date
04 April 2019 Thursday. 18:20:14 UTC
description
Email ransomware inbound to our corporate support@********.com dl internal and was saying that we had been infected with software and needed to pay this address with USD via BitCoin to have them remove it. Tracked the IP and found it's a hopped IP via 2 or 3 VPN's from the middle east. Please shut this user down.