nk.ca E-mail phishing from Performive LLC Boise Idaho USA

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 25 Jan 2024 05:34:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rSyvK-00000000C5n-3jPl

for dave@doctor.nl2k.ab.ca;

Thu, 25 Jan 2024 05:33:38 -0700

Resent-From: The Doctor

Resent-Date: Thu, 25 Jan 2024 05:33:38 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [154.6.95.25] (port=51981 helo=[154.6.12.4])

by doctor.nl2k.ab.ca with esmtp (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rSr93-00000000FMR-2fuO

for root@nl2k.ab.ca;

Wed, 24 Jan 2024 21:15:39 -0700

From: Mail Administrator

To: root@nl2k.ab.ca

Subject: WARNING: Password Expired 1/24/2024 11:12:14 p.m.

Date: 24 Jan 2024 23:12:21 -0500

Message-ID: <20240124231214.8B0A1517D34BBD57@mail.admin>

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="----=_NextPart_000_0012_04D365BA.C41F02AE"





------=_NextPart_000_0012_04D365BA.C41F02AE

Content-Type: text/plain;

charset="utf-8"

Content-Transfer-Encoding: quoted-printable



HI root,



Your password for root@nl2k.ab.ca, expired today 1/24/2024=20

11:12:14 p.m., and marked for deletion

If not reconfirm within the next hour, your account would become=20

inactive,

equiring manual activation.





KEEP MY PASSWORD=20

(=C2=A0https://cloudflare-ipfs.com/ipfs/bafkreiblnmvyo4ssbcrni6avguuqd7jwlb=

gid72am2kxyyikgr3mykxtym#root@nl2k.ab.ca=C2=A0)

NOTICE OF CONFIDENTIALITY:Information included in and/or attached=20

to this transmission may be confidential.This transmission is=20

intended for the addressee(s) only.Any unauthorized=20

disclosure,reproduction,or distribution of and/or any=20

unauthorized action taken inreliance on the information in this=20

transmission is prohibited.If you believe that you received this=20

transmission in error, please notify the sender by reply=20

transmission and destroy the transmission without copying or=20

disclosing it.We may also need to contact you for additional=20

information as required by HIPAA or state law.

------=_NextPart_000_0012_04D365BA.C41F02AE

Content-Type: text/html;

charset="iso-8859-1"

Content-Transfer-Encoding: quoted-printable
















left; color: rgb(0, 0, 0); text-transform: none; letter-spacing: normal; f=

ont-family: arial, helvetica, sans-serif; font-size: 14px; font-style: norm=

al; font-weight: 400; word-spacing: 0px; white-space: normal; table-layout:=

fixed; orphans: 2; widows: 2; font-variant-ligatures: normal; font-variant=

-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thickness: i=

nitial; text-decoration-style: initial;=20

text-decoration-color: initial;" border=3D"0" cellspacing=3D"0" cellpadding=

=3D"0" data-muid=3D"9387a63b-5d00-4538-9139-285a9c6aa954" data-type=3D"text=

">

le=3D"padding: 18px 0px; text-align: inherit; line-height: 22px;" bgcolor=

=3D"">

4px;">

color: rgb(0, 0, 0); font-size: 14px;">HI root,



Your password for root@nl2k.ab.ca, expired today 1/24/2024 11:12:14 p.m., a=

nd marked for deletion
If not reconfirm within the next hour, your accou=

nt would become inactive,
equiring manual activation.

tyle=3D"font-family: arial, helvetica, sans-serif; font-size: 14px;">
=




left; color: rgb(0, 0, 0); text-transform: none; letter-spacing: normal; f=

ont-family: arial, helvetica, sans-serif; font-size: 14px; font-style: norm=

al; font-weight: 400; word-spacing: 0px; white-space: normal; table-layout:=

fixed; orphans: 2; widows: 2; font-variant-ligatures: normal; font-variant=

-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thickness: i=

nitial; text-decoration-style: initial;=20

text-decoration-color: initial;" border=3D"0" cellspacing=3D"0" cellpadding=

=3D"0" data-muid=3D"c9c27479-54aa-47f9-8b17-1e7dea1e69ad" data-type=3D"butt=

on" data-role=3D"module-button">

r-td" style=3D"padding: 0px;" bgcolor=3D"">
style=3D"text-align: center;" border=3D"0" cellspacing=3D"0" cellpadding=3D=

