File: /home/asjudine/mail/.policia@asjudinet_com/new/1677898518.H646531P3817.server.asjudinet.com,S=6775
Return-path: <>
Envelope-to: policia@asjudinet.com
Delivery-date: Fri, 03 Mar 2023 20:55:18 -0600
Received: from gw-web.webley.net ([208.64.100.134]:50702 helo=mailcluster.webley.net)
by server.asjudinet.com with smtp (Exim 4.87)
id 1pYI3B-0000wN-5Z
for policia@asjudinet.com; Fri, 03 Mar 2023 20:55:18 -0600
Received: (qmail 14590 invoked for bounce); 4 Mar 2023 02:54:13 -0000
Date: 4 Mar 2023 02:54:13 -0000
From: MAILER-DAEMON@mailcluster.webley.net
To: policia@asjudinet.com
Subject: failure notice
X-Spam-Status: No, score=0.7
X-Spam-Score: 7
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "server.asjudinet.com",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Hi. This is the qmail-send program at mailcluster.webley.net.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out. [...]
Content analysis details: (0.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URIs: pldt.net]
-1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1%
[score: 0.0000]
-0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[208.64.100.134 listed in wl.mailspike.net]
0.0 RCVD_IN_DNSWL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to DNSWL
was blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[208.64.100.134 listed in list.dnswl.org]
1.6 MISSING_MID Missing Message-Id: header
1.0 MALWARE_PASSWORD Malware bragging + "password"
X-Spam-Flag: NO
Hi. This is the qmail-send program at mailcluster.webley.net.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<shirley_galindoxr@wwdb.org>:
Sorry, no mailbox here by that name. (#5.1.1)
--- Below this line is a copy of the message.
Return-Path: <policia@asjudinet.com>
Received: (qmail 14586 invoked by uid 1031); 4 Mar 2023 02:54:13 -0000
Received: from dsl.49.145.238.31.pldt.net (HELO dsl.49.145.238.31.pldt.net) (49.145.238.31)
by mailcluster.webley.net (qpsmtpd/0.93) with ESMTP; Fri, 03 Mar 2023 20:54:13 -0600
Authentication-Results: mailcluster.webley.net; auth=none; iprev=permerror; iprev=fail
X-Spam-CMAE-Analysis: v=2.1 cv=ceFcrxzM c=1 sm=0 tr=0 a=FdjhB7wAAAAA:8
a=tV8vin5e5ZgA:10 a=L405mhjrI-AA:10 a=edaE1czyNOoA:10
a=0dwXgXSptwVgj6YubBsA:9 a=tfwewdB7HFUA:10 a=ViXo3W7vCnch9nAzBzgA:22
X-Spam-Status: No, score=0.0 required=9.9 tests=none autolearn=disabled
version=3.3.2
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
wmailapp01-prod.webley
X-HELO: dsl.49.145.238.31.pldt.net
From: <policia@asjudinet.com>
To: <shirley_galindoxr@wwdb.org>
Date: 4 Mar 2023 17:47:19 +0700
MIME-Version: 1.0
Subject: Security Notice. shirley_galindoxr@wwdb.org was hacked! Change your password now!
Message-ID: <6403235B.6412.6CA00E@policia.asjudinet.com>
Priority: normal
X-mailer: Pegasus Mail for Windows (4.52)
Content-type: text/plain; charset="cp-850"
Content-transfer-encoding: 8BIT
Content-description: Mail message body
Dear user of wwdb.org!
I am a spyware software developer.
Your account has been hacked by me couple months ago.
The hacking was carried out using a hardware vulnerability through which you went online (Cisco router, vulnerability CVE-2023-20026).
I went around the security system in the router, installed an exploit there.
When you went online, my exploit downloaded my malicious code (rootkit) to your device.
This is driver software, I constantly updated it, so your antivirus is silent all time.
Since then I have been following you (I can connect to your device via the VNC protocol).
That is, I can see absolutely everything that you do, view and download your files and any data to yourself.
I also have access to the camera on your device, and I periodically take photos and videos with you.
At the moment, I have harvested a solid dirt... on you...
I saved all your email and chats from your messangers. I also saved the entire history of the sites you visit.
I note that it is useless to change the passwords. My malware update passwords from your accounts every times.
I know what you like hard funs (adult sites).
Oh, yes .. I'm know your secret life, which you are hiding from everyone.
Oh my God, what are your like... I saw THIS ... Oh, you dirty naughty person ... :)
I took photos and videos of your most passionate funs with adult content, and synchronized them in real time with the image of your camera.
Believe it turned out very high quality!
So, to the business!
I'm sure you don't want to show these files and visiting history to all your contacts.
Transfer $1390 to my Bitcoin cryptocurrency wallet: 1PNWAf qoNQhTR2 jCpcSPL 6P5XrC xCofqB3
Just copy and paste the wallet number when transferring.
An important notice: I have specified my Bitcoin wallet with spaces, hence once you carry out a transfer,
please make sure that you key-in my bitcoin address without spaces to be sure that your funds successfully reach my wallet!
If you do not know how to do this - ask Google.
My system automatically recognizes the translation.
As soon as the specified amount is received, all your data will be destroyed from my server, and the rootkit will be automatically removed from your system.
Do not worry, I really will delete everything, since I am 'working' with many people who have fallen into your position.
You will only have to inform your provider about the vulnerabilities in the router so that other hackers will not use it.
Since opening this letter you have 48 hours.
If funds not will be received, after the specified time has elapsed, the disk of your device will be formatted,
and from my server will automatically send email and sms to all your contacts with compromising material.
P.S. Do not try to contact me (this is impossible, sender's address was randomly generated).
I advise you to remain prudent and not engage in nonsense (all files on my server).
Good luck!