An
Email with the Subject "Belangrijke mededeling" was
received in one of Scamdex's honeypot email accounts on Thu, 29 Aug 2013 07:55:51 -0700 (PDT)
and has been classified as a Generic Scam Email.
The sender shows as BNP <prensa@mrecic.gov.ar>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
bankcontactaccountserviceclientinternetonlineach
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[delivered-to:] => scamdex@gmail.com
[received:] => Array
(
[0] => by 10.224.50.65 with SMTP id y1csp14387qaf; Thu, 29 Aug 2013 07:55:51 -0700 (PDT)
[1] => from mx2.mrecic.gov.ar (mx2.mrecic.gov.ar. [200.16.110.15]) by mx.google.com with ESMTP id f5si1620028yhd.105.1969.12.31.16.00.00; Thu, 29 Aug 2013 07:55:51 -0700 (PDT)
[2] => from mrelmx07.mrec.ar ([140.191.48.38]) by mx2.mrecic.gov.ar with ESMTP; 29 Aug 2013 11:46:26 -0300
[3] => from localhost (localhost.localdomain [127.0.0.1])by mrelmx07.mrec.ar (Postfix) with ESMTP id F1CC2160E7;Thu, 29 Aug 2013 11:46:25 -0300 (ART)
[4] => from mrelmx07.mrec.ar ([127.0.0.1])by localhost (mrelmx07.mrec.ar [127.0.0.1]) (amavisd-new, port 10024)with ESMTP id hESpq350Wxpw; Thu, 29 Aug 2013 11:46:19 -0300 (ART)
[5] => from mrelmx05.mrec.ar (mrelmx09.mrec.ar [140.191.48.41])by mrelmx07.mrec.ar (Postfix) with ESMTP id 30E0C71C88;Thu, 29 Aug 2013 11:46:14 -0300 (ART)
)
[x-received:] => by 10.236.181.194 with SMTP id l42mr3371030yhm.26.1377788151014; Thu, 29 Aug 2013 07:55:51 -0700 (PDT)
[return-path:] =>
[received-spf:] => pass (google.com: domain of prensa@mrecic.gov.ar designates 200.16.110.15 as permitted sender) client-ip=200.16.110.15;
[authentication-results:] => Array
(
[0] => mx.google.com; spf=pass (google.com: domain of prensa@mrecic.gov.ar designates 200.16.110.15 as permitted sender) smtp.mail=prensa@mrecic.gov.ar; dkim=pass header.i=@mrecic.gov.ar
[1] => mx2.mrecic.gov.ar; dkim=neutral (message not signed) header.i=none
)
[dkim-signature:] => v=1; a=rsa-sha256; c=relaxed/relaxed; d=mrecic.gov.ar; i=@mrecic.gov.ar; q=dns/txt; s=mrecic; t=1377788150; x=1409324150; h=date:from:message-id:subject:mime-version:to; bh=Ucvk595/Lwgm32MSq+w5IIJkZ2rqlRc5SbfJcu86PZE=; b=izTevmz6KHASrPpoH/rY2Zb+SPikfBVBreq+IPGZc5Lv3BE4rR37YfYz bFV5yJ9+ed6gkHcaMLcrX2wdIbg8ht4L2PeOENLls9SQahfDXZbO13iic 6azmaK31qheppPVKLyTvfKAgtT3MCK/sWxwwSsnn6xr0laE0bbcg3Jj+t M=;
[x-ironport-anti-spam-filtered:] => true
[x-ironport-anti-spam-result:] => AuMDAIA5FVGMvzAmkGdsb2JhbABFgkmEBKd6JohyAYQYhRIWDgEBAQESKCYBghcyJVAlBBUCLQM1AQWFfYIbAgqdYo5VhCCOGY4ngiKBEwOEaok3iAmBF4U2jRqCCg
[x-ipas-result:] => AuMDAIA5FVGMvzAmkGdsb2JhbABFgkmEBKd6JohyAYQYhRIWDgEBAQESKCYBghcyJVAlBBUCLQM1AQWFfYIbAgqdYo5VhCCOGY4ngiKBEwOEaok3iAmBF4U2jRqCCg
[x-ironport-av:] => E=Sophos;i="4.84,630,1355108400"; d="scan'208,217";a="14752269"
[x-virus-scanned:] => amavisd-new at mrelmx07.mrec.ar
[date:] => Thu, 29 Aug 2013 11:46:14 -0300 (ART)
[from:] => BNP
[message-id:] => <423203171.464937.1377787574157.JavaMail.root@mrelmx09.mrec.ar>
[subject:] => Belangrijke mededeling
[mime-version:] => 1.0
[content-type:] => multipart/alternative; boundary="----=_Part_464936_348973704.1377787574154"
[x-originating-ip:] => [200.16.110.42]
[x-mailer:] => Zimbra 6.0.6_GA_2330.DEBIAN5_64 (zclient/6.0.6_GA_2330.DEBIAN5_64)
[to:] => undisclosed-recipients:;
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
Houd
er rekening mee dat de toegang tot uw online account dreigt te
verlopen. Om de toegang tot uw online account actief te houden, vragen
wij u dan gelieve om zo snel mogelijk te inloggen. Gebruik de
onderstaande link om verder te gaan en toegang te krijgen tot uw
account. Na dat u gebruik heeft gemaakt van de onderstaande link zal er
door een van onze medewerkers nog contact met u worden opgenomen om het
gehele proces te voltooien. Wanneer het gehele proces gereed is zal u
weer als vanouds gebruik kunnen maken van uw BNP PARIBAS FORTIS online.
Met
toegang tot uw BNP PARIBAS FORTIS online kunt u het grootste deel van
uw bankverrichtingen uitvoeren. Alles wat u nodig hebt is u aanmelden
bij internet bankieren.
Wij willen u alvast bedanken voor uw medewerking.
Hoogachtend,
Klantenservice.
Geachte BNP PARIBAS FORTIS Client, Houd
er rekening mee dat de toegang tot uw online account dreigt te
verlopen. Om de toegang tot uw online account actief te houden, vragen
wij u dan gelieve om zo snel mogelijk te inloggen. Gebruik de
onderstaande link om verder te gaan en toegang te krijgen tot uw
account. Na dat u gebruik heeft gemaakt van de onderstaande link zal er
door een van onze medewerkers nog contact met u worden opgenomen om het
gehele proces te voltooien. Wanneer het gehele proces gereed is zal u
weer als vanouds gebruik kunnen maken van uw BNP PARIBAS FORTIS online. Klik hier
Met
toegang tot uw BNP PARIBAS FORTIS online kunt u het grootste deel van
uw bankverrichtingen uitvoeren. Alles wat u nodig hebt is u aanmelden
bij internet bankieren. Wij willen u alvast bedanken voor uw medewerking. Hoogachtend,Klantenservice.