Windows 10: Can I tell where these emails came from?

Discus and support Can I tell where these emails came from? in Browsers and Email to solve the problem; The past three to four weeks I have been getting emails that are sent to me from me. In other words the to and from email address are my email address.... Discussion in 'Browsers and Email' started by idahosurge, Nov 3, 2018.

  1. Can I tell where these emails came from?


    The past three to four weeks I have been getting emails that are sent to me from me. In other words the to and from email address are my email address. These emails are from someone who either hacked someone I knew or they just bought a bunch of email address off the dark web. The emails are just a bunch of BS and basically want me to pay a ransom for information they say they have, but actually do not.

    I got curious if it would be possible to find out who is sending them so I want to know if there is anyway I can find out who is actually sending them. If there is a better website to post these kinds of questions please let me know where it is. Below is the header information from two of them. In both I changed all my email addresses to L: rodxxxx@xxxx.com
    _____________________________________________________
    Return-Path: L: rodxxxx@xxxx.com
    Received: from zm-mta00.neonova.net (LHLO zm-mta00.neonova.net)
    (137.118.45.14) by zm-mbs15.neonova.net with LMTP; Fri, 2 Nov 2018 16:31:32
    -0400 (EDT)
    Received: from smtp672.redcondor.net (smtp672.redcondor.net [208.80.206.72])
    by zm-mta00.neonova.net (Postfix) with ESMTPS id 336FE69FD8
    for <rodxxxx@xxxx.com>; Fri, 2 Nov 2018 16:32:17 -0400 (EDT)
    Received: from [186.119.119.226] ([186.119.119.226])
    by smtp672.redcondor.net ({ab9b8a0f-47dc-4027-bad5-230251ed7875})
    via TCP (inbound) with ESMTP id 20181102203131074_0672
    for <rodxxxxx@xxxxxx.com>;
    Fri, 02 Nov 2018 20:31:31 +0000
    X-RC-FROM: <rodxxxx@xxxx.com>
    X-RC-RCPT: <rodxxxx@xxxx.com>
    Message-ID: <5270D1E92EF348163495AD6AB70C5270@KE38M1Q4>
    From: <rodxxxx@xxxxx.com>
    To: <rodxxxx@xxxxx.com>
    Subject: Change your password immediately. Your account has been hacked.
    Date: 2 Nov 2018 09:26:26 -0600
    MIME-Version: 1.0
    Content-Type: text/plain;
    charset="ibm852"
    Content-Transfer-Encoding: 8bit
    X-Priority: 3
    X-MSMail-Priority: Normal
    Importance: Normal
    X-Mailer: Microsoft Windows Live Mail 16.4.3505.912
    X-MimeOLE: Produced By Microsoft MimeOLE V16.4.3505.912
    X-EsetId: 37303A2901EDF863677366

    ______________________________________________________

    Return-Path: L: rodxxxx@xxxxx.com
    Received: from zm-mta02.neonova.net (LHLO zm-mta02.neonova.net)
    (137.118.45.16) by zm-mbs15.neonova.net with LMTP; Fri, 2 Nov 2018 09:34:39
    -0400 (EDT)
    Received: from smtp473.redcondor.net (smtp473.redcondor.net [208.80.204.73])
    by zm-mta02.neonova.net (Postfix) with ESMTPS id B32F561D39
    for <rodxxxx@xxxxx.com>; Fri, 2 Nov 2018 09:34:40 -0400 (EDT)
    Received: from [175.125.196.143] ([175.125.196.143])
    by smtp473.redcondor.net ({6a37e3c6-627a-4a3f-9b85-f53a5f9acd7a})
    via TCP (inbound) with ESMTP id 20181102133428785_0473
    for <rodxxxxx@xxxx.com>;
    Fri, 02 Nov 2018 13:34:28 +0000
    X-RC-FROM: <rodxxxxx@xxxx.com>
    X-RC-RCPT: <rodxxxx@xxxx.com>
    From: <rodxxxxx@xxxxx.com>
    To: <rodxxxx@xxxxxx.com>
    Subject: Change your password immediately. Your account has been hacked.
    Date: 3 Nov 2018 06:01:21 +0800
    Message-ID: <003901d472fc$02118329$947889ba$@gcecisp.com>
    MIME-Version: 1.0
    Content-Type: text/plain;
    charset="ibm852"
    Content-Transfer-Encoding: 8bit
    X-Mailer: Microsoft Office Outlook 11
    Thread-Index: Accwu6x7y5hrcul6cwu6x7y5hrcul6==
    X-MimeOLE: Produced By Microsoft MimeOLE V6.1.7601.17514
    X-EsetId: 37303A2901EDF863677366
    _______________________________________________________________



    For anyone who is interested the actual email is posted below.


    __________________________________________________________
    -----Original Message-----
    From: L: rodxxxx@xxxxx.com [mailto:rodxxxxx@xxxxx.com]
    Sent: Friday, November 2, 2018 10:26 AM
    To: L: rodxxxxx@xxxxx.com
    Subject: Change your password immediately. Your account has been hacked.


    I greet you!

    I have bad news for you.
    11/08/2018 - on this day I hacked your operating system and got full access to your account L: rodxxxxx@xxxxx.com


    It is useless to change the password, my malware intercepts it every time.

    How it was:
    In the software of the router to which you were connected that day, there was a vulnerability.
    I first hacked this router and placed my malicious code on it.
    When you entered in the Internet, my trojan was installed on the operating system of your device.

    After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).

