| Current Path : /home2/seto/mail/.Trash/cur/ |
| Current File : //home2/seto/mail/.Trash/cur/1706802193.M365915P25810.web01.alphahost.lv,S=10131,W=10364:2,S |
Return-Path: <matchwind@rooseveltmail.com>
Delivered-To: seto+spam@web01.alphahost.lv
Received: from web01.alphahost.lv
by web01.alphahost.lv with LMTP
id gPjyEWV8TmW6bwAAiNxmsg
(envelope-from <matchwind@rooseveltmail.com>)
for <seto+spam@web01.alphahost.lv>; Fri, 10 Nov 2023 20:54:29 +0200
Return-path: <matchwind@rooseveltmail.com>
Envelope-to: jorma.kokkonen@huiput.fi
Delivery-date: Fri, 10 Nov 2023 20:54:29 +0200
Received: from [181.220.133.41] (port=10932 helo=b5dc8529.virtua.com.br)
by web01.alphahost.lv with esmtp (Exim 4.96.2)
(envelope-from <matchwind@rooseveltmail.com>)
id 1r1We9-0007UO-0G
for jorma.kokkonen@huiput.fi;
Fri, 10 Nov 2023 20:54:29 +0200
From: <matchwind@rooseveltmail.com>
To: <jorma.kokkonen@huiput.fi>
Date: 10 Nov 2023 11:41:22 -0400
Message-ID: <002801da13ee$0156e366$183e57a3$@rooseveltmail.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0025_01DA13EE.015157B0"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Acwfgqbdmn4xei7iwfgqbdmn4xei7i==
Content-Language: ru
X-Spam-Status: Yes, score=31.7
X-Spam-Score: 317
X-Spam-Bar: +++++++++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "web01.alphahost.lv",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Hello there!Unfortunately, there are some bad news for you.Some
time ago your device was infected with my private trojan, R.A.T (Remote Administration
Tool), if you want to find out more about it simp [...]
Content analysis details: (31.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: paybis.com]
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in
bl.spamcop.net
[Blocked - see <https://www.spamcop.net/bl.shtml?181.220.133.41>]
1.0 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
5.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
[score: 1.0000]
1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL,
https://senderscore.org/blocklistlookup/
[181.220.133.41 listed in bl.score.senderscore.com]
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[181.220.133.41 listed in psbl.surriel.com]
1.6 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received: date
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_EXTRA_CLOSE BODY: HTML contains far too many close tags
1.8 PYZOR_CHECK Listed in Pyzor
(https://pyzor.readthedocs.io/en/latest/)
1.9 BITCOIN_MALF_HTML Bitcoin + malformed HTML
1.8 RATWARE_NO_RDNS Suspicious MsgID and MIME boundary + no rDNS
-0.0 T_SCC_BODY_TEXT_LINE No description available.
1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
anti-forgery methods
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 KAM_SHORT Use of a URL Shortener for very short URL
2.3 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin
0.5 PDS_BTC_ID FP reduced Bitcoin ID
1.6 FSL_BULK_SIG Bulk signature with no Unsubscribe
3.0 GB_BITCOIN_CP Localized Bitcoin scam
2.8 DOS_OUTLOOK_TO_MX Delivered direct to MX with Outlook headers
X-Spam-Flag: YES
Subject: ***SPAM*** I recorded you.
This is a multi-part message in MIME format.
