An
Email with the Subject "Your Latest Statement & Charges Is Available" was
received in one of Scamdex's honeypot email accounts on Wed, 13 Jul 2011 11:11:06 -0700
and has been classified as a Generic Scam Email.
The sender shows as HALIFAX BANK <online_security@halifax.co.uk>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
halifaxbanksuspendendedpasswordaccountresidentcustomerserviceaccessprocesscustomonlinebank online banksharenhalifax bank usersecurity
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[return-path:] =>
[envelope-to:] => submitted@scamdex.com
[delivery-date:] => Wed, 13 Jul 2011 11:11:06 -0700
[received:] => Array
(
[0] => from mailrelay.daycohost.net ([200.74.193.139] helo=vsmailgate04.daycohost.net)by chester.loopbiz.com with esmtp (Exim 4.69)(envelope-from )id 1Qh3to-0005XN-2Qfor submitted@scamdex.com; Wed, 13 Jul 2011 11:11:06 -0700
[1] => from vsmailshared1.daycohost.net (unknown [200.74.199.18])by vsmailgate04.daycohost.net (Postfix) with ESMTP id 3B5D1499for ; Wed, 13 Jul 2011 13:02:54 -0430 (VET)
[2] => from localhost (localhost.localdomain [127.0.0.1])by vsmailshared1.daycohost.net (Postfix) with ESMTP id 7AAC8441ECFfor ; Wed, 13 Jul 2011 13:40:38 -0430 (VET)
[3] => from vsmailshared1.daycohost.net ([127.0.0.1])by localhost (vsmailshared1.daycohost.net [127.0.0.1]) (amavisd-new, port 10024)with ESMTP id StS8zvQ3Zx5I for ;Wed, 13 Jul 2011 13:40:38 -0430 (VET)
[4] => from daycohost.com (unknown [200.74.207.3])by vsmailshared1.daycohost.net (Postfix) with ESMTP id EBEEF441F04for ; Wed, 13 Jul 2011 13:39:42 -0430 (VET)
[5] => (qmail 14630 invoked by uid 48); 13 Jul 2011 10:31:06 -0430
)
[x-spam/virus-scanned:] => Spamassassin/ClamAV at vsmailcheckn1.daycohost.com
[date:] => 13 Jul 2011 10:31:06 -0430
[message-id:] => <20110713150106.14621.qmail@daycohost.com>
[x-additional-header:] => /var/www/vhosts/ciemi.org.ve/httpdocs/pdf
[to:] => submitted@scamdex.com
[subject:] => Your Latest Statement & Charges Is Available
[from:] => HALIFAX BANK
[reply-to:] =>
[mime-version:] => 1.0
[content-type:] => text/html
[content-transfer-encoding:] => quoted-printable
[x-spam-status:] => No, score=3.8
[x-spam-score:] => 38
[x-spam-bar:] => +++
[x-ham-report:] => Spam detection software, running on the system "chester.loopbiz.com", hasidentified this incoming email as possible spam. The original messagehas been attached to this so you can view it (if it isn't spam) or labelsimilar future email. If you have any questions, seethe administrator of that system for details.Content preview: Halifax - Welcome to Online Welcome to Online In order touse our Online Service your browser must support JavaScript. It appears thatyour browser does not currently support JavaScript, or it may have its JavaScriptsupport disabled. [...] Content analysis details: (3.8 points, 4.0 required)pts rule name description---- ---------------------- --------------------------------------------------2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL[200.74.193.139 listed in psbl.surriel.com]0.0 HTML_MESSAGE BODY: HTML included in message1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
[x-spam-flag:] => NO
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
In order to use our Online Service your browser must support _javascript_. It appears that your browser does not currently support _javascript_, or it may have its _javascript_ support disabled.
Please note that the "Remember my username" facility is not available when _javascript_ is disabled.
If you are not a UK resident, or are trying to access this site from outside the UK,please read this important message
Halifax is a division of Bank of Scotland plc. Registered in Scotland No. SC327000. Registered Office: The Mound, Edinburgh, EH1 1YZ.
Welcome to Online
In order to use our Online Service your browser must support _javascript_. It appears that your browser does not currently support _javascript_, or it may have its _javascript_ support disabled.
Please note that the "Remember my username" facility is not available when _javascript_ is disabled.
New To Online
New to Online
Complete our easy registration process.
Click on the relevant button below:
Stage 1:
Register my details
Start registration
Stage 2:
I've received my temporary password
Complete registration
Employee Share Scheme Customers
Register for Employee Share Schemes
Sign In
Sign In
Username
Password
Your mother's first name?
Remember my username*
*Do not select if this computer is used by anyone else.
More information about storing usernames
Useful infoFind out how Online works using our demoWhy use Online Banking?Apply for a new account
Problem signing in?Forgotten sign in details / access suspended?Service availabilityAre your phone details up to date?
If you are not a UK resident, or are trying to access this site from outside the UK,please read this important message
Halifax is a division of Bank of Scotland plc. Registered in Scotland No. SC327000. Registered Office: The Mound, Edinburgh, EH1 1YZ.