field.<br><br><textarea name="code" class="text" cols=50 rows=10>X-Apparently-To: x@yahoo.com via 66.163.178.140; Fri, 21 Mar 2008 12:47:59 -0700&#012;X-YahooFilteredBulk:65.97.182.163&#012;X-Originating-IP:&#91;65.97.182.163&#93;&#012;Return-Path:&lt;not-reply@bankfranklin.com&gt;&#012;Authentication-Results:mta110.mail.re2.yahoo.com from=bankfranklin.com; domainkeys=neutral (no sig)&#012;Received:from 65.97.182.163 (EHLO mail.1010xl.com) (65.97.182.163) by mta110.mail.re2.yahoo.com with SMTP; Fri, 21 Mar 2008 12:47:59 -0700&#012;Received:from User (&#91;208.69.59.178&#93;) by mail.1010xl.com with Microsoft SMTPSVC(6.0.3790.3959); Fri, 21 Mar 2008 14:33:03 -0400&#012;Reply-to:&lt;not-reply@bankfranklin.com&gt;&#012;From:"Franklin Bank" &lt;not-reply@bankfranklin.com&gt; &#012;Subject:Account Suspended.&#012;Date:Fri, 21 Mar 2008 13:34:15 -0500&#012;MIME-Version:1.0&#012;Content-Type:text/plain; charset="Windows-1251"&#012;Content-Transfer-Encoding:7bit&#012;X-Priority:1&#012;X-MSMail-Priority:High&#012;X-Mailer:Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Return-Path:not-reply@bankfranklin.com&#012;Message-ID:&lt;SBRSBS2oHzGkzMcvsq900002c75@mail.1010xl.com&gt;&#012;X-OriginalArrivalTime:21 Mar 2008 18:33:04.0328 (UTC) FILETIME=&#91;00127C80:01C88B82&#93;&#012;X-TM-AS-Product-Ver:SMEX-7.5.0.1166-5.0.1023-15788.002&#012;X-TM-AS-Result:No--8.198000-5.000000-31&#012;X-TM-AS-User-Approved-Sender:No&#012;X-TM-AS-User-Blocked-Sender:No&#012;Content-Length:361&#012; &#012;Message from Franklin Bank Customer Service&#012;Account Suspended.&#012;Date: 3/21/2008&#012; &#012;All Franklin Bank accounts were recently updated with a new security&#012; enhancement. &#012; &#012;Your account has been temporary suspended.&#012; &#012;To activate your account please call the security department at&#012; 972-704-2837&#012; &#012;Thank you for banking with Franklin Bank.&#012;Copyright &copy; 2008 Franklin Bank.&#012;</textarea><!--end code block--><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20204809</guid>
<pubDate>Fri, 21 Mar 2008 21:00:03 EDT</pubDate>
</item>

<item>
<title>Re: Colonial bank (334) 830-4240</title>
<link>http://www.dslreports.com/forum/remark,20163958</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : March 14:<br> <blockquote><small>quote:</small><hr>Dear customer,<br><br>VISA Debit Card, Security Departament suspended your acccount.<br>Reason: Energy Breakdown<br><br>After the energy breakdown from 13/03/2008 it appears that some of our hardware is not working properly. The data of five thousands customers stored on computer backup tapes was lost.<br><br>Some restrictions applied untill you update your account.<br><br>To reactivate your account please call at : 209-683-4515 Please note our number : +1 209-683-4515<br><br>The information provided will be treated in confidence and stored in our secure database.<br>If you fail to provide information about your account you'll discover that your account has been automatically deleted from VISA Debit Card database.<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;debit@visa.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Fri, 14 Mar 2008 08:05:16 -0400&#012;Received: from mail.privatehealthnews.com (&#91;63.84.188.168&#93;:1802)&#012;by laredo.root--servers.net with esmtp (Exim 4.68)&#012;(envelope-from &lt;debit@visa.com&gt;)&#012;id 1Ja8eu-0005A1-PS&#012;for gumu@removed.us; Fri, 14 Mar 2008 08:05:16 -0400&#012;Received: from User &#91;63.246.1.148&#93; by mail.privatehealthnews.com with ESMTP&#012;  (SMTPD-9.20) id A9F40238; Fri, 14 Mar 2008 08:05:08 -0400&#012;From: "VISA Debit Card"&lt;debit@visa.com&gt;&#012;Subject: Urgent Notification&#012;Date: Fri, 14 Mar 2008 12:00:35 -0000&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Message-Id: &lt;200803140805858.SM02840@User&gt;&#012;X-Spam-Subject: ***SPAM*** Urgent Notification&#012;X-Spam-Status: Yes, score=11.5&#012;X-Spam-Score: 115&#012;X-Spam-Bar: +++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear customer, VISA Debit Card, Security Departament suspended&#012;your acccount. Reason: Energy Breakdown After the energy breakdown from 13/03/2008&#012;it appears that some of our hardware is not working properly. The data of&#012;five thousands customers stored on computer backup tapes was lost. &#91;...&#93; &#012;Content analysis details:   (11.5 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%&#012;&#91;score: 1.0000&#93;&#012;2.8 TVD_PH_SUBJ_URGENT     TVD_PH_SUBJ_URGENT&#012;1.3 MISSING_HEADERS        Missing To: header&#012;0.8 MSOE_MID_WRONG_CASE    MSOE_MID_WRONG_CASE&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20163958</guid>
<pubDate>Fri, 14 Mar 2008 11:17:09 EDT</pubDate>
</item>

<item>
<title>Re: Colonial bank (334) 830-4240</title>
<link>http://www.dslreports.com/forum/remark,20160602</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : Got the same one as you did about the 334-830-4240 number. Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;colonial@colonialbank.