logo elektroda
logo elektroda
X
logo elektroda
Dostępna jest polska wersja

Czy wolisz polską wersję strony elektroda?

Nie, dziękuję Przekieruj mnie tam

Breaking into Mailbox & Dealing with Strange Emails: Tackling Spam & Hacker Threats (emmery20)

cheater 6600 19
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 17901491
    cheater
    Level 5  
    Dostałem dzisiaj takie 3 emaile, to jakiś spam?!

    Temat wiadomości:
    poczta.onet.pl security service. Third party accessed to xxx(_at_)poczta.onet.pl
    Treść wiadomości
    I'm is very good programmer, known in darkweb as emmery20.
    I hacked this mailbox more than 3 months ago,
    through it I infected your operating system with a virus (trojan) created by me and have been spying for you a very long time.

    I understand it is hard to believe, but I have full access to your account:
    You can check it yourself, I'm wrote you from yours account!

    Even if you changed the password after that - it does not matter, my virus intercepted all the caching data on your computer
    and automatically saved access for me.

    I have access to all your accounts, social networks, email, browsing history.
    Accordingly, I have the data of all your contacts, files from your computer, photos and videos.

    I was most struck by the intimate content sites that you occasionally visit.
    You have a very wild imagination, I tell you!

    During your pastime and entertainment there, I took screenshot through the camera of your device, synchronizing with what you are watching.
    Oh my god! You are so funny and excited!

    I think that you do not want all your contacts to get these files, right?
    If you are of the same opinion, then I think that $641 is quite a fair price to destroy the dirt I created.

    Send the above amount on my BTC wallet (bitcoin): 14DvFghvkzQujf5Kd5AL2VKjxaYm5KidxR
    As soon as the above amount is received, I guarantee that the data will be deleted, I do not need it.

    Otherwise, these files and history of visiting sites will get all your contacts from your device.
    Also, I'll send to everyone your contact access to your email and access logs, I have carefully saved it!

    Since reading this letter you have 48 hours!
    After your reading this message, I'll receive an automatic notification that you have seen the letter.

    Please do not try to answer me, the from-address is generated automatically!

    I hope I taught you a good lesson.
    Do not be so nonchalant, please visit only to proven resources, and don't enter your passwords anywhere!
    Good luck!


    translator:
    Jestem bardzo dobrym programistą, znanym w darkweb jako emmery20.
    Zhakowałem tę skrzynkę pocztową ponad 3 miesiące temu,
    za jego pośrednictwem zainfekowałem system operacyjny wirusem (trojanem) stworzonym przeze mnie i szpiegowałem przez długi czas.

    Rozumiem, że trudno w to uwierzyć, ale mam pełny dostęp do twojego konta:
    Możesz to sprawdzić sam, jestem napisany do ciebie z twojego konta!

    Nawet jeśli później zmienisz hasło - to nie ma znaczenia, mój wirus przechwycił wszystkie dane buforowania na twoim komputerze
    i automatycznie zapisany dla mnie dostęp.

    Mam dostęp do wszystkich Twoich kont, sieci społecznościowych, poczty e-mail, historii przeglądania.
    W związku z tym mam dane wszystkich kontaktów, plików z komputera, zdjęć i filmów.

    The sites with intimate content that you visit from time to time struck me the most.
    You have a very wild imagination, I tell you!

    During entertainment and entertainment, I took a screenshot through your device's camera, syncing with what you were watching.
    Oh my God! You are so funny and excited!

    I don't think you want all your contacts to receive these files, do you?
    If you are of the same opinion then I think $ 641 is a pretty good price to break down the dirt I created.

    Send the above amount to my BTC (bitcoin) wallet: 14DvFghvkzQujf5Kd5AL2VKjxaYm5KidxR
    After receiving the above amount, I guarantee that the data will be deleted, I do not need it.

    Otherwise, all your contacts from the device will get these files and history of visited sites.
    In addition, I will send all contacts access to email and access logs, I have saved them carefully!

    You have 48 hours from reading this letter!
    After reading this message, I will receive an automatic notification that the letter has been viewed.

    Don't try to answer me, the address from the address is generated automatically!

    Hope I have taught you a good lesson.
    Don't be so nonchalant, visit only proven resources and don't enter your passwords anywhere!
    Good luck!