------=_NextPart_000_0025_01DA13EE.015157B0
Content-Type: text/plain;
charset="koi8-r"
Content-Transfer-Encoding: quoted-printable
Hello there!Unfortunately, there are some bad news for you.Some time ago =
your device was infected with my private trojan, R.A.T (Remote =
Administration Tool), if you want to find out more about it simply use =
Google.My trojan allowed me to access your files, accounts and your =
camera.Check the sender of this email, I have sent it from your email =
account.To make sure you read this email, you will receive it multiple =
times.You truly enjoy checking out porn websites and watching dirty =
videos, while having a lot of kinky fun.I RECORDED YOU (through your =
camera) SATISFYING YOURSELF!After that I removed my malware to not leave =
any traces.If you still doubt my serious intentions, it only takes =
couple mouse clicks to share the video of you with your friends, =
relatives, all email contacts, on social networks, the darknet and to =
publish all your files.All you need is $1700 USD in =F7it=D3=CFin =
(=F7=F4=F3) transfer to my account.After the transaction is successful, =
I will proceed to delete everything.Be sure, I keep my promises.You can =
easily buy =F7it=D3=CFin (=F7=F4=F3) =
here:https://cex.io/https://nexo.com/https://bitpay.com/https://paybis.co=
m/https://invity.io/Or simply google other exchanger.After that send the =
=F7it=D3=CFin (=F7=F4=F3) directly to my wallet, or install the free =
software: Atomicwallet, or: Exodus wallet, then receive and send to =
mine.My =F7it=D3=CFin (=F7=F4=F3) address is: =
1MvogqA76t4o8Cya83SbPCGn52VRJsbiUVYes, that's how the address looks =
like, copy and paste my address, it's (cAsE-sEnSEtiVE).You are given not =
more than 3 days after you have opened this email.As I got access to =
this email account, I will know if this email has already been =
read.Everything will be carried out based on fairness.An advice from me, =
regularly change all your passwords to your accounts and update your =
device with newest security patches.
------=_NextPart_000_0025_01DA13EE.015157B0
Content-Type: text/html;
charset="koi8-r"
Content-Transfer-Encoding: quoted-printable
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dkoi8-r">
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta name=3DGenerator =
content=3D"Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
=09{font-family:Calibri;
=09panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
=09{margin:0in;
=09margin-bottom:.0001pt;
=09font-size:11.0pt;
=09font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
=09{mso-style-priority:99;
=09color:blue;
=09text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
=09{mso-style-priority:99;
=09color:purple;
=09text-decoration:underline;}
span.EmailStyle17
=09{mso-style-type:personal-compose;
=09font-family:"Calibri","sans-serif";
=09color:windowtext;}
.MsoChpDefault
=09{mso-style-type:export-only;
=09font-family:"Calibri","sans-serif";}
@page WordSection1
=09{size:8.5in 11.0in;
=09margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
=09{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
lang=3DRU>Hello there!</br>
</br>
Unfortunately, there are some bad news for you.</br>
</br>
Some time ago your device was infected with my private trojan, R.A.T =
(Remote Administration Tool), if you want to find out more about it =
simply use Google.</br>
</br>
My trojan allowed me to access your files, accounts and your =
camera.</br>
</br>
Check the sender of this email, I have sent it from your email =
account.</br>
</br>
To make sure you read this email, you will receive it multiple =
times.</br>
</br>
You truly enjoy checking out porn websites and watching dirty videos, =
while having a lot of kinky fun.</br>
</br>
I RECORDED YOU (through your camera) SATISFYING YOURSELF!</br>
</br>
After that I removed my malware to not leave any traces.</br>
</br>
If you still doubt my serious intentions, it only takes couple mouse =
clicks to share the video of you with your friends, relatives, all email =
contacts, on social networks, </br>
the darknet and to publish all your files.</br>
</br>
All you need is $1700 USD in =F7it=D3=CFin (=F7=F4=F3) transfer to my =
account.</br>
</br>
After the transaction is successful, I will proceed to delete =
everything.</br>
</br>
Be sure, I keep my promises.</br>
</br>
You can easily buy =F7it=D3=CFin (=F7=F4=F3) here:</br>
</br>
https://cex.io/</br>
https://nexo.com/</br>
https://bitpay.com/</br>
https://paybis.com/</br>
https://invity.io/</br>
</br>
Or simply google other exchanger.</br>
</br>
After that send the =F7it=D3=CFin (=F7=F4=F3) directly to my wallet, or =
install the free software: Atomicwallet, or: Exodus wallet, then receive =
and send to mine.</br>
</br>
My =F7it=D3=CFin (=F7=F4=F3) address is: =
1MvogqA76t4o8Cya83SbPCGn52VRJsbiUV</br>
</br>
Yes, that's how the address looks like, copy and paste my address, it's =
(cAsE-sEnSEtiVE).</br>
</br>
You are given not more than 3 days after you have opened this =
email.</br>
</br>
As I got access to this email account, I will know if this email has =
already been read.</br>
</br>
Everything will be carried out based on fairness.</br>
</br>
An advice from me, regularly change all your passwords to your accounts =
and update your device with newest security =
patches.</span><o:p></o:p></p></div></body></html>
------=_NextPart_000_0025_01DA13EE.015157B0--