dhcpcd-discuss

Undeliverable: Security Alert. dhcpcd-discuss@xxxxxxxxxxxx was compromised. You need change password!

postmaster

Thu Dec 13 05:29:22 2018

mx.google.com rejected your message to the following email addresses:

jfgiorgi+KG@xxxxxxxxx<mailto:jfgiorgi%2BKG@xxxxxxxxx>
Your message wasn't delivered because the recipient's email provider rejected it.


mx.google.com gave this error:
This message was blocked because its content presents a potential security issue. Please visit https://support.google.com/mail/?p=BlockedMessage to review our message content and attachment content guidelines. i4si524723wru.93 - gsmtp







Diagnostic information for administrators:

Generating server: DB5EUR01HT117.mail.protection.outlook.com

jfgiorgi+KG@xxxxxxxxx
mx.google.com
Remote Server returned '552-5.7.0 This message was blocked because its content presents a potential 552-5.7.0 security issue. Please visit 552-5.7.0 https://support.google.com/mail/?p=BlockedMessage to review our 552 5.7.0 message content and attachment content guidelines. i4si524723wru.93 - gsmtp'

Original message headers:

Received: from DB5EUR01FT030.eop-EUR01.prod.protection.outlook.com
 (10.152.4.57) by DB5EUR01HT117.eop-EUR01.prod.protection.outlook.com
 (10.152.5.44) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.20.1425.16; Thu, 13 Dec
 2018 05:30:04 +0000
Received: from VI1PR1001MB1040.EURPRD10.PROD.OUTLOOK.COM (10.152.4.57) by
 DB5EUR01FT030.mail.protection.outlook.com (10.152.4.254) with Microsoft SMTP
 Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id
 15.20.1425.16 via Frontend Transport; Thu, 13 Dec 2018 05:30:04 +0000
X-IncomingTopHeaderMarker: OriginalChecksum:1DBC8DCC54B1EF580121AEFBF3E55735F9F25EEA651432F9E1E36874D8787CA3;UpperCasedChecksum:6522D9ECD5E6C934117E49A8B2A7C01F8B012450652640A7DF4B9BE8CA970E25;SizeAsReceived:20126;Count:121
Resent-From: <kgersen@xxxxxxxxxxx>
Received: from VI1PR1001MB1040.EURPRD10.PROD.OUTLOOK.COM ([::1]) by
 VI1PR1001MB1040.EURPRD10.PROD.OUTLOOK.COM ([fe80::ac52:473f:4af1:a964%10])
 with Microsoft SMTP Server id 15.20.1404.026; Thu, 13 Dec 2018 05:30:04 +0000
Authentication-Results: spf=temperror (sender IP is 137.74.41.71)
 smtp.mailfrom=marples.name; hotmail.com; dkim=pass (signature was verified)
 header.d=marples.name;hotmail.com; dmarc=temperror action=none
 header.from=marples.name;
Received-SPF: TempError (protection.outlook.com: error in processing during
 lookup of marples.name: DNS Timeout)
X-IncomingTopHeaderMarker: OriginalChecksum:0BD47C94C4702F45FC7623F6B091980CC6733E2640E9A02AFC55433889F2B739;UpperCasedChecksum:81F56C9D7121E2497775940679DCF9EFE1A9D5970B6959CC3ED122500340324D;SizeAsReceived:2369;Count:23
Authentication-Results-Original: relay.marples.name; dmarc=pass