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Thu, 13 Mar 2008 14:45:01 -0400&#012;Received: from ptb-relay02.plus.net (&#91;212.159.14.213&#93;:39583)&#012;by laredo.root--servers.net with esmtps (TLSv1:AES256-SHA:256)&#012;(Exim 4.68)&#012;(envelope-from &lt;colonial@colonialbank.com&gt;)&#012;id 1JZsQC-0000MG-Ly&#012;for gumu@removed.us; Thu, 13 Mar 2008 14:45:00 -0400&#012;Received: from &#91;213.162.106.173&#93; (helo=nicholasashley.com)&#012; by ptb-relay02.plus.net with esmtp (Exim) id 1JZsQ7-0005RM-TY&#012;for gumu@removed.us; Thu, 13 Mar 2008 18:44:52 +0000&#012;Received: from User (&#91;86.157.156.37&#93;) by nicholasashley.com with Microsoft SMTPSVC(6.0.3790.1830);&#012; Thu, 13 Mar 2008 18:44:50 +0000&#012;Reply-To: &lt;colonial@colonialbank.com&gt;&#012;From: "Colonial Bank"&lt;colonial@colonialbank.com&gt;&#012;Subject: NOTICE ID:                                             DIITNVWFWE&#012;Date: Thu, 13 Mar 2008 18:46:49 -0000&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;SERVER-1odYE4KveYKW000065e5@nicholasashley.com&gt;&#012;X-OriginalArrivalTime: 13 Mar 2008 18:44:50.0810 (UTC) FILETIME=&#91;51DD15A0:01C8853A&#93;&#012;X-TM-AS-Product-Ver: SMEX-7.2.0.1122-5.0.1023-15786.000&#012;X-TM-AS-Result: No--2.268900-5.000000-31&#012;X-Plusnet-Relay: 708a69074e485b1aed8d28228d722ef2&#012;X-Spam-Subject: ***SPAM*** NOTICE ID:                                             DIITNVWFWE&#012;X-Spam-Status: Yes, score=11.2&#012;X-Spam-Score: 112&#012;X-Spam-Bar: +++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  &gt; Colonial Bank Online department temporary disabled your&#012;account. You no longer have access to the account registered with this email&#012;address After three unsuccessful login attempts your account was temporary&#012;disabled until further investigations. &#91;...&#93; &#012;Content analysis details:   (11.2 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%&#012;&#91;score: 0.9907&#93;&#012;1.5 DNS_FROM_RFC_BOGUSMX   RBL: Envelope sender in bogusmx.rfc-ignorant.org&#012;2.1 SUBJ_ALL_CAPS          Subject is all capitals&#012;1.3 MISSING_HEADERS        Missing To: header&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;-0.2 AWL                    AWL: From: address is in the auto white-list&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20160602</guid>
<pubDate>Thu, 13 Mar 2008 17:46:25 EDT</pubDate>
</item>

<item>
<title>Colonial bank (334) 830-4240</title>
<link>http://www.dslreports.com/forum/remark,20159662</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Another Colonial bank vish - different phone number<br> <blockquote><small>quote:</small><hr>> Colonial Bank Online department temporary disabled your account. <br><br>  You no longer have access to the account registered with this email address <br><br>  After three unsuccessful login attempts your account was temporary disabled until further investigations. <br><br>  Colonial Bank will never ask you any information via e-mail. Call this number (334) 830-4240 - Toll Free<br><br>  You must reactivate your account immediately, or you won't be able to use your cards again. <br><br>> Sorry for any inconvenience this may cause and thank you for your patience. <br><br>> To reactivate your account call us: (334) 830-4240 - Toll Free<br><br>2004-2008 Colonial Bank<br> <br>KFVIQCXMNBHRXJSRFIYSQJKLNMGFNRBSFENPMZ<hr></blockquote><br><br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;update@colonialbank.com&gt;&#012;Received: from EXTRANET.COMUNICACION (extranet.tecfa.com &#91;62.93.180.61&#93;)&#012;        by mp.cs.niu.edu (8.14.2/8.14.2) with ESMTP id m2DIbLDr024400&#012;        for &lt;munged@cs.niu.edu&gt;; Thu, 13 Mar 2008 13:37:26 -0500 (CDT)&#012;Received: from User (&#91;67.37.18.250&#93;) by EXTRANET.COMUNICACION with Microsoft SMTPSVC(5.0.2195.6713);&#012;         Thu, 13 Mar 2008 19:47:44 +0100&#012;Reply-To: &lt;update@colonialcolonial.com&gt;&#012;From: "Colonial Bank"&lt;update@colonialbank.com&gt;&#012;Subject: Colonial Bank Online department temporary disabled your account. &#012;Date: Thu, 13 Mar 2008 14:37:20 -0400&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;EXTRANETEEmYDKFJ2I10000216a@EXTRANET.COMUNICACION&gt;&#012;X-OriginalArrivalTime: 13 Mar 2008 18:47:44.0828 (UTC) FILETIME=&#91;B9961FC0:01C8853A&#93;&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.12</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20159662</guid>
<pubDate>Thu, 13 Mar 2008 15:02:58 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20156214</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Phone Phish delivered to my Mom's Yahoo email:<br><br><textarea name="code" class="text" cols=50 rows=10> &#012;X-Apparently-To: x@yahoo.com via 66.163.178.133; Wed, 12 Mar 2008 13:34:09 -0700&#012;X-YahooFilteredBulk:64.40.243.82&#012;X-Originating-IP:&#91;64.40.243.82&#93;&#012;Return-Path:&lt;netspend@netspendsecurity.com&gt;&#012;Authentication-Results:mta358.mail.mud.yahoo.com from=netspendsecurity.com; domainkeys=neutral (no sig)&#012;Received:from 64.40.243.82 (EHLO mail.travinfo1.net) (64.40.243.82) by mta358.mail.mud.yahoo.com with SMTP; Wed, 12 Mar 2008 13:34:08 -0700&#012;Received:from User (&#91;65.101.57.222&#93;) by mail.travinfo1.net (Merak 7.6.4) with ASMTP id VOV40501; Wed, 12 Mar 2008 14:49:50 -0500&#012;Reply-to:&lt;noreply@netspend.com&gt;&#012;From:"NetSpend" &lt;netspend@netspendsecurity.com&gt;  Add Mobile Alert&#012;Subject:SECURITY ALERT!&#012;Date:Wed, 12 Mar 2008 12:49:49 -0700&#012;MIME-Version:1.0&#012;Content-Type:text/html; charset="Windows-1251"&#012;Content-Transfer-Encoding:7bit&#012;X-Priority:3&#012;X-MSMail-Priority:Normal&#012;X-Mailer:Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Content-Length:2383&#012; &#012;  Card Deactivation&#012;  Message from: Customer Service&#012;  Date: 03/12/2008&#012; &#012;  We detected irregular activity on your NetSpend&reg; Card on 03/11/2008.&#012; &#012;  For your protection we have had to suspend any future authorizations&#012;  being conducted with your NetSpend&reg; Card.&#012; &#012;  For your security we have deactivate your card.&#012; &#012;  How to activate/re-activate your card ?&#012; &#012;  You may stop by your branch or call our Activation Center.&#012; &#012;  Activation Center: (888) 721-9034 (24 Hour Line)&#012; &#012;  Our automated system allows you to quickly activate your card.&#012; &#012;  We apologize for any inconvenience this may cause.&#012; &#012; &#012;NetSpend Corporation &#012;Card Department &#012;PO Box 2136&#012;Austin, TX 78768-2136  &#012;</textarea><!--end code block--><br>Only thing changed was my mom's email name. I replaced it<br>with the 'x'.<br><br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20156214</guid>