"0">


lign: left; font-size: 16px; background-color: inherit;" bgcolor=3D"#2e89ef=

">


6, 193, 193); border-image: none; text-align: center; color: rgb(255, 255, =

255); line-height: normal; letter-spacing: 0px; font-size: 14px; font-weigh=

t: bold; text-decoration: none; display: inline-block; background-color: rg=

b(46, 137, 239);" href=3D"https://cloudflare-ipfs.com/ipfs/bafkreiblnmvyo4s=

sbcrni6avguuqd7jwlbgid72am2kxyyikgr3mykxtym#root@nl2k.ab.ca" target=3D"_bla=

nk">

KEEP MY PASSWORD



left; color: rgb(0, 0, 0); text-transform: none; letter-spacing: normal; f=

ont-family: arial, helvetica, sans-serif; font-size: 14px; font-style: norm=

al; font-weight: 400; word-spacing: 0px; white-space: normal; table-layout:=

fixed; orphans: 2; widows: 2; font-variant-ligatures: normal; font-variant=

-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-thickness: i=

nitial; text-decoration-style: initial;=20

text-decoration-color: initial;" border=3D"0" cellspacing=3D"0" cellpadding=

=3D"0" data-muid=3D"33775382-1539-4bd2-9732-46f2f6cd07b1" data-type=3D"text=

">

le=3D"padding: 18px 0px; text-align: inherit; line-height: 22px;" bgcolor=

=3D"">

4px;">

color: rgb(225, 218, 218);">

NOTICE OF CONFIDENTIALITY:Information included in and/or attached to this t=

ransmission may be confidential.This transmission is intended for the addre=

ssee(s) only.Any unauthorized disclosure,reproduction,or distribution of an=

d/or any unauthorized action taken inreliance on the information in this tr=

ansmission is prohibited.If you believe that you received this transmission=

in error, please notify the sender by reply transmission and destroy the t=

ransmission without copying or disclosing it.We=20

may also need to contact you for additional information as required by HIPA=

A or state law.








------=_NextPart_000_0012_04D365BA.C41F02AE--

Fedex Phish from Google Gmail

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 25 Jan 2024 05:35:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rSywD-00000000C77-0lpC

for dave@doctor.nl2k.ab.ca;

Thu, 25 Jan 2024 05:34:33 -0700

Resent-From: The Doctor

Resent-Date: Thu, 25 Jan 2024 05:34:33 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from mail-wr1-f49.google.com ([209.85.221.49]:42009)

by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rStzQ-00000000K28-0ez4

for doctor@doctor.nl2k.ab.ca;

Thu, 25 Jan 2024 00:17:35 -0700

Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-3392b15ca41so241506f8f.0

for ; Wed, 24 Jan 2024 23:15:38 -0800 (PST)

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=gmail.com; s=20230601; t=1706166931; x=1706771731; darn=doctor.nl2k.ab.ca;

h=to:subject:message-id:date:from:mime-version:from:to:cc:subject

:date:message-id:reply-to;

bh=c7mby8xMvJhPNqxeIDlacUwQ/EiNRfuuotjvE131qTg=;

b=QHwW865V/k2ZeVsW8gP0/qcVFWXU6tJzwZs7SghjxJHXqPL1hKOu2H21Ul8m6s+Mnh

dyo2sPzZVXGLd+4GBAweOMs8toBvWwiwtNhlxZzqR2zrQ3e82eBI03gyZsp4o/R8/tdr

g7mg3lICI0qSflk7jwq+yW9zISoCOjxcXntnsBknFM2DDQ/j09T2uImrk9edWyEtHwcx

/Cf8KMLvFhqMVP0Ad2glmZn9/3kWowyfu3qOmaYLMTtvaIRN2ePP0OuQEiqCmaSVo9ea

DcZZwJh1cbnKR7ABB/6KJLcOEaa1nIM42lZQTu7R1OXuYjnNMSwGHq9QFTGJRONFEtY2

k0PQ==

X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=1e100.net; s=20230601; t=1706166931; x=1706771731;

h=to:subject:message-id:date:from:mime-version:x-gm-message-state

:from:to:cc:subject:date:message-id:reply-to;

bh=c7mby8xMvJhPNqxeIDlacUwQ/EiNRfuuotjvE131qTg=;

