Pervert Scam Email Pegasus

Reported
Anonymous
2024-08-05T19:10:24+00:00

Hi there

I received an email at 05:56 today stating that I had had Pegasus spyware installed on my PC and that explicit videos of me would be shared with my contacts unless I paid a virtual currency ransom.

I did find it in my junk folder, but I still wanted to reach out as this email has caused me a great deal of anxiety. I have viewed online forums that state the email is a common scam, and that there are others similar to it in circulation, but I would still appreciate an expert opinion.

Also it was send with my email, and outlook detect it like it was me

For person that face the same problem

You can check the source code of the email and see if fsp fails, that mean that the guy spoofed the email so you are not hacked guys

It look like this

protection.outlook.com: domain of hotmail.com does not designate 95.214.82.181 as permitted sender

Outlook | Web | Outlook.com | Email

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2024-08-06T03:34:45+00:00

Hi NEVARLeVrai,

Thank you for using Microsoft products and posting in the community.

I know you're worried about your email being hacked. Here are some suggestions to help you deal with this situation and keep your device safe:

  1. Do not respond or pay

First and foremost, do not respond to the threatener or make a payment to them. Such emails are usually phishing or blackmail, designed to intimidate you for money.

  1. Confirm the authenticity of the email

Check the sender's address: Double-check the sender's email address to make sure it matches your email address exactly. Sometimes, attackers forge sender information.

Check the header information: If you know how to view the full header information of an email, you can check if the email is really from your domain.

  1. Change your password

Change your Microsoft account password immediately. Make sure you choose a strong password and enable double authentication (2FA) for added security.

Check other accounts: if you use the same password for other websites, it is recommended that you change these as well.

  1. Check device security

Run a security scan: Use a trusted antivirus program to run a full scan of your device. Make sure your antivirus software is up to date.

Check applications: See if there are any unidentified applications or files on your device, especially recently installed ones.

  1. Monitor Account Activity

Check Account Activity: Sign in to your Microsoft account and review recent sign-in activity to make sure there aren't any suspicious sign-ins.

Check other important accounts: Check the activity of your banking, social media, and other important accounts to ensure there is no unauthorized access.

  1. Report an Incident

Contact local law enforcement: If you feel threatened or are concerned about your safety, consider reporting it to your local law enforcement agency.

  1. Understanding Pegasus spyware

How to check for infections: Detecting Pegasus spyware isn't easy, but there are a number of security tools you can try to scan for it.

Keep your device up-to-date: Make sure your operating system and applications are kept up-to-date to prevent known vulnerabilities from being exploited.

I hope these programs can help you.

Best regards

Jay | Microsoft Community Support Specialist

0 comments No comments

118 additional answers

Sort by: Oldest
  1. Anonymous
    2025-03-28T00:30:20+00:00

    If its in your junk mail im sure its spoofed so no need to worry. For piece of mind you can get the email headers and paste into chatGPT or Copolit to analyze.

    0 comments No comments
  2. Anonymous
    2025-04-01T23:07:57+00:00

    Hello, i have received a similar email, check the info I got from the header,

    ***

    • The email was received from 142.252.126.152, which belongs to camerageekphotox.com.
    • The SPF and DMARC checks failed, indicating a potential spoofing attempt.
    • SCL = 5, suggesting it was likely classified as spam.
    • The email passed through multiple Microsoft Exchange servers before reaching its final destination.

