Re: Re: for you FORWARD TO . Highlighted please review.
Bitch
You must have noticed that there are three of us. My friend and I are in New York and my brother is in Iran. I am different from my brother. I hate you white Americans. I'll give you 8 hours, send 2.5 bitcoins to my brother so he can give you the information. Otherwise, I'll blow your child's brain against the wall. I kill them like a dog.
This is last email
EFTA00146847
Gentlemen- I know [REDACTED] noted that the investigation is closed and to only highlight certain emails- this is one such email.
Sent from my iPhone
This is the latest email. I have done 2 emergency disclosure requests to google on this email account and both return back to IP addresses located in Iran. The last one was on Thursday, which I sent the results which showed the originating IP address as Iran.
He and his lawyer have been notified of this and to cease communications, but has continued to the point [ ]
where the person even sent him his picture and resume regarding being an entrepreneur and requesting
$25,000.00
The last time there was a countdown on a threat we had the local precinct increased patrols around residence located on with nothing happening.
continuous communication with this individual is the reason for these messages.
In my opinion, we cannot keep wasting resources, manpower, and time dedicated to someone who puts himself in these situations by not following the advice and suggestions of everyone investigating these matters. I suggest he hires a private security firm that will do exactly what he wants.
However, if you want, I will again put forth a google emergency disclosure request.
I apologize for the Saturday morning email.
Submitted Emergency Disclosure Request on [redacted] and also informed that precinct that
covers [redacted] to be aware of the situation.
Below are the results from the Google Emergency Disclosure:
GOOGLE SUBSCRIBER INFORMATION
Alternate e-Mails:
Created on: 2020-03-17 16:30:21 UTC
IP ACTIVITY
| Timestamp | IP Address | Activity Type |
|---|---|---|
| 2020-06-27 08:11:05 UTC |
92.38.169.231 | Login (New York utilizing a CDN) - Not actually in NY |
| 2020-06-27 07:47:30 UTC |
5.237.161.27 | Login (IRAN) |
| 2020-06-27 07:46:00 UTC |
5.237.161.27 | Login (IRAN) |
| 2020-06-26 20:37:41 UTC |
92.38.149.56 | Login (California utilizing a CDN) Uses the Same CDN |
| 2020-06-26 08:36:26 UTC |
5.211.157.79 | Login (IRAN) |
| 2020-06-26 06:43:42 UTC |
5.211.73.53 | Login (IRAN) |
New York IPaddress is utilizing a CDN (Content Delivery Network)
Organization: G-Core Labs S.A.
and Hostname : free-go-ny-11.com
CON : it is a set of linked servers which accelerate giving the data (photo, video, scripts) back to the user. CDN servers are placed as close as possible to the end audience.
This means the message appears to be sent to as close to the end user using one of their servers.
The IRAN ip address come from his mobile network
(Organization: Mobile Communication Company of Iran PLC)
I feel as though the threat, again has been mitigated as the sender is located in IRAN and is attempting to mask his location through these Content Delivery Networks.
EFTA00146845
And with the time being past 3pm the timeline for the threats has come and gone without any incidents. (Threat was posted at 0647 hours with a deadline of 8 hours which equals 1447 hours).
No further investigation deemed necessary.