<pubDate>Wed, 12 Mar 2008 23:02:25 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20151566</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : March 12: Colonial bank<br> <blockquote><small>quote:</small><hr>Dear Customer,<br><br>Colonial Bank temporarily suspended your account.<br><br>Reason: Fraud Attempts<br><br>To reactivate your account call the toll-free number: 1-334-246-4229<br><br>Never access Colonial Bank Web site by clicking on a link provided in an e-mail.<br> Colonial Bank will never solicit you to provide or update personal or financial<br> information. And, will never send an e-mail containing links to Web sites. <br><br>Copyright  2008 Colonial Bank . All Rights Reserved.<br> <br>KYDXBXIQSQHWJJWPKRDPWGQCLXDWJFVBUYGUTF<hr></blockquote><br><br><textarea name="code" class="text" cols=50 rows=10>Return-Path: &lt;online@colonialbank.com&gt;&#012;Received: from neptune.webfusion.co.uk (neptune.webfusion.co.uk &#91;212.67.202.9&#93;)&#012;        by mp.cs.niu.edu (8.14.2/8.14.2) with ESMTP id m2CDKBmL001529&#012;        (version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NOT)&#012;        for &lt;munged@cs.niu.edu&gt;; Wed, 12 Mar 2008 08:20:17 -0500 (CDT)&#012;Message-Id: &lt;200803121320.m2CDKBmL001529@mp.cs.niu.edu&gt;&#012;Received: from adsl-67-37-18-250.dsl.bcvloh.ameritech.net (&#91;67.37.18.250&#93; helo=User)&#012;        by neptune.webfusion.co.uk with esmtpa (Exim 4.54)&#012;        id 1JZQsM-0007eZ-Ce; Wed, 12 Mar 2008 13:20:10 +0000&#012;Reply-To: &lt;do-not-reply@colonialbank.com&gt;&#012;From: "Colonial Bank"&lt;online@colonialbank.com&gt;&#012;Subject: Colonial Bank temporarily suspended your account.&#012;Date: Wed, 12 Mar 2008 09:20:12 -0400&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;        charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.12</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20151566</guid>
<pubDate>Wed, 12 Mar 2008 10:01:53 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20146468</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : March 11:<br> <blockquote><small>quote:</small><hr>Dear Customer,<br><br>VISA Debit Card , Security Departament temporarily suspended your account.<br>Reason: Fraud Atempts<br><br>We require you to complete an account update so we can unlock your account.<br><br>To start the update process please call at total free number : 803-825-4293<br><br>The information provided will be treated in confidence and stored in our secure database.<br>If you fail to provide information about your account you'll discover that your account has been automatically deleted from our database.<br><br>Please note the total free number : +1 803-825-4293<br><br>Copyright &copy; VISA Debit Card, All Rights Reserved<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;debit@visa.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Tue, 11 Mar 2008 10:39:18 -0400&#012;Received: from mail.altayyargroup.com (&#91;212.100.194.83&#93;:38490)&#012;by laredo.root--servers.net with esmtp (Exim 4.68)&#012;(envelope-from &lt;debit@visa.com&gt;)&#012;id 1JZ5dJ-0001w6-Sf&#012;for gumu@removed.us; Tue, 11 Mar 2008 10:39:18 -0400&#012;Received: from User (&#91;10.65.28.1&#93;) by mail.altayyargroup.com with Microsoft SMTPSVC(6.0.3790.3959);&#012; Tue, 11 Mar 2008 17:41:43 +0300&#012;Reply-To: &lt;debit@visa.com&gt;&#012;From: "VISA Debit Card"&lt;debit@visa.com&gt;&#012;CC: gump13@hotmail.com,gumpond@netscape.com,gumshoe@uscyber.com,gumu@removed.us,gunadanu@hotmail.com&#012;Subject: Urgent Notification!&#012;Date: Tue, 11 Mar 2008 15.51.35 +0100&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Message-ID: &lt;MAILfMS9stbDEa7fzCL00004a24@mail.altayyargroup.com&gt;&#012;X-OriginalArrivalTime: 11 Mar 2008 14:41:44.0380 (UTC) FILETIME=&#91;06D8FFC0:01C88386&#93;&#012;X-Spam-Subject: ***SPAM*** Urgent Notification!&#012;X-Spam-Status: Yes, score=13.4&#012;X-Spam-Score: 134&#012;X-Spam-Bar: +++++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear Customer, VISA Debit Card , Security Departament temporarily&#012;suspended your account. Reason: Fraud Atempts We require you to complete&#012;an account update so we can unlock your account. &#91;...&#93; &#012;Content analysis details:   (13.4 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;1.2 INVALID_DATE           Invalid Date: header (not RFC 2822)&#012;2.8 TVD_PH_SUBJ_URGENT     TVD_PH_SUBJ_URGENT&#012;1.0 DATE_IN_PAST_12_24     Date: is 12 to 24 hours before Received: date&#012;2.9 SUSPICIOUS_RECIPS      Similar addresses in recipient list&#012;1.3 MISSING_HEADERS        Missing To: header&#012;1.0 BAYES_60               BODY: Bayesian spam probability is 60 to 80%&#012;&#91;score: 0.6898&#93;&#012;0.0 FM_IS_IT_OUR_ACCOUNT   Is it our account?&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20146468</guid>
<pubDate>Tue, 11 Mar 2008 13:11:00 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088286</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : January 21:<br>  <blockquote><small>quote:</small><hr>Dear Listerhill Credit Union Cardholder,<br><br>We detected irregular activity on your debit/credit card on 01/21/2008.<br>For your security, your online banking profile has been locked due to inactivity or because<br>of too many failed login attempts. <br><br>Listerhill Credit Union is serious about safeguarding your personal information online. <br><br>Unlocking your profile will take approximately one minute to complete . <br><br>To reactivate your debit/credit card :<br><br>Immediately call 1-(800) 554-8147 Monday-Friday during office hours.<br><br>or after hours and on weekends to reactivate your debit/credit card.