    ***

    1. Authentication & Security:
      • X-Ms-Exchange-Organization-AuthAs: Anonymous
        → The email was received without authentication (e.g., sent from an external domain).
      • Authentication-Results:
        → SPF (Sender Policy Framework) shows a softfail, meaning the sender's IP (142.252.126.152) is not explicitly allowed.
        → DKIM (DomainKeys Identified Mail) is none, meaning no digital signature was used to verify sender authenticity.
        → DMARC (Domain-based Message Authentication, Reporting & Conformance) fails, suggesting the domain's policy was not met.
      • Received-SPF: SoftFail
        → Confirms the SPF check resulted in a softfail, meaning the IP is not in the authorized list but was not completely rejected.
    2. Message Routing & Processing:
      • Received:
        → These headers show the servers the email passed through before reaching its destination.
      • X-Ms-Exchange-Organization-Network-Message-Id:
        → Unique identifier for tracking the email within Microsoft’s Exchange infrastructure.
      • X-Ms-Exchange-Crosstenant-Id:
        → Identifies the sending tenant (Microsoft 365 organization).
      • X-Ms-Exchange-Transport-EndToEndLatency:
        → The total time it took for the email to travel from sender to recipient (about 3 seconds here).
    3. Spam Filtering & Classification:
      • X-Microsoft-Antispam:
        → Contains spam confidence level (SCL) scores and filters used.
      • X-Ms-Exchange-Organization-Scl: 5
        → Spam Confidence Level (SCL) 5 suggests a moderate likelihood that this is spam (0 = clean, 9 = high confidence spam).
      • X-Microsoft-Antispam-Mailbox-Delivery:
        → Indicates that the email was filtered and classified as spam.
    4. Expiration & Message Handling:
      • X-Ms-Exchange-Organization-ExpirationStartTime:
        → Timestamp when email expiration was set (29 Mar 2025).
      • X-Ms-Exchange-Organization-ExpirationInterval:
        → Indicates how long the email is kept before deletion (1 day here).

    ***

    X-Eoptenantattributedmessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0 X-Incomingheadercount: 7 X-Ms-Exchange-Organization-Expirationstarttime: 29 Mar 2025 17:58:01.2218 (UTC) X-Ms-Exchange-Crosstenant-Originalarrivaltime: 29 Mar 2025 17:58:00.6437 (UTC) X-Ms-Exchange-Transport-Crosstenantheadersstamped: AS1PR03MB8192 X-Ms-Exchange-Organization-Authas: Anonymous X-Sid-Result: FAIL Authentication-Results: spf=softfail (sender IP is 142.252.126.152) smtp.mailfrom=outlook.com; dkim=none (message not signed) header.d=none;dmarc=fail action=none header.from=outlook.com; X-Ms-Exchange-Crosstenant-Authsource: CO1PEPF000066E8.namprd05.prod.outlook.com X-Ms-Userlastlogontime: 3/29/2025 5:53:07 PM X-Sender-Ip: 142.252.126.152 Return-Path: ******@outlook.com X-Ms-Exchange-Crosstenant-Rms-Persistedconsumerorg: 00000000-0000-0000-0000-000000000000 X-Ms-Exchange-Crosstenant-Fromentityheader: Internet X-Ms-Exchange-Crosstenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-Ms-Exchange-Organization-Expirationintervalreason: OriginalSubmit X-Ms-Exchange-Organization-Network-Message-Id: 849022d6-6959-4f25-b3d7-08dd6eeb3f24 X-Ms-Publictraffictype: Email X-Sid-Pra: ******@OUTLOOK.COM X-Ms-Exchange-Crosstenant-Authas: Anonymous X-Ms-Exchange-Eopdirect: true X-Microsoft-Antispam: BCL:0;ARA:1444111002|13020799006|58200799018|47200799021|461199028|6115599003|1370799030|1360799030|3412199025|440099028|1290799030|2980499032|7110799015; X-Ms-Exchange-Organization-Expirationstarttimereason: OriginalSubmit

    ***

    0 comments No comments
  3. Anonymous
    2025-04-04T14:41:23+00:00

    Thank you! Almost fell for it. Question please: Can we block this type of email(s) and report as phishing suggested?

    Grateful,

    DJ

    0 comments No comments
  4. Anonymous
    2025-04-10T22:01:52+00:00

    Hi,

    I received this email as a 'Note to Myself' and it is my email address but nothing in my sent.

    I looked at the source and this is what came up. I have no idea what any of it means so if someone can tell me I would really appreciate it. I have changed my password in the hopes that if someone had hacked into my email I have kicked them back out.

