
| Current Path : /home/ift/mails/37/ |
Linux ift1.ift-informatik.de 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64 |
| Current File : //home/ift/mails/37/1541379111.zrspam.376996_2018_11_05 |
From christian.gabriel@ift-informatik.de Mon Nov 5 01:51:51 2018
Return-Path: <christian.gabriel@ift-informatik.de>
X-Original-To: cgabriel@ift-informatik.de
Delivered-To: cgabriel@ift-informatik.de
Received: by ift-informatik.de (Postfix, from userid 5555)
id 613A63D200078; Mon, 5 Nov 2018 01:51:51 +0100 (CET)
Received: from localhost by h2486555.stratoserver.net
with SpamAssassin (version 3.4.0);
Mon, 05 Nov 2018 01:51:51 +0100
From: <christian.gabriel@ift-informatik.de>
To: <christian.gabriel@ift-informatik.de>
Subject: *****SPAM***** Change your password immediately. Your account has been hacked.
Date: 5 Nov 2018 03:17:49 +0100
Message-Id: <001e01d474b2$073c8844$04307a87@nvvtb>
X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
h2486555.stratoserver.net
X-Spam-Flag: YES
X-Spam-Level: ****************
X-Spam-Status: Yes, score=16.1 required=5.0 tests=AXB_XMAILER_MIMEOLE_OL_024C2,
BAYES_00,DOS_OE_TO_MX,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_BRBL_LASTEXT,
RCVD_IN_MSPIKE_BL,RCVD_IN_MSPIKE_L5,RCVD_IN_PBL,RCVD_IN_PSBL,RCVD_IN_RP_RNBL,
RDNS_NONE,URIBL_BLOCKED autolearn=no autolearn_force=no version=3.4.0
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_5BDF9427.9B9F1F0F"
This is a multi-part message in MIME format.
------------=_5BDF9427.9B9F1F0F
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Spam detection software, running on the system "h2486555.stratoserver.net",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: I greet you! I have bad news for you. 11/08/2018 - on this
day I hacked your operating system and got full access to your account christian.gabriel@ift-informatik.de
It is useless to change the password, my malware intercepts it every time.
[...]
Content analysis details: (16.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: ift-informatik.de]
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[176.219.72.81 listed in psbl.surriel.com]
3.3 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[176.219.72.81 listed in zen.spamhaus.org]
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?176.219.72.81>]
2.4 RCVD_IN_MSPIKE_L5 RBL: Very bad reputation (-5)
[176.219.72.81 listed in bl.mailspike.net]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[176.219.72.81 listed in bl.score.senderscore.com]
1.4 RCVD_IN_BRBL_LASTEXT RBL: No description available.
[176.219.72.81 listed in bb.barracudacentral.org]
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
0.0 RCVD_IN_MSPIKE_BL Mailspike blacklisted
0.8 RDNS_NONE Delivered to internal network by a host with no rDNS
2.2 AXB_XMAILER_MIMEOLE_OL_024C2 No description available.
2.5 DOS_OE_TO_MX Delivered direct to MX with OE headers
------------=_5BDF9427.9B9F1F0F
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Received: from [176.219.72.81] (unknown [176.219.72.81])
by ift-informatik.de (Postfix) with ESMTP id A95F13D20001F
for <christian.gabriel@ift-informatik.de>; Mon, 5 Nov 2018 01:51:49 +0100 (CET)
Message-ID: <001e01d474b2$073c8844$04307a87@nvvtb>
From: <christian.gabriel@ift-informatik.de>
To: <christian.gabriel@ift-informatik.de>
Subject: Change your password immediately. Your account has been hacked.
Date: 5 Nov 2018 03:17:49 +0100
MIME-Version: 1.0
Content-Type: text/plain;
charset="ibm852"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
I greet you!
I have bad news for you.
11/08/2018 - on this day I hacked your operating system and got full access to your account christian.gabriel@ift-informatik.de
It is useless to change the password, my malware intercepts it every time.
How it was:
In the software of the router to which you were connected that day, there was a vulnerability.
I first hacked this router and placed my malicious code on it.
When you entered in the Internet, my trojan was installed on the operating system of your device.
After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).
A month ago, I wanted to lock your device and ask for a small amount of money to unlock.
But I looked at the sites that you regularly visit, and came to the big delight of your favorite resources.
I'm talking about sites for adults.
I want to say - you are a big pervert. You have unbridled fantasy!
After that, an idea came to my mind.
I made a screenshot of the intimate website where you have fun (you know what it is about, right?).
After that, I took off your joys (using the camera of your device). It turned out beautifully, do not hesitate.
I am strongly belive that you would not like to show these pictures to your relatives, friends or colleagues.
I think $874 is a very small amount for my silence.
Besides, I spent a lot of time on you!
I accept money only in Bitcoins.
My BTC wallet: 1B1Vov1LTLGLcVG3ycPQhQLe81V67FZpMZ
You do not know how to replenish a Bitcoin wallet?
In any search engine write "how to send money to btc wallet".
It's easier than send money to a credit card!
For payment you have a little more than two days (exactly 50 hours).
Do not worry, the timer will start at the moment when you open this letter. Yes, yes .. it has already started!
After payment, my virus and dirty photos with you self-destruct automatically.
Narrative, if I do not receive the specified amount from you, then your device will be blocked, and all your contacts will receive a photos with your "joys".
I want you to be prudent.
- Do not try to find and destroy my virus! (All your data is already uploaded to a remote server)
- Do not try to contact me (this is not feasible, I sent you an email from your account)
- Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.
P.S. I guarantee you that I will not disturb you again after payment, as you are not my single victim.
This is a hacker code of honor.
From now on, I advise you to use good antiviruses and update them regularly (several times a day)!
Don't be mad at me, everyone has their own work.
Farewell.
------------=_5BDF9427.9B9F1F0F--