/home/smartonegroup/mail/.spam/new/1755045747.M150368P111197.server11.hhost.eg,S=7163,W=7279
Return-Path: <teca@smartonegroup.com>
Delivered-To: smartonegroup+spam@server11.hhost.eg
Received: from server11.hhost.eg
	by server11.hhost.eg with LMTP
	id QPTlCHPfm2hdsgEAq0RAHw
	(envelope-from <teca@smartonegroup.com>)
	for <smartonegroup+spam@server11.hhost.eg>; Wed, 13 Aug 2025 00:42:27 +0000
Return-path: <teca@smartonegroup.com>
Envelope-to: teca@smartonegroup.com
Delivery-date: Wed, 13 Aug 2025 00:42:27 +0000
Received: from [201.218.159.163] (port=33948)
	by server11.hhost.eg with esmtp (Exim 4.98.2)
	(envelope-from <teca@smartonegroup.com>)
	id 1ulzZT-00000000T2p-06zz
	for teca@smartonegroup.com;
	Wed, 13 Aug 2025 00:42:27 +0000
From: <teca@smartonegroup.com>
To: <teca@smartonegroup.com>
Date: 12 Aug 2025 13:34:43 -0600
Message-ID: <004f01dc0bc1$032bc8df$5cad5895$@smartonegroup.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="windows-1250"
Content-Transfer-Encoding: 8bit
X-Mailer: Microsoft Office Outlook 11
Thread-Index: Ac3h7m993u7h7t933h7m993u7h7t93==
X-MimeOLE: Produced By Microsoft MimeOLE V6.1.7601.17514
X-Spam-Status: Yes, score=38.1
X-Spam-Score: 381
X-Spam-Bar: ++++++++++++++++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "server11.hhost.eg",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Hello! Have you recently noticed that I have e-mailed you
   from your account? Yes, this simply means that I have total access to your
    device. For the last couple of months, I have been watching you. Still wondering
    how is that possible? Well, you have been infected with malware originating
    from an adult website that you visited. You may not [...] 
 Content analysis details:   (38.1 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  1.5 SPF_SOFTFAIL           SPF: sender does not match SPF record (softfail)
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  0.2 KAM_DMARC_NONE         DKIM has Failed or SPF has failed on the message and
                             the domain has no DMARC policy
  1.1 DATE_IN_PAST_03_06     Date: is 3 to 6 hours before Received: date
  4.2 GB_HASHBL_BTC          Message contains BTC address found on BTCBL
                             [12guc8drwhbqkpqez6fcrqe9a3nfovnqtr]
  8.0 BTC_HASHBL_BLACK       Message contains BTC address found on BTC blocklist
                             [12guc8drwhbqkpqez6fcrqe9a3nfovnqtr]
  0.0 RCVD_IN_ZEN_BLOCKED_OPENDNS RBL: ADMINISTRATOR NOTICE: The query to
                             zen.spamhaus.org was blocked due to usage of an
                              open resolver. See
                             https://www.spamhaus.org/returnc/pub/
                             [201.218.159.163 listed in zen.spamhaus.org]
  1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
             [Blocked - see <https://www.spamcop.net/bl.shtml?201.218.159.163>]
  8.5 KAM_CRIM               Extortion Email
  2.0 RDNS_NONE              Delivered to internal network by a host with no rDNS
  1.8 BITCOIN_SPAM_07        BitCoin spam pattern 07
  1.4 DOS_OUTLOOK_TO_MX      Delivered direct to MX with Outlook headers
  3.5 BITCOIN_TOEQFM         Bitcoin + To same as From
  0.5 PDS_BTC_ID             FP reduced Bitcoin ID
  0.0 TO_EQ_FM_DIRECT_MX     To == From and direct-to-MX
  0.0 MIMEOLE_DIRECT_TO_MX   MIMEOLE + direct-to-MX
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                           [201.218.159.163 listed in bl.score.senderscore.com]
  0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                        [201.218.159.163 listed in sa-trusted.bondedsender.org]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
                              Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [201.218.159.163 listed in sa-accredit.habeas.com]
  4.1 BITCOIN_EXTORT_01      Extortion spam, pay via BitCoin
X-Spam-Flag: YES
Subject:  ***SPAM***  Waiting for the payment.

Hello!
Have you recently noticed that I have e-mailed you from your account?
Yes, this simply means that I have total access to your device.

For the last couple of months, I have been watching you.
Still wondering how is that possible? Well, you have been infected with malware originating from an adult website that you visited. You may not be familiar with this, but I will try explaining it to you.

With help of the Trojan Virus, I have complete access to a PC or any other device.
This simply means I can see you at any time I wish to on your screen by simply turning on your camera and microphone, without you even noticing it. In addition, I have also got access to your contacts list and all your correspondence.

You may be asking yourself, "But my PC has an active antivirus, how is this even possible? Why didn't I receive any notification?" Well, the answer is simple: my malware uses drivers, where I update the signatures every four hours, making it undetectable, and hence keeping your antivirus silent.

I have a video of you wanking on the left screen, and on the right screen - the video you were watching while masturbating.
Wondering how bad could this get? With just a single click of my mouse, this video can be sent to all your social networks, and e-mail contacts.
I can also share access to all your e-mail correspondence and messengers that you use.

All you have to do to prevent this from happening is - transfer bitcoins worth $950 (USD) to my Bitcoin address (if you have no idea how to do this, you can open your browser and simply search: "Buy Bitcoin").

My bitcoin address (BTC Wallet) is: 12guc8DRWHBqKPQeZ6FCRqe9A3nfovnqTR

After receiving a confirmation of your payment, I will delete the video right away, and that's it, you will never hear from me again.
You have 2 days (48 hours) to complete this transaction.
Once you open this e-mail, I will receive a notification, and my timer will start ticking.

Any attempt to file a complaint will not result in anything, since this e-mail cannot be traced back, same as my bitcoin id.
I have been working on this for a very long time by now; I do not give any chance for a mistake. 

If, by any chance I find out that you have shared this message with anybody else, I will broadcast your video as mentioned above.