Confirmed scam — delete it
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
sextortionThis is a sextortion scam email that uses intimidation and threats of public shaming to demand a cryptocurrency payment.
- Uses high-pressure intimidation tactics by threatening to release compromising video footage.
- Demands a significant payment in Bitcoin to prevent the alleged release of private information.
- Employs a generic, impersonal greeting and lacks specific details about the recipient.
- Contains classic sextortion blackmail themes common in mass-distributed extortion campaigns.
- Includes multiple links to cryptocurrency exchanges to facilitate the requested payment.
Do not respond or pay the requested amount. Mark the email as junk or spam and delete it immediately.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 0The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.
- AI analyst flagged 95% phishing likelihood (sextortion).ai_phishing_detected-48
- Screenshot OCR + visual pass flagged 100/100 phishing risk: This is a classic sextortion scam email that uses fear and intimidation to demand a Bitcoin payment. It contains no personalized information and relies on common social engineering tropes.screenshot_phishing_visual-30
- Message body triggered 1 rule-based red-flag category (credential-harvest / urgency / attachment-bait / money-movement / etc.).body_red_flags-15
- AI analyst flagged 90% spam likelihood.ai_spam_detected-14
- Message-ID is stamped with "[number].com" rather than "ivanmueller.info" — the message was assembled on a server that doesn't belong to the claimed sender.message_id_apex_mismatch-5
Trust cannot go below 0, so 11 points of penalties below that were not counted.
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Authentication results
0/1 PASSResults extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.
Domain age
timeoutRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Phishing-pattern signals
1 signalRule-based pattern matches we ran across the message body and OCR text BEFORE the AI analyst. Each is a hint, not a verdict.
- Requests money, wire transfer, or gift cardshigh“, credit/debit cards, crypto, bank transfer, and other gift cards. http:/”
Links extracted from this email
5 sites shownGoogle Safe Browsing could not be checked for this scan. The links were checked against our own URL scan database, then scored on how they are built. Click Scan link for a full report on the destination.
- www.coinbase.comLink uses plain HTTP, not HTTPSSuspicion5
- www.binance.comLink uses plain HTTP, not HTTPSSuspicion5
- www.bitrefill.comLink uses plain HTTP, not HTTPSSuspicion5
- www.crypto.comLink uses plain HTTP, not HTTPSSuspicion5
- www.etoro.comLink uses plain HTTP, not HTTPSSuspicion5
Screenshot vision analysis
VISUAL · 100/100This is a classic sextortion scam email that uses fear and intimidation to demand a Bitcoin payment. It contains no personalized information and relies on common social engineering tropes.
- sextortion blackmail theme
- threat of public shaming
- demand for cryptocurrency payment
- generic greeting
- high-pressure intimidation tactics
- http://www.coinbase.com
- http://www.binance.com
- http://www.bitrefill.com
- http://www.crypto.com
- http://www.etoro.com
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedmta-gw.infomaniak.ch
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okClean across all 3 blocklists that answered (SURBL, Spamhaus DBL, URIBL).
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okSkipped — the breach check was not available for this scan.