Myantispyware team discovered a new variant of the “I sent you an email from your account” email scam that uses the 13nsNBfoVwXDHY4puRD1AHjARbomKhsxEL Bitcoin wallet account to get money from its victims. Like before, this bitcoin blackmail scam spreads via spam emails. The scam is sent out to thousands of emails at a time.
Threat Summary
Type | Bitcoin Blackmail Scam |
---|---|
Ransom amount | $756 |
BTC Wallet | 13nsNBfoVwXDHY4puRD1AHjARbomKhsxEL |
In order to know more about this bitcoin email scam and how to protect yourself, please read the article I sent you an email from your account Email Scam.
Further to my previous post, just in case, if this might help:
Return-Path: xxxxxxx@h…d.ca
Delivered-To: xxxxxxx@h…d.ca
Received: from 035-143-144-062.dhcp.bhn.net (035-143-144-062.dhcp.bhn.net [35.143.144.62])
by PALM.arvixe.com with ESMTP
; Tue, 8 Oct 2019 10:34:17 -0500
Message-ID:
From:
To:
Subject: Security Alert. Your account was compromissed. Password must be changed.
Date: 8 Oct 2019 06:08:15 -0500
MIME-Version: 1.0
Content-Type: text/plain; charset=”cp-850″
Content-Transfer-Encoding: 8bit
X-Mailer: Mfahokbr qkxvmnf 5.4
>tracert 35.143.144.62
Tracing route to 035-143-144-062.dhcp.bhn.net [35.143.144.62]
over a maximum of 30 hops:
1 1 ms 3 ms 1 ms 192.168.0.1
2 14 ms 14 ms 20 ms 24.156.151.142
3 13 ms 11 ms 10 ms newkirk.tpia.start.ca [104.153.24.86]
4 15 ms 12 ms 12 ms newkirk.tpia.start.ca [104.153.24.85]
5 13 ms 25 ms 26 ms 10ge5-3.core1.tor1.he.net [209.51.164.81]
6 21 ms 21 ms 21 ms 100ge9-2.core2.chi1.he.net [184.105.80.5]
7 24 ms 25 ms 23 ms twcable-backbone-as7843.10gigabitethernet7-7.cor
e2.chi1.he.net [216.66.74.238]
8 68 ms 63 ms 63 ms bu-ether29.chcgildt87w-bcr00.tbone.rr.com [107.1
4.17.195]
9 65 ms 69 ms 79 ms bu-ether11.chctilwc00w-bcr00.tbone.rr.com [66.10
9.6.21]
10 63 ms 62 ms 71 ms bu-ether13.dllstx976iw-bcr00.tbone.rr.com [66.10
9.6.22]
11 66 ms 63 ms 63 ms bu-ether11.tamsflde20w-bcr00.tbone.rr.com [66.10
9.1.71]
12 62 ms 62 ms 65 ms so-0-0-2.ar1.cdp01.tbone.rr.com [66.109.6.97]
13 66 ms 66 ms 70 ms hun0-0-0-0.tamp20-car2.bhn.net [72.31.3.96]
14 72 ms 67 ms 67 ms 72-31-6-179.net.bhntampa.com [72.31.6.179]
15 68 ms 66 ms 65 ms bundle-ether2.tamp31-ser2.bhn.net [72.31.92.2]
16 63 ms 69 ms 65 ms 71-46-20-238.res.bhn.net [71.46.20.238]
17 70 ms 72 ms 69 ms 035-143-144-062.dhcp.bhn.net [35.143.144.62]
Trace complete.