The original message was received at Thu, 7 Feb 2019 17:28:46 +0800
from wironout2b.netvigator.com [219.76.94.33]
----- The following addresses had permanent fatal errors -----
<xxxx>
(reason: 550 Message rejected as spam)
----- Transcript of session follows -----
... while talking to mail.xxx.at.:
DATA
<<< 550 Message rejected as spam
554 5.0.0 Service unavailable
Reporting-MTA: dns; imscm01.netvigator.com
Received-From-MTA: DNS; wironout2b.netvigator.com
Arrival-Date: Thu, 7 Feb 2019 17:28:46 +0800
Final-Recipient: RFC822; xxxx
Action: failed
Status: 5.2.0
Remote-MTA: DNS; mail.xxx.at
Diagnostic-Code: SMTP; 550 Message rejected as spam
Last-Attempt-Date: Thu, 7 Feb 2019 17:28:49 +0800
Betreff This account has been hacked! Change your password right now!
Von xxxx Add contact
An xxxx Add contact
Datum Do 10:28
You may not know me and you are probably wondering why you are getting this e mail, right?
I'm a hacker who cracked your devices a few months ago.
I sent you an email from YOUR hacked account.
I setup a malware on the adult vids (porno) web-site and guess what, you visited this site to have fun (you know what I mean).
While you were watching videos, your internet browser started out functioning as a RDP (Remote Control) having a keylogger which gave me accessibility to your screen and web cam.
after that, my software program obtained all of your contacts and files.
You entered a passwords on the websites you visited, and I intercepted it.
Of course you can will change it, or already changed it.
But it doesn't matter, my malware updated it every time.
What did I do?
I created a double-screen video. 1st part shows the video you were watching (you've got a good taste haha . . .), and 2nd part shows the recording of your web cam.
Do not try to find and destroy my virus! (All your data is already uploaded to a remote server)
– Do not try to contact with me
– Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.
I guarantee you that I will not disturb you again after payment, as you are not my single victim. This is a hacker code of honor.
Don't be mad at me, everyone has their own work.
exactly what should you do?
Well, in my opinion, $1000 (USD) is a fair price for our little secret. You'll make the payment by Bitcoin (if you do not know this, search "how to buy bitcoin" in Google).
My Bitcoin wallet Address:
1AyRZviUxoBaCU1pJM5m7C1V2LdhPYiRcB
(It is cAsE sensitive, so copy and paste it)
Important:
You have 48 hour in order to make the payment. (I've a facebook pixel in this mail, and at this moment I know that you have read through this email message).
To track the reading of a message and the actions in it, I use the facebook pixel.
Thanks to them. (Everything that is used for the authorities can help us.)
If I do not get the BitCoins, I will certainly send out your video recording to all of your contacts including relatives, coworkers, and so on. Having said that, if I receive the payment, I'll destroy the video immidiately.
If you need evidence, reply with "Yes!" and I will certainly send out your video recording to your 6 contacts. It is a non-negotiable offer, that being said don't waste my personal time and yours by responding to this message.
Filing a complaint somewhere does not make sense because this email cannot be tracked like my bitcoin address. I do not make any mistakes. If I find that you have shared this message with someone else, the video will be immediately distributed. Bye!
Spoiler:
