More Sexual Blackmail phishing scam coming from Mexico

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 27 Jun 2022 22:32:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o62sa-000BhR-MW

for dave@doctor.nl2k.ab.ca;

Mon, 27 Jun 2022 22:31:12 -0600

Resent-From: The Doctor

Resent-Date: Mon, 27 Jun 2022 22:31:12 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from 187.184.159.99.cable.dyn.cableonline.com.mx ([187.184.159.99]:53146)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o60Bs-000Erq-1L

for doctor@nl2k.ab.ca;

Mon, 27 Jun 2022 19:39:06 -0600

Message-ID: <51E95153F9E9EBFB43FBF953434151E9@XM95O7O>

From:

To:

Subject: There is an overdue payment under your name. Please, settle your debts ASAP.

Date: 27 Jun 2022 14:29:31 -0600

MIME-Version: 1.0

Content-Type: text/plain;

charset="cp-850"

Content-Transfer-Encoding: 8bit

X-Priority: 3

X-MSMail-Priority: Normal

X-Mailer: Microsoft Outlook Express 6.00.2900.5931

X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5994

X-Spam_score: 16.4

X-Spam_score_int: 164

X-Spam_bar: ++++++++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hi! Sadly, there are some bad news that you are about to hear.

About few months ago I have gained a full access to all devices used by you

for internet browsing. Shortly after, I started recording all int [...]



Content analysis details: (16.4 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

2.9 HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname

(Split IP)

0.0 TVD_RCVD_IP Message was received from an IP address

0.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP

address

[187.184.159.99 listed in dnsbl.sorbs.net]

0.9 SPF_FAIL SPF: sender does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=doctor%40nl2k.ab.ca;ip=187.184.159.99;r=doctor.nl2k.ab.ca]

1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.4 RDNS_DYNAMIC Delivered to internal network by host with

dynamic-looking rDNS

0.0 HDR_ORDER_FTSDMCXX_DIRECT Header order similar to spam

(FTSDMCXX/boundary variant) + direct-to-MX

2.5 HELO_DYNAMIC_HCC Relay HELO'd using suspicious hostname (HCC)

0.0 PDS_BTC_MSGID Bitcoin ID with T_MSGID_NOFQDN2

3.6 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin

0.0 BITCOIN_XPRIO Bitcoin + priority

0.5 PDS_BTC_ID FP reduced Bitcoin ID

0.4 TO_EQ_FM_DIRECT_MX To == From and direct-to-MX

1.0 BITCOIN_SPAM_07 BitCoin spam pattern 07

0.0 MIMEOLE_DIRECT_TO_MX MIMEOLE + direct-to-MX

3.1 DOS_OE_TO_MX Delivered direct to MX with OE headers

0.0 TO_EQ_FM_DOM_SPF_FAIL To domain == From domain and external SPF

failed

0.0 TO_EQ_FM_SPF_FAIL To == From and external SPF failed

0.0 NO_FM_NAME_IP_HOSTN No From name + hostname using IP address

Subject: {SPAM?} There is an overdue payment under your name. Please, settle your debts ASAP.



Hi!



Sadly, there are some bad news that you are about to hear.

About few months ago I have gained a full access to all devices used by you for internet browsing.

Shortly after, I started recording all internet activities done by you.



Below is the sequence of events of how that happened:

Earlier I purchased from hackers a unique access to diversified email accounts (at the moment, it is really easy to do using internet).

As you can see, I managed to log in to your email account without breaking a sweat: (doctor@nl2k.ab.ca).



Within one week afterwards, I installed a Trojan virus in your Operating Systems available on all devices that you utilize for logging in your email.

To be frank, it was somewhat a very easy task (since you were kind enough to open some of links provided in your inbox emails).

I know, you may be thinking now that I'm a genius.



With help of that useful software, I am now able to gain access to all the controllers located in your devices (e.g., video camera, keyboard, microphone and others).

As result, managed to download all your photos, personal data, history of web browsing and other info to my servers without any problems.

Moreover, I now have access to all accounts in your messengers, social networks, emails, contacts list, chat history - you name it.

My Trojan virus continues refreshing its signatures in a non-stop manner (because it is operated by driver),

hence it remains undetected by any antivirus software installed in your PC or device.



So, I guess now you finally understand the reason why I could never be caught until this very letter...



During the process of your personal info compilation, I could not help but notice that you are a huge admirer and regular guest of websites with adult content.

You endure a lot of pleasure while checking out porn websites, watching nasty porn movies and reaching breathtaking orgasms.

Let me be frank with you, it was really hard to resist from recording some of those naughty solo scenes with you in main role and compiling them in special videos

that expose your masturbation sessions, which end with you cumming.



