Ransomware
Abuser: Spoofed email
"I've been watching you for a few months now. But the fact is that you were infected with malware through an adult site that you visited."
United States, 2019-03-29 17:01:58"I've been watching you for a few months now. But the fact is that you were infected with malware through an adult site that you visited."
United States, 2019-03-29 17:01:58Same old story - "I have hacked your account and have a sex tape of you"
France, 2019-03-29 18:15:08Just another idiot piece of shit scammer living in a shithole country.
United States, 2019-03-29 18:25:26Wants $792 this time...
United States, 2019-03-29 18:35:40same old same old
United States, 2019-03-29 19:26:29"I sent you an email from your account" No, you sent it from 46.5.7.33, kabel-badenwuerttemberg.de. "This means that I have access to your account" No, if you did, the email would also be in my sent folder. "Your account you had this password" No, that was used on bit.ly. "I've been watching you" No. "The fact is you were infected with malware through an adult site" No, you are a lying troll with a useless password sending fake emails. "I can see everything, turn on the camera and microphone" Nope - no camera or microphone. "I have access to all your data" No you don't. "Why your antivirus did not detect my malware?" Ahhh... I guess cause there isn't any? "I made a video" No you did not. Remember, no camera. "I can send this video" No you can't, it does not exist. "If you want to prevent this" Ahhh... What? "Pay $748" Errr... No. "If I find that you have shared this message with someone else, the video will be immediately distributed" Go for it. "I do not make any mistakes" LOL
Canada, 2019-03-29 21:10:42Extortion. Must have bought old password. Claims to have videos. Isn’t there a way for the FBI to track this bitcoin address to the lowlife using it?
United States, 2019-03-29 22:10:39Received: from [5.172.236.223] (helo=ip-5-172-236-223.multi.internet.cyfrowypolsat.pl)
Australia, 2019-03-30 00:58:13Using a real password stolen from a website hack. Sextortion claiming trojan. Ignore claims. TIP: Ensure you never use that password again or even better, use a password manager to have complex unique passwords for each account you make.
Canada, 2019-03-30 02:53:02Please remove this person from humanity. They threaten: "Why your antivirus did not detect my malware? Answer: My malware uses the driver, I update its signatures every 4 hours so that your antivirus is silent. I made a video showing how you satisfy yourself in the left half of the screen, and in the right half you see the video that you watched. With one click of the mouse, I can send this video to all your emails and contacts on social networks. I can also post access to all your e-mail correspondence and messengers that you use. If you want to prevent this, transfer the amount of $759 to my bitcoin address (if you do not know how to do this, write to Google: "Buy Bitcoin"). My bitcoin address (BTC Wallet) is: 1GB22WpNfFPcAYnad1Sd3qWoVJeDbtN72M After receiving the payment, I will delete the video and you will never hear me again. I give you 48 hours to pay. I have a notice reading this letter, and the timer will work when you see this letter."
United States, 2019-03-30 03:40:06It look like with connect to another Bitcoin Address "1LygPTbNxFr3RzoBRzwBifQXmE7sCZwM9p" Before I received email ask to pay on the about Bitcoin address and now "1GB22WpNfFPcAYnad1Sd3qWoVJeDbtN72M"
Republic of Korea, 2019-03-30 05:44:03Return-Path: <[email protected]> Received: from bospopproxy10.eigbox.net ([10.20.15.8]) by bospop25.eigbox.net with LMTP id ULAcKbqPnVwaCQAAwL5MkA for Received: from bosmailscan08.eigbox.net ([10.20.15.8]) by bospopproxy10.eigbox.net with LMTP id MIcBKbqPnVwwOgAA4E6j5g ; Thu, 28 Mar 2019 23:23:38 -0400 Return-path: <[email protected]> Envelope-to: Delivery-date: Thu, 28 Mar 2019 23:23:38 -0400 Received: from [10.115.3.12] (helo=smtp.maileig.com) by bosmailscan08.eigbox.net with esmtp (Exim) id 1h9i7G-000570-IM for ; Thu, 28 Mar 2019 23:23:38 -0400 Received: from ns1.jtfassociates.net ([72.44.90.9]) by bosimpinc12 with bizsmtp id tfPa1z00H0C6QbL01fPe7P; Thu, 28 Mar 2019 23:23:38 -0400 X-EN-OrigIP: 72.44.90.9 X-EN-IMPSID: tfPa1z00H0C6QbL01fPe7P
Singapore, 2019-03-30 08:45:47Subject: High danger. Your account was attacked. Hi! As you may have noticed, I sent you an email from your account. This means that I have full access to your account: ... Answer: My malware uses the driver, I update its signatures every 4 hours so that your antivirus is silent. I made a video showing how you satisfy yourself in the left half of the screen, and in the right half you see the video that you watched. With one click of the mouse, I can send this video to all your emails and contacts on social networks. I can also post access to all your e-mail correspondence and messengers that you use. If you want to prevent this, transfer the amount of $763 to my bitcoin address (if you do not know how to do this, write to Google: "Buy Bitcoin"). My bitcoin address (BTC Wallet) is: 1GB22WpNfFPcAYnad1Sd3qWoVJeDbtN72M After receiving the payment,...
Singapore, 2019-03-30 08:54:55Claims stolen password bla bla bla...
Italy, 2019-03-30 09:17:06Claims stolen password bla bla bla...
Italy, 2019-03-30 09:18:57