Site logo

     



Advert.
Switch to full style
Scammers blackmailing people over webcam footage or photographs. Sometimes referred to as "sextortion". Your first port of call should be www.blackmailscams.com for the steps needed.
Topic locked

Re: "Belarus Phishing Expedition" - part 2.

Mon Jul 22, 2019 12:03 pm

All these in just 6 hours! All identical emails, just the email address and title being different.

Save Yourself <SaveYourself88@2190.com>
Save Yourself <SaveYourself71@3452.com>
Save Yourself <SaveYourself55@0104.com>
Save Yourself <SaveYourself79@8313.com>
Save Yourself <SaveYourself66@0517.com>
Save Yourself <SaveYourself55@8553.com>
Save Yourself <SaveYourself61@8915.com>
Save Yourself <SaveYourself13@8622.com>
Save Yourself <SaveYourself32@7809.com>
Save Yourself <SaveYourself51@3728.com>

***SPAM*** Dirty video of you - XXXXXX
***SPAM*** Seen everything - XXXXXX
***SPAM*** Save yourself - XXXXXX
***SPAM*** Recorded you - XXXXXX
***SPAM*** Dirty video of you - XXXXXX
***SPAM*** I know everything - XXXXXX
***SPAM*** Seen everything - XXXXXX
***SPAM*** You better pay me - XXXXXX
***SPAM*** Your privacy - XXXXXX
***SPAM*** Seen everything - XXXXXX

Hi, I know one of your passwords is: XXXXXX

Your computer was infected with my private malware, your browser wasn't updated / patched, in such case it's enough to just visit some website where my iframe is placed to get automatically infected, if you want to find out more - Google: "Drive-by exploit".

My malware gave me full access to all your accounts (see password above), full control over your computer and it also was possible to spy on you over your webcam.

I collected all your private data and I RECORDED YOU (through your webcam) SATISFYING YOURSELF!

After that I removed my malware to not leave any traces and this email was sent from some hacked server.

I can publish the video of you and all your private data on the whole web, social networks, over email of all contacts.

But you can stop me and only I can help you out in this situation.

The only way to stop me, is to pay exactly 800$ in bitcoin (BTC).

It's a very good offer, compared to all that horrible shit that will happen if I publish everything!

You can easily buy bitcoin here: www.paxful.com , www.coingate.com , www.coinbase.com , or check for bitcoin ATM near you, or Google for other exchanger.
You can send the bitcoin directly to my wallet, or create your own wallet first here: www.login.blockchain.com/en/#/signup/ , then receive and send to mine.

My bitcoin wallet is: 1EQSAqbFwiZhpHrg6Wy4xhySc9fPpt7DQw

Copy and paste my wallet, it's (cAsE-sEnSEtiVE)

You got 3 days time to pay.

As I got access to this email account, I will know if this email has already been read.
If you get this email multiple times, it's to make sure that you read it, my mailer script is configured like this and after payment you can ignore it.
After receiving the payment, I will remove everything and you can life your live in peace like before.

Next time update your browser before browsing the web!





Mail-Client-ID: 2215929479

Re: "Belarus Phishing Expedition" - part 2.

Tue Jul 23, 2019 1:49 pm

Another 15 today. (edit, make that 18)

My bitcoin wallet is: 1FLREuhB3U56yJBTTsj6zzEXjNf4BTzeZr

Re: "Belarus Phishing Expedition" - part 2.

Tue Jul 23, 2019 7:15 pm

19.

My bitcoin wallet is: 1Nq84HeDmd2JGyRtjqh32QRG4zoSrp8bdL

Re: "Belarus Phishing Expedition" - part 2.

Tue Jul 23, 2019 8:58 pm

Here's today's email addresses.

Save Yourself <SaveYourself28@8472.com>
Save Yourself <SaveYourself70@5034.com>
Save Yourself <SaveYourself56@7561.com>
Save Yourself <SaveYourself09@5297.com>
Save Yourself <SaveYourself86@2714.com>
Save Yourself <SaveYourself19@2714.com>
Save Yourself <SaveYourself06@3065.com>
Save Yourself <SaveYourself57@2069.com>
Save Yourself <SaveYourself51@4695.com>
Save Yourself <SaveYourself25@0684.com>
Save Yourself <SaveYourself44@4085.com>
Save Yourself <SaveYourself47@2000.com>
Save Yourself <SaveYourself27@6153.com>
Save Yourself <SaveYourself33@5594.com>
Save Yourself <SaveYourself11@6731.com>
Save Yourself <SaveYourself87@8239.com>
Save Yourself <SaveYourself87@3587.com>
Save Yourself <SaveYourself33@2905.com>
Save Yourself <SaveYourself67@3073.com>
Save Yourself <SaveYourself24@3699.com>
Save Yourself <SaveYourself41@3699.com>

Re: "Belarus Phishing Expedition" - part 2.

Thu Jul 25, 2019 11:44 am

Hi, dear user of scamsurvivors.com

We have installed one RAT software into you device For this moment your email account is hacked too.

Changed your password? You're doing great!
But my software recognizes every such action. I'm updating passwords!
I'm always one step ahead....

So... I have downloaded all confidential information from your system and I got some more evidence.
The most interesting moment that I have discovered are videos records where you m***urbating.