In case if you still have doubts, all I need is to click my mouse and all those nasty videos with you will be shared to friends, colleagues, and relatives of yours.

Moreover, nothing stops me from uploading all that hot content online, so all public can watch it too.

I sincerely hope, you would really not prefer that to happen, keeping in mind all the dirty things you like to watch,

(you certainly know what I mean) it will completely ruin your reputation.



However, don't worry, there is still a way to resolve this:

You need to carry out a $1190 USD transfer to my wallet (equivalent amount in bitcoins depending on exchange rate at the moment of funds transfer),

hence upon receiving the transaction, I will proceed with deleting all the filthy videos with you in main role.

Afterwards, we can forget about this unpleasant accident. Furthermore, I guarantee that all the malicious software will also be erased from your devices and accounts.

Mark my words, I never lie.



That is a great bargain with a low price, I assure you, because I have spent a lot of effort while recording

and tracking down all your activities and dirty deeds during a long period of time.

In case if you have no idea how to buy and transfer bitcoins - feel free to check the related info on the internet.



Here is my bitcoin wallet for your reference: 1EKdS2BjXd8BzYtsu8U9nQmpcygCjGCjZx



>From now on, you have only 48 hours and countdown has started once you opened this very email (in other words, 2 days).



The following list contains things you should definitely abstain from doing or even attempting:

> Abstain from trying to reply this email (since the email is generated inside your inbox alongside with return address).

> Abstain from trying to call or report to police or any other security services. In addition, it's a bad idea if you want to share it with your friends,

hoping they would help. If I happen to find out (knowing my awesome skills, it can be done effortlessly,

because I have all your devices and accounts under my control and unceasing observation) - kinky videos of yours will be share to public the same day.

> Abstain from trying to look for me - that would not lead anywhere either. Cryptocurrency transactions are absolutely anonymous and cannot be tracked.

> Abstain from reinstalling your OS on devices or throwing them away. That would not solve the problem as well,

since all your personal videos are already uploaded and stored at remote servers.



Things you may be confused about:

> That your funds transfer won't be delivered to me.

Chill, I can track down any transactions right away, so upon funds transfer I will receive a notification as well,

since I still control your devices (my trojan virus has ability of controlling all processes remotely, just like TeamViewer).

> That I am going to share your dirty videos after receiving money transfer from you.

Here you need to trust me, because there is absolutely no point to still bother you after receiving money.

Moreover, if I really wanted all those videos would be available to public long time ago!



I believe we can still handle this situation on fair terms!



Here is my last advice to you... in future you better ensure you stay away from this kind of situations!

My advice - don't forget to regularly update your passwords to feel completely secure.





parnter spam from Gmail

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Mon, 27 Jun 2022 15:09:46 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5vyx-000OYX-4z

for dave@doctor.nl2k.ab.ca;

Mon, 27 Jun 2022 15:09:19 -0600

Resent-From: The Doctor

Resent-Date: Mon, 27 Jun 2022 15:09:19 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-vk1-f171.google.com ([209.85.221.171]:46817)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.95 (FreeBSD))

(envelope-from )

id 1o5rGQ-000FUE-TB

for doctor@doctor.nl2k.ab.ca;

Mon, 27 Jun 2022 10:07:06 -0600

Received: by mail-vk1-f171.google.com with SMTP id 15so4664630vko.13

for ; Mon, 27 Jun 2022 09:06:45 -0700 (PDT)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=gmail.com; s=20210112;

h=mime-version:from:date:message-id:subject:to;

bh=GpehJi66kEC+m815gq5utRdUipyCawXhRJLHaeMiw24=;

b=S6q2nsOy3XnLB4xagpOR2ou83u5QdDRFpXsGsRRiJKUkVlicjEbQYf3D7MsXv3sNo2

mjrMoY7hqtW5quqEJFc2fcpxMQnxXr3P+CwIQ5oLuDREzpBDjgNlhO3mIhECdnwlM0sm

GKIt4lAtS6hovqKkBv0PNe7QBXPCT0Ii4AeityoUPWT+Dgp2zkOQSV43N1bhcy+wkcJA

tLIGxGrtiu7GPr5KE9IEy1MFEw9/TrVgm0pWAJxuplXlZnXiKlSiHL8R9tnQo9oR7Io4

4SI4ocGRjMmde948U2p/LFYAWl7Zhv/f2T0AJWcn3UvHp0RhsPRW0+0Bv3ktMYbot9Z+

9aOw==

X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1e100.net; s=20210112;

h=x-gm-message-state:mime-version:from:date:message-id:subject:to;

bh=GpehJi66kEC+m815gq5utRdUipyCawXhRJLHaeMiw24=;