Return-path: <> Envelope-to: xxx Delivery-date: Thu, 07 Feb 2019 12:00:06 +0100 Received: from [81.19.149.135] (helo=mx25lb.world4you.com) by mail28.world4you.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.91) id 1grhPa-0000ke-Pj for xxx; Thu, 07 Feb 2019 12:00:06 +0100 Received: from [218.102.62.196] (helo=imscm01.netvigator.com) by mx25lb.world4you.com with esmtps (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.91) id 1grhPY-00070h-Nk for xxx; Thu, 07 Feb 2019 12:00:06 +0100 Received: from localhost (localhost) by imscm01.netvigator.com (8.13.8/8.14.5) id x179Sn0q020619; Thu, 7 Feb 2019 17:28:49 +0800 Date: Thu, 7 Feb 2019 17:28:49 +0800 From: Mail Delivery Subsystem <MAILER-DAEMON@imscm01.netvigator.com> Message-Id: <201902070928.x179Sn0q020619@imscm01.netvigator.com> To: <xxx> MIME-Version: 1.0 Content-Type: multipart/report; report-type=delivery-status; boundary="x179Sn0q020619.1549531729/imscm01.netvigator.com" Auto-Submitted: auto-generated (failure) X-Spam-Score: 7.8 X-Spam-Report: Action: add header Symbol: GREYLIST(0.00) Symbol: TO_MATCH_ENVRCPT_ALL(0.00) Symbol: ASN(0.00) Symbol: FROM_HAS_DN(0.00) Symbol: RCPT_COUNT_ONE(0.00) Symbol: RBL_SENDERSCORE(2.00) Symbol: MID_RHS_MATCH_FROM(0.00) Symbol: FROM_NEQ_ENVFROM(0.00) Symbol: RCVD_COUNT_TWO(0.00) Symbol: TO_DN_NONE(0.00) Symbol: DMARC_NA(0.00) Symbol: MIME_UNKNOWN(0.10) Symbol: RWL_MAILSPIKE_GOOD(0.00) Symbol: AUTH_NA(1.00) Symbol: R_SPF_NA(0.00) Symbol: R_DKIM_NA(0.00) Symbol: MIME_BASE64_TEXT(0.10) Symbol: MIME_GOOD(-0.10) Symbol: IP_SCORE(4.65) Symbol: RCVD_TLS_LAST(0.00) Message-ID: 201902070928.x179Sn0q020619@imscm01.netvigator.com X-Spam-Flag: YES X-Spam-Bar: +++++++ Subject: [SPAM] Returned mail: see transcript for details This is a MIME-encapsulated message --x179Sn0q020619.1549531729/imscm01.netvigator.com The original message was received at Thu, 7 Feb 2019 17:28:46 +0800 from wironout2b.netvigator.com [219.76.94.33] ----- The following addresses had permanent fatal errors ----- <xxxxt> (reason: 550 Message rejected as spam) ----- Transcript of session follows ----- ... while talking to mail.xxx.at.: >>> DATA <<< 550 Message rejected as spam 554 5.0.0 Service unavailable --x179Sn0q020619.1549531729/imscm01.netvigator.com Content-Type: message/delivery-status Reporting-MTA: dns; imscm01.netvigator.com Received-From-MTA: DNS; wironout2b.netvigator.com Arrival-Date: Thu, 7 Feb 2019 17:28:46 +0800 Final-Recipient: RFC822; xxx Action: failed Status: 5.2.0 Remote-MTA: DNS; mail.xxx.at Diagnostic-Code: SMTP; 550 Message rejected as spam Last-Attempt-Date: Thu, 7 Feb 2019 17:28:49 +0800 --x179Sn0q020619.1549531729/imscm01.netvigator.com Content-Type: message/rfc822 Return-Path: <xxx> Received: from wironout2b.netvigator.com (wironout2b.netvigator.com [219.76.94.33]) by imscm01.netvigator.com (8.13.8/8.14.5) with ESMTP id x179SV1O020451 for <xxx>; Thu, 7 Feb 2019 17:28:46 +0800 X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0Bl/QBo+Vtc/y5eTNsRCUeCHAEBEAIBd?= =?us-ascii?q?02CJ4Y1AZQHl1BEgWc5gUuDDoN0BAIEAoEVQgEBAQMJAoYzDAMYDYYGAQWCbYN?= =?us-ascii?q?oqBQadYQtg0OBLIF2iAkkAS6BYg8XgX+DDmeBbwGCehIBEQIBCFUBBwiDBIMXY?= =?us-ascii?q?IY0jw2LYQmBdIRchE2BDIY1gWwBXYUMgwYDD4dhiX6OZoVuMHGEfIFkK2ABAo0?= =?us-ascii?q?bP4FbEzgCAoUJgi+DDRWCExYBAQ?= X-IPAS-Result: =?us-ascii?q?A0Bl/QBo+Vtc/y5eTNsRCUeCHAEBEAIBd02CJ4Y1AZQHl1B?= =?us-ascii?q?EgWc5gUuDDoN0BAIEAoEVQgEBAQMJAoYzDAMYDYYGAQWCbYNoqBQadYQtg0OBL?= =?us-ascii?q?IF2iAkkAS6BYg8XgX+DDmeBbwGCehIBEQIBCFUBBwiDBIMXYIY0jw2LYQmBdIR?= =?us-ascii?q?chE2BDIY1gWwBXYUMgwYDD4dhiX6OZoVuMHGEfIFkK2ABAo0bP4FbEzgCAoUJg?= =?us-ascii?q?i+DDRWCExYBAQ?= X-IronPort-AV: E=Sophos;i="5.58,342,1544457600"; d="scan'208,217";a="256653530" Received: from wironoah01.netvigator.com ([219.76.94.46]) by wironout2.netvigator.com with ESMTP; 07 Feb 2019 17:28:43 +0800 Received: from unknown (HELO Savesuvpig) ([45.162.81.248]) by wironoah01.netvigator.com with ESMTP; 07 Feb 2019 17:28:40 +0800 Content-Type: multipart/alternative; boundary="ZYpTdzhvLLWtw7py2W9wp1LaMl6ocDIWK2C2iSEc2qDLdNWsldzwoTpgO9mQmkGB" MIME-Version: 1.0 Date: Thu, 07 Feb 2019 09:28:39 -0000 From: <Meine Mailadresse> To: xxx Subject: This account has been hacked! Change your password right now! Message-ID: <616923228.61054766266727@xxx.at>
Mail über Brasilien! IP: 45.162.81.248
Decimal: 765612536
Hostname: 45.162.81.248
ASN: 267975
ISP:
Organization:
Services: None detected
Assignment: Static IP
Continent: South America
Country: Brazil
Zitat: Received: from unknown (HELO Savesuvpig) ([45.162.81.248]) by wironoah01.netvigator.com with ESMTP; 07 Feb 2019 17:28:40 +0800 Date: Thu, 07 Feb 2019 09:28:39 -0000 From: <Meine Mailadresse>