I am filing this complaint on behalf of a university. One of our faculty member got blackmailing email from someone named sam sam with email address [protected]@
india.com and subject "i have your nudes with xxxxx"
The email says:
Hi chubby,
Reply to make a fair deal,
If i don't hear anything soon, i will leak em.
—
The above email subject and contents are enough for categorizing it as cybercrime. Your help is solicited in blocking this account and making sure that such emails are not sent from this domain, as legal action will follow.
The mail transport log during transmission of this email is as under:
Received: from am6pr0702mb3670. Eurprd07. Prod. Outlook.com
(2603:10a6:209:2a:37) by am6pr0702mb3670. Eurprd07. Prod. Outlook.com with
Https via am6pr07ca0024. Eurprd07. Prod. Outlook.com; fri, 30 nov 2018 19:55:05
+0000
Received: from he1pr07ca0023. Eurprd07. Prod. Outlook.com (2603:10a6:7:67:33) by
Am6pr0702mb3670. Eurprd07. Prod. Outlook.com (2603:10a6:209:11:20) with
Microsoft smtp server (Version=tls1_2,
Cipher=tls_ecdhe_rsa_with_aes_256_gcm_sha384) id 15.20.1382.6; fri, 30 nov
2018 19:55:03 +0000
Received: from ve1eur02ft055. Eop-eur02. Prod. Protection. Outlook.com
(2a01:111:f400:7e06:209) by he1pr07ca0023. Outlook. Office365.com
(2603:10a6:7:67:33) with
microsoft smtp server (Version=tls1_2,
Cipher=tls_ecdhe_rsa_with_aes_256_gcm_sha384) id 15.20.1404.9 via frontend
Transport; fri, 30 nov 2018 19:55:03 +0000
Authentication-results: spf=pass (Sender ip is 82.165.227.143)
Smtp. Mailfrom=
india.com; uettaxila. Edu. Pk; dkim=none (Message not signed)
Header. D=none;uettaxila. Edu. Pk; dmarc=bestguesspass action=none
Header. From=
india.com;compauth=pass reason=109
Received-spf: pass (Protection. Outlook.com: domain of
india.com designates
82.165.227.143 as permitted sender) receiver=protection. Outlook.com;
Client-ip=82.165.227.143; helo=smtp. Zmail.com;
Received: from smtp. Zmail.com (82.165.227.143) by
Ve1eur02ft055. Mail. Protection. Outlook.com (10.152.13.34) with
microsoft smtp
Server (Version=tls1_2, cipher=tls_ecdhe_rsa_with_aes_256_gcm_sha384) id
15.20.1382.18 via frontend transport; fri, 30 nov 2018 19:55:02 +0000
Received: from india-live-spam01. Icom. Lan (India-live-spam01. Icom. Lan [10.72.59.41])
By smtp. Zmail.com (Postfix) with esmtp id 8b8421a0b34
For ; fri, 30 nov 2018 19:55:02 +0000 (Utc)
Received: from localhost (Localhost [127.0.0.1])
By india-live-spam01. Icom. Lan (Postfix) with esmtp id 86e54240de6
