Google
Edit File: 1776505840.M456624P2417362.server-619288.prediksijaya.com,S=6956,W=7086
Return-Path: <zensho@ponjosonek.com> Delivered-To: angker+spam@server-619288.prediksijaya.com Received: from server-619288.prediksijaya.com by server-619288.prediksijaya.com with LMTP id pNJ8GvBT42nS4iQAf7/9AQ (envelope-from <zensho@ponjosonek.com>) for <angker+spam@server-619288.prediksijaya.com>; Sat, 18 Apr 2026 16:50:40 +0700 Return-path: <zensho@ponjosonek.com> Envelope-to: zensho@ponjosonek.com Delivery-date: Sat, 18 Apr 2026 16:50:40 +0700 Received: from [221.210.80.141] (port=55507) by server-619288.prediksijaya.com with esmtp (Exim 4.99.1) (envelope-from <zensho@ponjosonek.com>) id 1wE2Jw-0000000A8lL-47XC for zensho@ponjosonek.com; Sat, 18 Apr 2026 16:50:40 +0700 Received: from pvgewqn ([66.187.40.244]) by 67945.com with MailEnable ESMTP; Sat, 18 Apr 2026 17:50:39 +0800 Received: (qmail 68221 invoked by uid 682); 18 Apr 2026 17:50:37 +0800 From: zensho@ponjosonek.com To: zensho@ponjosonek.com Date: Sat, 18 Apr 2026 17:50:39 +0800 Message-ID: <682212.682212@67945.com> Mime-Version: 1.0 Content-type: text/plain; X-Spam-Status: Yes, score=34.9 X-Spam-Score: 349 X-Spam-Bar: ++++++++++++++++++++++++++++++++++ X-Spam-Report: Spam detection software, running on the system "server-619288.prediksijaya.com", has identified this incoming email as possible spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see root\@localhost for details. Content preview: Hello! Unfortunately, there is some bad news for you. Some time ago, your device was infected with my private Trojan, R.A.T (Remote Administration Tool). Content analysis details: (34.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URI: bitrefill.com] [URI: crypto.com] [URI: binance.com] [URI: kucoin.com] 0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [221.210.80.141 listed in bl.score.senderscore.com] 0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [221.210.80.141 listed in sa-trusted.bondedsender.org] 0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. [221.210.80.141 listed in sa-accredit.habeas.com] 1.5 RCVD_IN_HOSTKARMA_BL RBL: Sender listed in HOSTKARMA-BLACK [221.210.80.141 listed in hostkarma.junkemailfilter.com] 0.0 RCVD_IN_DNSWL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to DNSWL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#DnsBlocklists-dnsbl-block for more information. [221.210.80.141 listed in list.dnswl.org] 1.5 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail) 0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict Alignment 0.2 KAM_DMARC_NONE DKIM has Failed or SPF has failed on the message and the domain has no DMARC policy 0.5 SUBJ_ALL_CAPS Subject is all capitals 2.0 RDNS_NONE Delivered to internal network by a host with no rDNS 0.8 BITCOIN_SPAM_07 BitCoin spam pattern 07 8.5 KAM_CRIM Extortion Email 3.5 BITCOIN_TOEQFM Bitcoin + To same as From 0.2 PDS_BTC_ID FP reduced Bitcoin ID 8.0 BTC_HASHBL_BLACK Message contains BTC address found on BTC blocklist [1lk753uyyyxpcuthytrxgnagc8qxxn8zuk] 2.9 GB_HASHBL_BTC Message contains BTC address found on BTCBL [1lk753uyyyxpcuthytrxgnagc8qxxn8zuk] 3.0 BITCOIN_EXTORT_01 Extortion spam, pay via BitCoin 2.3 GB_BITCOIN_CP Localized Bitcoin scam X-Spam-Flag: YES Subject: YOU PERVERT, I RECORDED YOU! Hello! Unfortunately, there is some bad news for you. Some time ago, your device was infected with my private Trojan, R.A.T (Remote Administration Tool). If you want to find out more about it, simply use Google. My Trojan allowed me to access your files, accounts, and your camera. Check the sender of this email, I have sent it from your email account. To ensure you read this email, you will receive it multiple times. I RECORDED YOU (through your camera) MASTURBATING! After that, I removed my malware to leave no traces. If you still doubt my serious intentions, it only takes a couple of mouse clicks to share the video of you masturbating with your family, friends, relatives, all email contacts, on social networks and the darknet. All you need is $800 USD in Bitcoin (BTC), transferred to my wallet address. After the transaction is successful, I will proceed to delete everything. I keep my promises! You can purchase Bitcoin (BTC) from reputable exchanges here: http://binance.com - Payment options: Credit/debit cards, bank transfers, P2P trading, third-party payment providers, and gift cards. http://bitrefill.com - Payment options: Paysafecard, credit/debit cards, crypto, bank transfer, and other gift card options. http://crypto.com - Payment options: Credit/debit cards, bank transfers, Apple Pay, Google Pay, and more. http://kucoin.com - Payment options: Credit/debit cards, bank transfer, third-party payment providers, and peer-to-peer. Alternatively, simply Google for other exchanges. Once purchased, you can send the Bitcoin directly to my wallet address or use a wallet application such as Atomic Wallet or Exodus Wallet to manage your transactions. My Bitcoin (BTC) wallet address is: 1LK753UYyYXPcUthYTrxgnaGC8qxXN8ZUK Yes, that's how the wallet address looks like. Copy and paste my wallet address, it's (case-sensitive). A piece of advice from me: regularly change all your passwords and update your device with the latest security patches.