    A month ago, I wanted to lock your device and ask for a small amount of money to unlock.
    But I looked at the sites that you regularly visit, and came to the big delight of your favorite resources.
    I'm talking about sites for adults.

    I want to say - you are a big pervert. You have unbridled fantasy!

    After that, an idea came to my mind.
    I made a screenshot of the intimate website where you have fun (you know what it is about, right?).
    After that, I took off your joys (using the camera of your device). It turned out beautifully, do not hesitate.

    I am strongly belive that you would not like to show these pictures to your relatives, friends or colleagues.
    I think $880 is a very small amount for my silence.
    Besides, I spent a lot of time on you!

    I accept money only in Bitcoins.
    My BTC wallet: 17vzpL7n29egdeJF1hvUE4tKV81MqsW4wF

    You do not know how to replenish a Bitcoin wallet?
    In any search engine write "how to send money to btc wallet".
    It's easier than send money to a credit card!

    For payment you have a little more than two days (exactly 50 hours).
    Do not worry, the timer will start at the moment when you open this letter. Yes, yes .. it has already started!

    After payment, my virus and dirty photos with you self-destruct automatically.
    Narrative, if I do not receive the specified amount from you, then your device will be blocked, and all your contacts will receive a photos with your "joys".

    I want you to be prudent.
    - Do not try to find and destroy my virus! (All your data is already uploaded to a remote server)
    - Do not try to contact me (this is not feasible, I sent you an email from your account)
    - Various security services will not help you; formatting a disk or destroying a device will not help either, since your data is already on a remote server.

    P.S. I guarantee you that I will not disturb you again after payment, as you are not my single victim.
    This is a hacker code of honor.

    From now on, I advise you to use good antiviruses and update them regularly (several times a day)!

    Don't be mad at me, everyone has their own work.
    Farewell.

    :)
     
    idahosurge, Nov 3, 2018
    #1
  2. Toothless Win User

    Silent boot failure

    List your specs out and tell us each step in cleaning you did.
     
    Toothless, Nov 3, 2018
    #2
  3. email


    My system is Windows 10, my browser is Google Chrome and my email is Windows live. When I open a hyperlink I get a blank/black page listed as "Untitled". Any suggestions?
     
    HELPlucy2016, Nov 3, 2018
    #3
  4. swat354 Win User

    Can I tell where these emails came from?

    Windows 10 infinite restart black screen


    Thank you john for all of your help i decided to get the usb my computer came with and factory reset it i didnt have anything that personal or valueable so its ok thanks for the help though i appreciate it
     
    swat354, Nov 3, 2018
    #4
Thema:

Can I tell where these emails came from?

Loading...
  1. Can I tell where these emails came from? - Similar Threads - tell where emails

  2. Can someone help me identify what is this or where it came from?

    in Windows 10 Gaming
    Can someone help me identify what is this or where it came from?: Hi all, I am running windows 11, insider build. Since my last update, my computer has been crashing frequently producing the error on a green screen, "windows insider build ran into a problem and needs to restart...." Yesterday was the first time since when the crash looped...
  3. Can someone help me identify what is this or where it came from?

    in Windows 10 Software and Apps
    Can someone help me identify what is this or where it came from?: Hi all, I am running windows 11, insider build. Since my last update, my computer has been crashing frequently producing the error on a green screen, "windows insider build ran into a problem and needs to restart...." Yesterday was the first time since when the crash looped...
  4. How to find where file came from

    in Windows 10 Network and Sharing
    How to find where file came from: I clicked several images at several websites and saved them as PDFs but I can open them only as JPGs, not as PDFs. I am trying to find out which websites I downloaded from so I could do it all over again. I clicked their file properties but they did not say where I got them...
  5. How to find where file came from

    in Windows 10 Gaming
    How to find where file came from: I clicked several images at several websites and saved them as PDFs but I can open them only as JPGs, not as PDFs. I am trying to find out which websites I downloaded from so I could do it all over again. I clicked their file properties but they did not say where I got them...
  6. How to find where file came from

    in Windows 10 Software and Apps
    How to find where file came from: I clicked several images at several websites and saved them as PDFs but I can open them only as JPGs, not as PDFs. I am trying to find out which websites I downloaded from so I could do it all over again. I clicked their file properties but they did not say where I got them...
  7. Can someone tell me where these padlock symbols came from on my W10 files?

    in Windows 10 Ask Insider
    Can someone tell me where these padlock symbols came from on my W10 files?: [ATTACH] I don't see any difference in behavior. I did do a recent Crashplan recovery to this folder. Not all files have the symbol. padlocks appeared on Windows 10 submitted by /u/triptanic [link] [comments]...
  8. where that bsod came from?

    in Windows 10 BSOD Crashes and Debugging
    where that bsod came from?: https://1drv.ms/u/s!Ar1B_9k62Xl1mDMOSo8i6z1t2flk?e=b4TrEI what's it related to? https://answers.microsoft.com/en-us/windows/forum/all/where-that-bsod-came-from/76a11b0f-55d3-4e04-ab6f-8fbf979b3209
  9. How can I tell where the links point

    in Windows 10 Support
    How can I tell where the links point: I'm trying to move my stuff into my new Win10 profiles, but some of the folders like cookies and start menu have links instead of the actual folders. How do I tell where the link points? [img] 128508
  10. Don't know where this User Account came from

    in Windows 10 Support
    Don't know where this User Account came from: I posted this in the User forum but I had no bites so I am trying here. I am not sure how to describe this issue. When my computer reboots, it tries to log into a user account that has the correct name but is not my account. My user account name is Mark. In the left lower...