From messagec49907cdf15e12@mackenziesbakery.com Sat Apr 17 01:19:04 2021 Return-path: Envelope-to: peter@bsdly.net Delivery-date: Sat, 17 Apr 2021 01:19:04 +0200 Received: from a2nlsmtp01-04.prod.iad2.secureserver.net ([198.71.225.38]) by skapet.bsdly.net with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94) (envelope-from ) id 1lXXjo-000Ib2-Db for peter@bsdly.net; Sat, 17 Apr 2021 01:19:04 +0200 Received: from a2plvcpnl96643.prod.iad2.secureserver.net ([148.72.25.96]) by : HOSTING RELAY : with ESMTP id XXQAlK2UGNbE3XXQAlLuD7; Fri, 16 Apr 2021 15:58:42 -0700 X-CMAE-Analysis: v=2.4 cv=d+MwdTvE c=1 sm=1 tr=0 ts=607a16a2 a=9u3Ij1eSKaZFyIBtn9sVjw==:117 a=ndAhEkyj3tJYdDWtKsipZQ==:17 a=9+rZDBEiDlHhcck0kWbJtElFXBc=:19 a=3YhXtTcJ-WEA:10 a=r77TgQKjGQsHNAKrUKIA:9 a=zZLhtI5XKBDK3fWvwgMA:9 a=CjuIK1q_8ugA:10 a=pHzHmUro8NiASowvMSCR:22 a=nt3jZW36AmriUCFCBwmW:22 X-SECURESERVER-ACCT: jessica@mackenziesbakery.com Received: from [124.70.88.254] (port=48316 helo=ecs-124-70-88-254.compute.prod-cloud-ocb.orange-business.com) by a2plvcpnl96643.prod.iad2.secureserver.net with esmtpa (Exim 4.93) (envelope-from ) id 1lXXQA-006Fda-BC for peter@bsdly.net; Fri, 16 Apr 2021 15:58:42 -0700 Date: Fri, 16 Apr 2021 22:58:20 +0000 To: peter@bsdly.net From: Ugo Subject: Come and read Message-ID: <3tCehKHgJbtI9fXeUkIptSJQQbQL9rWq2tUfQNhSU@ecs-124-70-88-254.compute.prod-cloud-ocb.orange-business.com> X-Mailer: PHPMailer 6.0.7 (https://github.com/PHPMailer/PHPMailer) MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="b1_3tCehKHgJbtI9fXeUkIptSJQQbQL9rWq2tUfQNhSU" Content-Transfer-Encoding: 8bit X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - a2plvcpnl96643.prod.iad2.secureserver.net X-AntiAbuse: Original Domain - bsdly.net X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - mackenziesbakery.com X-Get-Message-Sender-Via: a2plvcpnl96643.prod.iad2.secureserver.net: authenticated_id: jessica@mackenziesbakery.com X-Authenticated-Sender: a2plvcpnl96643.prod.iad2.secureserver.net: jessica@mackenziesbakery.com X-Source: X-Source-Args: X-Source-Dir: X-CMAE-Envelope: MS4xfOcc3iNBSM2YKjA92WvY0yM62FrGQr8TFuEO4RamPgKVTKp/KtVHQ0grMZjpyiFByItSxkvi66Yz/RsmF9gPB2dX3z2tM+m63jkCg59dtyvHb0GJjp85 GArzg79O9F6YfSAke1GmliOF/68ZR8a6jUPLAJ6ONHrH2e/s4niy2KQEQ18GpE28/tV5fKEMXIT9VK/vAYAiUK7yVu+theAQey1PB+MLvGyBWSDy9aZct8Rn mAfH0sFmlI65qysQIZ9FJw== X-Spam_score: 6.3 X-Spam_score_int: 63 X-Spam_bar: ++++++ X-Spam_report: Spam detection software, running on the system "skapet.bsdly.net", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see @@CONTACT_ADDRESS@@ for details. Content preview: Hi! The story is, you watch PRONOGRAPHlC videoz ... and I have you REC0RDED while you MASSTURBATE. Your phone got a MALLWARE and your CAMERRA was activated when... was important if we can say that. Also.. [...] Content analysis details: (6.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 5.0 BAYES_50 BODY: Bayes spam probability is 40 to 60% [score: 0.4083] 0.0 FROM_LOCAL_HEX From: localpart has long hexadecimal sequence 0.0 RCVD_IN_MSPIKE_L4 RBL: Bad reputation (-4) [198.71.225.38 listed in bl.mailspike.net] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [198.71.225.38 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 0.3 FUZZY_BITCOIN BODY: Obfuscated "Bitcoin" 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 RCVD_IN_MSPIKE_BL Mailspike blacklisted 0.0 OBFU_BITCOIN Obfuscated BitCoin references 0.5 PDS_BTC_ID FP reduced Bitcoin ID 0.5 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin Content analysis details: (6.3 points, 5.0 required, s/c no) X-Spam-Flag: YES X-New-Subject: *****SPAM***** Come and read Status: RO Content-Length: 2722 Lines: 38 This is a multi-part message in MIME format. --b1_3tCehKHgJbtI9fXeUkIptSJQQbQL9rWq2tUfQNhSU Content-Type: text/plain; charset=us-ascii Hi! The story is, you watch PRONOGRAPHlC videoz ... and I have you REC0RDED while you MASSTURBATE. Your phone got a MALLWARE and your CAMERRA was activated when... was important if we can say that. Also... your list of contacts/list of social contacts was copied and if you don`t send me 800$ worth in BlTC0IN I will drop the video with you too all your contacts. Do a search on Google for PAAXFUL and get some coins there. Use those details and send that amount approximately: The Address: 1-B-f-9-G-w-v-K-6-n-Q-m-s-1-x-4-F-i-m-P-5-1-X-c-Y-8-b-B-v-F-r-g-3-D The Amount: 0.013 Ok so, you have to remove manually all the dashes in my address and you will get a string of 34 characters that starts with "1" and ends with "D". Use that with no dashes when you transfer my bribery. Also important is that addrs is Case Sensitive. You have a few days to do this. Also to clean your device from my sneaky stuff that was installed look for "How to reset to factory settings" and your phone model. You may want to stop watching this stuffs to avoid this kind of situation ... you know.. Once the bribery is sent the footage will be erased and I`m gone. --b1_3tCehKHgJbtI9fXeUkIptSJQQbQL9rWq2tUfQNhSU Content-Type: text/html; charset=us-ascii

Hi!

The story is, you watch PRONOGRAPHlC videoz ... and I have you REC0RDED while you MASSTURBATE.

Your phone got a MALLWARE and your CAMERRA was activated when... was important if we can say that. Also... your list of contacts/list of social contacts was copied and if you don`t send me 800$ worth in BlTC0IN I will drop the video with you too all your contacts. Do a search on Google for PAAXFUL and get some coins there.

Use those details and send that amount approximately:

The Address: 1-B-f-9-G-w-v-K-6-n-Q-m-s-1-x-4-F-i-m-P-5-1-X-c-Y-8-b-B-v-F-r-g-3-D

The Amount: 0.013

Ok so, you have to remove manually all the dashes in my address and you will get a string of 34 characters that starts with "1" and ends with "D". Use that with no dashes when you transfer my bribery. Also important is that addrs is Case Sensitive.

You have a few days to do this. Also to clean your device from my sneaky stuff that was installed look for "How to reset to factory settings" and your phone model.

You may want to stop watching this stuffs to avoid this kind of situation ... you know..

Once the bribery is sent the footage will be erased and I`m gone.

--b1_3tCehKHgJbtI9fXeUkIptSJQQbQL9rWq2tUfQNhSU--