<br><hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;callus@listerhill.com&gt;&#012;Envelope-to: removed@laredo.root--servers.net&#012;Delivery-date: Mon, 21 Jan 2008 11:10:17 -0500&#012;Received: from removed by laredo.root--servers.net with local-bsmtp (Exim 4.68)&#012;(envelope-from &lt;callus@listerhill.com&gt;)&#012;id 1JGzDx-0004sI-91&#012;for removed@laredo.root--servers.net; Mon, 21 Jan 2008 11:10:17 -0500&#012;X-Spam-Flag: YES&#012;X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on&#012;laredo.root--servers.net&#012;X-Spam-Level: *************&#012;X-Spam-Status: Yes, score=13.7 required=4.5 tests=AWL,BAYES_95,&#012;FORGED_MUA_OUTLOOK,FORGED_OUTLOOK_HTML,FORGED_OUTLOOK_TAGS,HTML_IMAGE_ONLY_16,&#012;HTML_MESSAGE,HTML_MIME_NO_HTML_TAG,INVALID_TZ_EST,MIME_HTML_ONLY,&#012;MISSING_HEADERS,MISSING_MID,RCVD_NUMERIC_HELO,RDNS_NONE autolearn=spam&#012;version=3.2.3&#012;X-Spam-Report: &#012;*  0.0 MISSING_MID Missing Message-Id: header&#012;*  0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS&#012;*  2.7 INVALID_TZ_EST Invalid date in header (wrong EST timezone)&#012;*  2.1 RCVD_NUMERIC_HELO Received: contains an IP address used for HELO&#012;*  1.3 MISSING_HEADERS Missing To: header&#012;*  0.0 HTML_MESSAGE BODY: HTML included in message&#012;*  3.0 BAYES_95 BODY: Bayesian spam probability is 95 to 99%&#012;*      &#91;score: 0.9517&#93;&#012;*  1.5 MIME_HTML_ONLY BODY: Message only has text/html MIME parts&#012;*  1.5 HTML_IMAGE_ONLY_16 BODY: HTML: images with 1200-1600 bytes of words&#012;*  0.1 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag&#012;*  0.0 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format&#012;*  0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only&#012;*  3.1 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook&#012;* -1.7 AWL AWL: From: address is in the auto white-list&#012;Received: from &#91;75.144.105.41&#93; (port=3039 helo=mail)&#012;by laredo.root--servers.net with smtp (Exim 4.68)&#012;(envelope-from &lt;callus@listerhill.com&gt;)&#012;id 1JGzDx-0004sC-4R&#012;for gumu@removed.us; Mon, 21 Jan 2008 11:10:13 -0500&#012;X-DN-AuthenticatedSender: WJNMJ6Y49E9A33NMKKNEHR39FEECX49W-7N7XuX6kOrPPID+RQx8MCC0DUOpXVR+x6PY47D02NwesRKSVkkrKacEUZe6cnhv/---&#012;Received: from 24.65.64.219 (&#91;24.65.64.219&#93;)&#012;          by mail (DeskNow) with SMTP ID 180;&#012;          Mon, 21 Jan 2008 10:15:03 -0600 (EST)&#012;From: "Listerhill Credit Union"&lt;callus@listerhill.com&gt;&#012;Subject: *****SPAM***** Irregular Check Card Activity&#012;Date: Mon, 21 Jan 2008 09:10:11 -0700&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;X-Spam-Prev-Subject: Irregular Check Card Activity&#012;Message-Id: &lt;E1JGzDx-0004sI-91@laredo.root--servers.net&gt;&#012;</textarea><!--end code block--><br>That's just about it for 2008 so far. I won't bore you guys with copies of vish emails from 2007, unless you think they'll be useful...<br><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088286</guid>
<pubDate>Sat, 01 Mar 2008 03:34:14 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088281</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : January 23:<br> <blockquote><small>quote:</small><hr>Dear PUDCU Cardholder,<br><br>We detected irregular activity on your debit/credit card on 01/21/2008.<br>For your security, your online banking profile has been locked due to inactivity or because<br>of too many failed login attempts. <br><br>Snohomish County PUD Credit Union is serious about safeguarding your personal information online. <br><br>Unlocking your profile will take approximately one minute to complete . <br><br>To reactivate your debit/credit card :<br><br>Immediately call 1-(800) 319-9621 Monday-Friday during office hours.<br><br>or after hours and on weekends to reactivate your debit/credit card.<br><br>&copy; 2008 Snohomish County PUD Credit Union<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;account@pudcu.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Wed, 23 Jan 2008 11:17:32 -0500&#012;Received: from &#91;76.12.61.28&#93; (port=4637 helo=ds134642-1)&#012;by laredo.root--servers.net with esmtp (Exim 4.68)&#012;(envelope-from &lt;account@pudcu.com&gt;)&#012;id 1JHiI4-0006LC-EV&#012;for gumu@removed.us; Wed, 23 Jan 2008 11:17:32 -0500&#012;Received: from s0106003065fb8258.fm.shawcable.net &#91;24.65.64.219&#93; by ds134642-1 with SMTP;&#012;   Wed, 23 Jan 2008 23:16:04 -0500&#012;From: "PUDCU"&lt;account@pudcu.com&gt;&#012;Subject: Irregular Activity&#012;Date: Wed, 23 Jan 2008 09:15:27 -0700&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;X-Spam-Subject: ***SPAM*** Irregular Activity&#012;X-Spam-Status: Yes, score=15.7&#012;X-Spam-Score: 157&#012;X-Spam-Bar: +++++++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear PUDCU Cardholder, We detected irregular activity on your&#012;debit/credit card on 01/21/2008. For your security, your online banking profile&#012;has been locked due to inactivity or because of too many failed login attempts.&#012;&#91;...&#93; &#012;Content analysis details:   (15.7 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%&#012;&#91;score: 1.0000&#93;&#012;0.0 MISSING_MID            Missing Message-Id: header&#012;0.1 RDNS_NONE              Delivered to trusted network by a host with no rDNS&#012;3.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net&#012;&#91;Blocked - see &lt;http://www.spamcop.net/bl.shtml?24.65.64.219&gt;&#93;&#012;0.7 SPF_NEUTRAL            SPF: sender does not match SPF record (neutral)&#012;1.3 MISSING_HEADERS        Missing To: header&#012;2.5 HTML_IMAGE_ONLY_12     BODY: HTML: images with 800-1200 bytes of words&#012;0.0 HTML_MESSAGE           BODY: HTML included in message&#012;1.5 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts&#012;0.1 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML tag&#012;0.0 FORGED_OUTLOOK_TAGS    Outlook can't send HTML in this format&#012;0.0 FORGED_OUTLOOK_HTML    Outlook can't send HTML message only&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088281</guid>
<pubDate>Sat, 01 Mar 2008 03:33:17 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088278</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : January 23:<br> <blockquote><small>quote:</small><hr>Dear Cardholder,<br><br>We detected irregular activity on your debit card on 01/22/2008.<br>For your security, your online banking profile has been locked due to inactivity or because<br>of too many failed login attempts. <br><br>To reactivate your account, you must contact us at (800) 564-9401 and fallow the instructions .<br><br>Copyright &copy; National Credit Union Administration .<br><hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;support@ncua.gov&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Wed, 23 Jan 2008 23:57:11 -0500&#012;Received: from adsl-75-41-76-14.dsl.chcgil.sbcglobal.net (&#91;75.41.76.14&#93;:6758 helo=emailserver.nmct.net)&#012;by laredo.root--servers.net with esmtp (Exim 4.68)&#012;(envelope-from &lt;support@ncua.gov&gt;)&#012;id 1JHu9D-0005z9-7J&#012;for gumu@removed.us; Wed, 23 Jan 2008 23:57:11 -0500&#012;Received: from User (&#91;24.65.64.219&#93;) by emailserver.nmct.net with Microsoft SMTPSVC(5.0.2195.6713);&#012; Wed, 23 Jan 2008 22:50:56 -0600&#012;From: "National Credit Union Administration"&lt;support@ncua.gov&gt;&#012;Subject: Irregular Check Card Activity&#012;Date: Wed, 23 Jan 2008 21:51:18 -0700&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;EMAILSERVER66lRCR5Y00000609@emailserver.nmct.net&gt;&#012;X-OriginalArrivalTime: 24 Jan 2008 04:50:56.0625 (UTC) FILETIME=&#91;B4EC9610:01C85E44&#93;&#012;X-Spam-Subject: ***SPAM*** Irregular Check Card Activity&#012;X-Spam-Status: Yes, score=14.9&#012;X-Spam-Score: 149&#012;X-Spam-Bar: ++++++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear Cardholder, We detected irregular activity on your debit&#012;card on 01/22/2008. For your security, your online banking profile has been&#012;locked due to inactivity or because of too many failed login attempts. &#91;...&#93;&#012;Content analysis details:   (14.9 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%&#012;&#91;score: 1.0000&#93;&#012;3.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net&#012;&#91;Blocked - see &lt;http://www.spamcop.net/bl.shtml?24.65.64.219&gt;&#93;&#012;0.6 SPF_SOFTFAIL           SPF: sender does not match SPF record (softfail)&#012;1.3 MISSING_HEADERS        Missing To: header&#012;0.0 HTML_MESSAGE           BODY: HTML included in message&#012;1.8 HTML_IMAGE_ONLY_08     BODY: HTML: images with 400-800 bytes of words&#012;1.5 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts&#012;0.1 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML tag&#012;0.0 FORGED_OUTLOOK_TAGS    Outlook can't send HTML in this format&#012;0.1 RDNS_DYNAMIC           Delivered to trusted network by host with&#012;dynamic-looking rDNS&#012;0.0 FORGED_OUTLOOK_HTML    Outlook can't send HTML message only&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088278</guid>
<pubDate>Sat, 01 Mar 2008 03:31:57 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088274</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : February 4:<br> <blockquote><small>quote:</small><hr>Dear Empire Bank Cardholder,<br><br>We detected irregular activity on your debit/credit card on 02/03/2008.<br>For your security, your online banking profile has been locked due to inactivity or because<br>of too many failed login attempts. <br><br>Empire Bank is serious about safeguarding your personal information online. <br><br>Unlocking your profile will take approximately one minute to complete . <br><br>To reactivate your debit/credit card :<br><br>Immediately call 1-(800) 929-3209 Monday-Friday during office hours.<br><br>or after hours and on weekends to reactivate your debit/credit card.<br><br>Member FDIC &middot; Equal Housing Lender&middot; &copy; 2007 Empire Bank<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;gribble.dale+caf_=gumu=removed.us@gmail.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Mon, 04 Feb 2008 10:49:54 -0500&#012;Received: from ug-out-1314.google.com (&#91;66.249.92.168&#93;:31498)&#012;by laredo.root--servers.net with esmtp (Exim 4.68)&#012;(envelope-from &lt;gribble.dale+caf_=gumu=removed.us@gmail.com&gt;)&#012;id 1JM3Zu-0001UP-Ow&#012;for gumu@removed.us; Mon, 04 Feb 2008 10:49:54 -0500&#012;Received: by ug-out-1314.google.com with SMTP id q2so17805uge.50&#012;        for &lt;gumu@removed.us&gt;; Mon, 04 Feb 2008 07:49:49 -0800 (PST)&#012;Received: by 10.78.162.4 with SMTP id k4mr12433546hue.66.1202140188297;&#012;        Mon, 04 Feb 2008 07:49:48 -0800 (PST)&#012;X-Forwarded-To: gumu@removed.us&#012;X-Forwarded-For: gribble.dale@gmail.com gumu@removed.us&#012;Delivered-To: gribble.dale@gmail.com&#012;Received: by 10.78.156.16 with SMTP id d16cs104683hue;&#012;        Mon, 4 Feb 2008 07:49:46 -0800 (PST)&#012;Received: by 10.78.137.7 with SMTP id k7mr12431855hud.68.1202140185490;&#012;        Mon, 04 Feb 2008 07:49:45 -0800 (PST)&#012;Received: from centralfloridafair.com (cfsvr1.centralfloridafair.com &#91;64.90.0.1&#93;)&#012;        by mx.google.com with ESMTP id p25si1948067hub.29.2008.02.04.07.49.44;&#012;        Mon, 04 Feb 2008 07:49:45 -0800 (PST)&#012;Received-SPF: softfail (google.com: domain of transitioning info@empirebank.com does not designate 64.90.0.1 as permitted sender) client-ip=64.90.0.1;&#012;Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning info@empirebank.com does not designate 64.90.0.1 as permitted sender) smtp.mail=info@empirebank.com&#012;Received: from User (&#91;64.62.123.42&#93;) by centralfloridafair.com with Microsoft SMTPSVC(6.0.3790.3959);&#012; Mon, 4 Feb 2008 10:43:42 -0500&#012;From: "Empire Bank"&lt;info@empirebank.com&gt;&#012;Subject: Irregular Check Card Activity&#012;Date: Mon, 4 Feb 2008 07:48:39 -0800&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Bcc:&#012;Message-ID: &lt;CFSVR14Ogddu5qE8DzH0000178c@centralfloridafair.com&gt;&#012;X-OriginalArrivalTime: 04 Feb 2008 15:43:42.0656 (UTC) FILETIME=&#91;B83DE400:01C86744&#93;&#012;X-Spam-Subject: ***SPAM*** Irregular Check Card Activity&#012;X-Spam-Status: Yes, score=11.9&#012;X-Spam-Score: 119&#012;X-Spam-Bar: +++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear Empire Bank Cardholder, We detected irregular activity&#012;on your debit/credit card on 02/03/2008. For your security, your online banking&#012;profile has been locked due to inactivity or because of too many failed login&#012;attempts. &#91;...&#93; &#012;Content analysis details:   (11.9 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%&#012;&#91;score: 1.0000&#93;&#012;-0.0 SPF_PASS               SPF: sender matches SPF record&#012;1.3 MISSING_HEADERS        Missing To: header&#012;2.5 HTML_IMAGE_ONLY_12     BODY: HTML: images with 800-1200 bytes of words&#012;0.0 HTML_MESSAGE           BODY: HTML included in message&#012;1.5 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts&#012;0.1 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML tag&#012;0.0 FORGED_OUTLOOK_TAGS    Outlook can't send HTML in this format&#012;0.0 FORGED_OUTLOOK_HTML    Outlook can't send HTML message only&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088274</guid>
<pubDate>Sat, 01 Mar 2008 03:29:31 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088268</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : February 13:<br> <blockquote><small>quote:</small><hr>Dear Customer,<br><br>VISA Debit Card , Security Departament temporarily suspended your account.<br>Reason: Fraud Atempts<br><br>We require you to complete an account update so we can unlock your account.<br><br>To start the update process please call at total free number : 805-203-4523<br><br>The information provided will be treated in confidence and stored in our secure database.<br>If you fail to provide information about your account you'll discover that your account has been automatically deleted from our database.<br><br>Please note the total free number : +1 805-203-4523<br><br>Copyright &copy; VISA Debit Card, All Rights Reserved<br><hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;debit@visa.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Wed, 13 Feb 2008 11:42:35 -0500&#012;Received: from host50-server.com (&#91;66.49.136.205&#93;:42309 helo=host50.host50-server.com)&#012;by laredo.root--servers.net with esmtps (TLSv1:AES256-SHA:256)&#012;(Exim 4.68)&#012;(envelope-from &lt;debit@visa.com&gt;)&#012;id 1JPKgp-0007YL-VN&#012;for gumu@removed.us; Wed, 13 Feb 2008 11:42:35 -0500&#012;Received: from User (host-209-174-182-70.champaignschools.org &#91;209.174.182.70&#93; (may be forged))&#012;(authenticated bits=0)&#012;by host50.host50-server.com (8.12.10/8.12.10) with ESMTP id m1DGl9M4002562;&#012;Wed, 13 Feb 2008 11:47:09 -0500&#012;Message-Id: &lt;200802131647.m1DGl9M4002562@host50.host50-server.com&gt;&#012;Reply-To: &lt;debit@visa.com&gt;&#012;From: "VISA Debit Cards"&lt;debit@visa.com&gt;&#012;Subject: Urgent Notification&#012;Date: Wed, 13 Feb 2008 10:45:05 -0600&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Content-Transfer-Encoding: quoted-printable&#012;X-MIME-Autoconverted: from 8bit to quoted-printable by host50.host50-server.com id m1DGl9M4002562&#012;X-Spam-Subject: ***SPAM*** Urgent Notification&#012;X-Spam-Status: Yes, score=11.0&#012;X-Spam-Score: 110&#012;X-Spam-Bar: +++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear Customer, VISA Debit Card , Security Departament temporarily&#012;suspended your account. Reason: Fraud Atempts We require you to complete&#012;an account update so we can unlock your account. &#91;...&#93; &#012;Content analysis details:   (11.0 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;2.8 TVD_PH_SUBJ_URGENT     TVD_PH_SUBJ_URGENT&#012;1.3 MISSING_HEADERS        Missing To: header&#012;3.0 BAYES_95               BODY: Bayesian spam probability is 95 to 99%&#012;&#91;score: 0.9858&#93;&#012;0.8 MSOE_MID_WRONG_CASE    MSOE_MID_WRONG_CASE&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088268</guid>
<pubDate>Sat, 01 Mar 2008 03:27:02 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088264</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : February 19:<br> <blockquote><small>quote:</small><hr>Dear Customer,<br><br>VISA Debit Card , Security Departament temporarily suspended your account.<br>Reason: Fraud Atempts<br><br>We require you to complete an account update so we can unlock your account.<br><br>To start the update process please call at total free number : 847-481-8194<br><br>The information provided will be treated in confidence and stored in our secure database.<br>If you fail to provide information about your account you'll discover that your account has been automatically deleted from our database.<br><br>Please note the total free number : +1 847-481-8194<br><br>Copyright &copy; VISA Debit Card, All Rights Reserved<hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;debit@visa.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Tue, 19 Feb 2008 12:32:34 -0500&#012;Received: from host101.host101-server.com (&#91;66.49.199.16&#93;:56250)&#012;by laredo.root--servers.net with esmtps (TLSv1:AES256-SHA:256)&#012;(Exim 4.68)&#012;(envelope-from &lt;debit@visa.com&gt;)&#012;id 1JRWKV-0001Me-9y&#012;for gumu@removed.us; Tue, 19 Feb 2008 12:32:34 -0500&#012;Received: from User (playa-capital74.ucn.net &#91;63.110.44.74&#93; (may be forged))&#012;(authenticated bits=0)&#012;by host101.host101-server.com (8.12.10/8.12.10) with ESMTP id m1JHWAmb003323;&#012;Tue, 19 Feb 2008 12:32:12 -0500&#012;Message-Id: &lt;200802191732.m1JHWAmb003323@host101.host101-server.com&gt;&#012;From: "VISA Debit Card"&lt;debit@visa.com&gt;&#012;Subject: Urgent Notification&#012;Date: Tue, 19 Feb 2008 09:36:34 -0800&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;Content-Transfer-Encoding: quoted-printable&#012;X-MIME-Autoconverted: from 8bit to quoted-printable by host101.host101-server.com id m1JHWAmb003323&#012;X-Spam-Subject: ***SPAM*** Urgent Notification&#012;X-Spam-Status: Yes, score=10.0&#012;X-Spam-Score: 100&#012;X-Spam-Bar: ++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear Customer, VISA Debit Card , Security Departament temporarily&#012;suspended your account. Reason: Fraud Atempts We require you to complete&#012;an account update so we can unlock your account. &#91;...