b=o3T6UEfTQvpsAOqpRncagRH66tWD7Kl6Tyyv6ypSP6RRxEhPJuAimoZeoxjFH6WyP8

WWKQ1rQLy81LwzVwkJs5diDEz8KlDtjGpniVDzNRggz2CWFsESqdiMAtrX2XsY8wdox+

mktEhvpTonDHIR3xSROStwCuBNuhauTi4XQpFXOqP3+bh9FTGSDnYR2Fu6wAQNeE2V72

xAvwaB5BIZ2jTQ8Ep2/tlqpo9YXCav5x0/0uuFMevlD4d8HPGZF4gQSRCa1PcV6eAtYB

59pE1gLmG7LBGqLLwVTYM1Prs0ZJ2pbqgMar/5VyTtMmNNFtSwHFP8YuI/9vR/Iho7b0

wfRQ==

X-Gm-Message-State: AOJu0YzicHP9hhMmD5L849+kwgAlU+NDHwHiOAlFKy0sHFVspSI+ywxm

b0GqL6xL2kJ4m55VirlCVS511bY3ZE43bgUl5IwwW2CYYdk3+kkqKW2JWVh5GgoVOaV2F7NPvVW

ypmd3GBdVy+ZNoA4UWDoZlKfoXwcorjYxzho=

X-Google-Smtp-Source: AGHT+IH5h/gdXGRKWXJzuWw9HTnbVBrtdpxK61R20bJcSy4UXeASlvn1RumEOPJgqHk62jpro3PjcrvKz4md25aQtQA=

X-Received: by 2002:adf:e60a:0:b0:33a:1fa:c868 with SMTP id

p10-20020adfe60a000000b0033a01fac868mr205653wrm.28.1706166931397; Wed, 24 Jan

2024 23:15:31 -0800 (PST)

MIME-Version: 1.0

Received: by 2002:a5d:5648:0:b0:336:a125:141e with HTTP; Wed, 24 Jan 2024

23:15:31 -0800 (PST)

From: fedexcouriers57

Date: Thu, 25 Jan 2024 08:15:31 +0100

Message-ID:

Subject: Attention

To: undisclosed-recipients:;

Content-Type: text/plain; charset="UTF-8"

Bcc: doctor@doctor.nl2k.ab.ca

X-Spam_score: 10.8

X-Spam_score_int: 108

X-Spam_bar: ++++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Attention: Dear Beneficiary This is to bring to your notice

that we have credited your total sum of $5.500.000.00 USD into an ATM VISA

card and we have deposited it with DHL Express Company to deliver it to you.

We paid all the [...]



Content analysis details: (10.8 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no

trust

[209.85.221.49 listed in list.dnswl.org]

-0.0 SPF_PASS SPF: sender matches SPF record

-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's

domain

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from

envelope-from domain

0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider

[fedexcouriers57(at)gmail.com]

0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in

digit

[fedexcouriers57(at)gmail.com]

-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)

[209.85.221.49 listed in wl.mailspike.net]

3.5 DEAR_BENEFICIARY BODY: Dear Beneficiary:

2.5 US_DOLLARS_3 BODY: Mentions millions of $ ($NN,NNN,NNN.NN)

0.0 LOTS_OF_MONEY Huge... sums of money

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.1 MONEY_NOHTML Lots of money in plain text

0.0 FILL_THIS_FORM Fill in a form with personal information

1.0 FREEMAIL_REPLY From and body contain different freemails

0.0 MONEY_FORM Lots of money if you fill out a form

2.9 UNDISC_MONEY Undisclosed recipients + money/fraud signs

Subject: {SPAM?} Attention



Attention: Dear Beneficiary



This is to bring to your notice that we have credited your total sum of

$5.500.000.00 USD into an ATM VISA card and we have deposited it with DHL

Express Company to deliver it to you. We paid all the necessary charges

such as Company registration and delivery fee.



The only money you will send to them is the security keeping charges of your

ATM VISA card $35.00 dollars. We tried to pay that but they complained that

they don't know when you will contact them for the delivery and the demurrage

might have increased by then. I deposited it on 25/01/2024. Therefore, contact

them now with Your:



Your Full Name........

Your Country............

Your City Airport........

Your Home Address........

Telephone Number.........

Gender...................