 header.from=marples.name
Authentication-Results-Original: relay.marples.name; dkim=pass
        reason="1024-bit key; unprotected key"  header.d=marples.name
 header.i=@marples.name header.b=Z6gBTwOY;      dkim-adsp=pass; dkim-atps=neutral
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=marples.name;
        s=mail; t=1544678955; h=from:from:sender:reply-to:subject:subject:date:date:
         message-id:message-id:to:to:cc:mime-version:mime-version:
         content-type:content-type:
         content-transfer-encoding:content-transfer-encoding:in-reply-to:
         references:list-id:list-unsubscribe:list-subscribe:list-post;
        bh=E7l4GlZr6KZ4gJGEBykNa6aITE/vxxv087zRiDF6sPo=;
        b=Z6gBTwOYei1RxLBk6MZ8iYebPJRCMQbCc6IgOiAObH1DvrEBJQqGyhXiSuoaMVXGgN/yN/
        F2gHKA9AfdEfG6X153hrWnxefQ3PejhNxFVPP9lEcFTNWLzAUJJf5kBA8yYuw4vQnWJiGl
        BIDSpLx52lwr74h7cK2bal8W6Vh6BRQ=
X-Original-To: dhcpcd-discuss@xxxxxxxxxxxx
Message-ID: <831468798111257809132678@xxxxxxxxxxxx>
From: <dhcpcd-discuss@xxxxxxxxxxxx>
To: <dhcpcd-discuss@xxxxxxxxxxxx>
Subject: [dhcpcd-discuss] Security Alert. dhcpcd-discuss@xxxxxxxxxxxx was compromised. You need change password!
Date: Thu, 13 Dec 2018 03:51:38 -0100
List-Id: <dhcpcd-discuss.marples.name>
List-Help: <mailto:dhcpcd-discuss+help@xxxxxxxxxxxx>
List-Post: <mailto:dhcpcd-discuss@xxxxxxxxxxxx>
List-Subscribe: <mailto:dhcpcd-discuss+subscribe@xxxxxxxxxxxx>
List-Unsubscribe: <mailto:dhcpcd-discuss+unsubscribe@xxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Mailer: Vnwxngt iryillq
Authentication-Results-Original: mail.marples.name;     spf=temperror
 smtp.mailfrom=dhcpcd-discuss@xxxxxxxxxxxx
X-Spam: Yes
X-IncomingHeaderCount: 23
Return-Path: dhcpcd-discuss@xxxxxxxxxxxx
X-EOPAttributedMessage: 1
X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0
X-Microsoft-Exchange-Diagnostics: 1;CY1NAM02FT048;1:EgqMwpZBthos6coUkviKXcLDSmEGOr74DsKrevaJoNdZgqoxyAJyXgMiD2S7oVxXdMQ43tolXgIzhU8ZCGgJ3950n/m6dL7Obtbk92CEpEO6rvntGJ4c/RuooMuK8qvX
X-Forefront-Antispam-Report: EFV:NLI;
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 7a9bda5b-6afb-462f-ff59-08d660bc07cb
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:(2390098)(5000110)(711020)(4605076)(610169)(651021)(8291501071);SRVR:CY1NAM02HT185;
X-Microsoft-Exchange-Diagnostics: 