OwlCyberSecurity - MANAGER
Edit File: 1718417409.M784647P2747412.premium128.web-hosting.com,S=9174,W=9361:2,
Return-Path: <ijawoy@email.emeyle.com> Delivered-To: contact+spam@gourayafroid.com Received: from premium128.web-hosting.com by premium128.web-hosting.com with LMTP id yHn1LAH4bGYU7CkAAvhI2g (envelope-from <ijawoy@email.emeyle.com>) for <contact+spam@gourayafroid.com>; Fri, 14 Jun 2024 22:10:09 -0400 Return-path: <ijawoy@email.emeyle.com> Envelope-to: contact@gourayafroid.com Delivery-date: Fri, 14 Jun 2024 22:10:09 -0400 Received: from [201.240.196.243] (port=15784 helo=client-201.240.196.243.speedy.net.pe) by premium128.web-hosting.com with esmtp (Exim 4.96.2) (envelope-from <ijawoy@email.emeyle.com>) id 1sIIrj-00BfPD-0f for contact@gourayafroid.com; Fri, 14 Jun 2024 22:10:09 -0400 To: <contact@gourayafroid.com> MIME-Version: 1.0 From: "brion jin" <ijawoy@email.emeyle.com> Message-ID: <0614_1509M3F6POT7TYVM19@email.emeyle.com> Date: 14 Jun 2024 14:49:19 -0600 Content-type: multipart/alternative; boundary="cnpw.90sjqn8u-308E-0614" X-Spam-Status: Yes, score=22.9 X-Spam-Score: 229 X-Spam-Bar: ++++++++++++++++++++++ X-Spam-Report: Spam detection software, running on the system "premium128.web-hosting.com", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: Your system has been hacked. You have been under surveillance for an extended period of time. The virus was infected by an adult website you visited. I've recorded several videos of you jerking off to [...] Content analysis details: (22.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 4.7 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL [201.240.196.243 listed in zen.spamhaus.org] 3.6 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL 1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL, https://senderscore.org/blocklistlookup/ [201.240.196.243 listed in bl.score.senderscore.com] 0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [201.240.196.243 listed in sa-accredit.habeas.com] 1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date 0.0 MISSING_MIME_HB_SEP BODY: Missing blank line between MIME header and body 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict Alignment 1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any anti-forgery methods 2.5 BITCOIN_SPAM_03 BitCoin spam pattern 03 -0.0 T_SCC_BODY_TEXT_LINE No description available. 2.0 RDNS_NONE Delivered to internal network by a host with no rDNS 3.2 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP addr 1) 0.5 PDS_BTC_ID FP reduced Bitcoin ID 0.0 BITCOIN_YOUR_INFO BitCoin with your personal info 3.0 BITCOIN_DEADLINE BitCoin with a deadline 0.0 BITCOIN_MALWARE BitCoin + malware bragging 0.0 MALWARE_NORDNS Malware bragging + no rDNS X-Spam-Flag: YES Subject: ***SPAM*** Fw: This is a multi-part message in MIME format. --cnpw.90sjqn8u-308E-0614 Content-type: text/plain; charset="iso-8859-1" Content-transfer-encoding: quoted-printable Your system has been hacked. You have been under surveillance for an extended period of time. The virus was infected by an adult website you visited. I've recorded several videos of you jerking off to highly controversial = adult videos. All data from your devices has been copied to my servers. I have access to all your messengers, social media, email, chat history = and contact list. I also have access to all of your personal data, which I've already = copied to my servers. I can also put all your data in the public domain. Illegal material in your country has been found on your device. You = could get in trouble with the law. And also I have all the records of your calls, which I will also put in = public access to the Internet if you do not go to my conditions. I know all your secrets. I could ruin your life forever. My virus is constantly updating its signature (it is driver based) so it = remains invisible to your system. I think you can see why I went undetected until this letter. There's no point in changing passwords, all the data's already copied to = my servers. I guess you really don't want that to happen. Let's solve it this way: you transfer me 1300 US dollars (in bitcoin = equivalent at the exchange rate at the time of transfer), and I will = immediately remove all this dirt from my servers. After this, we will forget about each other. I always keep my word. My bitcoin wallet for payment: 18iBnN32exmmRuBjeK4agUPghzHqwKTUV If you don't know how to transfer money and what Bitcoin is. Use Google. I give you 50 hours (a little over 2 days) to complete the payment. I get an automatic notification when I read this email. Similarly, the = timer will automatically start after you read the current email. If payment is not confirmed after the given time, all data will be = published on the public internet, sent to law enforcement agencies and = sent to all your contacts. Don't waste your time sending me a reply because it won't work (the = sender address is automatically created). Furthermore, do not try to complain anywhere because this text and my = bitcoin address cannot be traced anyway. Do not try to complain anywhere, as the wallet is untraceable, the mail = from where the letter came from is also untraceable and created = automatically, so there is no point in writing to me. Do not attempt to contact the police or other security services, = otherwise your data will be published. --cnpw.90sjqn8u-308E-0614 Content-type: text/html; charset="iso-8859-1" Content-transfer-encoding: quoted-printable <!DOCTYPE html> <html> <head> <meta Http-Equiv=3DContent-Type content=3D"text/html; = charset=3Diso-8859-1"> </head> <body> <p></p> <p>Your system has been hacked.</p> <p>You have been under surveillance for an extended period of time.<br = />The virus was infected by an adult website you visited.<br />I've = recorded several videos of you jerking off to highly controversial adult = videos.</p> <p>All data from your devices has been copied to my servers.</p> <p><br />I have access to all your messengers, social media, email, chat = history and contact list.<br />I also have access to all of your = personal data, which I've already copied to my servers.</p> <p>I can also put all your data in the public domain.</p> <p>Illegal material in your country has been found on your device. You = could get in trouble with the law.</p> <p>And also I have all the records of your calls, which I will also put = in public access to the Internet if you do not go to my conditions.</p> <p>I know all your secrets.</p> <p>I could ruin your life forever.</p> <p>My virus is constantly updating its signature (it is driver based) so = it remains invisible to your system.<br />I think you can see why I went = undetected until this letter.</p> <p>There's no point in changing passwords, all the data's already copied = to my servers.</p> <p>I guess you really don't want that to happen.</p> <p>Let's solve it this way: you transfer me 1300 US dollars (in bitcoin = equivalent at the exchange rate at the time of transfer), and I will = immediately remove all this dirt from my servers.<br />After this, we = will forget about each other. I always keep my word.</p> <p>My bitcoin wallet for payment: 18iBnN32exmmRuBjeK4agUPghzHqwKTUV<br = />If you don't know how to transfer money and what Bitcoin is. Use = Google.</p> <p>I give you 50 hours (a little over 2 days) to complete the = payment.<br />I get an automatic notification when I read this email. = Similarly, the timer will automatically start after you read the current = email.</p> <p>If payment is not confirmed after the given time, all data will be = published on the public internet, sent to law enforcement agencies and = sent to all your contacts.</p> <p>Don't waste your time sending me a reply because it won't work (the = sender address is automatically created).<br />Furthermore, do not try = to complain anywhere because this text and my bitcoin address cannot be = traced anyway.</p> <p><br />Do not try to complain anywhere, as the wallet is untraceable, = the mail from where the letter came from is also untraceable and created = automatically, so there is no point in writing to me.<br />Do not = attempt to contact the police or other security services, otherwise your = data will be published.</p> </body> </html> --cnpw.90sjqn8u-308E-0614--