DHL Express

Email address: deploymentagent711@gmail.com

Tel/+22964083699

sexual bribe phish from 192-232-200-129.unifiedlayer.com PRovo Utah USA

Return-path:

Envelope-to: dave@doctor.nl2k.ab.ca

Delivery-date: Thu, 25 Jan 2024 05:38:00 -0700

Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rSyz3-00000000CLJ-3bcT

for dave@doctor.nl2k.ab.ca;

Thu, 25 Jan 2024 05:37:29 -0700

Resent-From: The Doctor

Resent-Date: Thu, 25 Jan 2024 05:37:29 -0700

Resent-Message-ID:

Resent-To: Dave Yadallee

Received: from [192.232.200.129] (port=56186 helo=hom.homebusinessradionetwork.com)

by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

(Exim 4.97.1 (FreeBSD))

(envelope-from )

id 1rSyfv-00000000A62-1Bml

for doctor@doctor.nl2k.ab.ca;

Thu, 25 Jan 2024 05:17:48 -0700

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;

d=abovebeyondteam.net; s=default; h=Content-Transfer-Encoding:Content-Type:

MIME-Version:Message-ID:Subject:From:To:Date:Sender:Reply-To:Cc:Content-ID:

Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc

:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:

List-Subscribe:List-Post:List-Owner:List-Archive;

bh=B14/Onc61B/9d3zXrQE/4Ybe5sRYlKBPhFxjvRE1gWk=; b=j+T83Wk51Q5LnPOqOMzjvPOivO

8U5AeDTlJHgmnwh4p3kZz2VKeycEZ4osBJmPjjj+pbVp3afDpvd28spTl7Gp/lHZTjtToEDOKBoP2

4UlsUzWt/ISYsPG3jykslUrLwYh+3k3/VMqR56k4Vf+XZsKErMYp+rwLoF8Xn1Z+exDY=;

Received: from [213.164.24.12] (port=50574 helo=rgo347ur)

by hom.homebusinessradionetwork.com with esmtpa (Exim 4.91)

(envelope-from )

id 1rSyf6-0000h2-0e

for doctor@doctor.nl2k.ab.ca; Thu, 25 Jan 2024 06:16:52 -0600

Date: Thu, 25 Jan 2024 12:16:50 +0000

To: doctor@doctor.nl2k.ab.ca

From: "doctor@doctor.nl2k.ab.ca"

Subject: Payment associated to your account.

Message-ID:

Mailer: Exim 4.93

MIME-Version: 1.0

Content-Type: multipart/alternative;

boundary="b1_O82JpBwckW9vZvx6gjNbEyq07CFeJTk8QyOrVwuZEuE"

Content-Transfer-Encoding: 8bit

X-AntiAbuse: This header was added to track abuse, please include it with any abuse report

X-AntiAbuse: Primary Hostname - hom.homebusinessradionetwork.com

X-AntiAbuse: Original Domain - doctor.nl2k.ab.ca

X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]

X-AntiAbuse: Sender Address Domain - doctor.nl2k.ab.ca

X-Get-Message-Sender-Via: hom.homebusinessradionetwork.com: authenticated_id: norepl@abovebeyondteam.net

X-Authenticated-Sender: hom.homebusinessradionetwork.com: norepl@abovebeyondteam.net

X-Spam_score: 8.3

X-Spam_score_int: 83

X-Spam_bar: ++++++++

X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",

has identified this incoming email as possible spam. The original

message has been attached to this so you can view it or label

similar future email. If you have any questions, see

@@CONTACT_ADDRESS@@ for details.



Content preview: Hi there! Unfortunately, I need to start our conversation

with bad news for you. Around few months back I managed to get full access

to all devices of yours, which are used by you on a daily basis to browse

int [...]



Content analysis details: (8.3 points, 5.0 required)



pts rule name description

---- ---------------------- --------------------------------------------------

1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net

[Blocked - see ]

0.9 SPF_FAIL SPF: sender does not match SPF record (fail)

[SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=doctor%40doctor.nl2k.ab.ca;ip=192.232.200.129;r=doctor.nl2k.ab.ca]

0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid

-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature

1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.

[192.232.200.129 listed in bb.barracudacentral.org]

0.0 HTML_MESSAGE BODY: HTML included in message

-0.0 T_SCC_BODY_TEXT_LINE No description available.

1.3 RDNS_NONE Delivered to internal network by a host with no rDNS

0.2 PDS_BTC_ID FP reduced Bitcoin ID

3.0 BITCOIN_YOUR_INFO BitCoin with your personal info

Subject: {SPAM?} Payment associated to your account.



This is a multi-part message in MIME format.



