Your IP : 216.73.217.78


Current Path : /home2/seto/mail/.Trash/cur/
Upload File :
Current File : //home2/seto/mail/.Trash/cur/1706802193.M365915P25810.web01.alphahost.lv,S=10131,W=10364:2,S

Return-Path: <matchwind@rooseveltmail.com>
Delivered-To: seto+spam@web01.alphahost.lv
Received: from web01.alphahost.lv
	by web01.alphahost.lv with LMTP
	id gPjyEWV8TmW6bwAAiNxmsg
	(envelope-from <matchwind@rooseveltmail.com>)
	for <seto+spam@web01.alphahost.lv>; Fri, 10 Nov 2023 20:54:29 +0200
Return-path: <matchwind@rooseveltmail.com>
Envelope-to: jorma.kokkonen@huiput.fi
Delivery-date: Fri, 10 Nov 2023 20:54:29 +0200
Received: from [181.220.133.41] (port=10932 helo=b5dc8529.virtua.com.br)
	by web01.alphahost.lv with esmtp (Exim 4.96.2)
	(envelope-from <matchwind@rooseveltmail.com>)
	id 1r1We9-0007UO-0G
	for jorma.kokkonen@huiput.fi;
	Fri, 10 Nov 2023 20:54:29 +0200
From: <matchwind@rooseveltmail.com>
To: <jorma.kokkonen@huiput.fi>
Date: 10 Nov 2023 11:41:22 -0400
Message-ID: <002801da13ee$0156e366$183e57a3$@rooseveltmail.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0025_01DA13EE.015157B0"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Acwfgqbdmn4xei7iwfgqbdmn4xei7i==
Content-Language: ru
X-Spam-Status: Yes, score=31.7
X-Spam-Score: 317
X-Spam-Bar: +++++++++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "web01.alphahost.lv",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Hello there!Unfortunately, there are some bad news for you.Some
    time ago your device was infected with my private trojan, R.A.T (Remote Administration
    Tool), if you want to find out more about it simp [...] 
 Content analysis details:   (31.7 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                             blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: paybis.com]
  1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in
                             bl.spamcop.net
              [Blocked - see <https://www.spamcop.net/bl.shtml?181.220.133.41>]
  1.0 BAYES_999              BODY: Bayes spam probability is 99.9 to 100%
                             [score: 1.0000]
  5.0 BAYES_99               BODY: Bayes spam probability is 99 to 100%
                             [score: 1.0000]
  1.3 RCVD_IN_VALIDITY_RPBL  RBL: Relay in Validity RPBL,
                             https://senderscore.org/blocklistlookup/
                            [181.220.133.41 listed in bl.score.senderscore.com]
  2.7 RCVD_IN_PSBL           RBL: Received via a relay in PSBL
                             [181.220.133.41 listed in psbl.surriel.com]
  1.6 DATE_IN_PAST_03_06     Date: is 3 to 6 hours before Received: date
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.0 HTML_EXTRA_CLOSE       BODY: HTML contains far too many close tags
  1.8 PYZOR_CHECK            Listed in Pyzor
                             (https://pyzor.readthedocs.io/en/latest/)
  1.9 BITCOIN_MALF_HTML      Bitcoin + malformed HTML
  1.8 RATWARE_NO_RDNS        Suspicious MsgID and MIME boundary + no rDNS
 -0.0 T_SCC_BODY_TEXT_LINE   No description available.
  1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
                             anti-forgery methods
  2.0 RDNS_NONE              Delivered to internal network by a host with no rDNS
  0.0 KAM_SHORT              Use of a URL Shortener for very short URL
  2.3 BITCOIN_EXTORT_01      Extortion spam, pay via BitCoin
  0.5 PDS_BTC_ID             FP reduced Bitcoin ID
  1.6 FSL_BULK_SIG           Bulk signature with no Unsubscribe
  3.0 GB_BITCOIN_CP          Localized Bitcoin scam
  2.8 DOS_OUTLOOK_TO_MX      Delivered direct to MX with Outlook headers
X-Spam-Flag: YES
Subject:  ***SPAM***  I recorded you.

This is a multi-part message in MIME format.

