Skip to content

Instantly share code, notes, and snippets.

@amcgregor
Created September 23, 2023 15:50
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save amcgregor/037bd5bb9cc6010aef0c425206c438ea to your computer and use it in GitHub Desktop.
Save amcgregor/037bd5bb9cc6010aef0c425206c438ea to your computer and use it in GitHub Desktop.
Interesting extortion spam (that obviously was easily caught by my spam filter) with some interesting tell-tale signs. I just really can't help but ridicule it publicly.

Original e-mail contained the following, where the full sentence is a link:

Hi,

I have important information for you (and about you).

Good luck!

The link was of a large block of text encoded into: https://translate.google.com/?sl=auto&tl=en&text=…

And yes, that's going from broken English to English as a target language. I really didn't grok this, but I guess having someone click the link would indicate a higher liklihood of attack success. Like Nigerian 419 scams; it's a "great filter".

My commentary is interspersed.

I regret to inform you about some sad news for you.

Approximately a month or two ago I have succeeded to gain a total access to all your devices utilized for browsing internet.

Moving forward: I have started observing your internet activities on continuous basis.

So you're mirroring out 800MBit or so of active traffic? Good luck yourself!

Go ahead and take a look at the sequence of events provided below for your reference:

Initially I bought an exclusive access from hackers to a long list of email accounts (in today's world: that is really a common thing: which can arranged via internet).

Not The Internet™! 😱 Whatever shall I do?!

Evidently: it wasn't hard for me to proceed with logging in your email account.

I totally believe you. If this were the case, this e-mail would have been dead-dropped, not delivered normally, and would not have been sent to a honeypot address. I mean, come on, this is an easy thing to be able to demonstrate.

Received: from server12.skydone.net (server12.skydone.net [185.129.250.74]) by ci74p00im-qukt09080302.me.com (Postfix) with ESMTP id 502C121C00D9 for…

Within the same week: I moved on with installing a Trojan virus in Operating Sy stems for all devices that you use to login to email.

Also doubtful. Beyond the spelling issue which is merely amusing, there would have been no access to several due to air-gap. The ones not kept air-gapped run outbound monitoring firewalls, and there has been no suspicious outbound activity.

Frankly speaking: it wasn't a challenging task for me at all (since you were kind enough to click some of the links in your inbox emails before).

Frankly! Howdy, Frank, I'm dad!

I'm also not that stupid.

Yeah: geniuses are among us.

They certainly are, and they aren't you.

Because of this Trojan I am able to gain access to entire set of controllers in devices (e.g.: your video camera: keyboard: microphone and others).

Controllers… now you're just throwing in pointless technobabble. Might work on the elderly, certianly, but that just means you really need to target your attempts better.

As result: I effortlessly downloaded all data: as well as photos: web browsing history and other types of data to my servers.

You "effortlessly" downloaded more than 50 terabytes? Colour me impressed!

Moreover: I have access to all social networks accounts that you regularly use: including emails: including chat history: messengers: contacts list etc.

I regularly use social networks? News to me! Messengers? Haven't used MSN or AIM in more than 15 years. You're welcome to those, no wukkas.

My unique virus is incessantly refreshing its signatures (du e to control by a driver): and hence remains undetected by any type of antiviruses.

Now you're just wanking; I've written unique virii, but 99.5% these days are packaged kits. Skipping the fact that my systems are literally immune to virii. If you mean trojan, a simple audit demonstrates your falsehood.

Hence: I guess by now you can already see the reason why I always remained undetected until this very letter...

Actually, no, this "letter" is gibberish.

During the process of compilation of all the materials associated with you:

I also noticed that you are a huge supporter and regular user of websites hosting nasty adult content.

Of my 50TB of data, around 1.5TB are carefully curated and meticulously sorted pornography. I… guess some of it could be considered "nasty"? But that's very subjective. I'd gladly share if asked, though; I run internet-facing hosting services and can totally spin up a subdomain for the purpose. Just ask, man, if you're that desperate.

Turns out to be: you really love visiting porn websites: as well as watching exciting videos and enduring unforgettable pleasures.