1;CY1NAM02HT185;3:pBU+Ni4p2vXS9H+CZ1u7VQoQHDvwkoiUO9C06w8eevRig1BvAXDv+ti+0ANEiaQ6aOoWQ+TrcFUE4gkteoefLkF/+1MxoGXtuL9mvJATW6Oa/zwD5TYSsMGmKOm3wEYqVgWU9bC4hJV+eGc0w2Sfb2v0iu1hXOqOs7o6mXiGodBA75/fhAJXe2jCodtB7L/hz/SiTD38BW5WNPWInzs6z/jzrX8jLs9d3wKoUiXR4tm9P9PYaYf49doPq+doKrpwmL+Yr0VEvHh6krlAfFwkoJHp43Hq7hLQUdh9irBKm6Zm9xpmKyK4aH64grfpqO1T5+X0v73h9/g8kDUsmGKTTA==;25:SROXnvFJ3bHhRPesWrcQgp2+AwLvNgxd8py06uNlt1GZ8OoUllTyO6aEIk4J8C2sd8yeGHHzV91xMOEkxCnNX7wbRQFtO7e8gm8ZBV4aVvXw3NPCtA3e+QCysJAL5TMp0jSGqE6rXcBDOzD3Ob2gbYpDeLSkAAwulP/4q1XfE17h/HpnIOa4Iqs8x+jZxcLrLaGv9dZZknoTNedC4vwuGc7chccMhPXrIDyG8IMmn67+crPS24nmxCBvUro8PGdKAH4lob/60Z/qL5D9Y6xMEIkEYSWxO0iQXG2b76ur26ji2m9j0Mh/4zMOJhqMWg/h4waQ6el/6BMirGYrfcLFQQ==;31:C+wp00TXH/J4A9b2LuYPyQMjfO8A4uDeUCDdjmvl4f/V76yAcuoW/ouGwBuBoeAetafVlxZnjoREoEXls06dbDCaNzcXRFNBIO/nOil7hUXbJczIb2BV7UqcK68wCz30Y3fIlfN0xUjyE+B6deRsCJtOmB57LPMgcahbev/lEHjIWWI0Fkd+BcvSVPGhQq9JzffWuWsKacPW3u78GUDdXLDOSE/6+xM9aMU9cfCvJ2w=
X-MS-TrafficTypeDiagnostic: CY1NAM02HT185:|DB5EUR01HT117:
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 137.74.41.71
X-SID-PRA: DHCPCD-DISCUSS@xxxxxxxxxxxx
X-SID-Result: PASS
X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(444111751)(2890499008)(6300000075)(1201097)(52401380)(52601095)(52505095)(52406095)(52402095)(52301095)(52202115)(88860335)(82015058);SRVR:CY1NAM02HT185;BCL:0;PCL:0;RULEID:;SRVR:CY1NAM02HT185;
X-Microsoft-Exchange-Diagnostics: 1;CY1NAM02HT185;4:XB7poENTPLAzhaFopC7aW3q5nXud2DjOXlQxcV2OpwNcrBY5G8f1SEtNrE21/M6qm29QQhyitLXiCyiYrWPWVYNWMK5yU0ZDpPLc8d/BtoU8hPk6Cpxj9PwzYM8DWYZEhQMTe4FuCIe+XDEurZHSj75sq5n5fIEV9AkSeHOSVlbSyEBuQyA6Mnd9ctF87mPp9cwhAgdWUaK5AYF95ZodTIjLPUlDrp/3MoFPRbSXCiOz7nsex1wGrCVbrWxtHPksBKBs1in3oUq3i8IQPJbHMw==;6:nxGsNEH818euTyPuduhB87ubAbziQcuRSJLj8sjYPvl+OWEeFllyONPtUoozwFUmCOfzhHSbx1jKISHV6YI92ceq7MSMwLGCjkIjK4LPuQbKgxr1LBMO5hOW9K8ylIqXK2NLqjh6OYcUec1wyiIWvO8hon5Q5aumiWw0wXvfhTegWQ0crCw7rwwFgAJm/IMjwVT+FNZfUnlN+UiBSiJpTkWhaX359E14tCJT+OQiOgc5iZFy52GHkkjOfuTfVvGRuS6FingFcTNMR6M39RshSGHwYPZO8lC2BMVuPJuCM/6NDCNk2SSsv9mg7NJAg5y6l4HJfYfaubEAYf5qq5R/z6MMRVJcIuw00wB5ZXGR+Dsah79DeqvJMGIX2iZDSNjDCXztV2aY62HW8sckd3MlFzSmFzTkThsYDgR8QjvQAY72jMXBXqEH4o4MywCFYrweM/heDp/KFpqU1auHdFtSIg==;5:YWX0SbSn9JLgRpmfvvz+0RuVd7Bd7zxyV4AHIX1vLsq4sthzQKnOYeUKM8yRTcaa34XIe4kW4/rLXNgzZp5gPEsS3MY+JgLY+xF0piHmZ9N8WH+PAykvLIstPXxSglMP4Rj2ln93alYov27aHRK7RX0+qBfS+kxzAvRQovs84vg=
X-Microsoft-Exchange-Diagnostics: 1;CY1NAM02HT185;7:aLNO46W2RVoJTwunyUpWFzS+ZhbycTbf6WFIpf0j+C7CV1tgS+0uqc68GdCyiXhSN0O9rKd+/O+7dTWGW9hS8NtoHPonsUexSWV4EdHl5d7c+Ajmi+BkGebkkXSFMtn/YSe0FWayV6GycGjcyM8R4g==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY1NAM02HT185
X-MS-Exchange-Transport-EndToEndLatency: 00:00:02.7964633
X-MS-Exchange-Processed-By-BccFoldering: 15.20.1404.009
X-MS-Exchange-Inbox-Rules-Loop: kgersen@xxxxxxxxxxx
X-IncomingHeaderCount: 121
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DB5EUR01FT030.eop-EUR01.prod.protection.outlook.com
X-Microsoft-Exchange-Diagnostics: 1;DB5EUR01FT030;1:G7gAhLvBoE0/WMPFo83TMcJ5hA2AkjTe03TwBU7vXxYFcR1ZQlCLl64+Spcu9l4Y0OSYX7Cvfqb86QJfxYhf9lAnn+Zp5ArM9krOM28gPoJQpuV6+ixjOUU48+HdKJJD
X-OriginatorOrg: outlook.com

