OSINT informix
1.34K subscribers
68 photos
84 links
Get your daily dose of OSINT-Related resources, case studies and news from around the globe.

We publish only the most interesting or useful stories each day. No spamming. No call to actions. No fake news.

Join today and see for yourself.
Download Telegram
How to get information on a Russian Federation citizen.
Here are some of the top resources to help you identity verification or get additional useful information about any Russian citizen:

▫️If you are not in the territory of the Russian Federation, then install a VPN in Russia.

1️⃣ Validity of the passport:
http://services.guvm.mvd.rf/info-service.htm?sid=2000

2️⃣ Checking the TIN:
https://service.nalog.ru/inn.do

3️⃣ Credits:
https://app.exbico.ru/

4️⃣ Enforcement proceedings:
http://fssprus.ru/iss/ip

5️⃣ Tax debts:
https://peney.net/

6️⃣ Pledges of property:
https://www.reestr-zalogov.ru/state/index#

7️⃣ Bankruptcy:
https://bankrot.fedresurs.ru/

8️⃣ Participation in legal proceedings:
https://bsr.sudrf.ru/bigs/portal.html

9️⃣ Decisions of justices of the peace of St. Petersburg:
https://mirsud.spb.ru/

🔟 Participation in business:
https://zachestnyibiznes.ru/
👍1
Hackers brute-forced TransUnion servers using the password "‎Password"
Whenever you want to complain about the low information security culture in Eastern Europe, remember this news. Hackers brute-forced the servers of the credit insurance company TransUnion South Africa using the password "‎Password".
https://www.bleepingcomputer.com/news/security/hackers-claim-to-breach-transunion-south-africa-with-password-password/

The data of more than 50 million customers have been stolen, with a ransom demand of $15,000,000

“Securing customer data is our top priority,” says the company's CEO.

To us it feels like their crystal-clear insecurity obviously has other priorities.
How to really stay anonymous on Telegram?
Telegram continues to evolve and adapt to world events, which is why it is often called the protest messenger. As it matures, each time acquires additional functions and features, for example:

- Blocking in Russia gave the messenger a built-in proxy.
- Protests in Hong Kong made it possible to hide your number from everyone.
- The protests in Russia made it possible for group admins to become anonymous.

There are still ways to uncover the identity behind a Telegram user, as we previously published here:
https://t.me/espyOSINT/9

And here is a quick guide that will show you what extra measures you can take in order to maintain Telegram anonymity: https://telegra.ph/Naskolko-vy-dejstvitelno-anonimny-v-Telegram-11-21
UK soldiers banned from using WhatsApp messenger due to "Russian hackers"
According to Daily Mail, the military has been ordered to stop using WhatsApp for professional purposes, otherwise If so, they may be subject to disciplinary action. The thing is that the command is afraid of the messenger being hacked by Russian hackers, estimating such a probability as high-like: "It is considered highly likely Russia has acquired the same capability"

Regular military units are advised to use Signal instead of WhatsApp. The news will not pass by Boris Johnson, who constantly uses WhatsApp for business correspondence.
https://www.dailymail.co.uk/news/article-10633873/British-soldiers-ordered-WhatsApp-hacking-fears.html
Top OSINT Resources to Identify Email Address Owners
Here is a list of the top sources we use to uncover the identities of email address owners as part of OSINT research or investigation. The topic is quite relevant now so I'm sure this would be helpful for many:

zerobounce (SMTP)
mailboxlayer (SMTP)
epieos (Gmail Check)
GHunt (Gmail Check)
@UniversalSearchBot (Yandex Check)
@yandexidbot (Yandex Phone)
ProtOSINT (Protonmail Check)
intelx (Dorks)
epieos (Skype Check)
infotracer (Service)
pipl (Service)
telpoisk (Service)
@EmailPhoneOSINT_bot (Service)
eyeofgod (Service)
@Tpoisk_Bot (Service)
isphere (Service)
AVinfoBot (Service)
The best tool to identify a vehicle’s brand and model using AI
Some people are great at identifying cars’ brands and models just by looking at the vehicle. I’m afraid I am not one of them. In fact, if I ever had to describe a car involved in some crime I would probably go with something like “it was grey”. Extremely unhelpful I know.