With this volume of data, any physical impact pornography may typically have is eliminated. Body parts and positions become rather academic. (For a fun time, Urban Dictionary "angry dragon"; it's hilarious.)

As a matter of fact: I was not able to withstand the temptation: but to record certain nasty solo action with you in main role:

and later produced a few videos exposing your masturbation and cumming scenes.

Very curious to see imagined wish fulfillment arise, but I guess such statements might… increase the pressure? Really waiting for you to get to a point, though.

If until now you don't believe me: all I need is one-two mouse clicks to make all those videos with everyone you know:

including your friends: colleagues: relatives and others.

Moreover: I am able to upload all that video content online for everyone to see.

Good luck with that; hard to upload things which don't exist. Less difficult in the age of AI and deepfakes, buuuut… that still suffers the problem of sourcing training data. Which you can't have, as it doesn't exist.

I sincerely think: you certainly would not wish such incidents to take place: in view of the lustful things demonstrated in your commonly watched videos:

(you absolutely know what I mean by that) it will cause a huge adversity for you.

Do it.

Do it now.

Play your cards, show your hand.

Fucking do it.

There is still a solution to this matter: and here is what you need to do:

You make a transaction of $700 USD to my account (an equivalent in bitcoins: which recorded depending on the exchange rate at the date of funds transf er):

Why so cheap? Given the impressive verbiage of the threat, I'm sure you could get $2000 or more! Use of bitcoin, though, is a nice indicator of how much of a rube you really expect your blanket targets to be. I'm vehmitely anti-"coin", so that'd never happen.

Did you include an address, though?

hence upon receiving the transfer: I will immediately get rid of all those lustful videos without delay.

After that we can make it look like there was nothing happening beforehand.

That's not how hostage negotiations work.

See, when I deal with these, I shoot both the hostage taker and the hostage. Then it can't happen again. (Plus the typical "if you have leverage, why would you give it up—oh right, you wouldn't" aspect.)

Additionally: I can confirm that all the Trojan software is going to be disabled and erased from all devices that you use. You have nothing to worry about:

because I keep my word at all times.

🤣 I should get this framed.

That is indeed a beneficial bargain that comes with a relatively reduced price:

taking into consideration that your profile and traffic were under close monitoring during a long time frame.

If you are still unclear regarding how to buy and perform transactions with bitcoins - everything is available online.

Below is my bitcoin wallet for your further%2 0reference%3A

Ah, cool, there's the address.

Balance: 0.198 coins, or ~$5.2K, not half bad. Love the transaction on the 18th with 173 outputs for 0.00062206 BTC where you paid more in fee than the value of the transaction, and the 20th with 32 outputs, not quite as badly balanced. Totally not traceable, excapt wait, it's traceable.

All you have is 48 hours and the countdown begins once this email is opened (in other words 2 days).

Glad it's not possible for you to know I've opened it, other than by way of this public letter of ridicule. Which if you're monitoring my traffic (which you aren't) you'd be able to notice.

Things that may be concerning you%3A

That funds transfer won't be delivered to me.

That's not a concern, that's a promise!

Breathe out: I can track down everything right away: so once funds transfer is finished:

What's the current BTC transaction commit time? Recent spikes have reached 45 hours. "Right away" and you'd be magic. Or duped into accepting a transaction I'd just roll back. Learn how BTC works.

I will know for sure: since I interminably track down all activities done by you (my Trojan virus controls all processes remotely: just as TeamViewer).

Prove it.

That your videos will be distributed: even though you have completed money transfer to my wallet.

Trust me: it is worthless for me to still bother you after money transfer is successful. Moreover: if that was ever part of my plan: I would do make it happen way earlier!

Hmm; your link was to Google Translate, and I can only assume from the quality of writing that the English, here, was also badly machine translated. "I would do make it" — Indian, perchance? The frivolous attempts to make the English sound fancier also has me leaning towards India.

We are going to approach and deal with it in a clear manner!

Then, uh, I suggest learning English first?

In conclusion: I'd like to recommend one more thing... after this you need to make certain you don't get involved in similar kind of unpleasant events anymore!

My recommendation - ensure all your passwords are replaced with new ones on a regular basis.

They are. They're also of a length that makes brute-force technically unfeisable. Good advice, though!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment