An
Email with the Subject "FW: We have restricted access to your Chase Online Account msg#0001" was
received in one of Scamdex's honeypot email accounts on Sun, 14 Jun 2009 11:16:24 -0700
and has been classified as a Generic Scam Email.
The sender shows as "Connie Kubis" <c_kub@msn.com>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
essologinlog increditverificationmicrosoftendedcontactwinsafeaccountpaymentcustomerserviceon behalf ofaccessprocesscustomverifyreportsentonlinedeliverymailreferencesincerelyc_kub@msn.comc_kub@msn.comsubject will maintenancesecurityach([81.174.66.26])(6.0.3790.2668)(envelope-from <yellov...(utc) filetime=[d06c4610:...[mailto:yellovei@lnx01.ho...dearhttp://www.chase.com/cred...
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[return-path:] =>
[envelope-to:] => scams@scamdex.com
[delivery-date:] => Sun, 14 Jun 2009 11:16:24 -0700
[received:] => Array
(
[0] => from bay0-omc1-s14.bay0.hotmail.com ([65.54.246.86])by fire.newsblaze.com with esmtp (Exim 4.69)(envelope-from )id 1MFuFg-0003vf-QOfor scams@scamdex.com; Sun, 14 Jun 2009 11:16:24 -0700
[1] => from hotmail.com ([10.12.232.152]) by bay0-omc1-s14.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Sun, 14 Jun 2009 11:16:15 -0700
[2] => from mail pickup service by hotmail.com with Microsoft SMTPSVC; Sun, 14 Jun 2009 11:16:15 -0700
[3] => from 68.92.155.150 by COL0-DAV14.phx.gbl with DAV;Sun, 14 Jun 2009 18:16:09 +0000
)
[message-id:] => Array
(
[0] =>
[1] => <000c01c9ed1c$26922930$f54dfea9@Connie>
)
[x-originating-ip:] => [68.92.155.150]
[x-originating-email:] => [c_kub@msn.com]
[x-sender:] => c_kub@msn.com
[from:] => "Connie Kubis"
[to:] => ,"'phish'" ,
[subject:] => FW: We have restricted access to your Chase Online Account msg#0001
[date:] => Sun, 14 Jun 2009 13:15:51 -0500
[mime-version:] => 1.0
[content-type:] => multipart/alternative;boundary="----=_NextPart_000_000D_01C9ECF2.3DBC2130"
[x-mailer:] => Microsoft Office Outlook 11
[thread-index:] => AcnsLc/B6Buo60PZRDSy3rizT2ohrQA7k2mQ
[x-mimeole:] => Produced By Microsoft MimeOLE V6.00.2900.3350
[x-originalarrivaltime:] => 14 Jun 2009 18:16:15.0106 (UTC) FILETIME=[346AEE20:01C9ED1C]
[x-spam-status:] => No, score=-3.5
[x-spam-score:] => -34
[x-spam-bar:] => ---
[x-spam-flag:] => NO
[x-scamdex-scores:] => S:66 P:72 A:70 L:62 E:67 G:57
[x-scamdex-classtype:] => P
[x-scamdex-classscore:] => 72
[x-scamdex-totscore:] => 394
[x-scamdex-kw:] => 000.000,access,account,card,contact,credit,customer,ended,inc.,log in,login,payment,process,report,safe,sent,service,user,verification,verify
[x-scamdex-em:] => TheSystem@yellove.it,c_kub@msn.com,c_kub@msn.comS,info@hi5.com,info@hi5.comM,yellovei@lnx01.host
[x-scamdex-dir:] => D
[x-scamdex-id:] => D1245003384.H431329P15179
[x-scamdex-copyright:] => This Email is Copyright Scamdex.com 2009, Reproduction Prohibited
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
X-Message-Delivery:
Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtTQ0w9Ng== X-Message-Status: n:0 X-SID-PRA:
yellovei@lnx01.hostingbay.it X-Message-Info:
6sSXyD95QpWPq0UkPMFhJfHQkHUy20Ca9xrlvIsJwDvnY10LbiAy5i6PNpBWVUog2oKJq2xTCzXzLBnRwt3De427/QtXygjT Received:
from lnx01.hostingbay.it ([81.174.66.26]) by bay0-mc11-f15.bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.2668); Sat, 13 Jun 2009 06:49:46
-0700 Received: from yellovei by lnx01.hostingbay.it with local (Exim
4.69) (envelope-from <yellovei@lnx01.hostingbay.it>) id
1MFTc9-0007x6-U1 for c_kub@msn.com;
Sat, 13 Jun 2009 15:49:45 +0200 To: c_kub@msn.com Subject: We have restricted
access to your Chase Online Account msg#0001 X-PHP-Script:
yellove.it/images/cache.php for 201.143.211.167 Message-ID: <TheSystem@yellove.it> X-Priority:
3 X-Mailer: php From: JP Morgan Chase - Fraud Department <info@hi5.com> Reply-To: info@hi5.com MIME-Version:
1.0 Content-Type: text/html Content-Transfer-Encoding:
8bit Sender: <yellovei@lnx01.hostingbay.it> Date:
Sat, 13 Jun 2009 15:49:45 +0200 Return-Path: yellovei@lnx01.hostingbay.it X-OriginalArrivalTime:
13 Jun 2009 13:49:47.0121 (UTC) FILETIME=[D06C4610:01C9EC2D]
From: yellovei@lnx01.hostingbay.it
[mailto:yellovei@lnx01.hostingbay.it] On Behalf Of JP Morgan Chase -
Fraud Department Sent: Saturday, June 13, 2009 8:50 AM To:
c_kub@msn.com Subject: We have restricted access to your Chase Online
Account msg#0001
X-Message-Delivery:
Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtTQ0w9Ng== X-Message-Status: n:0 X-SID-PRA:
yellovei@lnx01.hostingbay.it X-Message-Info:
6sSXyD95QpWPq0UkPMFhJfHQkHUy20Ca9xrlvIsJwDvnY10LbiAy5i6PNpBWVUog2oKJq2xTCzXzLBnRwt3De427/QtXygjT Received:
from lnx01.hostingbay.it ([81.174.66.26]) by bay0-mc11-f15.bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.2668); Sat, 13 Jun 2009 06:49:46
-0700 Received: from yellovei by lnx01.hostingbay.it with local (Exim
4.69) (envelope-from <yellovei@lnx01.hostingbay.it>) id
1MFTc9-0007x6-U1 for c_kub@msn.com;
Sat, 13 Jun 2009 15:49:45 +0200 To: c_kub@msn.com Subject: We have restricted
access to your Chase Online Account msg#0001 X-PHP-Script:
yellove.it/images/cache.php for 201.143.211.167 Message-ID: <TheSystem@yellove.it> X-Priority:
3 X-Mailer: php From: JP Morgan Chase - Fraud Department <info@hi5.com> Reply-To: info@hi5.com MIME-Version:
1.0 Content-Type: text/html Content-Transfer-Encoding:
8bit Sender: <yellovei@lnx01.hostingbay.it> Date:
Sat, 13 Jun 2009 15:49:45 +0200 Return-Path: yellovei@lnx01.hostingbay.it X-OriginalArrivalTime:
13 Jun 2009 13:49:47.0121 (UTC) FILETIME=[D06C4610:01C9EC2D]
From: yellovei@lnx01.hostingbay.it
[mailto:yellovei@lnx01.hostingbay.it] On Behalf Of JP Morgan Chase -
Fraud Department Sent: Saturday, June 13, 2009 8:50 AM To:
c_kub@msn.com Subject: We have restricted access to your Chase Online
Account msg#0001
Dear Customer, During our regularly scheduled account
maintenance and verification procedures, we have detected a slight error
in your billing information.
This might be due to either of the
following reasons:
1. A
recent change in your personal information ( i.e.change of
address). 2. Submiting invalid information during the initial
sign up process. 3. An inability to accurately verify your
selected option of payment due to an internal error within our
processors.
We have decided to put you in an extra verification
process to make sure that your account is safe and the same person is
using it as when it was opened and in the same time ensure the security
that only JPMorgan Chase & Co can offer its
customers. Login to your Chase
Online account to resolve this problem.
We apologize for any
inconvenience.
Sincerely, Chase Online Accounts
Department
E-mail Security
Information
E-mail intended for: Customer.
If you are
concerned about the authenticity of this message, please click
here or call the phone number on the back of your credit
card and reference the Chase Library Code: 0808ePay. If you
would like to learn more about e-mail security or want to
report a suspicious e-mail, click
here.
Note: If you are concerned about
clicking links in this e-mail, the Chase Online services
mentioned above can be accessed by typing www.chase.com/creditcards directly into your
browser.
ABOUT THIS MESSAGE: This service message
was delivered to you as a Chase Credit Card customer to provide you with
account updates and information about your card benefits. Chase values
your privacy and your preferences.
If you want to contact Chase,
please do not reply to this message, but instead go to http://www.chase.com/creditcards. For faster service,
please enroll or log in to your account. Replies to this message will not
be read or responded to.
Your personal information is protected by
state-of-the-art technology. For more detailed security information, view
our Online Privacy Policy. To request in writing: Chase
Privacy Operations, 451 Florida Street, Fourth Floor, LA2-9376, Baton
Rouge, LA 70801