b=4d2vADe9/UyaYvPR4MYWsXxl5CpiVDmWEh22Wb0YZY2Oaln/GEcm3j7rThei6mKhN5

lQX30W797JWYUSEnFKd6WCq1TuHaVYV6R4NxmDZ5zY+y7cgioHumSdguwZZLq0E9YNIA

cUMDpeiAxzawgOMwAbJfoITUHmkmYyHWLVT1zpUpFOw+Nl+yeTmQ+WQGzeQXKXvIOtVn

fWwUhIBwREspkOsubnnyDG6gQsawUrXXKVSwYZp7u9mZsj3aSSW7XVlx7BlGUPl9OZ+E

ww/c+w3sLWpcMbv8X+NZRL5bJrLJMuA8u+YbEN+8Wb962tpU9Kwcrriprvv2pS6HtQPL

SdUQ==

X-Gm-Message-State: AJIora9CMOZUa+G47/8jWGq9Ab5fiSLScereKbAMhwgiIO/DF7CiMqkp

/ep2lvVpq28FuE8Ey4+/JamyvjlqussDQpmm2iE=

X-Google-Smtp-Source: AGRyM1sw5ykmzdjL3GnnQA+r/espe/ta/Fr/MFabWnQbD3J1kJx4AniN5jP5NuY4xYhFEdKSucPZddMBl0ax8bxTucQ=

X-Received: by 2002:a1f:300c:0:b0:36f:eb7d:746f with SMTP id

w12-20020a1f300c000000b0036feb7d746fmr3327429vkw.27.1656345999828; Mon, 27

Jun 2022 09:06:39 -0700 (PDT)

MIME-Version: 1.0

From: Dr Umar Bello

Date: Mon, 27 Jun 2022 16:05:43 -0700

Message-ID:

Subject: Greetingz partner:

To: undisclosed-recipients:;

Content-Type: multipart/alternative; boundary="000000000000f1ea6e05e2701a7f"

Bcc: doctor@doctor.nl2k.ab.ca

X-Spam_score: 10.5

X-Spam_score_int: 105

X-Spam_bar: ++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Greetingz partner: I am contacting you on a business deal

of $19.5 Million US Dollars, ready for transfer into your account if we make

this claim, we will share it 60%/40%.100% risk free and it will be legally

backed up with government approved If you are interested reply for more details.





Content analysis details: (10.5 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[209.85.221.171 listed in wl.mailspike.net]

-0.0 SPF_PASS SPF: sender matches SPF record

0.0 DATE_IN_FUTURE_06_12 Date: is 6 to 12 hours after Received: date

0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends

in digit

[maki3chisom3[at]gmail.com]

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail

provider

[umarbellod46[at]gmail.com]

3.6 NA_DOLLARS BODY: Talks about a million North American dollars

0.0 HTML_MESSAGE BODY: HTML included in message

-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from

author's domain

-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from

envelope-from domain

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily

valid

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

-0.0 T_SCC_BODY_TEXT_LINE No description available.

0.0 T_HK_NAME_FM_DR No description available.

0.0 LOTS_OF_MONEY Huge... sums of money

3.1 RISK_FREE No risk!

2.0 UNDISC_MONEY Undisclosed recipients + money/fraud signs

2.0 ADVANCE_FEE_2_NEW_MONEY Advance Fee fraud and lots of money

Subject: {SPAM?} Greetingz partner:



--000000000000f1ea6e05e2701a7f

Content-Type: text/plain; charset="UTF-8"



Greetingz partner:



I am contacting you on a business deal of $19.5 Million US Dollars,

ready for transfer into your account



if we make this claim, we will share it 60%/40%.100% risk free and it

will be legally backed up with government approved If you are

interested reply for more details.



Kindly reply for more details Waiting for your reply Make Sure You

Write To My Via E-mail Address...(umarbellod46@gmail.com)



Best regards

Dr.Umar Bello,



--000000000000f1ea6e05e2701a7f

Content-Type: text/html; charset="UTF-8"

Content-Transfer-Encoding: quoted-printable



Greetingz partner:
=C2=A0 =C2=A0
=C2=A0 I am contac=

ting you on a business deal of $19.5 Million US Dollars,
ready for trans=

fer into your account

if we make this claim, we will share it 60%/40=

%.100% risk free and it
will be legally backed up with government approv=

ed If you are
interested reply for more details.

Kindly reply =C2=

=A0for more details Waiting for your reply =C2=A0Make Sure You
Write To =

My Via E-mail Address...(umarbell=

od46@gmail.com
)

Best regards
Dr.Umar Bello,




--000000000000f1ea6e05e2701a7f--