Sexual Blackmail phishing scam

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sun, 11 Sep 2022 05:49:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1oXKta-000Iij-0s

for dave@doctor.nl2k.ab.ca;

Sun, 11 Sep 2022 05:13:02 -0600

Resent-From: The Doctor

Resent-Date: Sun, 11 Sep 2022 05:13:02 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from ppp089210072195.access.hol.gr ([89.210.72.195]:28977)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

(envelope-from )

id 1oXDAg-000NE5-QA

for sales@nk.ca;

Sat, 10 Sep 2022 20:58:16 -0600

Message-ID: <631D78DC.6030706@nk.ca>

Date: Sun, 11 Sep 2022 07:57:48 +0200

From:

User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:6.0) Gecko/20110812 Thunderbird/6.0

MIME-Version: 1.0

To:

Subject: =?UTF-8?B?RG8gWW91IERvIEFueSBvZiBUaGVzZSBFbWJhcnJhc3NpbmcgVGhpbmdzPw==?=

Content-Type: multipart/alternative;

boundary="------------080207030208010806030001"



This is a multi-part message in MIME format.

--------------080207030208010806030001

Content-Type: text/plain; charset=ISO-8859-1; format=flowed

Content-Transfer-Encoding: quoted-printable



I am sorry to inform you but your device was hacked.



That's what happened. I have used a Zero Click vulnerability with a =

special code to hack your device through a website.

A complicated software that requires precise skills that I posess.

This exploit works in a chain with a specially crafted unique code and =

such type of an attack goes undetected.

You only had to visit a website to be infected, and unfortunately for =

you it's that simple for me.



You were not targeted, but just became one of the many unlucky people =

who got hacked through that webpage.

All of this happened in August. So I’ve had enough time to collect =

the information.



I think you already know what is going to happen next.

For a couple of month my software was quietly collecting information =

about your habits, websites you visit, websearches, texts you send.

There is more to it, but I have listed just a few reasons for you to =

understand how serious this is.



To be clear, my software controlled your camera and microphone as well.

It was just about right timing to get you privacy violated. I have made =

a few pornhub worthy videos with you as a lead actor.



I’ve been waiting enough and have decided that it’s time to =

put an end to this.

Here is my offer. Let’s name this a “consulting fee” I =

need to get, so I can delete the media content I have been collecting.

Your privacy stays untouched, if I get the payment.

Otherwise, I will leak the most damaging content to your contacts and =

post it to a public website for perverts to view.



You and I understand how damaging this will be to you, it's not that =

much money to keep your privacy.



I don’t care about you personally, that's why you can be sure that =

all files I have and software on your device will be deleted immediately =

after I receive the transfer.

I only care about getting paid.



My modest consulting fee is 1700 US Dollars to be transferred in =

Bitcoin. Exchange rate at the time of the transfer.

You need to send that amount to this wallet: =

18YFLJHGufQQukMFRkJJJiz51mp21qN96p



The fee is non negotiable, to be transferred within 2 business days.



Obviously do not try to ask for help from the law enforcement unless you =

want your privacy to be violated.

I will monitor your every move until I get paid. If you keep your end of =

the agreement, you wont hear from me ever again.



Take care and have a good day.



--------------080207030208010806030001

Content-Type: text/html; charset="ISO-8859-1"

Content-Transfer-Encoding: quoted-printable










charset=3DISO-8859-1">





I am sorry to inform you but your device was hacked.



That's what happened. I have used a Zero Click vulnerability with a =

special code to hack your device through a website.


A complicated software that requires precise skills that I posess.


This exploit works in a chain with a specially crafted unique code and =

such type of an attack goes undetected.


You only had to visit a website to be infected, and unfortunately for =

you it's that simple for me.



You were not targeted, but just became one of the many unlucky people =

who got hacked through that webpage.


All of this happened in August. So I’ve had enough time to collect =

the information.



I think you already know what is going to happen next.


For a couple of month my software was quietly collecting information =

about your habits, websites you visit, websearches, texts you send.


There is more to it, but I have listed just a few reasons for you to =

understand how serious this is.



To be clear, my software controlled your camera and microphone as =

well.


It was just about right timing to get you privacy violated. I have made =

a few pornhub worthy videos with you as a lead actor.



I’ve been waiting enough and have decided that it’s time to =

put an end to this.


Here is my offer. Let’s name this a “consulting fee” I =

need to get, so I can delete the media content I have been =

collecting.


Your privacy stays untouched, if I get the payment.


Otherwise, I will leak the most damaging content to your contacts and =

post it to a public website for perverts to view.



You and I understand how damaging this will be to you, it's not that =

much money to keep your privacy.



I don’t care about you personally, that's why you can be sure that =

all files I have and software on your device will be deleted immediately =

after I receive the transfer.


I only care about getting paid.



My modest consulting fee is 1700 US Dollars to be transferred in =

Bitcoin. Exchange rate at the time of the transfer.


You need to send that amount to this wallet: =

18YFLJHGufQQukMFRkJJJiz51mp21qN96p



The fee is non negotiable, to be transferred within 2 business =

days.



Obviously do not try to ask for help from the law enforcement unless you =

want your privacy to be violated.


I will monitor your every move until I get paid. If you keep your end of =

the agreement, you wont hear from me ever again.



Take care and have a good day.








--------------080207030208010806030001--





Home Depot Phish

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Sat, 10 Sep 2022 15:09:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.95 (FreeBSD))

(envelope-from )

id 1oX5yM-000O8R-AM

for dave@doctor.nl2k.ab.ca;

Sat, 10 Sep 2022 13:16:58 -0600

Resent-From: The Doctor

Resent-Date: Sat, 10 Sep 2022 13:16:58 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [45.10.245.230] (port=36261 helo=24cash.ca)

by doctor.nl2k.ab.ca with esmtp (Exim 4.95 (FreeBSD))

id 1oX3VC-0004xK-Ke

for doctor@netknow.ca;

Sat, 10 Sep 2022 10:38:47 -0600

MIME-Version: 1.0

Message-Id:

From:_Congratulations

Subject:_We have a surprise for our shoppers!

Reply-To: reply_Z383BpwPDiJhSdzHzGl3w4NCEyLcylrPR1uk7l.bounce9@inx1and1.de

To: doctor@netknow.ca

Content-Transfer-Encoding: 7bit

Content-Type: text/html; charset=UTF-8

Date: Sat, 10 Sep 2022 18:38:12 +0200

X-Spam_score: 7.7

X-Spam_score_int: 77

X-Spam_bar: +++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: SURVEY ABOUT: THE HOME DEPOT THE HOME DEPOT Please tell us

about your: THE HOME DEPOT Experiences and as a thank you, you can select

from several exclusive offer rewards! Supply is extremely limited so act

fast today!



Content analysis details: (7.7 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was

blocked. See

http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block

for more information.

[URIs: googleapis.com]

0.0 SPF_HELO_NEUTRAL SPF: HELO does not match SPF record (neutral)

0.5 URI_NOVOWEL URI: URI hostname has long non-vowel sequence

0.0 HTML_MESSAGE BODY: HTML included in message

1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

1.8 HDRS_MISSP Misspaced headers

3.0 GOOG_STO_NOIMG_HTML Apparently using google content hosting to

avoid URIBL

Subject: {SPAM?} _We have a surprise for our shoppers!