OwlCyberSecurity - MANAGER
Edit File: 1717358537.M962339P3339763.premium128.web-hosting.com,S=8748,W=8930:2,
Return-Path: <dunny-o-rama@hojmail.com> Delivered-To: contact+spam@gourayafroid.com Received: from premium128.web-hosting.com by premium128.web-hosting.com with LMTP id yCeXN8nPXGbz9TIAAvhI2g (envelope-from <dunny-o-rama@hojmail.com>) for <contact+spam@gourayafroid.com>; Sun, 02 Jun 2024 16:02:17 -0400 Return-path: <dunny-o-rama@hojmail.com> Envelope-to: contact@gourayafroid.com Delivery-date: Sun, 02 Jun 2024 16:02:17 -0400 Received: from [190.246.250.174] (port=30007 helo=174-250-246-190.fibertel.com.ar) by premium128.web-hosting.com with esmtp (Exim 4.96.2) (envelope-from <dunny-o-rama@hojmail.com>) id 1sDrP9-00E2zd-2N for contact@gourayafroid.com; Sun, 02 Jun 2024 16:02:17 -0400 From: "laurent loyola" <dunny-o-rama@hojmail.com> To: <contact@gourayafroid.com> Date: 2 Jun 2024 12:51:28 -0400 MIME-Version: 1.0 Message-ID: <665CA568.3297.CE6A05@dunny-o-rama.hojmail.com> Priority: normal X-mailer: Pegasus Mail for Windows (4.61) Content-type: multipart/alternative; boundary="Alt-Boundary-70548.7937498" X-Spam-Status: Yes, score=30.0 X-Spam-Score: 300 X-Spam-Bar: ++++++++++++++++++++++++++++++ X-Spam-Report: Spam detection software, running on the system "premium128.web-hosting.com", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: Hi. This is the last warning. I hacked your operating system. All personal data from your devices has been copied to my servers. I have access to your messengers, social networks, emails, chat history [...] Content analysis details: (30.0 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.2 KAM_BLANKSUBJECT Message has a blank Subject 3.6 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL [190.246.250.174 listed in zen.spamhaus.org] 4.7 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL 0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [190.246.250.174 listed in sa-trusted.bondedsender.org] 1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date 0.0 HTML_MESSAGE BODY: HTML included in message 3.9 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr 2) 0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict Alignment 8.5 KAM_CRIM Extortion Email -0.0 T_SCC_BODY_TEXT_LINE No description available. 1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any anti-forgery methods 2.0 RDNS_NONE Delivered to internal network by a host with no rDNS 0.5 PDS_BTC_ID FP reduced Bitcoin ID 2.5 BITCOIN_YOUR_INFO BitCoin with your personal info 1.0 BITCOIN_MALWARE BitCoin + malware bragging 1.0 MALWARE_NORDNS Malware bragging + no rDNS X-Spam-Flag: YES Subject: ***SPAM*** --Alt-Boundary-70548.7937498 Content-type: text/plain; charset="iso-8859-1" Content-transfer-encoding: QUOTED-PRINTABLE Content-description: Mail message body Hi. This is the last warning. I hacked your operating system. All personal data from your devices has been copied to my servers. I have access to your messengers, social networks, emails, chat history = and contact list. My virus constantly updates signatures (it is driver-based) so it = remains invisible to antivirus software. While collecting information about you, I found out that you are a big = fan of adult websites. You really like to visit porn sites and watch dirty videos while having = an orgasm. I've already made a screen capture. It's a montage of the pornographic video you were watching at the time = and your masturbation. Your face is perfectly visible.I don't think this kind of content will = have a positive impact on your reputation. I can send this video to everyone who knows you. I also have no problem with making all of your personal information = public on the Internet. I think you know what I mean. It would be a real disaster for you. I could ruin your life forever. I think you really don't want that to happen. Let's solve it this way: you transfer me 1200 dollars (USD) (in bitcoin = equivalent at the exchange rate at the moment of funds transfer), and I = will immediately remove all this dirt from my servers. After that we will forget about each other. My bitcoin wallet for payment: = bc1q7df546x5cjj9fhlzczru5wvg86mltnfv3lvg5d If you do not know how to transfer money and what Bitcoin is. Use = Google. I give you 2 working days to transfer the money. The timer started automatically as soon as you opened the email. I’ll receive a notification about the opening of this email. Do not try to complain anywhere, as there is no way to track the wallet, = the mail from where the letter came, and is not tracked and created = automatically, so there is no point in writing to me. Do not try to contact the police and other security services, otherwise = your data will be published. Changing passwords in social networks, mail, device will not help you, = because all the data is already downloaded to a cluster of my servers. Good luck and don't do anything stupid. Think about your future. --Alt-Boundary-70548.7937498 Content-type: text/html; charset="ISO-8859-1" Content-transfer-encoding: QUOTED-PRINTABLE Content-description: Mail message body <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns=3D"http://www.w3.org/1999/xhtml" xml:lang=3D"en" = lang=3D"en"><head> <title></title> <meta http-equiv=3D"content-type" = content=3D"text/html;charset=3Diso-8859-1""/> <meta http-equiv=3D"Content-Style-Type" content=3D"text/css"/> </head> <body> <div align=3D"left"><font face=3D"Arial" size=3D"4"><span style=3D" = font-size:14pt"><p>Hi.</p> <p>This is the last warning.</p> <p>I hacked your operating system.</p> <p>All personal data from your devices has been copied to my = servers.</p> <p>I have access to your messengers, social networks, emails, chat = history and contact list.</p> <p>My virus constantly updates signatures (it is driver-based) so it = remains invisible to antivirus software.</p> <p>While collecting information about you, I found out that you are a = big fan of adult websites.<br />You really like to visit porn sites and = watch dirty videos while having an orgasm.</p> <p>I've already made a screen capture.<br />It's a montage of the = pornographic video you were watching at the time and your = masturbation.<br />Your face is perfectly visible.I don't think this = kind of content will have a positive impact on your reputation.</p> <p>I can send this video to everyone who knows you.</p> <p>I also have no problem with making all of your personal information = public on the Internet.<br />I think you know what I mean.</p> <p>It would be a real disaster for you.</p> <p>I could ruin your life forever.</p> <p>I think you really don't want that to happen.</p> <p>Let's solve it this way: you transfer me 1200 dollars (USD) (in = bitcoin equivalent at the exchange rate at the moment of funds = transfer), and I will immediately remove all this dirt from my = servers.<br />After that we will forget about each other.</p> <p>My bitcoin wallet for payment: = bc1q7df546x5cjj9fhlzczru5wvg86mltnfv3lvg5d</p> <p>If you do not know how to transfer money and what Bitcoin is. Use = Google.</p> <p></p> <p>I give you 2 working days to transfer the money.<br />The timer = started automatically as soon as you opened the email.<br />I’ll = receive a notification about the opening of this email.</p> <p></p> <p>Do not try to complain anywhere, as there is no way to track the = wallet, the mail from where the letter came, and is not tracked and = created automatically, so there is no point in writing to me.<br />Do = not try to contact the police and other security services, otherwise = your data will be published.</p> <p>Changing passwords in social networks, mail, device will not help = you, because all the data is already downloaded to a cluster of my = servers.</p> <p>Good luck and don't do anything stupid. Think about your = future.</p></span></font></div> </body> </html> --Alt-Boundary-70548.7937498--