Received: from nobody by stodi.digitalkingdom.org with local (Exim 4.92) (envelope-from ) id 1hGx08-00041G-6q for lojban-newreal@lojban.org; Wed, 17 Apr 2019 19:42:12 -0700 Received: from exim by stodi.digitalkingdom.org with local (Exim 4.92) id 1hGx07-00040S-WF for lojban@lojban.org; Wed, 17 Apr 2019 19:42:12 -0700 X-Failed-Recipients: comcaresvcs@gmail.com Auto-Submitted: auto-replied From: Mail Delivery System To: lojban@lojban.org Content-Type: multipart/report; report-type=delivery-status; boundary=1555555331-eximdsn-747346652 MIME-Version: 1.0 Subject: Mail delivery failed: returning message to sender Message-Id: Date: Wed, 17 Apr 2019 19:42:11 -0700 --1555555331-eximdsn-747346652 Content-type: text/plain; charset=us-ascii This message was created automatically by mail delivery software. A message that you sent could not be delivered to one or more of its recipients. This is a permanent error. The following address(es) failed: comcaresvcs@gmail.com (generated from lojban@lojban.org) host gmail-smtp-in.l.google.com [74.125.20.27] SMTP error from remote mail server after pipelined end of data: 552-5.7.0 This message was blocked because its content presents a potential 552-5.7.0 security issue. Please visit 552-5.7.0 https://support.google.com/mail/?p=BlockedMessage to review our 552 5.7.0 message content and attachment content guidelines. o70si935282pfa.33 - gsmtp --1555555331-eximdsn-747346652 Content-type: message/delivery-status Reporting-MTA: dns; stodi.digitalkingdom.org Action: failed Final-Recipient: rfc822;comcaresvcs@gmail.com Status: 5.0.0 Remote-MTA: dns; gmail-smtp-in.l.google.com Diagnostic-Code: smtp; 552-5.7.0 This message was blocked because its content presents a potential 552-5.7.0 security issue. Please visit 552-5.7.0 https://support.google.com/mail/?p=BlockedMessage to review our 552 5.7.0 message content and attachment content guidelines. o70si935282pfa.33 - gsmtp --1555555331-eximdsn-747346652 Content-type: message/rfc822 Return-path: Received: from aftr-37-201-215-247.unity-media.net ([37.201.215.247]:11835) by stodi.digitalkingdom.org with esmtp (Exim 4.92) (envelope-from ) id 1hGx03-0003yc-2W for lojban@lojban.org; Wed, 17 Apr 2019 19:42:11 -0700 Message-ID: <5CB80018.3040904@lojban.org> Date: Thu, 18 Apr 2019 05:42:00 +0100 From: User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.9) Gecko/20100825 Thunderbird/3.1.3 MIME-Version: 1.0 To: Subject: Your account is being used by another person! Content-Type: text/plain; charset=CP-850; format=flowed Content-Transfer-Encoding: 8bit X-Spam-Flag: YES X-Spam-Score: 8.8 (++++++++) X-Spam_score: 8.8 X-Spam_score_int: 88 X-Spam_bar: ++++++++ X-Spam-Report: Spam detection software, running on the system "stodi.digitalkingdom.org", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Hello! I hacked your device, because I sent you this message from your account. If you have already changed your password, my malware will be intercepts it every time. You may not know me, and you are most likely wondering why you are receiving this email, right? In fact, I posted a malicious program on adults (pornography) of some websites, and you know that you vi [...] Content analysis details: (8.8 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 BAYES_40 BODY: Bayes spam probability is 20 to 40% [score: 0.2856] 1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see ] 1.0 RDNS_DYNAMIC Delivered to internal network by host with dynamic-looking rDNS 1.6 BITCOIN_SPAM_02 BitCoin spam pattern 02 3.0 BITCOIN_MALWARE BitCoin + malware 1.9 NO_FM_NAME_IP_HOSTN No From name + hostname using IP address Hello! I hacked your device, because I sent you this message from your account. If you have already changed your password, my malware will be intercepts it every time. You may not know me, and you are most likely wondering why you are receiving this email, right? In fact, I posted a malicious program on adults (pornography) of some websites, and you know that you visited these websites to enjoy (you know what I mean). While you were watching video clips, my trojan started working as a RDP (remote desktop) with a keylogger that gave me access to your screen as well as a webcam. Immediately after this, my program gathered all your contacts from messenger, social networks, and also by e-mail. What I've done? I made a double screen video. The first part shows the video you watched (you have good taste, yes ... but strange for me and other normal people), and the second part shows the recording of your webcam. What should you do? Well, I think $766 (USD dollars) is a fair price for our little secret. You will make a bitcoin payment (if you don't know, look for "how to buy bitcoins" on Google). BTC Address: 1DUjPSp8LeCt8oGYGQkpCD1wH6tTxG4k9v (This is CASE sensitive, please copy and paste it) Remarks: You have 2 days (48 hours) to pay. (I have a special code, and at the moment I know that you have read this email). If I don't get bitcoins, I will send your video to all your contacts, including family members, colleagues, etc. However, if I am paid, I will immediately destroy the video, and my trojan will be destruct someself. If you want to get proof, answer "Yes!" and resend this letter to youself. And I will definitely send your video to your any 19 contacts. This is a non-negotiable offer, so please do not waste my personal and other people's time by replying to this email. Bye! --1555555331-eximdsn-747346652--