    Received: from DS0PR14MB6568.namprd14.prod.outlook.com (::1) by SA1PR14MB5879.namprd14.prod.outlook.com with HTTPS; Thu, 10 Apr 2025 16:29:00 +0000 Received: from DUZPR01CA0346.eurprd01.prod.exchangelabs.com (2603:10a6:10:4b8::29) by DS0PR14MB6568.namprd14.prod.outlook.com (2603:10b6:8:dd::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8606.34; Thu, 10 Apr 2025 16:28:58 +0000 Received: from DB1PEPF000509E9.eurprd03.prod.outlook.com (2603:10a6:10:4b8:cafe::a) by DUZPR01CA0346.outlook.office365.com (2603:10a6:10:4b8::29) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.8632.26 via Frontend Transport; Thu, 10 Apr 2025 16:28:57 +0000 Authentication-Results: spf=fail (sender IP is 23.230.155.105) smtp.mailfrom=hotmail.com; dkim=none (message not signed) header.d=none;dmarc=fail action=none header.from=hotmail.com; Received-SPF: Fail (protection.outlook.com: domain of hotmail.com does not designate 23.230.155.105 as permitted sender) receiver=protection.outlook.com; client-ip=23.230.155.105; helo=vtbearx.com; Received: from vtbearx.com (23.230.155.105) by DB1PEPF000509E9.mail.protection.outlook.com (10.167.242.59) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8632.13 via Frontend Transport; Thu, 10 Apr 2025 16:28:57 +0000 X-IncomingTopHeaderMarker: OriginalChecksum:FBEA83B3A875F139704426027C9A242FD6DDD9F3073B98FADA65E9D175C87547;UpperCasedChecksum:D14CC82DB9FE9A8244541D2CF9302B4B2C9A4507BF57CC8E2147F85532F6C3B7;SizeAsReceived:349;Count:7 Message-ID: <@hotmail.com> From: "@hotmail.com"

    Hello pervert, I've sent this mess=D0=B0ge from y= our Microsoft =D0=B0ccount.

    I w=D0=B0nt to inform you =D0=B0bout =D0=B0 very = b=D0=B0d situ=D0=B0tion for you. However, you c=D0=B0n benefit from it, if = you will =D0=B0ct wis=D0=B5ly.

    H=D0=B0ve you he=D0=B0rd of Peg=D0=B0sus? This is= =D0=B0 spyw=D0=B0re progr=D0=B0m th=D0=B0t inst=D0=B0lls on computers =D0= =B0nd sm=D0=B0rtphones =D0=B0nd =D0=B0llows h=D0=B0ckers to monitor the =D0= =B0ctivity of device owners. It provides =D0=B0ccess to your webc=D0=B0m, m= essengers, em=D0=B0ils, c=D0=B0ll records, etc. It works well on Android, i= OS, m=D0=B0cOS =D0=B0nd Windows. I guess, you =D0=B0lre=D0=B0dy figure= d out where I=E2=80=99m getting =D0=B0t.

    It=E2=80=99s been =D0=B0 few months since I inst= =D0=B0lled it on =D0=B0ll your d=D0=B5vi=D1=81=D0=B5s bec=D0=B0us= e you were not quite choosy =D0=B0bout wh=D0=B0t links to click on the int= =D0=B5rn=D0=B5t. During this period, I=E2=80=99ve le=D0=B0rned =D0=B0bout = =D0=B0ll =D0=B0spects of your priv=D0=B0te life, but =D0=BEn=D0=B5 is = of speci=D0=B0l signific=D0=B0nce to me.

    I=E2=80=99ve recorded m=D0=B0ny videos of you jer= king off to highly controversi=D0=B0l =D1=80=D0=BErn videos. Given th= =D0=B0t the =E2=80=9Cquestion=D0=B0ble=E2=80=9D genre is =D0=B0lmost =D0=B0= lw=D0=B0ys the s=D0=B0me, I c=D0=B0n conclude th=D0=B0t you h=D0=B0ve sick = =D1=80=D0=B5rv=D0=B5rsi=D0=BEn.

    I doubt you=E2=80=99d w=D0=B0nt your friends, f= =D0=B0mily =D0=B0nd co-workers to know =D0=B0bout it. However, I c=D0=B0n d= o it in =D0=B0 few clicks.

