Abuse to Bitcoin address
1HYfCuh3t75bgP7KBQguuiq238sdYZCsvk

Blackmail scam

Abuser: kf@chengmei.com

some brainless idiot trying to blackmail with FAKE hacking. just copy and paste bitcoinaddress on a picture very clever HA HA HA

Sweden flag Sweden, 2019-04-25 10:14:55

Sextortion

Abuser: Some wanker

Same old bullshit sextortion scam using an image so you can't cut and paste.

United Kingdom flag United Kingdom, 2019-04-25 14:42:57

Blackmail scam

Abuser: abuse@mailer.microsave.com.br

Received: from [142.161.75.177.infopasa.com.br] (142.161.75.177.infopasa.com.br [177.75.161.142]) (Authenticated sender: lucas@microsave.com.br) by smtp-sp203-149.hospedagem.net (Postfix) with ESMTPA id 1E9ED6002F0C for <redacted>; Wed, 24 Apr 2019 18:17:27 -0300 (-03) Message-ID: <krt2si9-k38s76-00@microsave.com.br> X-Complaints-To: abuse@mailer.microsave.com.br

United States flag United States, 2019-04-25 15:50:14

Blackmail scam

Abuser: hr@palm-plaza.zp.ua

Hacked my computer and used my non existent web cam to spy on me.. Blah! blah! The email wasn't even text - it was a scanned image! I had to type in his bit coin wallet.

United Kingdom flag United Kingdom, 2019-04-26 13:39:09

Sextortion

Abuser: defesacivil@araras.sp.gov.br

as described here: https://www.hoax-slayer.net/this-account-is-now-infected-fake-blackmail-sextortion-scam/ details from email: eceived-SPF: Permerror (SPF Permanent Error: Too many DNS lookups) identity=mailfrom; client-ip=200.147.32.41; helo=smtp.uhserver.com; envelope-from=defesacivil@araras.sp.gov.br; receiver=... Received: from smtp.uhserver.com (a2-smithers1.uhserver.com [200.147.32.41]) by ... (Postfix) with ESMTPS id C559B304771AE for <...>; Fri, 26 Apr 2019 19:26:44 +0200 (CEST) Received: from localhost (localhost.localdomain [127.0.0.1]) by a2-smithers1.uhserver.com (Postfix) with ESMTP id 4C79A1A0000CE for <...>; Fri, 26 Apr 2019 14:26:41 -0300 (BRT) Received: from [177-67-38-131.netslim.com.br] (unknown [177.67.38.131]) (Authenticated sender: defesacivil@araras.sp.gov.br) by a2-smithers1.uhserver.com (Postfix) with ESMTPA id CC7551A0000D8 for <...>; Fri, 26 Apr 2019 14:26:21 -0300 (BRT)

Slovakia flag Slovakia, 2019-04-26 22:14:36

Ransomware

Abuser: unknown

your account was recently infected

Australia flag Australia, 2019-05-11 23:00:16