x-rated blackmail phish

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 26 Jul 2023 12:26:12 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qOjCU-000ERh-2s

for dave@doctor.nl2k.ab.ca;

Wed, 26 Jul 2023 12:25:30 -0600

Resent-From: The Doctor

Resent-Date: Wed, 26 Jul 2023 12:25:30 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [203.162.29.57] (port=40868 helo=mail2.khanhhoa.net.vn)

by doctor.nl2k.ab.ca with esmtp (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qOhwJ-0008t0-2D

for sales@nk.ca;

Wed, 26 Jul 2023 11:04:49 -0600

Received: from mail.khanhhoa.net.vn by mail2.khanhhoa.net.vn (MDaemon PRO v13.0.5)

with ESMTP id md50006090397.msg

for ; Thu, 27 Jul 2023 00:02:03 +0700

X-Spam-Processed: mail2.khanhhoa.net.vn, Thu, 27 Jul 2023 00:02:03 +0700

(not processed: message from trusted or authenticated source)

X-Authenticated-Sender: relay@khanhhoa.net.vn

X-Return-Path: info@thnhatrang.vn

X-Envelope-From: info@thnhatrang.vn

X-MDaemon-Deliver-To: sales@nk.ca

X-MDAV-Result: clean

X-MDAV-Processed: mail.khanhhoa.net.vn, Thu, 27 Jul 2023 00:02:01 +0700

Received: from mail.thnhatrang.vn by mail.khanhhoa.net.vn (MDaemon PRO v13.0.5)

with ESMTP id md50010750186.msg

for ; Thu, 27 Jul 2023 00:02:00 +0700

X-Spam-Processed: mail.khanhhoa.net.vn, Thu, 27 Jul 2023 00:02:00 +0700

(not processed: message from trusted or authenticated source)

Reply-To: sales@nk.ca

From: sales@nk.ca

To: sales@nk.ca

Subject: Hey what are you doing ? you forgot to pay your bills #sales-556504

Date: 27 Jul 2023 01:02:14 +0800

Message-ID: <20230727010214.A55CBFAC96215A95@nk.ca>

MIME-Version: 1.0

Content-Type: text/plain;

charset="utf-8"

Content-Transfer-Encoding: quoted-printable

X-Spam_score: 5.2

X-Spam_score_int: 52

X-Spam_bar: +++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hi. How are you? I know, it’s unpleasant to start the conversation

with bad news, but I have no choice. Few months ago, I have gained access

to your devices that used by you for internet browsing. Afterwards, I coul

[...]



Content analysis details: (5.2 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low

trust

[203.162.29.57 listed in list.dnswl.org]

-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)

[203.162.29.57 listed in wl.mailspike.net]

0.0 T_SPF_HELO_TEMPERROR SPF: test of HELO record failed (temperror)

-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders

0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail

domains are different

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

4.2 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin

0.5 PDS_BTC_ID FP reduced Bitcoin ID

Subject: {SPAM?} Hey what are you doing ? you forgot to pay your bills #sales-556504

X-Antivirus: AVG (VPS 230726-4, 7/26/2023), Inbound message

X-Antivirus-Status: Clean



Hi. How are you?



I know, it=E2=80=99s unpleasant to start the conversation with bad news, bu=

t I have no choice.

Few months ago, I have gained access to your devices that used by you for i=

nternet browsing.

Afterwards, I could track down all your internet activities.



Here is the history of how it could become possible:

At first, I purchased from hackers the access to multiple email accounts (n=

owadays, it is a really simple thing to do online).

As result, I could easily log in to your email account sales@nk.ca.



One week later, I installed Trojan virus in Operating Systems of all device=

s of yours, which you use to open email.

Frankly speaking, it was rather straightforward (since you were opening the=

links from your inbox emails).

Everything ingenious is quite simple. (o_0)!



My software enables me with access to all controllers inside devices of you=

rs, like microphone, keyboard and video camera.

I could easily download to my servers all your private info, including the =

history of web browsing and photos.

I can effortlessly gain access to all your messengers, social networks acco=

unts, emails, contact list as well as chat history.

Virus of mine constantly keeps refreshing its signatures (because it is dri=

ver-based), and as result remains unnoticed by your antivirus.



Hence, you can already guess why I stayed undetected all this while.



As I was gathering information about you, I couldn=E2=80=99t help but notic=

e that you are also a true fan of adult-content websites.

You actually love visiting porn sites and browsing through kinky videos, wh=

ile pleasuring yourself.

I could make a few dirty records with you in the main focus and montaged se=

veral videos showing the way you reach orgasm while masturbating with joy.

=



If you are still uncertain regarding the seriousness of my intentions,

it only requires several mouse clicks for me to forward your videos to all =

your relatives, as well as friends and colleagues.

I can also make those vids become accessible by public.

I honestly think that you do not really want that to happen, considering th=

e peculiarity of videos you like to watch,

(you obviously know what I mean) all that kinky content can become a reason=

of serious troubles for you.



