OSINT informix
1.34K subscribers
68 photos
84 links
Get your daily dose of OSINT-Related resources, case studies and news from around the globe.

We publish only the most interesting or useful stories each day. No spamming. No call to actions. No fake news.

Join today and see for yourself.
Download Telegram
100,000 Google Play Users Were Infected with Facebook Malware
Facebook password stealing malware has infected 100,000 Google Play users. The software masquerades as a cartoon app called Craftsart Cartoon Photo Tools, which allows users to upload an image and convert it into a cartoon rendering. Inside it contains FaceStealer, which allows you to steal Facebook login passwords.

https://www.bleepingcomputer.com/news/security/android-password-stealing-malware-infects-100-000-google-play-users/
Learning from Analysis of 800 Million Breached Passwords
A research led by Specops Software compiled through surveys and data analysis of 800 million breached passwords, a subset of the more than 2 billion breached passwords within Specops Breached Password Protection list.

It seems like that password length and complexity do not corollate with security and that password overload is a big problem.

With that in mind, here are few facts about the use of passwords that came to light during this case study:

1️⃣ 93% of the passwords used in brute force attacks include 8 or more characters
2️⃣ 54% of organizations do not have a tool to manage work passwords
3️⃣ 48% of organizations do not have user verification in place for calls to the IT desk
4️⃣ 41% of passwords used in real attacks are 12 characters or longer
5️⃣ 68% of passwords used in real attacks include at least two character types

You can download the full report here:
https://specopssoft.com/our-resources/specops-ureset-datasheet/
1
The Cybercrime Group that Target Servers of IT Giants
A threat group calling itself Lapsus$ managed to hack the servers of some IT giants. This time the hack was confirmed by Microsoft and Okta. Microsoft says there is nothing sensitive in the leaked data, only code for projects such as Bing, Cortana and Bing Maps.

With Okta, everything can be much more serious. The company's IS is still at a loss to assess the extent of the leak, and, judging by the screenshots from Lapsus$, they have had access to the servers since January. The hackers are giggling on Twitter at Okta's excuses, which is sort of a hint.

In both cases, the attacks went through compromised access rights. Specialists also speculate that Lapsus$'s attempts to bribe insiders in companies could be successful. And they say that serious guys are hiding under the sign. So we'll keep following the developments.

https://www.securityweek.com/microsoft-okta-confirm-data-breaches-involving-compromised-accounts/
OSINT Resources for Investigating Cryptocurrency Transactions
Here is a useful list of resources for conducting an OSINT investigation related to the analysis of cryptocurrency transactions.

BTC-ETH-XRP-BCH-LTC-XLM-DASH-ZEC-XMR (Blockchain)
blockchair (Explorer)
tokenview (Explorer)
blockcypher (Explorer)
blockpath (Visualization)
oxt (Visualization)
graphsense (Visualization)
orbit (Visualization)
sicp (Visualization)
maltego (Visualization)
crystal (Visualization)
ethtective (Visualization ETH)
walletexplorer (Grouping)
bitinfocharts (Grouping)
bitcoinabuse (Abuse)
bitcoinwhoswho (Abuse)
checkbitcoinaddress (Abuse)
scamalert (Abuse)
cryptscam (Abuse)
bitrankverified (Scoring)
cryptocurrencyalerting (Monitoring)
cryptotxalert (Monitoring)
kycp (Block Analysis)
blockstream (Block Analysis)
btcrecover (Wallet Brute)
Google Dorks
How to Identify Users by Their Passwords
Here is a list of sources used to identify users by their password. There are several resources on the web that allow you to search for related nicknames and email addresses on leaked passwords databases. Here they are:

leaklookup (Need Registration)
leakpeek (Free)
breachdirectory (Need Registration)
eyeofgod (Command /pas)
leakcheck (Enterprise Plan)
karma (GitHub)
darknet (Need TOR)
🔥1
Chrome Extension Can Detect Fake Profile Pictures with 99.29% Accuracy
A new artificial intelligence-based (AI) software that works as a Google Chrome extension called Fake Profile Detector (Deepfake, GAN) that can detect artificially generated profile pictures with a claimed 99.28% accuracy.
The developers says that the world relies on visual decision making and it is working towards making deep learning more robust and easier to develop so that any business can implement state-of-the-art AI from a single platform.
👍1
We automate data collection

A handy automation framework called Katalon Studio. It will serve as an effective and at the same time free alternative to Selenium and will allow you to spend less time on routine processes.
👍2
Advanced information gathering & OSINT framework for phone numbers. PhoneInfoga is one of the most advanced tools to scan international phone numbers. It allows you to first gather standard information such as country, area, carrier, and line type on any international phone number, then searches for footprints on search engines to try to find the VoIP provider or identify the owner.
👍1
Hydra—Russia’s Largest Dark Market, was shuts down by BKA According to the Federal Criminal Police Office (BKA), the world's largest Darknet marketplace "Hydra Market" has been shut down.
A message said that the "server infrastructure located in Germany" was secured - and the marketplace was thus closed. In the attack by the Attorney General's Office (Central Office for Combating Internet Crime) and the Federal Criminal Police Office, bitcoins amounting to the equivalent of around 23 million euros were seized.
🤔21
☝️😉 Few systems for studying arrays of textual information in order to identify entities and relationships between them (Doctor Watson, Archivist 3000, Ambar, DocFetcher):

http://ambar.cloud
https://dtsearch.com/
http://www.likasoft.com/ru/
https://dr-watson.wixsite.com/home
http://docfetcher.sourceforge.net/

Archivist 3000 certainly stands out. It can extract entities (phones, email, ip-addresses, etc.) from a large number of documents. Can organize the search for information on a colossal list of different files.
👍4
EagleEye - OSINT module that allows you to find people on social networks by photo and suggested name.