--b1_O82JpBwckW9vZvx6gjNbEyq07CFeJTk8QyOrVwuZEuE

Content-Type: text/plain; charset=us-ascii



Hi there!



Unfortunately, I need to start our conversation with bad news for you.

Around few months back I managed to get full access to all devices of yours, which are used by you on a daily basis to browse internet.

Afterwards, I could initiate monitoring and tracking of all your activities on the internet.



I am proud to share the sequence of how it happened: In the past I bought from hackers the access to various email accounts (today, that is rather a simple thing to do online).

Clearly, it was not hard at all for me to log in to your email account (doctor@doctor.nl2k.ab.ca).



A week after that, I had already managed to effortlessly install Trojan virus to Operating Systems of all devices that are currently in your use, and as result gained access to your email.

To be honest, that was not really difficult at all (because you were eagerly opening the links from your inbox emails). I know, I am a genius. (=



With help of that software, I can gain access to all controllers in your devices (such as video camera, keyboard and microphone).

As result, I downloaded to my remote cloud servers all your personal data, photos and other information including web browsing history.

Likewise, I have complete access to all your social networks, messengers, chat history, emails, as well as contacts list.

My intelligent virus unceasingly refreshes its signatures (due to its driver-based nature), and hereby stays unnoticed by your antivirus software.



Herbey, I believe that now you finally start realizing how I could easily remain unnoticed all this while until this very letter...

While collecting information related to you, I had also unveiled that you are a true fan of porn sites.

You truly enjoy browsing through adult sites and watching horny vids, while playing your dirty solo games.

Bingo! I also recorded several filthy scenes with you in the main focus and montaged some dirty videos, which demonstrate your passionate masturbation and cum sessions.



In case you still don't believe me, all I need is just one-two mouse clicks to make all your unmasking videos become available to your friends, colleagues, and even relatives(ALL YOUR SOCIAL MEDIA CONTACTS).

Well, if you still doubt me, I can easily make recorded videos of your orgasms become a public.

I truly believe that you surely would avoid that from happening, taking in consideration the type of the XXX videos you love watching, (you are clearly aware of what I mean) it will result in a huge disaster for you.



Well, there is still a way to settle this tricky situation in a peaceful manner:

You will need to transfer $1450 USD to my account (refer to Bitcoin equivalent based on the exchange rate at the moment transfer), so once funds transfer is complete, I will straight away proceed with deleting all that dirty content from servers once and for all.



Afterwards, you can consider that we never met before. You have my honest word, that all the harmful software will also be deactivated and deleted from all your devices currently in use. Worry not, I keep my promises.

That is truly a win-win solution that comes at a relatively reduced cost, mostly knowing how much effort I spent on monitoring your profile and traffic for a considerably long time.

In event that you have no idea about means of buying and transferring bitcoins - don't hesitate to use any search engine for your assistance (e.g., Google, Yahoo, Bing, etc.).



My bitcoin wallet is as follows: bc1qyytkg0un7zm3npjev5z5xycrrzqx09kdtg44l2



I have allocated 48 hours for you to do that, and the timer started right after you opened this very email (2 days to be exact).



Don't even think of doing anything of the following:

! Abstain from attempting to reply me (this email was created by me inside your inbox page and the return address was generated accordingly).

! Abstain from attempting to get in touch with police or any other security services. Moreover, don't even think of sharing this to you friends. Once I discover this (apparently, that is absolutely easy for me, taking in consideration that I have complete control over all systems you use) - kinky video will straight away be made public. ! Don't even think of attempting to find me, that is completely useless. Don't forget that all cryptocurrency transactions remain completely anonymous.

! Don't attempt reinstalling the OS on all your devices or getting rid of them. That won't lead you to success either, because I have already saved all videos at my remote servers as a backup.



Things you should not be concerned about:

! That your funds transfer won't reach my wallet.

- Worry not, I can see everything, hence after you finish the transfer, I will get a notification right away (trojan virus of mine uses a remote-control feature, which functions similarly to TeamViewer).

! That I will still distribute your videos although you make the funds transfer.

- My word, I have no intention or interest in continuing making your life troublesome. Anyway, If I truly wanted that, it would happen long time ago without me notifying you!



Everything can be settled in a peaceful and just way!

And lastly... make sure you don't get caught afterwards in such type of incidents anymore!

My fair advice - ensure you change all your passwords on a regular basis.