However, we can still resolve this situation in the following manner:

Everything you are required to do is a single transfer of $955 USD to my ac=

count (or amount equivalent to bitcoin depending on exchange rate at the mo=

ment of transfer),

and once the transaction is complete, I will straight away remove all the d=

irty content exposing you.

After that, you can even forget that you have come across me. Moreover, I s=

wear that all the harmful software will be removed from all devices of your=

s as well.

Make no doubt that I will fulfill my part.



This is really a great deal that comes at a reasonable price, given that I =

have used quite a lot of energy to check your profile as well as traffic ov=

er an extended period of time.

If you have no idea about bitcoin purchase process =E2=80=93 it can be stra=

ightforwardly done by getting all the necessary information online.



Here is my bitcoin wallet provided below: bc1q8k2z7u5s9mx0jzcvtfmawg33drhue=

v5dj6uds7



You should complete the abovementioned transfer within 48 hours (2 days) af=

ter opening this email.



The following list contains actions you should avoid attempting:

#Do not try calling police as well as other security forces. In addition, a=

bstain from sharing this story with your friends.

After I find out (be sure, I can easily do that, given that I keep complete=

control of all your devices) =E2=80=93 your kinky video will end up being =

available to public right away.

#Do not try searching for me =E2=80=93 there is absolutely no reason to do =

that. Moreover, all transactions in cryptocurrency are always anonymous.

#Do not try reinstalling the OS on your devices or throwing them away. It i=

s pointless as well, since all your videos have already been uploaded to re=

mote servers.



The following list contains things you should not be worried about:

#That your money won=E2=80=99t reach my account.

=E2=80=93 Rest assured, the transactions can be tracked, hence once the tra=

nsaction is complete,

I will know about it, because I continuously observe all your activities (m=

y trojan virus allows me to control remotely your devices, same as TeamView=

er).

#That I still will share your kinky videos to public after you complete mon=

ey transfer.

=E2=80=93 Trust me, it=E2=80=99s pointless for me to continue troubling you=

r life. If I really wanted, I would make it happen already!



Let=E2=80=99s make this deal in a fair manner!



Owh, one more thing=E2=80=A6in future it is best that you don=E2=80=99t inv=

olve yourself in similar situations any longer!

One last advice from me =E2=80=93 recurrently change all your passwords fro=

m all accounts.=20





Geek Squad phish from Google / Gmail

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Wed, 26 Jul 2023 12:23:00 -0600

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.96 (FreeBSD))

(envelope-from )

id 1qOj9t-000BT9-0X

for dave@doctor.nl2k.ab.ca;

Wed, 26 Jul 2023 12:22:49 -0600

Resent-From: The Doctor

Resent-Date: Wed, 26 Jul 2023 12:22:49 -0600

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-qk1-f194.google.com ([209.85.222.194]:53693)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.96 (FreeBSD))

(envelope-from )

id 1qOfWj-000GfK-1a

for sales@nk.ca;

Wed, 26 Jul 2023 08:30:16 -0600

Received: by mail-qk1-f194.google.com with SMTP id af79cd13be357-7659cb9c42aso552566785a.3

for ; Wed, 26 Jul 2023 07:28:10 -0700 (PDT)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=gmail.com; s=20221208; t=1690381684; x=1690986484;

h=date:mime-version:to:subject:from:message-id:from:to:cc:subject

:date:message-id:reply-to;

bh=IgNMklSeYxtEc3N3UCyaHtegV9hfU4+AZQ2Vw5kBvCE=;

b=IpiL9fFhLzEDfdUFDvMf9I3cnLn7D4BYbT2cyf60xA6R2h4ESA+oMte/kS8h201ti/

vBo69GMjx2vyO+OP9rtvsYni4GP37No3UnKrw+B20ElAfKHDhqCILEe2Eg0pL1OiRZmU

L5zFMCoFRWuLujqFL7tus4gSCahPQMTNIDtLoOxOekNJoABkqun1lOoCrvJ8QoOy4IkP

2li452DgpYXfAvHEwja2LGswhNPhUuo7hpqwDZKSVKmahAEKcSr4ybrFBSd7g7aC5LZA

kPzqCa+N0VOVYFEF9lAkBN5fGhZ7jgE47FX1UqGZDFx5ueY9HcBQuf4S5b960wiKm0Tn

bG+Q==

X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1e100.net; s=20221208; t=1690381684; x=1690986484;

h=date:mime-version:to:subject:from:message-id:x-gm-message-state

:from:to:cc:subject:date:message-id:reply-to;

bh=IgNMklSeYxtEc3N3UCyaHtegV9hfU4+AZQ2Vw5kBvCE=;

b=dr6VFLCA5Xi2ofZwJC/MmE6HGwvD0eFqYo9dt9Q2TtrZhZZy54t+oeAJMFG6C2eilD

BNqmYrrrjW08/Fs+XjRednmfbKR8Uj5/eqYn5staM8C95v5lGTzCvoeEkpF1pcKK7cVv

Fn/HahPedqk8+6x001FQLmMC73sCwHBmLxMMApT6XCNFJeckATXUYM0pZDwSDdHVOaiZ

yPo8RLzLDYu4UrKaMqw5zYz7iRXQtHbenb+Cv9sg10jO5bsVOcgl2iPssctd/IfZSEns

4cyNGqJ0VywU6tCo+32pCVHa9VXwPOmuwylgLtP8M2AMnUF8jbJiamlhpAMSq2H3Sabh

myGQ==

X-Gm-Message-State: ABy/qLYiatxXVTr0cz35ni6/gU+kOMXMbxBU2UyqQBZ+OyyB4uoDNXJw

dU5e1dtECq9kAlL/8G4ZcFp9Ky/udrJl9E0OjEUNzSSE

X-Google-Smtp-Source: APBJJlEabGb4nhuKB+Lxt5B9Kz3bARq+i/WRm/fW9MgRPhJUFlTRoy3U6achJttuTnpwpMb0NkTSmg==