CarNet Uses advanced technology to build an automotive API which is capable of recognizing the Make, Model and Generation of most cars built since 1995, with 97+% accuracy.
https://carnet.ai/
Top OSINT Resources to Identify Email Address Locations
Here is a list of the OSINT tools we use to roughly tell where the sender or recipient of an e-mail is located:

emailheaders (Header Check)
traceemail (Header Check)
emailheader (Header Check)
azurewebsites (Header Check)
suip (Header Check)
domaintools (WHOIS)
getnotify (Mail Tracking)
readnotify (Mail Tracking)
didtheyreadit (Mail Tracking)
mailtracking (Mail Tracking)
canarytokens (Logger IP)
grabify (Logger IP)
iplogger (Logger IP)
yandex (ADINT)
google (ADINT)
mytarget (ADINT)
Geolocating Russian Damage on a Small Ukrainian Zoo
An OSINT volunteer for the Ukraine Witness project by the Centre for Information Resilience, was able to geolocate a zoo that was destroyed by Russian forces. Here’s how he was able to geolocate the exact place where the video was recorded.
https://gralhix.wordpress.com/2022/03/10/geolocating-russian-damage-on-a-small-ukranian-zoo/
OSINTFramework » Consider Malfrat's OSINT Map Instead
The OSINTFramework didn't get an update for years, so Twitter user @MalfratsInd forked the original repo on GitHub and recreated it, filling it with links that are currently active and useful for investigations.

There's still a lot of sites to cover, so if you have more ideas, head over to the GitHub repo and help it grow!
https://map.malfrats.industries/
BBC Sheds More Light on the Life of Cyber Scammers
The BBC team has made an excellent film about the life of cyber scammers. The original title of the film is "Hunting the Social Media Fraudsters". After a short time, OSINT researchers were able to deanonymize one of the alleged perpetrators, that were discussed in the film. It was very interesting to look at their practices and patterns from this angle.
https://youtu.be/H0Mzdswq8M0
100,000 Google Play Users Were Infected with Facebook Malware
Facebook password stealing malware has infected 100,000 Google Play users. The software masquerades as a cartoon app called Craftsart Cartoon Photo Tools, which allows users to upload an image and convert it into a cartoon rendering. Inside it contains FaceStealer, which allows you to steal Facebook login passwords.

https://www.bleepingcomputer.com/news/security/android-password-stealing-malware-infects-100-000-google-play-users/
Learning from Analysis of 800 Million Breached Passwords
A research led by Specops Software compiled through surveys and data analysis of 800 million breached passwords, a subset of the more than 2 billion breached passwords within Specops Breached Password Protection list.

It seems like that password length and complexity do not corollate with security and that password overload is a big problem.

With that in mind, here are few facts about the use of passwords that came to light during this case study:

1️⃣ 93% of the passwords used in brute force attacks include 8 or more characters
2️⃣ 54% of organizations do not have a tool to manage work passwords
3️⃣ 48% of organizations do not have user verification in place for calls to the IT desk
4️⃣ 41% of passwords used in real attacks are 12 characters or longer
5️⃣ 68% of passwords used in real attacks include at least two character types

You can download the full report here:
https://specopssoft.com/our-resources/specops-ureset-datasheet/
1
The Cybercrime Group that Target Servers of IT Giants
A threat group calling itself Lapsus$ managed to hack the servers of some IT giants. This time the hack was confirmed by Microsoft and Okta. Microsoft says there is nothing sensitive in the leaked data, only code for projects such as Bing, Cortana and Bing Maps.

