hostmaster@ximalas.info is compromised. Password must be changed
This is all so cute. Scammers don’t bother doing any research at all, but harvest our email addresses and send their junk emails high and low. Scammers usually have no sense of spelling nor grammar, which is the case in the matter at hand. Sorry, I don’t scare so easily.
From hostmaster@ximalas.info Sun Oct 28 02:41:32 2018 Return-Path: <hostmaster@ximalas.info> Received: from [117.153.134.222] ([117.153.134.222]) by enterprise.ximalas.info (8.15.2/8.15.2) with ESMTP id w9S0fS76066064 for <hostmaster@ximalas.info>; Sun, 28 Oct 2018 02:41:28 +0200 (CEST) (envelope-from hostmaster@ximalas.info) Message-ID: <2715587FAA6A328DBFF2D500C0982715@ximalas.info> From: <hostmaster@ximalas.info> To: <hostmaster@ximalas.info> Subject: hostmaster@ximalas.info is compromised. Password must be changed Date: 28 Oct 2018 08:13:30 +0700 MIME-Version: 1.0 Content-Type: text/plain; charset="ibm852" Content-Transfer-Encoding: 8bit X-Mailer: Ugbswihq blsjmiu 6.2 X-Spam-Status: No, score=1.9 required=5.0 tests=BAYES_50,BITCOIN_MALWARE, BITCOIN_PAY_ME,FROM_IN_TO_AND_SUBJ,HELO_MISC_IP,RDNS_NONE,SPF_FAIL, TO_EQ_FM_DOM_SPF_FAIL,TO_EQ_FM_SPF_FAIL autolearn=no autolearn_force=no version=3.4.2 X-Spam-Level: * X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on enterprise.ximalas.info Status: RO X-Status: X-Keywords: X-UID: 19089 Hello! I'm a programmer who cracked your email account and device about half year ago. You entered a password on one of the insecure site you visited, and I catched it. Of course you can will change your password, or already made it. But it doesn't matter, my rat software update it every time. Please don't try to contact me or find me, it is impossible, since I sent you an email from your email account. Through your e-mail, I uploaded malicious code to your Operation System. I saved all of your contacts with friends, colleagues, relatives and a complete history of visits to the Internet resources. Also I installed a rat software on your device and long tome spying for you. You are not my only victim, I usually lock devices and ask for a ransom. But I was struck by the sites of intimate content that you very often visit. I am in shock of your reach fantasies! Wow! I've never seen anything like this! I did not even know that SUCH content could be so exciting! So, when you had fun on intime sites (you know what I mean!) I made screenshot with using my program from your camera of yours device. After that, I jointed them to the content of the currently viewed site. Will be funny when I send these photos to your contacts! And if your relatives see it? BUT I'm sure you don't want it. I definitely would not want to ... I will not do this if you pay me a little amount. I think $838 is a nice price for it! I accept only Bitcoins. My BTC wallet: 17XHRucfd4kx3W5ty7ySLGiKHqmPUUdpus If you have difficulty with this - Ask Google "how to make a payment on a bitcoin wallet". It's easy. After receiving the above amount, all your data will be immediately removed automatically. My virus will also will be destroy itself from your operating system. My Trojan have auto alert, after this email is looked, I will be know it! You have 2 days (48 hours) for make a payment. If this does not happen - all your contacts will get crazy shots with your dirty life! And so that you do not obstruct me, your device will be locked (also after 48 hours) Do not take this frivolously! This is the last warning! Various security services or antiviruses won't help you for sure (I have already collected all your data). Here are the recommendations of a professional: Antiviruses do not help against modern malicious code. Just do not enter your passwords on unsafe sites! I hope you will be prudent. Bye.
Update 2018-10-29
I received a couple more of these scams. I noticed a few interesting bits in the headers and body.
Sample 2:
[31.10.171.58] MIME-Version: 1.0 Content-Type: text/plain; charset="ibm852" Content-Transfer-Encoding: 8bit X-Mailer: Microsoft Windows Live Mail 16.4.3505.912 X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3505.912 My BTC wallet: 17XHRucfd4kx3W5ty7ySLGiKHqmPUUdpus
Sample 3:
[190.157.249.224] MIME-Version: 1.0 Content-Type: text/plain; charset="ibm852" Content-Transfer-Encoding: 8bit X-Mailer: Microsoft Outlook Express 6.00.2900.3721 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3721 My BTC wallet: 17XHRucfd4kx3W5ty7ySLGiKHqmPUUdpus
At least the Bitcoin wallet is consistent, but I wonder if it’s for real.