X-Received: by 2002:a0c:a80a:0:b0:626:2bf5:d532 with SMTP id w10-20020a0ca80a000000b006262bf5d532mr1687514qva.14.1690381683947;

Wed, 26 Jul 2023 07:28:03 -0700 (PDT)

Received: from 64.44.84.36 ([45.88.220.238])

by smtp.gmail.com with ESMTPSA id b14-20020a0cb3ce000000b005dd8b9345b4sm5182441qvf.76.2023.07.26.07.28.02

for

(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);

Wed, 26 Jul 2023 07:28:03 -0700 (PDT)

Message-ID: <64c12d73.0c0a0220.437f9.58f9@mx.google.com>

From: "Alfonso W. Bertie"

Subject: Order Confirmation Details#067354

To: "sales"

Content-Type: multipart/alternative; boundary="UaBWa=_nVjTCdCFtaLor9lx3ay9zsNqhE5"

MIME-Version: 1.0

Date: Wed, 26 Jul 2023 07:28:02 -0700

X-Antivirus: AVG (VPS 230726-4, 7/26/2023), Inbound message

X-Antivirus-Status: Clean



This is a multi-part message in MIME format



--UaBWa=_nVjTCdCFtaLor9lx3ay9zsNqhE5

Content-Type: text/plain; charset="utf-8"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline



Hello Dear, sales@nk.ca



Annual Transaction: Successful!



This email is to remind you that your last-year PC Care subscription h=

as lapsed today.



As per our contract, your annual subscription (PC Care and Network Pro=

tection) has been successfully renewed and reactivated.



The subscription fee of $ 385.79 is automat=C3=ACcally debited from th=

e updated payment source; this amount will appear on the statement as =

a GKS*PC charge.



For any queries, please feel free to contact us toll-free at +1 855 26=

2 3380=20



Here is your order and transaction information:



Invoice number: 974-3881-7306741

Description: GEEK Total Protection

Current plan: one-year subscription

Payment method: automatic debit

Next renewal date: July 25, 2024

Subscription charge: $ 385.79



If you wish to unsubscribe or stop auto-debit payments and want a full=

refund to the original payment source, please reach out to us immedia=

tely to claim a d=C3=ACspute.



Customer Helpline Toll-Free Number: +1 855 262 3380



=20



regards,



Alfonso W. Bertie

Consumer Service Activation Dept.





--UaBWa=_nVjTCdCFtaLor9lx3ay9zsNqhE5

Content-Type: text/html; charset="utf-8"

Content-Transfer-Encoding: quoted-printable

Content-Disposition: inline













Hey Exist=

ing User,  sales@nk.ca




tyle=3D"color: rgb(37, 37, 37);">Annual Transaction: Successful!
ng>



This emai=

l is to remind you that your last-year PC Care subscription has lapsed=

today.



As per ou=

r contract, your annual subscription (PC Care and Network Protection) =

has been successfully renewed and reactivated.



The subsc=

ription fee of $ 385.79 is automat=C3=ACcally debited from the updated=

payment source; this amount will appear on the statement as a GKS*PC =

charge.



For any q=

ueries, please feel free to contact us toll-free at
olor: rgb(37, 37, 37);">+1 855 262 3380 




tyle=3D"color: rgb(37, 37, 37);">Here is your order and transaction in=

formation:



Invoice n=

umber: 974-3881-98621
Description=

: GEEK Total Protection
Current p=

lan: one-year subscription
Paymen=

t method: automatic debit
Next re=

newal date: July 25, 2024
Subscri=

ption charge: $ 385.79



If you wi=

sh to unsubscribe or stop auto-debit payments and want a full refund t=

o the original payment source, please reach out to us immediately to c=

laim a d=C3=ACspute.



Customer =

Helpline Toll-Free Number:
rgb(37, 37, 37); text-transform: none; text-indent: 0px; letter-spaci=

ng: normal; font-family: "Times New Roman"; font-size: medium; font-st=

yle: normal; font-weight: 700; word-spacing: 0px; white-space: normal;=

orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-var=

iant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke=

-width: 0px; text-decoration-thickness: initial; text-decoration-style=

: initial; text-decoration-color: initial;'>+1 855 262 3380

p>

 
>

sincerely=

,



Alfonso W=

=2E Bertie
Client Support Team
>











--UaBWa=_nVjTCdCFtaLor9lx3ay9zsNqhE5--