Heather Ill probably get your attention with this letter

From: "Heather" <iaeidyrz@la-passion-des-sables.net>
Reply: "Heather" <iaeidyrz@la-passion-des-sables.net>
Date: Sun, 10 Oct 2021 14:51:14 +0300
Subject: Ill probably get your attention with this letter


Howdy,

Wish u will not care about my english sentence structure, since i am from
Indonesia. I toxified your system with a virus and im in possession of your
private files from your os.

It previously was mounted on a mature internet page and after that you’ve
selected the video, clicked on it, my software immediately gain access to
your computer.

Then simply, your webcamera captured you going manual, furthermore i
documented a vid that you’ve seen.

Immediately after a while additionally, it picked up your social contacts.
If you happen to want me to get rid of your everything i currently have –
transmit me 840 euros in bitcoin it is a cryptocurrency. It’s my btc wallet
address
– bc1qjw86ve0ll9x4xyzsl74qpfresxuyfnw50x8v57

At this moment you will have 25 hrs. to make a decision The moment i will
receive the transaction i am going to wipe out this movie and every little
thing completely. Otherwise, please be certain this video will be sent to
all of your buddies.

Do Not Reply to This Email

I created a double-screen video recording.

From: Maricela <expose>
Reply: expose@junecarroll.com
Date: Wed, 08 Aug 2018 18:13:38 +0200
Subject: nigel@brendinghat.com password abc123

It appears that, (*), ‘s your password. You may not know me and you are probably wondering why you’re getting this e-mail, right?

actually, I put in place a malware over the adult vids (adult porn) web site and you know what, you visited this website to have fun (you know what I mean). While you were watching videos, your internet browser started out operating as a RDP (Team Viewer) which provided accessibility of your screen and web camera. after that, my computer software obtained your complete contacts out of your Messenger, Outlook, FB, along with emails.

What did I actually do?

I created a double-screen video recording. Very first part shows the recording you’re seeing (you’ve got a good taste haha . . .), and 2nd part shows the recording of your web camera.

exactly what should you do?

Well, I think, $1000 is a reasonable price for our little secret. You’ll make the payment by Bitcoin (if you do not know this, search “how to purchase bitcoin” in Google).

Bitcoin Address: 19bdZEXGTC9CPFgCH7KiBtApLww4e9BiSd
(It is case sensitive, so copy and paste it)

Important:
You have one day in order to make the payment. (I’ve a special pixel in this e-mail, and at this moment I know that you have read this email message). If I don’t get the BitCoins, I will certainly send your video recording to all of your contacts including relatives, coworkers, and so on. Having said that, if I get the payment, I’ll destroy the video immidiately. If you’d like evidence, reply with “Yes!” and I will certainly mail out your video recording to your 6 contacts. It is a non-negotiable offer, that being said don’t waste my personal time and yours by responding to this message.


Technical Analysis


This came to one of my personal accounts.  I have seen similar, but this one shows a bit of ingenuity from the scammer.  The scary thing is that it mentions your password in the subject and the main message. I say “your password” because the scam relies on the majority of the public using a single password across applications. 

The scammer has utilised a user/password list from a hacked website in an attempt to make the Email more believable.  In my case, they have used details that I was using back in 2011. Looking further into the source of the mailing list using the Have I Been Pwned? website, I have five possible lists.

  1. Evony:
  2. Exploit.In (unverified):
  3. MySpace:
  4. Onliner Spambot (spam list):
  5. tumblr:

Today, I use a different Email address and a random 32 character password for any website that requires registration, handled with a password manager. 

Exit mobile version