For ; fri, 30 nov 2018 19:55:02 +0000 (Utc)
Received: from smtp. Zmail.com ([10.72.59.197])
By localhost (India-live-spam01. Icom. Lan [10.72.59.40]) (Amavisd-new, port 20025)
With esmtp id kajzupqdrhsk for ;
Fri, 30 nov 2018 19:55:02 +0000 (Utc)
Received: from india-live-be04. Icom. Lan (India-live-be04. Icom. Lan [10.72.59.36])
By smtp. Zmail.com (Postfix) with esmtp id 48e2f3012f3
For ; fri, 30 nov 2018 19:55:02 +0000 (Utc)
Date: fri, 30 nov 2018 19:55:02 +0000
From: sam sam
To:
Message-id:
Subject: i have your nudes with xxxxx
Mime-version: 1.0
Content-type: text/html; charset="utf-8"
Content-transfer-encoding: quoted-printable
X-priority: 3
X-mailer: zmail mailer (Beta)
Return-path: [protected]@
india.com
X-ms-exchange-organization-expirationstarttime: 30 nov 2018 19:55:02.8907
(Utc)
X-ms-exchange-organization-expirationstarttimereason: originalsubmit
X-ms-exchange-organization-expirationinterval: 2:00:00:00.0000000
X-ms-exchange-organization-expirationintervalreason: originalsubmit
X-ms-exchange-organization-network-message-id:
Cd03ded3-a060-47f1-18a8-08d656fdb7be
X-eopattributedmessage: 0
X-eoptenantattributedmessage: fa4630b9-65b1-465d-9d71-2d6f9cb85a8b:0
X-ms-exchange-organization-messagedirectionality: incoming
X-forefront-antispam-report:
Cip:82.165.227.143;ipv:nli;ctry:us;efv:nli;sfv:nspm;sfs: ([protected]) ([protected])
([protected][protected][protected][protected][protected])[protected][protected][...⇄ Zmail.com;fpr:;spf:pass;lang:en;ptr:smtp02. Zmail.com;a:1;mx:1;
X-
microsoft-exchange-diagnostics:
1;ve1eur02ft055;1:qjdm0qdfwg0swygghhdz48+uom7kaauqh4ibyrkz4lrus6fspwki3iwfsz1nif...⇄
X-ms-exchange-organization-authsource:
Ve1eur02ft055. Eop-eur02. Prod. Protection. Outlook.com
X-ms-exchange-organization-authas: anonymous
X-ms-publictraffictype: email
X-ms-office365-filtering-correlation-id: cd03ded3-a060-47f1-18a8-08d656fdb7be
X-
microsoft-antispam:
Bcl:5;pcl:0;ruleid:[protected][protected][protected][protected][protected][prote...⇄
X-
microsoft-exchange-diagnostics:
1;am6pr0702mb3670;3:2zjhixbt3g5sbkqzdu9zxo5hju4wxogxb+krc72epgze/fmyts7jco9+txf9...⇄
X-ms-traffictypediagnostic: am6pr0702mb3670:
X-
microsoft-exchange-diagnostics:
1;am6pr0702mb3670;31:hyvhkjfmb5+tzb8t4r96yb1p/h7jvvrvrzi8ksruytacb0qu8siqu2o8vzt...⇄
X-exchange-antispam-report-cfa-test:
=? Utf-8? B? Qknmoju7uenmoja7ulvmruleoigymde4mdyymzk5mdmwksgymde4mdexmjaw?=
=? Utf-8? B? Mjgzksg3mdexmdupkdi0mdewndcpkdgxmje1mdewndypkduyndewmdq3ksgy?=