The program works with Instagram, YouTube, Facebook and Twitter
IDENTIFY EMAIL OWNERS BY THEIR PASSWORD AND PGP Article about: how to to identify users by their password and PGP key.
👍1
How to harvest the maximum information from the e-mail? In this article I will tell you how to search by mail address. For example, I will use the mailing address of scammers. https://espysys.com/blog/search-by-mail/
🔥2
During the international operation TOURNIQUET, the well-known hacker resource RaidForums, was closed. https://espysys.com/blog/law-enforcers-seized-the-domains-hosting-raidforums/
🤔1
SEARCH PEOPLE BY TIME AND PLACE… Read full article..
👍2
#OSINT #GOOGLE Today, dear ESPYERS, we will explore the possibility of identifying the owner of Google documents. In the simplest version, you just need to open the file properties and hover over the owner's profile picture.

If your document is presented in edit format, then the work becomes more complicated. Go to your Google Drive, open the "Shared with me" tab. Press F12 to put the browser in code view mode. Select the "Network" tab, below "Fetch/XHR". Now click on the file in question in Google Drive. In the code, open the "v2internal?%24ct=..." item and find an indication of the @gmail.com mail there. I tried to illustrate this on the screen.

You can also use an open source tool to identify Google Docs - Malfrats
👍4
HOW TO CHECK ACCOUNTS IN LEAKED TELEGRAM DATABASES #GitHub | #Python | #Osint
👍2🔥2
HOW TO DEANONYMIZE A USER OF A TELEGRAM ACCOUNT. Telegram is one of the most popular instant messengers in the world. Why? Pavel Durov built the marketing strategy of his project on the idea of "security". Under the slogan "Taking back our right to privacy", users were assured that no special services would be able to read their messages. And it worked!

But the question is: is Telegram really anonymous or is Durov just a good salesman? All you need to know about the “privacy” of this messenger is when registering here you need to specify your cell number. There is simply no better solution! Is it difficult to find out who is the owner of a Telegram account? Not at all. You just need to know where to poke, and then the messenger itself will give out all the necessary information.

OK! What do we have? The account itself, or rather its numerical identifier (ID), username (symbolic alias), nickname (sometimes it is the first and last name, sometimes it is a pseudonym), avatar and, finally, messages that are sent from the account. Thumbs up! Behind all this lies an almost complete package of data about a Telegram user.

Let's start with ID. What can be learned from it? Phone number (@QuickOSINT_bot ), approximate account creation date (@creationdatebot), nickname change history (@SangMataInfo_bot), chats and groups with target account membership (@telesint_bot).

“This is all, of course, wonderful, but how can you find out the ID itself?” - you ask. A very pertinent question! This can be done, firstly, through a third-party Telegram client - for example, Graph Messenger. There you can find out the ID of any profile, you just need to press the button in the form of three dots in the upper right corner of the screen. Conveniently! But there is another way (in case the first one is prohibited by religion or did not fit for another reason) - bots. This is @getmyid_bot (you need to forward the victim's message) or @telesint_bot (you need to send username).

Next - nickname and username. Everything is simple here: users often use the same nickname for all their accounts. If we find the victim's accounts on other services, this may complement the virtual portrait of the target. Let's use the tools to search by nickname! These are, for example, @maigret_osint_bot, Sherlock utility, namechk.com, knowem.com, etc.

It would also be nice to check which aliases the victim used before (@SangMataInfo_bot, @telesint_bot). This will give us even more information! Those. the current nickname may be new, and therefore not "highlighted" anywhere. But here are the old ones... There is a chance here, and not a small one.

The next step is the avatar. Download it, then look for exact copies of the photo (exact (using quotes) search in Yandex and Google). If there is a face in the photo, you can and should use advanced search tools - Eye of God, findclone.ru, primeyes.com, tineye.com, search4faces.com.

Now - messages of the victim in public chats. @telesint_bot is responsible for this. There may be useful clues - audio, photo or video - to which the methods already listed can be applied. In addition, this can be used to determine the linguistic behavior of the victim - writing style, types of emoji used, expressiveness of speech, etc. This can help when we find another account of the target (for example, on a cinephile forum) and want to make sure that the profile really belongs to her.

BONUS! Psst, boy, would you like some social engineering? Let's not forget about the human factor - people will hand themselves over with giblets if a professional is engaged in "processing". Get to know the person, gain confidence, embed a logger (iplogger.ru, grabify.link) into a harmless link and convince the account owner to follow it. Everyone knows what happens next - we will have the IP address of the victim at our disposal.
1👍1
Binance shared users' personal data with the FSB.

The information the FSB wanted included the names and addresses of Binance users. The head of Russian Binance, Gleb Kostarev, agreed to the request of the FSB and shared the database with the security forces. Kostarev also said he "didn't have a choice".

In addition, Rosfinmonitoring demanded from the crypto-exchange data on “millions of dollars” that went to support the opposition leader Alexei Navalny (Opposition of Putin)
👍1