With Okta, everything can be much more serious. The company's IS is still at a loss to assess the extent of the leak, and, judging by the screenshots from Lapsus$, they have had access to the servers since January. The hackers are giggling on Twitter at Okta's excuses, which is sort of a hint.

In both cases, the attacks went through compromised access rights. Specialists also speculate that Lapsus$'s attempts to bribe insiders in companies could be successful. And they say that serious guys are hiding under the sign. So we'll keep following the developments.

https://www.securityweek.com/microsoft-okta-confirm-data-breaches-involving-compromised-accounts/
OSINT Resources for Investigating Cryptocurrency Transactions
Here is a useful list of resources for conducting an OSINT investigation related to the analysis of cryptocurrency transactions.

BTC-ETH-XRP-BCH-LTC-XLM-DASH-ZEC-XMR (Blockchain)
blockchair (Explorer)
tokenview (Explorer)
blockcypher (Explorer)
blockpath (Visualization)
oxt (Visualization)
graphsense (Visualization)
orbit (Visualization)
sicp (Visualization)
maltego (Visualization)
crystal (Visualization)
ethtective (Visualization ETH)
walletexplorer (Grouping)
bitinfocharts (Grouping)
bitcoinabuse (Abuse)
bitcoinwhoswho (Abuse)
checkbitcoinaddress (Abuse)
scamalert (Abuse)
cryptscam (Abuse)
bitrankverified (Scoring)
cryptocurrencyalerting (Monitoring)
cryptotxalert (Monitoring)
kycp (Block Analysis)
blockstream (Block Analysis)
btcrecover (Wallet Brute)
Google Dorks
How to Identify Users by Their Passwords
Here is a list of sources used to identify users by their password. There are several resources on the web that allow you to search for related nicknames and email addresses on leaked passwords databases. Here they are:

leaklookup (Need Registration)
leakpeek (Free)
breachdirectory (Need Registration)
eyeofgod (Command /pas)
leakcheck (Enterprise Plan)
karma (GitHub)
darknet (Need TOR)
🔥1
Chrome Extension Can Detect Fake Profile Pictures with 99.29% Accuracy
A new artificial intelligence-based (AI) software that works as a Google Chrome extension called Fake Profile Detector (Deepfake, GAN) that can detect artificially generated profile pictures with a claimed 99.28% accuracy.
The developers says that the world relies on visual decision making and it is working towards making deep learning more robust and easier to develop so that any business can implement state-of-the-art AI from a single platform.
👍1
We automate data collection

A handy automation framework called Katalon Studio. It will serve as an effective and at the same time free alternative to Selenium and will allow you to spend less time on routine processes.
👍2
Advanced information gathering & OSINT framework for phone numbers. PhoneInfoga is one of the most advanced tools to scan international phone numbers. It allows you to first gather standard information such as country, area, carrier, and line type on any international phone number, then searches for footprints on search engines to try to find the VoIP provider or identify the owner.
👍1
Hydra—Russia’s Largest Dark Market, was shuts down by BKA According to the Federal Criminal Police Office (BKA), the world's largest Darknet marketplace "Hydra Market" has been shut down.
A message said that the "server infrastructure located in Germany" was secured - and the marketplace was thus closed. In the attack by the Attorney General's Office (Central Office for Combating Internet Crime) and the Federal Criminal Police Office, bitcoins amounting to the equivalent of around 23 million euros were seized.
🤔21
☝️😉 Few systems for studying arrays of textual information in order to identify entities and relationships between them (Doctor Watson, Archivist 3000, Ambar, DocFetcher):

http://ambar.cloud
https://dtsearch.com/
http://www.likasoft.com/ru/
https://dr-watson.wixsite.com/home
http://docfetcher.sourceforge.net/

Archivist 3000 certainly stands out. It can extract entities (phones, email, ip-addresses, etc.) from a large number of documents. Can organize the search for information on a colossal list of different files.
👍4