Tier · dangerous
Verdict

Confirmed scam — delete it

Our AI analyst read the message body and judged it likely to be phishing.

ivan@ivanmueller.info
At a glance
AI · 95% phishing
Risk score
100
/ 100
malicious
AI analyst

MalwareTips analyst · message material

sextortion

This is a sextortion scam email that uses intimidation and threats of public shaming to demand a cryptocurrency payment.

Phishing likelihood95%
Spam likelihood90%
Red flags identified
  • Uses high-pressure intimidation tactics by threatening to release compromising video footage.
  • Demands a significant payment in Bitcoin to prevent the alleged release of private information.
  • Employs a generic, impersonal greeting and lacks specific details about the recipient.
  • Contains classic sextortion blackmail themes common in mass-distributed extortion campaigns.
  • Includes multiple links to cryptocurrency exchanges to facilitate the requested payment.
What to do

Do not respond or pay the requested amount. Mark the email as junk or spam and delete it immediately.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

1000

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.

  • AI analyst flagged 95% phishing likelihood (sextortion).
    ai_phishing_detected
    -48
  • Screenshot OCR + visual pass flagged 100/100 phishing risk: This is a classic sextortion scam email that uses fear and intimidation to demand a Bitcoin payment. It contains no personalized information and relies on common social engineering tropes.
    screenshot_phishing_visual
    -30
  • Message body triggered 1 rule-based red-flag category (credential-harvest / urgency / attachment-bait / money-movement / etc.).
    body_red_flags
    -15
  • AI analyst flagged 90% spam likelihood.
    ai_spam_detected
    -14
  • Message-ID is stamped with "70313.com" rather than "ivanmueller.info" — the message was assembled on a server that doesn't belong to the claimed sender.
    message_id_apex_mismatch
    -5
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Authentication results

0/1 PASS

Results extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.

SPF
DKIM
DMARC
none
Return-Pathivan@ivanmueller.info

Domain age

timeout

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Phishing-pattern signals

1 signal

Rule-based pattern matches we ran across the message body and OCR text BEFORE the AI analyst. Each is a hint, not a verdict.

  • Requests money, wire transfer, or gift cardshigh
    , credit/debit cards, crypto, bank transfer, and other gift cards. http:/

Links extracted from this email

5 shown

Each link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.

  • www.coinbase.com
    Link uses plain HTTP, not HTTPS
    Suspicion
    5
  • www.binance.com
    Link uses plain HTTP, not HTTPS
    Suspicion
    5
  • www.bitrefill.com
    Link uses plain HTTP, not HTTPS
    Suspicion
    5
  • www.crypto.com
    Link uses plain HTTP, not HTTPS
    Suspicion
    5
  • www.etoro.com
    Link uses plain HTTP, not HTTPS
    Suspicion
    5

Screenshot vision analysis

VISUAL · 100/100

This is a classic sextortion scam email that uses fear and intimidation to demand a Bitcoin payment. It contains no personalized information and relies on common social engineering tropes.

Visual red flags
  • sextortion blackmail theme
  • threat of public shaming
  • demand for cryptocurrency payment
  • generic greeting
  • high-pressure intimidation tactics
Visible URLs in screenshot
  • http://www.coinbase.com
  • http://www.binance.com
  • http://www.bitrefill.com
  • http://www.crypto.com
  • http://www.etoro.com
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 1 MX record published
    mta-gw.infomaniak.ch
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Clean across all 3 blocklists checked (SURBL, Spamhaus DBL, URIBL).

Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
ivanmueller.info
Domain age
Unknown
Provider
custom domain
MX hosts
mta-gw.infomaniak.ch
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.