    Breaking into Mailbox & Dealing with Strange Emails: Tackling Spam & Hacker Threats (emmery20)
  • ADVERTISEMENT
  • ADVERTISEMENT
  • #3 17901505
    CHAST
    Level 28  
    Are you serious?
    It's just a scam.
  • ADVERTISEMENT
  • #4 17901535
    bumble
    Level 40  
    This is nonsense and probably hundreds if not thousands of users received such e-mails. If someone had access to your bank account, do you think they would write you about it? Haha good. You still wasted time translating it. I always look at the sender first, when I don't know, I delete the e-mail without reading the title when I know it, and usually I also remove advertising or some nonsense.
  • #5 17901551
    nuszek
    Level 30  
    I even got a reminder that I got the notice three months ago and now he is giving me my last chance.
    At least here is English, I have already received it translated.
    Ma recordings from my webcams / defacto no webcam in my computer /.
    Dump it.
  • #6 17901565
    bumble
    Level 40  
    Eeee. You definitely have a webcam but you don't know about it.
  • #7 17901581
    cheater
    Level 5  
    Tomequ123 wrote:
    Do not worry.
    Install malwarebytes and FRST, scan, remove anything found with malwarebytes, insert FRST.txt and Addition.txt logs here from FRST.

    Reset the router, update the firmware downloaded from the manufacturer's website.
    You can apply these tips:
    https://www.komputerswiat.pl/poradniki/sprzet...swoja-siec-wi-fi-kompleksowy-poradnik/l7gs9r9


    The malware found nothing
    Attachments:
    • FRST.txt (58.65 KB) You must be logged in to download this attachment.
    • Addition.txt (29.94 KB) You must be logged in to download this attachment.
  • ADVERTISEMENT
  • #9 17901603
    Anonymous
    Level 1  
  • #10 17902983
    Majo26
    Level 1  
    I got an identical e-mail, but not from "emmery20" but from "norby27", I also have e-mail on the internet. I don't think there is anything to worry about. Best regards! ;)
  • #11 17903172
    karol662
    Level 1  
    I also got a similar email. I scanned malwarebytes and it found PUP.Reimage for me.
  • #12 17903214
    Anonymous
    Level 1  
  • #13 17904224
    Daniel_GSM
    Level 25  
    And I get these types of e-mails from ... my own e-mail address.
    The sender is my own e-mail.
    In the body of such e-mails I have information that someone has hacked into my inbox and may be sending e-mails from my inbox.

    Question:
    How does this someone do that, with their address identical to mine - and not the display name - that's exactly my e-mail address.
  • #14 17904252
    Anonymous
    Level 1  
  • #15 17904259
    Daniel_GSM
    Level 25  
    but how do they do it?
  • #16 17904286
    Anonymous
    Level 1  
  • #17 17904470
    CHAST
    Level 28  
    Daniel_GSM wrote:
    And I get these types of e-mails from ... my own e-mail address.
    The sender is my own e-mail.
    In the body of such e-mails I have information that someone has hacked into my inbox and may be sending e-mails from my inbox.

    Question:
    How does this someone do that, with their address identical to mine - and not the display name - that's exactly my e-mail address.

    Read about masking the sender's email address.
  • #18 17904490
    kris8888
    Level 40  
    Daniel_GSM wrote:
    And I get these types of e-mails from ... my own e-mail address.
    The sender is my own e-mail.

    These are not emails sent from your account. I suppose that on the internet, just like on wp, it is possible to display the exact data of the received email with the "Show news source" function. You get the exact parameters of the e-mail account from which the message came, along with the ip address of the mail server. Compare this data with the data of any email you sent from your account. They will definitely be different.
    Anyway, a fragment of this type:
    cheater wrote:

    Don't try to answer me, the address from the address is generated automatically!

    it also points to it.
    So this is the most ordinary spam that must be thrown into the trash as soon as possible, under no circumstances opening attachments or links contained in it.
  • #19 17904679
    CHAST
    Level 28  
    The biggest problem with spam like this is that a lot of people have fun in front of the laptop and take it seriously ...
  • #20 17905030
    BANANvanDYK
    Level 42  
    A simple social engineering fraud attempt. It can be categorized as regular spam.
    I also got two similar messages.
    Breaking into Mailbox & Dealing with Strange Emails: Tackling Spam & Hacker Threats (emmery20)
    There is not a grain of truth in this message.

