Blackmail scam
Abuser: Spammer
Subject: High level of danger. Your account was under attack.
Subject: High level of danger. Your account was under attack.
I have very bad news for you. 17/07/2019 - on this day I hacked your OS and got full access to your account You can check it - I sent this message from your account. ...
Hello other victims. The abuser used a vulnerability of your mail server to fake his email address. A possible solution is to ask your admin to add a DNS SPF entry to your mail server, example for single domain: @ IN TXT "v=spf1 mx -all" Good luck!
"And I got an idea.... I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?). After that, I made a screenshot of your joys (using the camera of your device) and glued them together. Turned out amazing! You are so spectacular! I'm know that you would not like to show these screenshots to your friends, relatives or colleagues. I think $951 is a very, very small amount for my silence. Besides, I have been spying on you for so long, having spent a lot of time!"
So, you can change the password, yes.. But my malware intercepts it every time. How I made it: In the software of the router, through which you went online, was a vulnerability. I just hacked this router and placed my malicious code on it. When you went online, my trojan was installed on the OS of your device. After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts). A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock. But I looked at the sites that you regularly visit, and I was shocked by what I saw!!!
Received: from host109-158-99-160.range109-158.btcentralplus.com ([109.158.99.160]:13690) Content-Transfer-Encoding: 8bit X-Mailer: Microsoft Office Outlook 12.0 Thread-Index: Ac59pvr38imqekvu59pvr38imqekvu== Content-Language: en x-cr-hashedpuzzle: 2D4= pvr3 8imq ekvu 59pv r38i mqek vu59 pvr3 8imq ekvu 59pv r38i mqek vu70 jd2k;1;cica01ly70jd2kcica01ly70jd2kcica01ly70jd2kcica01;Sosha1_v1;7;\{EDE9CD50-25C9-74B8-BC98-05709C21EDE9\};ZQB3AGUAZgjd2kcica01ly70jd2kcica01ly70jd2kcica01;9 Oct 2019 16:04:14 +0000;ly70jd2kcica01ly x-cr-puzzleid: \{EDE9CD50-25C9-74B8-BC98-05709C21EDE9\} X-From-Rewrite: unmodified, no actual sender determined from check mail permissions Pay ONLY in Bitcoins! My BTC wallet: 15yF8WkUg8PRjJehYW4tGdqcyzc4z7dScM You do not know how to use bitcoins? Enter a query in any search engine: "how to replenish btc wallet". It's extremely easy For this payment I give you two days (48 hours). As soon as this letter is opened, the timer will work.
The same spoof email that looks like it is coming from your computer. Don't pay these people -- it's all a scam.
same email "screen shots" from adult websites
Email claims to have "hacked OS" and "has full access" "Hello!, I have very bad news for you. 17/07/2019 - on this day I hacked your OS and got full access to your account........" Perpretrator targets your published email address and also guesses others that may exist on your domain i.e. admin@ , administrator@ , etc 3 samples, internet headers quoted (NOTE THESE LIKELY ARE INNOCENT VICTIMS) User: phcomput Domain: ph-computers.com From Address: <Spoofed - chose destination address> Sender: sales AT <Domain> Sent Time: Oct 8, 2019, 9:51:21 PM Sender Host: 181.210.135.146 User: citrusco Domain: hdmedia.uk From Address: <Spoofed - chose destination address> Sender: henry AT <Domain> Sent Time: Oct 8, 2019, 9:54:21 PM Sender Host: 190.4.3.82 User: electrom Domain: electromechcontracts.com From Address: <Spoofed - chose destination address> Sender: mail AT <Domain> Sent Time: Oct 8, 2019, 10:52:22 PM Sender Host: adsl-ull-162-35.51-151.wind.it
So, you can change the password, yes.. But my malware intercepts it every time. How I made it: In the software of the router, through which you went online, was a vulnerability. I just hacked this router and placed my malicious code on it. When you went online, my trojan was installed on the OS of your device. After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts). A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock. But I looked at the sites that you regularly visit, and I was shocked by what I saw!!! I'm talk you about sites for adults. I want to say - you are a BIG pervert. Your fantasy is shifted far away from the normal course! And I got an idea.... I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?).
is going to ruin the life of non existing person if the don't receive money. ruin away you fucking dumbass.
this dumbass sent sextortion emails to 8 different made up email addresses just so he can prove how credible he is at hacking email accounts. I stopped looking at 8 I'm sure there were more.
How I made it: In the software of the router, through which you went online, was a vulnerability. I just hacked this router and placed my malicious code on it. When you went online, my trojan was installed on the OS of your device. After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts). A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock. But I looked at the sites that you regularly visit, and I was shocked by what I saw!!! I'm talk you about sites for adults. I want to say - you are a BIG pervert. Your fantasy is shifted far away from the normal course!
Sextortion/ransomware. Also uses impersonation for email sender.
mail spam mail spam