Security

This Account Was Recently Infected! Email Extortion Scam

I recently got an email purportedly from my own account that began with “This Account Was Recently Infected!’ The full email is shown as an image below with the text in the description tag of the image reference. The text was contained in an an image file and since it spoofed my own account, my email client displayed the image. Concerned that my account had been hacked, I looked at the email source, and discovered that it was just a spoofed email originating from a server in Japan. I Googled the first sentence and found many hits for descriptions of the email scam and one that suggested reporting to the FBI.

Because it included a Bitcoin wallet ID, I decided to go ahead and report to the FBI. Finding the right site is not a trivial task, but I did end up filing a report.

Image of Email Extortion Text

The extortion email was presented as an image, which allowed it to get past SpamAssassin and the spam filtering in Thunderbird. It also made it impossible to cut and paste the Bitcoin wallet ID into the FBI report.

Text of “This Account Was Recently Infected!” extortion email presented as an image.
Image of email extortion scam text

Headers from the Extortion Email

In most email clients, you can view the source of the email which will give you information on where the email may have originated. In this case, the header shows that the email started out in intercom-45-29.pro which does not point to anything in DNSLytics, but intercom.pro does point to Russian ownership. From the first server, it went to max-luomo.com which is registered with a Japanese domain registrar. In any case, it is clear that the sender did not compromise my email account or server.

Return-Path: Delivered-To: mail@domain_name.com Received: from cpanel.domain_name.com by cpanel.domain_name.com with LMTP id 4C3ZCfrnn1xMEQAAdMgoMg for ; Sat, 30 Mar 2019 17:04:42 -0500 Return-path: Envelope-to: mail@domain_name.com Delivery-date: Sat, 30 Mar 2019 17:04:42 -0500 Received: from oogw1239.ocn.ad.jp ([153.149.141.169]:47343) by cpanel.domain_name.com with esmtp (Exim 4.91) (envelope-from ) id 1hAM5e-00019t-N8 for mail@domain_name.com; Sat, 30 Mar 2019 17:04:42 -0500 Received: from cmn-spm-mts-006c1.ocn.ad.jp (cmn-spm-mts-006c1.ocn.ad.jp [153.153.67.160]) by oogw1239.ocn.ad.jp (Postfix) with ESMTP id 6551360E8B for ; Sun, 31 Mar 2019 07:03:57 +0900 (JST) Received: from mwb-vc-mts-002c1.ocn.ad.jp ([153.138.237.206]) by cmn-spm-mts-006c1.ocn.ad.jp with ESMTP id AM3Shggxt07dLAM4zhkTVZ; Sun, 31 Mar 2019 07:03:57 +0900 X-BIZ-RELAY: yes Received: from sgs-vcgw117.ocn.ad.jp ([153.149.141.227]) by mwb-vc-mts-002c1.ocn.ad.jp with ESMTP id AM4zhSVQmPu64AM4zhc1qI; Sun, 31 Mar 2019 07:03:57 +0900 Received: from max-luomo.com (max-luomo.com [210.190.145.37]) by sgs-vcgw117.ocn.ad.jp (Postfix) with ESMTP id E800024019A for ; Sun, 31 Mar 2019 07:03:56 +0900 (JST) Received: from [intercom-45-29.pro] (unknown [185.153.45.29]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by max-luomo.com (Postfix) with ESMTPSA id DB58F8401F6B for ; Sun, 31 Mar 2019 07:03:50 +0900 (JST) Content-Type: multipart/related; boundary="--_com.android.email_84542265731905" MIME-Version: 1.0 To: mail@domain_name.com List-Help: X-aid: 7446357115 From: Date: Sat, 30 Mar 2019 23:03:47 +0100 X-CSA-Complaints: This email address is being protected from spambots. You need JavaScript enabled to view it. Message-ID: <714g1951i8hd13pbkr7ggspa1baaxrwv@p33o3zg1lyt59sw8zro101uxkts4rlbeym9hwbr8kpm91ibkhnd5spa41x2amg6m> Organization: Ymfyoolx Subject: mailid Feedback-ID: 478791:07697752.05799481:yw18:hh Abuse-Reports-To: This email address is being protected from spambots. You need JavaScript enabled to view it. X-Sender: This email address is being protected from spambots. You need JavaScript enabled to view it. This is a multi-part message in MIME format ----_com.android.email_84542265731905 Content-Type: multipart/alternative; boundary="--_com.android.email_25217509735885" ----_com.android.email_25217509735885

Conclusion

This is a hoax and a scam. Sadly, it is a part of life today.