Topic summary

✨ The discussion revolves around a user receiving suspicious emails claiming their mailbox has been hacked, with threats of personal data exposure. Responses indicate that these emails are likely scams or spam, with many users sharing similar experiences. Recommendations include installing malware detection software like Malwarebytes, scanning for threats, and resetting router settings. Users emphasize the importance of checking the sender's email address and not engaging with suspicious messages. The conversation also touches on the concept of email spoofing, where attackers can disguise their email address to appear as if they are sending from the victim's account.
Generated by the language model.

FAQ

TL;DR: This is sextortion spam; one user got two similar emails, and "There is not a grain of truth in this message." Do not pay. Secure your email and PC with scans, updates, and 2FA. [Elektroda, BANANvanDYK, post #17905030]

Why it matters: It helps Onet.pl and other email users spot the scam fast and harden accounts before any real compromise.

Quick Facts

Is this email a hack or just spam?

Treat it as sextortion spam. The community response is clear: "It's just a scam." Do not respond or pay. Delete the message and relax. [Elektroda, CHAST, post #17901505]

How can someone send an email that looks like it came from my address?

They spoof the From field via SMTP. Use your mail’s “Show original/source” to view headers. Compare the sending server and IP with a real message you sent. You will see they differ. [Elektroda, kris8888, post #17904490]

What immediate steps should I take to stay safe?

  1. Scan with Malwarebytes and FRST; remove anything Malwarebytes finds.
  2. Reset your router and install firmware from the manufacturer’s site.
  3. Apply Wi‑Fi hardening from a reputable guide. [Elektroda, Anonymous, post #17901504]

What does the $641 and 48‑hour threat mean?

It is a pressure tactic from the template used here. The email in this thread demanded $641 in Bitcoin and a 48‑hour deadline. The scammer claims access and recordings to scare you. Recognize it as boilerplate intimidation. [Elektroda, cheater, post #17901491]

Is my computer infected?

In this case, a Malwarebytes scan found nothing. Run your own scans to confirm. Keep Windows Update current. If scans are clean, treat the message as spam. [Elektroda, cheater, post #17901581]

Malwarebytes flagged adware/PUP — what should I do?

Quarantine and remove what Malwarebytes detects. Reboot and rescan to confirm. Then reset the router and update its firmware as suggested. [Elektroda, Anonymous, post #17901504]

Where can I report the Bitcoin wallet used in the scam?

You can look up and report the wallet to BitcoinAbuse. The thread links the specific wallet used: 14DvFghvkzQujf5Kd5AL2VKjxaYm5KidxR. [Elektroda, CHAST, post #17901601]

How can I verify if the message actually came from my mailbox?

Open the message’s full source in your webmail. Compare its sending server and IP with one of your real sent emails. They will not match when spoofed. That confirms it did not originate from your account. [Elektroda, kris8888, post #17904490]

They claim webcam recordings, but I have no webcam. Should I worry?

No. A forum user received the same threat and had no webcam installed. Delete the message and move on. It is empty intimidation. [Elektroda, nuszek, post #17901551]

Can the scam appear in Polish or under different aliases like “emmery20” or “norby27”?

Yes. Another user received an identical email signed "norby27." The template and alias vary across waves. Treat all variants the same. [Elektroda, Majo26, post #17902983]

What is FRST and how do I use it safely?

FRST is a diagnostic and fix tool. Place a fixlist.txt beside FRST and click Fix. Only run scripts you understand or that a helper provides. Always create a restore point first. [Elektroda, Anonymous, post #17903214]

Should I reset my router or update firmware because of this?

Yes, as a precaution. Reset the router, then update firmware downloaded from the manufacturer’s site. This closes known bugs and removes suspect settings. [Elektroda, Anonymous, post #17901504]

How do I block future emails like this?

Mark it as spam and delete. Do not open attachments or click any links. Your provider will better filter future copies once you report it. [Elektroda, kris8888, post #17904490]

Why does the sender claim they’ll know when I read the email?

This line appears in the scam text shared by the OP. It attempts to scare you into paying. Ignore it and avoid replying. [Elektroda, cheater, post #17901491]

Is it normal to get reminders weeks or months later?

Yes. A user received a "reminder" months after the first threat. Spammers recycle lists and resend templates. Delete and carry on. [Elektroda, nuszek, post #17901551]
Generated by the language model.
ADVERTISEMENT