Bitcoin Forum
April 24, 2024, 05:36:01 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Strange recovery / password phrase  (Read 224 times)
WildDreams (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
May 31, 2018, 12:23:41 PM
 #1

Hi

I hope I'm posting this to the correct forum, please excuse a newbie.

I received an email that looks like it may have been sent to my address by mistake, but it looks suspiciously like some sort of crypto recovery phrase!

It was sent From: "*******" <*******@aydinbey.biz.ua> any I can't seem to find any info about aydinbey.biz.ua except that it's a mail server hosted in the Ukraine and was registered by some entity that has registered various bitcoin sites - clue 1

clue 2 - The subject line is as follows, uzmuthp eccaljr atmihnp evnektl    (4 groups of 7 characters)
The body just contains another 5 groups of 7 characters in a similar format to the subject.

Strangely, the from address is also made up of 2 groups of 7 characters  in a similar format to the subject

unfortunately this only makes 11 words in total which do not meet the 12 word BIP39 criteria.

I have also translated the words to Cyrillic but they don't appear in the Ukrainian BIP wordlist either.

Does anyone have any ideas?

 
1713980161
Hero Member
*
Offline Offline

Posts: 1713980161

View Profile Personal Message (Offline)

Ignore
1713980161
Reply with quote  #2

1713980161
Report to moderator
According to NIST and ECRYPT II, the cryptographic algorithms used in Bitcoin are expected to be strong until at least 2030. (After that, it will not be too difficult to transition to different algorithms.)
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713980161
Hero Member
*
Offline Offline

Posts: 1713980161

View Profile Personal Message (Offline)

Ignore
1713980161
Reply with quote  #2

1713980161
Report to moderator
odolvlobo
Legendary
*
Online Online

Activity: 4298
Merit: 3208



View Profile
May 31, 2018, 05:09:45 PM
 #2

Does the email have a body? Does it contain a url to click on? Post the entire email including its headers. Regardless, it is unlikely to be a seed.

Join an anti-signature campaign: Click ignore on the members of signature campaigns.
PGP Fingerprint: 6B6BC26599EC24EF7E29A405EAF050539D0B2925 Signing address: 13GAVJo8YaAuenj6keiEykwxWUZ7jMoSLt
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
May 31, 2018, 05:40:37 PM
 #3

You could try the 11 words in electrum or somewhere similar and just see if it works. It's' not normally exactly 12 words, sometimes it can be 13 or 14 so it might have a chance of being 11 also.

You could also experiment to see if anything works on an offline copy of the bitaddress.org website on "wallet details" to see if it's a private key you have.
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
June 01, 2018, 12:34:04 AM
 #4

It's more probable that this is just some sort of spam or phising email gone wrong...

Assuming it IS a recovery phrase of some description, it seems logical  that given that it's arrived via email, it would mean it's from some sort of online service like a web wallet or exchange or something like that.

However, I'm not aware of any web wallets that use that format for recovery phrases. Huh

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
eelp0904251
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
June 01, 2018, 02:22:46 AM
 #5

 Consider the sender and recipient information too.  7 character seems to be a key of some sort. Does your email address contain 7 characters?
nc50lc
Legendary
*
Offline Offline

Activity: 2394
Merit: 5531


Self-proclaimed Genius


View Profile
June 01, 2018, 04:27:05 AM
 #6

Before thinking about the email if it was something else, ask yourself if you're expecting an email regarding a passphrase.
You might be wasting your time on that.

Emails containing malware and links aren't "that" rare specially if you're actively using that particular email address as a contact on websites that requires registration or subscription.
Can you tell us about your email address' info (not your email address) if it contains a name which is known among Bitcoin users like "Satoshi", "Nakamoto", "John Mcafee" etc because those are often targeted by malicious email senders.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
WildDreams (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
June 01, 2018, 12:49:28 PM
 #7

Hi

Thanks for all the reply's

The body of the email only contains the 5 groups of 7 character "words", all in text
I have a catchall mailbox for my website and the Envelope-to: address is in my domain.

The To: address is for someone else.

Return-path: <ytmoqys@aydinbey.biz.ua>
Envelope-to: ****@**************.co.za                                        (within my domain)
Delivery-date: Thu, 31 May 2018 10:47:21 +0200
Received: from mail.aydinbey.biz.ua ([185.49.70.99])
   by www22.jnb2.host-h.net with esmtp (Exim 4.84_2)
   (envelope-from <ytmoqys@aydinbey.biz.ua>)
   id 1fOJEr-0005yu-3n
   for ****@****************.co.za; Thu, 31 May 2018 10:47:21 +0200                    (within my domain)
Received: from aydinbey.biz.ua (mail.aydinbey.biz.ua [185.49.70.99])
   by mail.aydinbey.biz.ua (Postfix) with ESMTPA id 193B6AE06;
   Thu, 31 May 2018 09:29:44 +0300 (EEST)
Message-ID: <cf7201d3f8c1$e0a36ea0$38728164@ytmoqys>
From: "adnyqfy" <ytmoqys@aydinbey.biz.ua>
To: <******@******.co.za>                                                                                      (other receipient)
Subject: uzmuthp eccaljr atmihnp evnektl
Date: Thu, 31 May 2018 09:29:30 +0300
MIME-Version: 1.0
Content-Type: text/plain;
   charset="windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Windows Live Mail 14.0.8117.416
X-MimeOLE: Produced By Microsoft MimeOLE V14.0.8117.416
X-Virus-Scanned: Clear (ClamAV 0.99.2/24619/Thu May 31 06:34:57 2018)
X-Unfudged-Spam-Score: -0.0 (/)
Delivered-To: creatird-*****@******************.co.za                                         (within my domain)
 
******* ******* ******* ******* *******                                                            (just in case it is a key to millions Grin Grin Grin)
 
WildDreams (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
June 07, 2018, 03:39:56 PM
 #8

BUMP

Has anyone any other ideas?

Thanks
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
June 07, 2018, 04:17:34 PM
 #9

BUMP

Has anyone any other ideas?

Thanks

What does the first word begin with?
What happens when you put it into electrum, anything? Try putting it in as a bip38 seed and setting the derivation path to different things like m/0'/0 or m/49'/0'/0.



The others were probably right though this might just be an email sent to tease you into wondering what it could be that the private key contains rather than it actually having anything in it as some sort of spam attempt.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!