=? Utf-8? B? Mde4mdexmjewmtc0ksgymde4mdexmjexmdy0ksgymde4mdexmjeymdi4ksgy?=
=? Utf-8? B? Mde4mdexmjezmdi4ksgymde4mdexmje0mdi4ksgymde4mdexmje1mdi4ksgy?=
=? Utf-8? B? Mde4mdexmje2mdi4ksgymde4mdexmje3mdi4ksgymde4mdexmje4mdi4ksgy?=
=? Utf-8? B? Mde4mdexmje5mdkyksgymde4mdexmjiwmjuyksgymde4mdexmjixmdyzksgy?=
=? Utf-8? B? Mde4mdexmjiymdi3ksgymde4mdexmjizmdi3ksgymde4mdexmji0mdi3ksgy?=
=? Utf-8? B? Mde4mdexmji1mdm1ksgymde4mdexmji5mdm1ksgymde4mdexmjmymjy5ksgy?=
=? Utf-8? B? Mde4mdexmjmzmduyksgymde4mdixmjaymtq5ksg5odgxmde3nikomjaxoday?=
=? Utf-8? B? Mtiwmze0oskootg4mtuxnzypkdgymzmwmte1ockoodizmzawmjy0ksg4mjmz?=
=? Utf-8? B? Mtewnzupkdkxmde1mzywnzqpkdmymze0ntmpkdkwmtaynskootaymdc1ksg5?=
=? Utf-8? B? Mtmwodgpkdk5otawmikonza0nta4nckomtqzmdu2nykomtqzmta2ockomtqz?=
=? Utf-8? B? Mje5mckomtq1ota1ockomtyzmta2mckomtu1mta2nckootmxmtazmykootq0?=
=? Utf-8? B? Ntawmdg3ksg5ndq1mtaymtcpkdk0ndkymta3nskootq2odaxmdc4ksg5ndy5?=
=? Utf-8? B? Mdewnzgpkdk0nzezmda3mckootmwmdaxmda1ockootmwmdawmdmwnykootmw?=
=? Utf-8? B? Mtawmdi0nckootmwntawmdaynikontixmdmwotupkduymta1mteyksg1mjew?=
=? Utf-8? B? Nje3mckonti0mdgwotupkdk4odixmdi3ksg5odgymjaynykonti0mdezodap?=
=? Utf-8? B? Kduynta1mdk1ksg1mjqwnja5nskontizmduwotupkduymja2mdk1ksg4odg2?=
=? Utf-8? B? Mdmznskomzawmjawmskootmwmdywotupkdkzmda0mdk1ksgxmdiwmtuwmta0?=
=? Utf-8? B? Nikomtyxmdawmskoodmwmtawmta3nskoodmwmtawmze4mykomtq4mde2ksgy?=
=? Utf-8? B? Mde3mdgwnze3ndiwmtepkdc2otkwntepkdc2otkxmdk1ktttulzsokfnnlbs?=
=? Utf-8? B? Mdcwmk1cmzy3mdtcq0w6nttqq0w6mdtsvuxfsuq6o1nsvli6qu02ufiwnzay?=
=? Utf-8? Q? Mb3670;?=
X-ms-exchange-organization-scl: 1
X-
microsoft-exchange-diagnostics:
=? Utf-8? B? Mttbttzquja3mdjnqjm2nza7mjm6bhirs0xtdw44kzbtvfhuous2shi2skw2?=
=? Utf-8? B? R01hqwfdatj6vmzyb3i5ctbvddhounm4teo0t0k2c3h2ufgzzlhcqkiwsu1t?=
=? Utf-8? B? Dgtxmhzuzgcrmferuuo1dvk0zuvvr2lrcex3afhcngrjtehmcg56efpzalpy?=
=? Utf-8? B? Znbxnuvbunhiefzlehdsvi9gqi8xtlfqwhrkvvpdmnbzrkmrywnzzk9kcmjq?=
=? Utf-8? B? Rli4mm9iqljyclvlujvymnc1q2rpmfnxrgj0d1zvnzj4rtderedocfhsceu5?=
=? Utf-8? B? Yw8ycwpcsglty251y0m5qk1hovvbdejiogliuen6wfnrqwftnnk1zwv5k21r?=
=? Utf-8? B? Dxr4uwdzskt1akrutkvtuunbnxboogfydxnrzmy4qzh3kzbtzlbmugfluhlt?=
=? Utf-8? B? Yznksmx0sdjyqksxd3bpmy9rd2nrv1qzrmvkekc2ykuwavj3avfjag9xskrt?=
=? Utf-8? B? Mtu2sk1ecgnqmvbdwe10au01qwh1aw5pvhk2ynnmc1dyaznmwg5hnvzqrzbo?=
=? Utf-8? B? T3rdd3kva243cgvyeu9ems9rrhh4vufdde1ycfnwnnlod2o2zdq3bwnfovvl?=
=? Utf-8? B? Zvzyswppuu00rvlwngs2cmrjmnzua2xyvmkvuuzwce1ycnmwc0y5sgo5tm9r?=
=? Utf-8? B? Wgpym3brze93btkwsgr3mujnr3hsn0n4axrhzxh3bujjdvf2zljnqjdmnvbn?=
=? Utf-8? B? Sue1buuxbedcekxeatlqz1hjdfprrgxamkxdoujmcglrqndyvfnkvlnlukdp?=
=? Utf-8? B? Bgc1vwfmtjfzec93dgu4t0myt0l1qxhwylhiru1rzeh2t2eyrktvtkg1dfjr?=
=? Utf-8? B? Vne4cjgydmx2rmi0ynzwd01ptwruvdjycs9uwfn6vfu0r05sus9vm2tnrfdu?=
=? Utf-8? B? Cflicmvrtmxus3z0wunoyzhtzkvsvfpmz3dxd1ozsujktzr6r205rxjvt1ve?=
=? Utf-8? B? Z1rsyy9vk3kwl05nr1bqz3jrsm9tsnbrsdlzcvbdbxvhtdnsrvjpumlvn3no?=
=? Utf-8? B? R0jddfa4weczvknzrgk1nnpreknybgprtxdymll5swo1qktya2tvu29pz3lm?=
=? Utf-8? B? K3hjnknsthvrnxv0d1dyrdhdntgvzmzzc3v2vfe0b3dbl2f5cuviofhysmpw?=
=? Utf-8? B? Vfhok2kxdtnczmi0zmw0qunndhnmq0xudk5wtldcve1rafr0t3b5yi9namoz?=
=? Utf-8? B? Tk9dmgpku2gynujyn0vfn1c1afdzk0lmwm8rctdfeeyyrjdpemywqwzev0np?=
=? Utf-8? B? Vmn4yndnn0rdsvlat1rns09hr1rvsfzpckxzstzen0zjzfzym203mvhmovhw?=
=? Utf-8? B? Zufkbgnpwmlhn0wvtzbuvum1l09zrytorc9vd1lqk2txc0juz3n5z084um0w?=
=? Utf-8? Q? V/vpjf083t?=
X-
microsoft-exchange-diagnostics:
1;am6pr0702mb3670;6:gtaocsowimwewp9a5hkmzilxc1trxe1son9arno4ao0qslzti5mgjcoctslw...⇄
Spamdiagnosticoutput: 1:5
Spamdiagnosticmetadata: default:5
X-
microsoft-exchange-diagnostics:
1;am6pr0702mb3670;20:pokav3rxvf0cupvjaxgxqf7zrshm8qmdhryvey5dhnu4oev4ouh3cfwskog...⇄
X-ms-exchange-crosstenant-originalarrivaltime: 30 nov 2018 19:55:02.7969
(Utc)
X-ms-exchange-crosstenant-network-message-id: cd03ded3-a060-47f1-18a8-08d656fdb7be
X-ms-exchange-crosstenant-id: fa4630b9-65b1-465d-9d71-2d6f9cb85a8b
X-ms-exchange-crosstenant-fromentityheader: internet
X-ms-exchange-transport-crosstenantheadersstamped: am6pr0702mb3670
X-ms-exchange-transport-endtoendlatency: 00:00:02.3489900
X-ms-exchange-processed-by-bccfoldering: 15.20.1382.017
X-
microsoft-exchange-diagnostics:
1;am6pr0702mb3670;9:hjh7lspcd4jhgyc1og3ir0z0eo33qdutil4n6lfbkkwlar81os5rkinhq4cr...⇄
X-
microsoft-antispam-mailbox-delivery:
Ucf:0;jmr:0;ex:0;auth:0;dest:i;eng: ([protected][protected];
X-
microsoft-antispam-message-info:
Z69kjxk+5z4ug9swtqkqaumpdd+wncb0bg4evc0cn6jfws0yavr7hs2f8tkeawuyqoz0oydbgfn/uvxd...⇄
X-
microsoft-exchange-diagnostics:
1;am6pr0702mb3670;27:ba9xl/gbg6tveobwokszvbjrartjcvn/wtqhoffpi3vh6aupcmbkkhq2uma...⇄
I ahve an email account with India.com from last 9 years but all of sudden my Email id [protected]@india.com is blocked . I am unable to retrieve my important document and other things from.
Request you to kindly unlock the same ASAP and give some time to retrive all necessary documents
Regards,
Alok Singh