I posted EternalBlue Exploit modification on porn site, and then you installed my malicious code (trojan) on your operation system.
When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device.
After installation, your front camera shoots video every time you m***urbate, in addition, the software is synchronized with the video you choose.

For the moment, the software has harvrested all your contact information from social networks and email addresses.
If you need to erase all of your collected data and video with your enjoy, send me $600(usd) in BTC (crypto currency).

This is my Bitcoin wallet: 1GMUM5rDLTARGFQfwHicdwySAy21wsHKpR
You have 48 hours after reading this letter.

After your transaction I will erase all your data.
Otherwise, I will send video with your pranks to all your colleagues, friends and relatives!!!

P.S. I'm asking you - not to answer this letter because the sender's address is fake, just to keep me incognito.

And henceforth be more careful!
Please visit only secure sites!
Bye,Bye...

Re: "Belarus Phishing Expedition" - part 2.

Fri Jul 26, 2019 4:30 pm

Hi, I know one of your passwords is: XXXXXX

Your computer was infected with my private malware, your browser wasn't updated / patched, in such case it's enough to just visit some website where my iframe is placed to get automatically infected, if you want to find out more - Google: "Drive-by exploit".

My malware gave me full access to all your accounts (see password above), full control over your computer and it also was possible to spy on you over your webcam.

I collected all your private data and I RECORDED YOU (through your webcam) SATISFYING YOURSELF!

After that I removed my malware to not leave any traces and this email was sent from some hacked server.

I can publish the videos of you and all your private data on the whole web, including the darknet, where the very sick people are, social networks, over email of all contacts.

But you can stop me and only I can help you out in this situation.

Transfer exactly 900$ in bitcoin (BTC).

It's a very good offer, compared to all that horrible shit that will happen if I publish everything!

You can easily buy bitcoin here: www.paxful.com , www.coingate.com , www.coinbase.com , or check for bitcoin ATM near you, or Google for other exchanger.
You can send the bitcoin directly to my wallet, or create your own wallet first here: www.login.blockchain.com/en/#/signup/ , then receive and send to mine.

My bitcoin wallet is: 1BXavFhbxCpno2dFpS4BU4NvEJjjqCN8Kd

Copy and paste my wallet, it's (cAsE-sEnSEtiVE)

I give you 3 days time to pay.

As I got access to this email account, I will know if this email has already been read.
If you get this email multiple times, it's to make sure that you read it, my mailer script is configured like this and after payment you can ignore it.
After receiving the payment, I will remove everything and you can life your live in peace like before.

Sorry, next time update your browser before browsing the web!





Mail-Client-ID: 5820746879

Re: "Belarus Phishing Expedition" - part 2.

Mon Jul 29, 2019 1:46 pm

Finally a new @Bitcoin address

My bitcoin wallet is: 18jZzWe4Wv4mUNm93rjeWJscqPdhecwsAY

Re: "Belarus Phishing Expedition" - part 2.

Thu Aug 01, 2019 11:35 am

My bitcoin wallet is: 1CSDpCjyVHsuTb6i7zZ8dr81iUGL5ff7vM

Re: "Belarus Phishing Expedition" - part 2.

Thu Aug 01, 2019 5:18 pm

Email received:

Hi, dear user of xxx

We have installed one RAT software into you device
For this moment your email account is hacked too.

Changed your password? You're doing great!
But my software recognizes every such action. I'm updating passwords!
I'm always one step ahead....

So... I have downloaded all confidential information from your system and I got some more evidence.
The most interesting moment that I have discovered are videos records where you m***urbating.

I posted EternalBlue Exploit modification on porn site, and then you installed my malicious code (trojan) on your operation system.
When you clicked the button Play on porn video, at that moment my trojan was downloaded to your device.
After installation, your front camera shoots video every time you m***urbate, in addition, the software is synchronized with the video you choose.

For the moment, the software has harvrested all your contact information from social networks and email addresses.
If you need to erase all of your collected data and video with your enjoy, send me $600(usd) in BTC (crypto currency).

This is my Bitcoin wallet: 1A19CzQQ5ZFxK57LWoAn2rFScTda6DnK1q
You have 48 hours after reading this letter.

After your transaction I will erase all your data.
Otherwise, I will send video with your pranks to all your colleagues, friends and relatives!!!

P.S. I'm asking you - not to answer this letter because the sender's address is fake, just to keep me incognito.

And henceforth be more careful!
Please visit only secure sites!
Bye,Bye...


Return-Path: <xxx@dm.duke.edu>
Received: from m90-131-34-50.cust.tele2.lt (m90-131-34-50.cust.tele2.lt [90.131.34.50])
From: alston29 <xxx@dm.duke.edu>
Subject: The decision to suspend your account. Waiting for payment.
Date: 30 Jul 2019 00:18:03
Message-ID: <001701d5465d$02151e70$283ea4b1$@dm.duke.edu>
X-Mailer: Microsoft Office Outlook 11

Originating IP: 90.131.34.50
Originating ISP: Tele2
City: Vilnius
Country of Origin: Lithuania

Note: the wallet received so far 531USD.

Re: "Belarus Phishing Expedition" - part 2.

Fri Aug 02, 2019 9:31 pm

I'll see your last email and raise you a new @Bitcoin wallet:
1FAKhLxgiaXY4MfS7QE8N45oTTn3HWWXwA
Topic locked