Ransomware
Abuser: Some sad person
Same bullshit story again.
Netherlands, 2021-07-11 23:01:02Same bullshit story again.
Netherlands, 2021-07-11 23:01:02Same description as all others
United States, 2021-07-11 23:27:06Same as below
United States, 2021-07-12 04:22:36Seems they sent this to me twice... same as the others
United States, 2021-07-12 04:23:51Claimed to put a so-called trojan on my system and stole personal information. Wants payment in exchange not to disclose. If a third party is hosting this wallet address, notify the authorities of this criminal activity.
United States, 2021-07-12 04:51:36I am sorry to inform you that your device was compromised. I'll explain what led to all of this. I have used a Zero Day vulnerability with a special code to infect your device through a website. This is a complicated software that requires precise skills that I have. It works as a chain with specially crafted and unique code and that’s why this type of an attack can go undetected.
Ecuador, 2021-07-12 05:18:44a letter came to the mail of the organization with the address of the organization, demanding a ransom and payment for a bitcoin wallet. I enclose the text of the letter. You only need one not patched vulnerability to be infected, and unfortunately for you – it works that simple. You were not targeted specifically, but just became one of the quite a few unlucky people who got hacked that day. All of this happened a few month ago. So I’ve had time to collect information on you. I think you already know what is going to happen next. During that time, my software was quietly collecting information about your habits, websites that you visit, searches you do, texts you send. There is more to it, but I have listed a few reasons for you to understand how serious this is. For you to clearly understand, my software controlled your camera and microphone as well and it was impossible for you to know about it. It was just about right timing for me to get you privacy violated. I’ve been waiting enough and have decided that it’s time to put an end to this. So here is my offer. I need a consulting fee to delete the media content I have been collecting. Your privacy stays untouched, if I get paid. Otherwise, I will leak the most damaging content to your contacts and post it to a public tube for perverts to explore. I understand how damaging this will be for you, and amount is not that big for you to keep your privacy. Please dont blame me – we all have different ways of making a living. I have no intention of destroying your reputation or life, but only if I get paid. I don’t care about you personally, that's why you can be sure that all files I have and software on your device will be deleted immediately after I receive the transfer. I only care about getting paid. My modest consulting fee is 1650 US Dollars transferred in Bitcoin. Exchange rate at the time of the transfer. You need to send that amount to this wallet: 1HSb4fZHmyNro5LGyjQFpcDwqKjRUqJhh2
Russia, 2021-07-12 05:24:19So here is my offer. I need a consulting fee to delete the media content I have been collecting.
United States, 2021-07-12 05:29:36Was contacted and told they were infected through a website. Address and domain are spoofed coming from the actual Address IPs: 168-220-29-85.dyn.estpak.ee, 85.29.220.168
United States, 2021-07-12 16:37:41Asking for $1650 equivalent bitcoin deposit
United States, 2021-07-12 17:06:21Email sent to me about wanting money
United States, 2021-07-13 00:49:38I have no intention of destroying your reputation or life, but only if I get paid. I don’t care about you personally, that's why you can be sure that all files I have and software on your device will be deleted immediately after I receive the transfer. I only care about getting paid. My modest consulting fee is 1650 US Dollars transferred in Bitcoin. Exchange rate at the time of the transfer. You need to send that amount to this wallet: 1HSb4fZHmyNro5LGyjQFpcDwqKjRUqJhh2
Malaysia, 2021-07-13 01:28:11Received:from rain-197-185-100-205.rain.network (rain-197-185-100-205.rain.network [197.185.100.205] (may be forged)) Subject:Important Updates
France, 2021-07-13 07:07:02I think you already know what is going to happen next.... your btc address is getting reported, you scumbug.
Uruguay, 2021-07-13 16:20:04$1650 bitcoin extortion spam ---- Received: from abts-north-dynamic-174.118.161.122.airtelbroadband.in (unknown [122.161.118.174]) by xxx.xxx (Postfix) with ESMTP id 53287B204A for <[email protected]>; Sun, 11 Jul 2021 11:03:03 -0700 (PDT) Message-ID: <83F5D3ECCBA5CAF482A49BBCD2BD83F5@WWEVTV89> Subject: Important Updates Date: 12 Jul 2021 03:00:00 +0400 X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Windows Live Mail 15.4.3508.1109 X-MimeOLE: Produced By Microsoft MimeOLE V15.4.3508.1109 I am sorry to inform you that your device was compromised. I'll explain what led to all of this. I have used a Zero Day vulnerability with a special code to infect your device through a website. This is a complicated software that requires precise skills that I have. It works as a chain with specially crafted and unique code and that’s why this type of an attack can go undetected. You only need one not patched vulnerability to be infected, and unfortunately for you – it works that simple. You were not targeted specifically, but just became one of the quite a few unlucky people who got hacked that day. All of this happened a few month ago. So I’ve had time to collect information on you. I think you already know what is going to happen next. During that time, my software was quietly collecting information about your habits, websites that you visit, searches you do, texts you send. There is more to it, but I have listed a few reasons for you to understand how serious this is. For you to clearly understand, my software controlled your camera and microphone as well and it was impossible for you to know about it. It was just about right timing for me to get you privacy violated. I’ve been waiting enough and have decided that it’s time to put an end to this. So here is my offer. I need a consulting fee to delete the media content I have been collecting. Your privacy stays untouched, if I get paid.
United States, 2021-07-14 02:56:35