&#93; &#012;Content analysis details:   (10.0 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;2.8 TVD_PH_SUBJ_URGENT     TVD_PH_SUBJ_URGENT&#012;1.3 MISSING_HEADERS        Missing To: header&#012;2.0 BAYES_80               BODY: Bayesian spam probability is 80 to 95%&#012;&#91;score: 0.9225&#93;&#012;0.8 MSOE_MID_WRONG_CASE    MSOE_MID_WRONG_CASE&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088264</guid>
<pubDate>Sat, 01 Mar 2008 03:25:25 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088263</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : February 20:<br> <blockquote><small>quote:</small><hr>Dear customer,<br><br>Due to recent online fraud, all cardholders are required to contact our Town North Bank, Security Departament at our total free number : 972-546-0398<br><br>Contacting this number will enable us to monitor your account closely, and suspend it as soon as we notice any fraudulent activity.<br><br>CONTACTING THIS NUMBER IS MANDATORY, OR YOUR CARD WILL BE CONSIDERED A SECURITY RISK AND IT WILL BE BLOCKED FROM ONLINE USAGE !<br><br>Please DO NOT reply to any emails asking for sensitive information, as many of our customers have been frauded for considerable ammounts of money.<br>If you receive any type of email please report it immediately !<br><br>Please note the total free number : +1 972-546-0398<br><br>Town North Bank Security Departamanet ,<br>PO Box 814810<br>Dallas, Texas 75381-4810<br><hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;security@townnorthbank.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Wed, 20 Feb 2008 07:44:37 -0500&#012;Received: from host74.host74-server.com (&#91;66.49.248.230&#93;:46981)&#012;by laredo.root--servers.net with esmtps (TLSv1:AES256-SHA:256)&#012;(Exim 4.68)&#012;(envelope-from &lt;security@townnorthbank.com&gt;)&#012;id 1JRoJN-0002Qe-Ew&#012;for gumu@removed.us; Wed, 20 Feb 2008 07:44:37 -0500&#012;Received: from User (ev1s-209-62-3-50.ev1servers.net &#91;209.62.3.50&#93; (may be forged))&#012;(authenticated bits=0)&#012;by host74.host74-server.com (8.12.11/8.12.11) with ESMTP id m1KCiNY4010269;&#012;Wed, 20 Feb 2008 07:44:24 -0500&#012;Message-Id: &lt;200802201244.m1KCiNY4010269@host74.host74-server.com&gt;&#012;From: "Town North Bank"&lt;security@townnorthbank.com&gt;&#012;Subject: Urgent Notification&#012;Date: Wed, 20 Feb 2008 06:44:22 -0600&#012;MIME-Version: 1.0&#012;Content-Type: text/plain;&#012;charset="Windows-1251"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 1&#012;X-MSMail-Priority: High&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;X-Spam-Subject: ***SPAM*** Urgent Notification&#012;X-Spam-Status: Yes, score=11.0&#012;X-Spam-Score: 110&#012;X-Spam-Bar: +++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Dear customer, Due to recent online fraud, all cardholders&#012;are required to contact our Town North Bank, Security Departament at our&#012;total free number : 972-546-0398 Contacting this number will enable us to&#012;monitor your account closely, and suspend it as soon as we notice any fraudulent&#012;activity. &#91;...&#93; &#012;Content analysis details:   (11.0 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;2.8 TVD_PH_SUBJ_URGENT     TVD_PH_SUBJ_URGENT&#012;1.3 MISSING_HEADERS        Missing To: header&#012;3.0 BAYES_95               BODY: Bayesian spam probability is 95 to 99%&#012;&#91;score: 0.9726&#93;&#012;0.8 MSOE_MID_WRONG_CASE    MSOE_MID_WRONG_CASE&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088263</guid>
<pubDate>Sat, 01 Mar 2008 03:24:32 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20088260</link>
<description><![CDATA[<A HREF="/useremail/u/581232"><b>removed</b></A> : Hope these are useful to someone...<br><br>February 21:<br> <blockquote><small>quote:</small><hr>  Visa ATM/Check Card Deactivation <br>  Message from: Customer Service<br>  Date: 02/21/2008<br><br>  We detected irregular activity on your Gesa ATM/Check Card  on 02/20/2008.<br><br>  For your protection we have had to suspend any future authorizations<br>  being conducted with your Gesa Visa ATM/Check Card.<br><br>  For your security we have deactivate your card. <br><br>  How to activate/re-activate your card ?<br><br>  You may stop by your branch or call our Activation Center. <br><br> Activation Center: (509) 210-4256 (24 Hour Line) <br><hr></blockquote><br><br>Headers:<br><textarea name="code" class="text" cols=50 rows=10>Return-path: &lt;gesa@accountsecurity.com&gt;&#012;Envelope-to: gumu@removed.us&#012;Delivery-date: Thu, 21 Feb 2008 14:33:59 -0500&#012;Received: from mail.netafrique.com (&#91;63.219.177.34&#93;:3983 helo=MC100814)&#012;by laredo.root--servers.net with esmtp (Exim 4.68)&#012;(envelope-from &lt;gesa@accountsecurity.com&gt;)&#012;id 1JSHB5-0000Hc-0J&#012;for gumu@removed.us; Thu, 21 Feb 2008 14:33:58 -0500&#012;Received: from 66-52-78-214.jklmail.com &#91;66.52.78.214&#93; by MC100814 with SMTP;&#012;   Thu, 21 Feb 2008 14:34:28 -0500&#012;Reply-To: &lt;noreply@gesa.com&gt;&#012;From: "Gesa Credit Union"&lt;gesa@accountsecurity.com&gt;&#012;Subject: SECURITY ALERT!&#012;Date: Thu, 21 Feb 2008 11:30:32 -0800&#012;MIME-Version: 1.0&#012;Content-Type: text/html;&#012;charset="koi8-u"&#012;Content-Transfer-Encoding: 7bit&#012;X-Priority: 3&#012;X-MSMail-Priority: Normal&#012;X-Mailer: Microsoft Outlook Express 6.00.2600.0000&#012;X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000&#012;X-Spam-Subject: ***SPAM*** SECURITY ALERT!