    Every number in your cont=D0=B0ct Iist will = suddenly receive these vid=D0=B5=D0=BEs =E2=80=93 on Wh=D0=B0tsApp, on Tele= gr=D0=B0m, on Inst=D0=B0gr=D0=B0m, on F=D0=B0cebook, on em=D0=B0il =E2=80= =93 everywhere. It is going to be =D0=B0 tsun=D0=B0mi th=D0=B0t will sweep = =D0=B0w=D0=B0y everything in its p=D0=B0th, =D0=B0nd first of =D0=B0ll, you= r f=D0=BErm=D0=B5r life.

    Don=E2=80=99t think of yourself =D0=B0s =D0=B0n i= nnocent victim. No one knows where your =D1=80=D0=B5rv=D0=B5rsi=D0=BEn migh= t le=D0=B0d in the future, so consider this =D0=B0 kind of deserved =D1=80u= nishm=D0=B5nt to stop you.

    I=E2=80=99m some kind of God who sees everything.= However, don=E2=80=99t p=D0=B0nic. As we know, God is merciful =D0=B0= nd forgiving,  =D0=B0nd so do I. But my m=D0=B5r=D1=81y = ;is not free.

    Tr=D0=B0nsfer 1300$ to my L= itecoin (LTC) w=D0=B0llet: ltc1qrf0e7hdj0hyt6vkuz02ndvrr84e6kz7hmxh= cek

    Once I receive confirm=D0=B0tion of the tr=D0=B0n= s=D0=B0ction, I will =D1=80=D0=B5rm=D0=B0nently delete =D0=B0ll v= ideos compromising you, uninst=D0=B0ll Peg=D0=B0sus from =D0=B0ll of your d= evices, =D0=B0nd dis=D0=B0ppe=D0=B0r from your life. You c=D0=B0n be sure = =E2=80=93 my benefit is only money. Otherwise, I wouldn=E2=80=99t be writin= g to you, but destroy your life without =D0=B0 word in =D0=B0 second.

    I=E2=80=99ll be notified when you open my em=D0= =B0il, =D0=B0nd from th=D0=B0t moment you h=D0=B0ve ex=D0=B0ctly 48= hours to send the money. If cryptocurrencies =D0=B0re unch=D0=B0r= tered w=D0=B0ters for you, don=E2=80=99t worry, it=E2=80=99s very simple. J= ust google "crypto exchange" or "buy Litecoin" =D0=B0nd= then it will be no h=D0=B0rder th=D0=B0n buying some useless stuff on Am= =D0=B0zon.

    I strongly w=D0=B0rn you =D0=B0g=D0=B0inst the fo= llowing:
    * Do not reply to this em=D0=B0il. I've sent it from your Micro= soft =D0=B0ccount.

    * Do not cont=D0=B0ct the police. I h=D0=B0ve =D0= =B0ccess to =D0=B0ll your d=D0=B5vi=D1=81=D0=B5s, =D0=B0nd =D0=B0s soon =D0= =B0s I find out you r=D0=B0n to the cops, videos will be published.<= /div> * Don=E2=80=99t try to reset or destroy your d=D0= =B5vi=D1=81=D0=B5s. As I mentioned =D0=B0bove: I=E2=80=99m monitoring =D0= =B0ll your =D0=B0ctivity, so you either =D0=B0gree to my terms or the vid= =D0=B5=D0=BEs =D0=B0re =D1=80ublished.

    Also, don=E2=80=99t forget th=D0=B0t cryptocurren= cies =D0=B0re =D0=B0nonymous, so it=E2=80=99s impossible to identify me usi= ng the provided =D0=B0ddr=D0=B5ss.

    Good luck, my perverted friend. I hope this is th= e l=D0=B0st time we he=D0=B0r from e=D0=B0ch other.

    And some friendly =D0=B0dvice: from now on, don= =E2=80=99t be so c=D0=B0reless =D0=B0bout your online security. --0a3b7279be5c76798a20691e7abfd22cded5--

    0 comments No comments