MOON
Server: Apache/2.2.34 (Unix) mod_ssl/2.2.34 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 FrontPage/5.0.2.2635
System: Linux server.asjudinet.com 2.6.32-042stab141.3 #1 SMP Fri Nov 15 22:45:34 MSK 2019 i686
User: asjudine (504)
PHP: 5.2.17
Disabled: NONE
Upload Files
File: /home/asjudine/mail/asjudinet.com/servi/new/1623207553.H467535P22103.server.asjudinet.com,S=6656
Return-path: <servi@asjudinet.com>
Envelope-to: servi@asjudinet.com
Delivery-date: Tue, 08 Jun 2021 21:59:13 -0500
Received: from [106.223.179.235] (port=5013)
	by server.asjudinet.com with esmtp (Exim 4.87)
	(envelope-from <servi@asjudinet.com>)
	id 1lqoQq-0005jy-RG
	for servi@asjudinet.com; Tue, 08 Jun 2021 21:59:13 -0500
Message-ID: <C1BDE363BE9F3D3E421C9C4160C2C1BD@asjudinet.com>
From: <servi@asjudinet.com>
To: <servi@asjudinet.com>
Subject: =?UTF-8?B?V2l0aCByZWZlcmVuY2UgdG8geW91ciBjbG91ZCBzdG9yYWdl?=
Date: 9 Jun 2021 11:59:52 +0400
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="---------6392005136996761"
X-Mailer: Upbjdfpu gdbin 5.2
X-Spam-Status: No, score=4.4
X-Spam-Score: 44
X-Spam-Bar: ++++
X-Ham-Report: Spam detection software, running on the system "server.asjudinet.com",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 
 Content preview:  Hello. I am sorry to inform you that your mobile backup storage
    was compromised. I'll explain what led to all of this. One website where
   you have an account was hacked. I've got access to your password from that
    breach and with some advanced hacking techniques and bruteforce, I have extracted
    your backup data from the cloud storage used for backups. Nothing could have
    prevented this, not even 2FA. [...] 
 
 Content analysis details:   (4.4 points, 5.0 required)
 
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  2.4 DATE_IN_FUTURE_03_06   Date: is 3 to 6 hours after Received: date
 -5.0 RCVD_IN_DNSWL_HI       RBL: Sender listed at https://www.dnswl.org/, high
                             trust
                             [106.223.179.235 listed in list.dnswl.org]
  0.0 HTML_MESSAGE           BODY: HTML included in message
  2.0 RDNS_NONE              Delivered to internal network by a host with no rDNS
  1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
                             anti-forgery methods
  0.5 PDS_BTC_ID             FP reduced Bitcoin ID
  1.0 BITCOIN_EXTORT_01      Extortion spam, pay via BitCoin
  2.5 BITCOIN_SPAM_07        BitCoin spam pattern 07
  0.0 TO_EQ_FM_DIRECT_MX     To == From and direct-to-MX
X-Spam-Flag: NO

This is a multi-part message in MIME format.

-----------6392005136996761
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hello.
I am sorry to inform you that your mobile backup storage was =
compromised.

I'll explain what led to all of this. One website where you have an =
account was hacked.
I've got access to your password from that breach and with some advanced =
hacking techniques and bruteforce, I have extracted your backup data =
from the cloud storage used for backups.
Nothing could have prevented this, not even 2FA.

The data that I have downloaded contains your personal photos and =
videos, chats, documents, emails, contacts, your browsing history, =
notes, social media history and more including some deleted files.
Basically it's a full copy of your mobile device.

I am sure that you dont want any part of the data to be seen by other =
people. And you can prevent this.
If I dont get what I'm asking for, I will use this information against =
you. I find some of the media content quite entertaining(you know what =
I'm talking about), your friends and colleagues will not think the same.

If you are not sure of what I can do, just imagine what would happen if =
I use your email or phone number to send the most private and damaging =
content to your contacts. And can spice up things with you browsing =
history as well.
It will be very damaging to you personally.

However, I offer you a solution. You will avoid this mess by paying me a =
consulting fee to delete the files I have.
I guarantee, that after I receive the payment, the files will be deleted =
on my side and I will not bother you again about this. You will need to =
change your password as well.
So let's make it simple. You pay me $1500 USD. Use Bitcoin to make the =
transfer.

Wallet address is bc1qej30uk9medzyykvaghg38dtry7xuyc0f3fzg78 , it's =
unique and I will know that you made the payment immediately.
You have 2 days to make the transfer, I think that's reasonable.
Take care.

-----------6392005136996761
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html><head>
 <meta Http-Equiv=3Dcontent-type content=3D"text/html; =
charset=3Diso-8859-1">
 </head>
<body>Hello.<br>
I am sorry to inform you that your mobile backup storage was =
compromised.<br><br>
I'll explain what led to all of this. One website where you have an =
account was hacked.<br>
I've got access to your password from that breach and with some advanced =
hacking techniques and bruteforce, I have extracted your backup data =
from the cloud storage used for backups.<br>
Nothing could have prevented this, not even 2FA.<br><br>
The data that I have downloaded contains your personal photos and =
videos, chats, documents, emails, contacts, your browsing history, =
notes, social media history and more including some deleted files.<br>
Basically it's a full copy of your mobile device.<br><br>
I am sure that you dont want any part of the data to be seen by other =
people. And you can prevent this.<br>
If I dont get what I'm asking for, I will use this information against =
you. I find some of the media content quite entertaining(you know what =
I'm talking about), your friends and colleagues will not think the =
same.<br><br>
If you are not sure of what I can do, just imagine what would happen if =
I use your email or phone number to send the most private and damaging =
content to your contacts. And can spice up things with you browsing =
history as well.<br>
It will be very damaging to you personally.<br><br>
However, I offer you a solution. You will avoid this mess by paying me a =
consulting fee to delete the files I have.<br>
I guarantee, that after I receive the payment, the files will be deleted =
on my side and I will not bother you again about this. You will need to =
change your password as well.<br>
So let's make it simple. You pay me $1500 USD. Use Bitcoin to make the =
transfer.<br><br>
Wallet address is bc1qej30uk9medzyykvaghg38dtry7xuyc0f3fzg78 , it's =
unique and I will know that you made the payment immediately.<br>
You have 2 days to make the transfer, I think that's reasonable.<br>
Take care.<br>
 </body></html>
-----------6392005136996761--