------=_NextPart_000_0025_01DA13EE.015157B0
Content-Type: text/plain;
	charset="koi8-r"
Content-Transfer-Encoding: quoted-printable

Hello there!Unfortunately, there are some bad news for you.Some time ago =
your device was infected with my private trojan, R.A.T (Remote =
Administration Tool), if you want to find out more about it simply use =
Google.My trojan allowed me to access your files, accounts and your =
camera.Check the sender of this email, I have sent it from your email =
account.To make sure you read this email, you will receive it multiple =
times.You truly enjoy checking out porn websites and watching dirty =
videos, while having a lot of kinky fun.I RECORDED YOU (through your =
camera) SATISFYING YOURSELF!After that I removed my malware to not leave =
any traces.If you still doubt my serious intentions, it only takes =
couple mouse clicks to share the video of you with your friends, =
relatives, all email contacts, on social networks, the darknet and to =
publish all your files.All you need is $1700 USD in =F7it=D3=CFin =
(=F7=F4=F3) transfer to my account.After the transaction is successful, =
I will proceed to delete everything.Be sure, I keep my promises.You can =
easily buy =F7it=D3=CFin (=F7=F4=F3) =
here:https://cex.io/https://nexo.com/https://bitpay.com/https://paybis.co=
m/https://invity.io/Or simply google other exchanger.After that send the =
=F7it=D3=CFin (=F7=F4=F3) directly to my wallet, or install the free =
software: Atomicwallet, or: Exodus wallet, then receive and send to =
mine.My =F7it=D3=CFin (=F7=F4=F3) address is: =
1MvogqA76t4o8Cya83SbPCGn52VRJsbiUVYes, that's how the address looks =
like, copy and paste my address, it's (cAsE-sEnSEtiVE).You are given not =
more than 3 days after you have opened this email.As I got access to =
this email account, I will know if this email has already been =
read.Everything will be carried out based on fairness.An advice from me, =
regularly change all your passwords to your accounts and update your =
device with newest security patches.
------=_NextPart_000_0025_01DA13EE.015157B0
Content-Type: text/html;
	charset="koi8-r"
Content-Transfer-Encoding: quoted-printable

<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dkoi8-r">
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta name=3DGenerator =
content=3D"Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0in;
=09margin-bottom:.0001pt;
=09font-size:11.0pt;
=09font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:blue;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:purple;
=09text-decoration:underline;}
span.EmailStyle17
=09{mso-style-type:personal-compose;
=09font-family:"Calibri","sans-serif";
=09color:windowtext;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-family:"Calibri","sans-serif";}
@page WordSection1
=09{size:8.5in 11.0in;
=09margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
=09{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
lang=3DRU>Hello there!</br>
</br>
Unfortunately, there are some bad news for you.</br>
</br>
Some time ago your device was infected with my private trojan, R.A.T =
(Remote Administration Tool), if you want to find out more about it =
simply use Google.</br>
</br>
My trojan allowed me to access your files, accounts and your =
camera.</br>
</br>
Check the sender of this email, I have sent it from your email =
account.</br>
</br>
To make sure you read this email, you will receive it multiple =
times.</br>
</br>
You truly enjoy checking out porn websites and watching dirty videos, =
while having a lot of kinky fun.</br>
</br>
I RECORDED YOU (through your camera) SATISFYING YOURSELF!</br>
</br>
After that I removed my malware to not leave any traces.</br>
</br>
If you still doubt my serious intentions, it only takes couple mouse =
clicks to share the video of you with your friends, relatives, all email =
contacts, on social networks, </br>
the darknet and to publish all your files.</br>
</br>
All you need is $1700 USD in =F7it=D3=CFin (=F7=F4=F3) transfer to my =
account.</br>
</br>
After the transaction is successful, I will proceed to delete =
everything.</br>
</br>
Be sure, I keep my promises.</br>
</br>
You can easily buy =F7it=D3=CFin (=F7=F4=F3) here:</br>
</br>
https://cex.io/</br>
https://nexo.com/</br>
https://bitpay.com/</br>
https://paybis.com/</br>
https://invity.io/</br>
</br>
Or simply google other exchanger.</br>
</br>
After that send the =F7it=D3=CFin (=F7=F4=F3) directly to my wallet, or =
install the free software: Atomicwallet, or: Exodus wallet, then receive =
and send to mine.</br>
</br>
My =F7it=D3=CFin (=F7=F4=F3) address is: =
1MvogqA76t4o8Cya83SbPCGn52VRJsbiUV</br>
</br>
Yes, that's how the address looks like, copy and paste my address, it's =
(cAsE-sEnSEtiVE).</br>
</br>
You are given not more than 3 days after you have opened this =
email.</br>
</br>
As I got access to this email account, I will know if this email has =
already been read.</br>
</br>
Everything will be carried out based on fairness.</br>
</br>
An advice from me, regularly change all your passwords to your accounts =
and update your device with newest security =
patches.</span><o:p></o:p></p></div></body></html>
------=_NextPart_000_0025_01DA13EE.015157B0--