&#012;X-Spam-Status: Yes, score=10.6&#012;X-Spam-Score: 106&#012;X-Spam-Bar: ++++++++++&#012;X-Spam-Report: Spam detection software, running on the system "laredo.root--servers.net", has&#012;identified this incoming email as possible spam.  The original message&#012;has been attached to this so you can view it (if it isn't spam) or label&#012;similar future email.  If you have any questions, see&#012;the administrator of that system for details.&#012;Content preview:  Visa ATM/Check Card Deactivation Message from: Customer Service&#012;Date: 02/21/2008 We detected irregular activity on your Gesa ATM/Check Card&#012;on 02/20/2008. For your protection we have had to suspend any future authorizations&#012;being conducted with your Gesa Visa ATM/Check Card. &#91;...&#93; &#012;Content analysis details:   (10.6 points, 4.5 required)&#012;pts rule name              description&#012;---- ---------------------- --------------------------------------------------&#012;0.0 MISSING_MID            Missing Message-Id: header&#012;2.1 SUBJ_ALL_CAPS          Subject is all capitals&#012;1.3 MISSING_HEADERS        Missing To: header&#012;1.0 BAYES_60               BODY: Bayesian spam probability is 60 to 80%&#012;&#91;score: 0.7967&#93;&#012;0.0 HTML_MESSAGE           BODY: HTML included in message&#012;1.5 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts&#012;1.5 HTML_IMAGE_ONLY_16     BODY: HTML: images with 1200-1600 bytes of words&#012;0.1 HTML_MIME_NO_HTML_TAG  HTML-only message, but there is no HTML tag&#012;0.0 FORGED_OUTLOOK_TAGS    Outlook can't send HTML in this format&#012;0.0 FORGED_OUTLOOK_HTML    Outlook can't send HTML message only&#012;3.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook&#012;X-Spam-Flag: YES&#012;</textarea><!--end code block--><br><small>--<br><A HREF="http://removed.us/eirc">irc.removed.us - #dslr</a> | <A HREF="http://dslreports.com/phishtrack">DSLR Phishtracker</a> | <b>Email: removed@dslr.net</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20088260</guid>
<pubDate>Sat, 01 Mar 2008 03:23:20 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20061188</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : I would guess it might be a VOIP number, in which case it could be anywhere.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20061188</guid>
<pubDate>Mon, 25 Feb 2008 20:16:23 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20061176</link>
<description><![CDATA[<A HREF="/useremail/u/101498"><b>Kibbles</b></A> : Would you get in trouble if you fax'd a FBI cover sheet?<br>Looks like the call goes to NY...or is that forwarded somewhere else?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20061176</guid>
<pubDate>Mon, 25 Feb 2008 20:14:46 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20060473</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><small>said by  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I am hoping this can be made a sticky thread for reporting telephone phishing (includes vishing - voice phish as well as fax phish).<br></div>Agreed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20060473</guid>
<pubDate>Mon, 25 Feb 2008 18:13:56 EDT</pubDate>
</item>

<item>
<title>Fax phish - 914-293-2651 (paypal)</title>
<link>http://www.dslreports.com/forum/remark,20059882</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Excerpts from phish:<br><div class="bquote"> Your account access will be limited if in less than 48 hours we do not receive the fax with the information asked.<br># (Your case ID for this reason is PP-136-124-102.)</div>and<br><div class="bquote"> Please send us all of the following information so we can verify your identity with our records. (we require a fax in less than 48 hours)<br><br>1) Photocopy of a government-issued photo identification (identity card or passport)<br>2) Photocopy of your credit card (front and back side are required)<br> <br><br>Please be informed that the photocopies must be specific and readable otherwise they will not be taken in consideration.<br><br>Please send us only one fax message that will contain all the photocopies required.<br><br>Please send us the information requested to the fax number or address below.<br><br>Faxing from US: 914-293-2651<br>Faxing from outside US: +1 914-293-2651 </div>Excerpt from mail headers:<br><textarea name="code" class="text" cols=50 rows=10>Received: from hs16.order-vault.net (ftp.hs16.order-vault.net &#91;65.18.148.238&#93;)&#012;        by mp.cs.niu.edu (8.14.2/8.14.2) with ESMTP id m1PKWmoK022961&#012;        (version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NOT);&#012;        Mon, 25 Feb 2008 14:32:51 -0600 (CST)&#012;Received: from User (&#91;74.8.99.49&#93;)&#012;        (authenticated (0 bits))&#012;        by hs16.order-vault.net (8.11.6/8.11.6) with ESMTP id m1PKVwS20195;&#012;        Mon, 25 Feb 2008 15:31:58 -0500&#012;</textarea><!--end code block--><br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.12</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20059882</guid>
<pubDate>Mon, 25 Feb 2008 16:46:22 EDT</pubDate>
</item>

<item>
<title>[Phish] Telephone phishing thread</title>
<link>http://www.dslreports.com/forum/remark,20059853</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : I am hoping this can be made a sticky thread for reporting telephone phishing (includes vishing - voice phish as well as fax phish).<br><br>Note that ordinary phishes should be reported to &raquo;<A HREF="/phishtrack">/phishtrack</A> rather than here.<br><small>--<br>AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.12</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20059853</guid>
<pubDate>Mon, 25 Feb 2008 16:42:07 EDT</pubDate>
</item>

</channel>
</rss>
