An
Email with the Subject "Re: To All Webmail Account Owner" was
received in one of Scamdex's honeypot email accounts on Mon, 06 Feb 2012 01:37:09 -0800
and has been classified as a Phishing, ID Theft Scam Email.
The sender shows as andreas.zweifel@uzh.ch.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
passwordaccountserviceprocessverifymailuserwebmailin-active will spammaintenance(***********) and passwor...dear
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[return-path:] =>
[envelope-to:] => josh@scamdex.com
[delivery-date:] => Mon, 06 Feb 2012 01:37:09 -0800
[received:] => Array
(
[0] => from idmailgate2.uzh.ch ([130.60.127.101])by lester.newsblaze.com with esmtps (TLSv1:AES256-SHA:256)(Exim 4.69)(envelope-from )id 1RuL0W-0005xf-8Lfor josh@scamdex.com; Mon, 06 Feb 2012 01:37:09 -0800
[1] => from virus3.uzh.ch (virus3.uzh.ch [130.60.69.43])by idmailgate2.uzh.ch (8.14.3/8.14.3/SuSE Linux 0.8) with ESMTP id q169b4qc022064for ; Mon, 6 Feb 2012 10:37:04 +0100
[2] => from idmailgate2.uzh.ch ([130.60.127.101])by virus3.uzh.ch (virus3.uzh.ch [130.60.69.43]) (amavisd-new, port 10024)with LMTP id gcC6zdzFjQ3r for ;Mon, 6 Feb 2012 10:37:04 +0100 (CET)
[3] => from idsmtp01.uzh.ch (idsmtp01.uzh.ch [130.60.206.120])by idmailgate2.uzh.ch (8.14.3/8.14.3/SuSE Linux 0.7) with ESMTP id q169b4LG022058(version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO)for ; Mon, 6 Feb 2012 10:37:04 +0100
[4] => from idlmail02.uzh.ch ([130.60.207.43])by idsmtp01.uzh.ch with esmtp (Exim 4.71)(envelope-from )id 1RuKwm-0003ga-U6for josh@scamdex.com; Mon, 06 Feb 2012 10:33:16 +0100
)
[x-virus-scanned:] => amavisd-new at uzh.ch
[x-disclaimed:] => 1
[mime-version:] => 1.0
[importance:] => Normal
[x-priority:] => 3 (Normal)
[in-reply-to:] =>
[references:] =>
[subject:] => Re: To All Webmail Account Owner
[from:] => andreas.zweifel@uzh.ch
[date:] => Mon, 6 Feb 2012 10:32:20 +0100
[message-id:] =>
[x-mailer:] => Lotus Domino Web Server Release 8.5.3HF240 December 29, 2011
[x-mimetrack:] => Serialize by Notes Server on idlmail02/Server/UZH(Release 8.5.3HF240 | December29, 2011) at 02/06/2012 10:32:20 AM,Serialize complete at 02/06/2012 10:32:20 AM,Serialize by Router on idlmail02/Server/UZH(Release 8.5.3HF240 | December29, 2011) at 02/06/2012 10:32:31 AM
[content-type:] => text/html; charset=UTF-8
[content-transfer-encoding:] => quoted-printable
[x-notes-item:] => josh@scamdex.com; name=AltBlindCopyTo
[to:] => undisclosed-recipients:;
[x-spam-status:] => No, score=1.7
[x-spam-score:] => 17
[x-spam-bar:] => +
[x-ham-report:] => Spam detection software, running on the system "lester.newsblaze.com", hasidentified this incoming email as possible spam. The original messagehas been attached to this so you can view it (if it isn't spam) or labelsimilar future email. If you have any questions, seethe administrator of that system for details.Content preview: Dear Webmail Account Owner, We are currently carrying outa Maintenance/Upgrade Process on Webmail accounts, to complete this processyou must respond to this email immediately, and enter your User Name here() and Password here (), or click here to verify your webmail, we are verysorry for the inconvenience we are making you pass through this period. [...]Content analysis details: (1.7 points, 4.0 required)pts rule name description---- ---------------------- ---------------------------------------------------0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relaydomain-0.0 SPF_PASS SPF: sender matches SPF record0.0 HTML_MESSAGE BODY: HTML included in message1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
[x-spam-flag:] => NO
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
We are currently carrying out a Maintenance/Upgrade Process on Webmail accounts, to complete this process you must respond to this email immediately, and enter your User Name here (***********) and Password here (***********), or click here to verify your webmail, we are very sorry for the inconvenience we are making you pass through this period.
This process we help us to fight against Spam Emails. Failure to summit your password, will render your email address in-active from our Webmail system.
NOTE: Your email will not be tampered with or changed.
Thank you for using Webmail Service ****************************** ******************* Webmail Technical Support  2012 Copyright. All Rights Reserved!
Dear Webmail Account Owner,
We are currently carrying out a Maintenance/Upgrade Process on Webmail accounts, to complete this process you must respond to this email immediately, and enter your User Name here (***********) and Password here (***********), or click here to verify your webmail, we are very sorry for the inconvenience we are making you pass through this period.
This process we help us to fight against Spam Emails. Failure to summit your password, will render your email address in-active from our Webmail system.
NOTE: Your email will not be tampered with or changed.
Thank you for using Webmail Service ****************************** ******************* Webmail Technical Support  2012 Copyright. All Rights Reserved!