--b1_O82JpBwckW9vZvx6gjNbEyq07CFeJTk8QyOrVwuZEuE

Content-Type: text/html; charset=us-ascii



Hi there!





Unfortunately, I need to start our conversation with bad news for you.


Around few months back I managed to get full access to all devices of yours, which are used by you on a daily basis to browse internet.


Afterwards, I could initiate monitoring and tracking of all your activities on the internet.





I am proud to share the sequence of how it happened: In the past I bought from hackers the access to various email accounts (today, that is rather a simple thing to do online).


Clearly, it was not hard at all for me to log in to your email account (doctor@doctor.nl2k.ab.ca).





A week after that, I had already managed to effortlessly install Trojan virus to Operating Systems of all devices that are currently in your use, and as result gained access to your email.


To be honest, that was not really difficult at all (because you were eagerly opening the links from your inbox emails). I know, I am a genius. (=





With help of that software, I can gain access to all controllers in your devices (such as video camera, keyboard and microphone).


As result, I downloaded to my remote cloud servers all your personal data, photos and other information including web browsing history.


Likewise, I have complete access to all your social networks, messengers, chat history, emails, as well as contacts list.


My intelligent virus unceasingly refreshes its signatures (due to its driver-based nature), and hereby stays unnoticed by your antivirus software.





Herbey, I believe that now you finally start realizing how I could easily remain unnoticed all this while until this very letter...


While collecting information related to you, I had also unveiled that you are a true fan of porn sites.


You truly enjoy browsing through adult sites and watching horny vids, while playing your dirty solo games.


Bingo! I also recorded several filthy scenes with you in the main focus and montaged some dirty videos, which demonstrate your passionate masturbation and cum sessions.





In case you still don't believe me, all I need is just one-two mouse clicks to make all your unmasking videos become available to your friends, colleagues, and even relatives(ALL YOUR SOCIAL MEDIA CONTACTS).


Well, if you still doubt me, I can easily make recorded videos of your orgasms become a public.


I truly believe that you surely would avoid that from happening, taking in consideration the type of the XXX videos you love watching, (you are clearly aware of what I mean) it will result in a huge disaster for you.





Well, there is still a way to settle this tricky situation in a peaceful manner:


You will need to transfer $1450 USD to my account (refer to Bitcoin equivalent based on the exchange rate at the moment transfer), so once funds transfer is complete, I will straight away proceed with deleting all that dirty content from servers once and for all.





Afterwards, you can consider that we never met before. You have my honest word, that all the harmful software will also be deactivated and deleted from all your devices currently in use. Worry not, I keep my promises.


That is truly a win-win solution that comes at a relatively reduced cost, mostly knowing how much effort I spent on monitoring your profile and traffic for a considerably long time.


In event that you have no idea about means of buying and transferring bitcoins - don't hesitate to use any search engine for your assistance (e.g., Google, Yahoo, Bing, etc.).





My bitcoin wallet is as follows: bc1qyytkg0un7zm3npjev5z5xycrrzqx09kdtg44l2





I have allocated 48 hours for you to do that, and the timer started right after you opened this very email (2 days to be exact).





Don't even think of doing anything of the following:


! Abstain from attempting to reply me (this email was created by me inside your inbox page and the return address was generated accordingly).


! Abstain from attempting to get in touch with police or any other security services. Moreover, don't even think of sharing this to you friends. Once I discover this (apparently, that is absolutely easy for me, taking in consideration that I have complete control over all systems you use) - kinky video will straight away be made public. ! Don't even think of attempting to find me, that is completely useless. Don't forget that all cryptocurrency transactions remain completely anonymous.


! Don't attempt reinstalling the OS on all your devices or getting rid of them. That won't lead you to success either, because I have already saved all videos at my remote servers as a backup.





Things you should not be concerned about:


! That your funds transfer won't reach my wallet.


- Worry not, I can see everything, hence after you finish the transfer, I will get a notification right away (trojan virus of mine uses a remote-control feature, which functions similarly to TeamViewer).


! That I will still distribute your videos although you make the funds transfer.


- My word, I have no intention or interest in continuing making your life troublesome. Anyway, If I truly wanted that, it would happen long time ago without me notifying you!





Everything can be settled in a peaceful and just way!


And lastly... make sure you don't get caught afterwards in such type of incidents anymore!


My fair advice - ensure you change all your passwords on a regular basis.







--b1_O82JpBwckW9vZvx6gjNbEyq07CFeJTk8QyOrVwuZEuE--