Ransomware
Abuser: blackmail
Your account was recently hacked! Change the pswd right away! You might not heard about me and you obviously are most likely surprised why you're getting this e-mail, right?
Poland, 2019-03-06 12:04:33Your account was recently hacked! Change the pswd right away! You might not heard about me and you obviously are most likely surprised why you're getting this e-mail, right?
Poland, 2019-03-06 12:04:33Your account was recently hacked! Modify the password this time! You might not know me me and you really are most probably interested why you're reading this electronic message, right? I am ahacker who exploitedyour emailand OSa few months ago. Do not try out to talk to me or seek for me, it's impossible, considering that I directed you this message from YOUR account that I've hacked.
United States, 2019-03-06 16:45:44send $1000 or we send videos of you to your contact list.
United States, 2019-03-06 19:16:42Spoofed e-mail sent from the following domain: X-AntiAbuse: Sender Address Domain - bosstrinidad.com X-Get-Message-Sender-Via: ux4.ultragate.com: authenticated_id: [email protected] X-Authenticated-Sender: ux4.ultragate.com: [email protected]
United States, 2019-03-07 08:04:00Scam email; pretended to have planted malware on my computer recording porn viewing habits and wanted 1000 USD for his silence.
Australia, 2019-03-07 10:12:10Usual alleged webcam blackmail scam, sent to an address leaked from nethouseprices.com
United Kingdom, 2019-03-07 11:07:35I exploited your email box and installed spear etc
United Kingdom, 2019-03-07 14:07:04Received: from mail.treslagoas.ms.gov.br (mail.treslagoas.ms.gov.br [179.191.12.27]) --- Received: from localhost (localhost [127.0.0.1]) by mail.treslagoas.ms.gov.br (Postfix) with ESMTP id 4AE257B0CE7 --- Received: from mail.treslagoas.ms.gov.br ([127.0.0.1]) by localhost (mail.treslagoas.ms.gov.br [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id h8yxX1F9Fzsj --- Received: from localhost (localhost [127.0.0.1]) by mail.treslagoas.ms.gov.br (Postfix) with ESMTP id B02E47B0C44 --- Received: from mail.treslagoas.ms.gov.br ([127.0.0.1]) by localhost (mail.treslagoas.ms.gov.br [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id yQyx_rdFDZbM --- Received: from [170-83-88-17.netribas.net.br] (unknown [170.83.88.2]) by mail.treslagoas.ms.gov.br (Postfix) with ESMTPSA id C270E7B0AB0 --- Return-Path: <[email protected]>
Canada, 2019-03-07 16:58:53Sent a spoofed email and demanded 1000 dollars to this wallet.
United States, 2019-03-07 19:06:25Hi, your account was recently hacked! Change the pswd right away! You may not know me me and you really are definitely wondering why you are getting this email, proper? I'm ahacker who crackedyour emailand digital devicestwo months ago.
Canada, 2019-03-07 19:36:58Details from Email header: X-Sender [email protected] X-Source-IP 202.162.196.135 X-Sender-Auth [email protected] X-Local-Domain programmersbd.com This IP address 202.162.196.135 checks out to originate from Indonesia. Source: whois.apnic.netIP netname: NUSANET descr: PT. Media Antar Nusa descr: Medan country: ID address: PT. Media Antar Nusa address: Internet Service Provider address: Jakarta, Indonesia e-mail: [email protected] abuse-mailbox: [email protected] person: Rully Sumbayak address: PT. Media Antar Nusa address: NUSANET address: Kompleks Multatuli Indah, Blok D No. 1 address: Medan 20151 country: ID phone: +62-61-4558100 e-mail: [email protected]
Australia, 2019-03-07 23:28:48Sending email to me in regards to the email being hacked and asking for ransom.
Hong Kong, 2019-03-08 06:46:25Demanding payment or release of supposed hacked video and webcam logs.
United States, 2019-03-08 14:26:49Note, that is just the email listed in the EHLO that spoofed the from address. Here is the full EHLO line: Received: from unknown (EHLO [rrcs-70-61-166-78.central.biz.rr.com]) (70.61.166.78) by server4204.maintenis.com (Spanel SMTPD 1.3.16.011) with SMTP auth ([email protected], account=k0843744) id c5e11ccf06aceae010d8a639c40e31e3; 07 Mar 2019 15:51:06 +0000
United States, 2019-03-08 17:42:02this hacker is asking for $1000 in bitcoin; another cut/paste email asking for ransom otherwise he's going to release an alleged video. I got 3 of these emails this morning from different accounts, so it appears that these guys are selling email lists of people they've hacked.
United States, 2019-03-08 20:19:40