Reporting-MTA: dns;DB5EUR01HT117.mail.protection.outlook.com
Received-From-MTA: dns;VI1PR1001MB1040.EURPRD10.PROD.OUTLOOK.COM
Arrival-Date: Thu, 13 Dec 2018 05:30:04 +0000

Final-Recipient: rfc822;jfgiorgi+KG@gmail.com
Action: failed
Status: 5.7.0
Diagnostic-Code: smtp;552-5.7.0 This message was blocked because its content presents a potential
 552-5.7.0 security issue. Please visit
 552-5.7.0  https://support.google.com/mail/?p=BlockedMessage to review our
 552 5.7.0 message content and attachment content guidelines. i4si524723wru.93 - gsmtp
Remote-MTA: dns;mx.google.com

--- Begin Message ---
Hello!

I have very bad news for you.
09/08/2018 - on this day I hacked your OS and got full access to your account dhcpcd-discuss@xxxxxxxxxxxx

So, you can change the password, yes... But my malware intercepts it every time.

How I made it:
In the software of the router, through which you went online, was a vulnerability.
I just hacked this router and placed my malicious code on it.
When you went online, my trojan was installed on the OS of your device.

After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).

A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock.
But I looked at the sites that you regularly visit, and I was shocked by what I saw!!!
I'm talk you about sites for adults.

I want to say - you are a BIG pervert. Your fantasy is shifted far away from the normal course!

And I got an idea....
I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?).
After that, I made a screenshot of your joys (using the camera of your device) and glued them together.
Turned out amazing! You are so spectacular!

I'm know that you would not like to show these screenshots to your friends, relatives or colleagues.
I think $752 is a very, very small amount for my silence.
Besides, I have been spying on you for so long, having spent a lot of time!

Pay ONLY in Bitcoins!
My BTC wallet: 1292tZj4921PqE1ikjd4m5hmZd4RuVzdpF

You do not know how to use bitcoins?
Enter a query in any search engine: "how to replenish btc wallet".
It's extremely easy

For this payment I give you two days (48 hours).
As soon as this letter is opened, the timer will work.

After payment, my virus and dirty screenshots with your enjoys will be self-destruct automatically.
If I do not receive from you the specified amount, then your device will be locked, and all your contacts will receive a screenshots with your "enjoys".

I hope you understand your situation.
- Do not try to find and destroy my virus! (All your data, files and screenshots is already uploaded to a remote server)
- Do not try to contact me (this is not feasible, I sent you an email from your account)
- Various security services will not help you; formatting a disk or destroying a device will not help, since your data is already on a remote server.

P.S. You are not my single victim. so, I guarantee you that I will not disturb you again after payment!
 This is the word of honor hacker

I also ask you to regularly update your antiviruses in the future. This way you will no longer fall into a similar situation.

Do not hold evil! I just do my job.
Good luck.



--- End Message ---

References:
Security Alert. dhcpcd-discuss@xxxxxxxxxxxx was compromised. You need change password!dhcpcd-discuss
Archive administrator: postmaster@marples.name