Pervert Scam Email Pegasus

Reported
Anonymous
2024-08-05T19:10:24+00:00

Hi there

I received an email at 05:56 today stating that I had had Pegasus spyware installed on my PC and that explicit videos of me would be shared with my contacts unless I paid a virtual currency ransom.

I did find it in my junk folder, but I still wanted to reach out as this email has caused me a great deal of anxiety. I have viewed online forums that state the email is a common scam, and that there are others similar to it in circulation, but I would still appreciate an expert opinion.

Also it was send with my email, and outlook detect it like it was me

For person that face the same problem

You can check the source code of the email and see if fsp fails, that mean that the guy spoofed the email so you are not hacked guys

It look like this

protection.outlook.com: domain of hotmail.com does not designate 95.214.82.181 as permitted sender

Outlook | Web | Outlook.com | Email

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2024-08-06T03:34:45+00:00

Hi NEVARLeVrai,

Thank you for using Microsoft products and posting in the community.

I know you're worried about your email being hacked. Here are some suggestions to help you deal with this situation and keep your device safe:

  1. Do not respond or pay

First and foremost, do not respond to the threatener or make a payment to them. Such emails are usually phishing or blackmail, designed to intimidate you for money.

  1. Confirm the authenticity of the email

Check the sender's address: Double-check the sender's email address to make sure it matches your email address exactly. Sometimes, attackers forge sender information.

Check the header information: If you know how to view the full header information of an email, you can check if the email is really from your domain.

  1. Change your password

Change your Microsoft account password immediately. Make sure you choose a strong password and enable double authentication (2FA) for added security.

Check other accounts: if you use the same password for other websites, it is recommended that you change these as well.

  1. Check device security

Run a security scan: Use a trusted antivirus program to run a full scan of your device. Make sure your antivirus software is up to date.

Check applications: See if there are any unidentified applications or files on your device, especially recently installed ones.

  1. Monitor Account Activity

Check Account Activity: Sign in to your Microsoft account and review recent sign-in activity to make sure there aren't any suspicious sign-ins.

Check other important accounts: Check the activity of your banking, social media, and other important accounts to ensure there is no unauthorized access.

  1. Report an Incident

Contact local law enforcement: If you feel threatened or are concerned about your safety, consider reporting it to your local law enforcement agency.

  1. Understanding Pegasus spyware

How to check for infections: Detecting Pegasus spyware isn't easy, but there are a number of security tools you can try to scan for it.

Keep your device up-to-date: Make sure your operating system and applications are kept up-to-date to prevent known vulnerabilities from being exploited.

I hope these programs can help you.

Best regards

Jay | Microsoft Community Support Specialist

0 comments No comments

118 additional answers

Sort by: Newest
  1. Anonymous
    2025-04-01T23:07:57+00:00

    Hello, i have received a similar email, check the info I got from the header,

    ***

    • The email was received from 142.252.126.152, which belongs to camerageekphotox.com.
    • The SPF and DMARC checks failed, indicating a potential spoofing attempt.
    • SCL = 5, suggesting it was likely classified as spam.
    • The email passed through multiple Microsoft Exchange servers before reaching its final destination.

    ***

    1. Authentication & Security:
      • X-Ms-Exchange-Organization-AuthAs: Anonymous
        → The email was received without authentication (e.g., sent from an external domain).
      • Authentication-Results:
        → SPF (Sender Policy Framework) shows a softfail, meaning the sender's IP (142.252.126.152) is not explicitly allowed.
        → DKIM (DomainKeys Identified Mail) is none, meaning no digital signature was used to verify sender authenticity.
        → DMARC (Domain-based Message Authentication, Reporting & Conformance) fails, suggesting the domain's policy was not met.
      • Received-SPF: SoftFail
        → Confirms the SPF check resulted in a softfail, meaning the IP is not in the authorized list but was not completely rejected.
    2. Message Routing & Processing:
      • Received:
        → These headers show the servers the email passed through before reaching its destination.
      • X-Ms-Exchange-Organization-Network-Message-Id:
        → Unique identifier for tracking the email within Microsoft’s Exchange infrastructure.
      • X-Ms-Exchange-Crosstenant-Id:
        → Identifies the sending tenant (Microsoft 365 organization).
      • X-Ms-Exchange-Transport-EndToEndLatency:
        → The total time it took for the email to travel from sender to recipient (about 3 seconds here).
    3. Spam Filtering & Classification:
      • X-Microsoft-Antispam:
        → Contains spam confidence level (SCL) scores and filters used.
      • X-Ms-Exchange-Organization-Scl: 5
        → Spam Confidence Level (SCL) 5 suggests a moderate likelihood that this is spam (0 = clean, 9 = high confidence spam).
      • X-Microsoft-Antispam-Mailbox-Delivery:
        → Indicates that the email was filtered and classified as spam.
    4. Expiration & Message Handling:
      • X-Ms-Exchange-Organization-ExpirationStartTime:
        → Timestamp when email expiration was set (29 Mar 2025).
      • X-Ms-Exchange-Organization-ExpirationInterval:
        → Indicates how long the email is kept before deletion (1 day here).

    ***

    X-Eoptenantattributedmessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0 X-Incomingheadercount: 7 X-Ms-Exchange-Organization-Expirationstarttime: 29 Mar 2025 17:58:01.2218 (UTC) X-Ms-Exchange-Crosstenant-Originalarrivaltime: 29 Mar 2025 17:58:00.6437 (UTC) X-Ms-Exchange-Transport-Crosstenantheadersstamped: AS1PR03MB8192 X-Ms-Exchange-Organization-Authas: Anonymous X-Sid-Result: FAIL Authentication-Results: spf=softfail (sender IP is 142.252.126.152) smtp.mailfrom=outlook.com; dkim=none (message not signed) header.d=none;dmarc=fail action=none header.from=outlook.com; X-Ms-Exchange-Crosstenant-Authsource: CO1PEPF000066E8.namprd05.prod.outlook.com X-Ms-Userlastlogontime: 3/29/2025 5:53:07 PM X-Sender-Ip: 142.252.126.152 Return-Path: ******@outlook.com X-Ms-Exchange-Crosstenant-Rms-Persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-Ms-Exchange-Crosstenant-Fromentityheader: Internet X-Ms-Exchange-Crosstenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-Ms-Exchange-Organization-Expirationintervalreason: OriginalSubmit X-Ms-Exchange-Organization-Network-Message-Id: 849022d6-6959-4f25-b3d7-08dd6eeb3f24 X-Ms-Publictraffictype: Email X-Sid-Pra: ******@OUTLOOK.COM X-Ms-Exchange-Crosstenant-Authas: Anonymous X-Ms-Exchange-Eopdirect: true X-Microsoft-Antispam: BCL:0;ARA:1444111002|13020799006|58200799018|47200799021|461199028|6115599003|1370799030|1360799030|3412199025|440099028|1290799030|2980499032|7110799015; X-Ms-Exchange-Organization-Expirationstarttimereason: OriginalSubmit

    ***

    0 comments No comments
  2. Anonymous
    2025-03-28T00:30:20+00:00

    If its in your junk mail im sure its spoofed so no need to worry. For piece of mind you can get the email headers and paste into chatGPT or Copolit to analyze.

    0 comments No comments
  3. Anonymous
    2025-03-27T23:15:05+00:00

    Hi I have also received the same email, any help would be greatly appreciated

    0 comments No comments
  4. Anonymous
    2025-03-27T04:34:31+00:00

    Yup, your all good mate

    0 comments No comments