Intelligence X
Open in Telegram
intelx.io - search engine & data archive
Show moreThe country is not specifiedTechnologies & Applications15 181
7 004
Subscribers
No data24 hours
+57 days
+8830 days
Posts Archive
7 004
Profile of one of the individuals who launched DDoS attacks against us:
Dovid Friedman. Nickname "Mailgator".
Can be contacted via dovidgfriedman@gmail.com (the email is public, from his project). Claims to be ethical, but starts DDoS attacks.
Twitter handle @DovidFriedman
7 004
Looking up a 🇷🇺 phone number and need details? ☎️ Despair no more!
We've forked a free #OSINT site that finds a lot of information:
👉🏻 https://data.intelx.io/saverudata/
Credit goes to its anonymous authors @RuDataLeaks. Their tool deserves much more attention. 👊🏻
7 004
Twitter user "vxzeroknowledge" (Touhami Kasbaoui from Morocco) joins our Wall of Shame. 🐑
He attempted to use 7 stolen credit cards this night. 💳🚫
He used these email addresses:
* youssef.achanane@uit.ac.ma
* areversermalw@gmail.com
* malwareanalyst@0btemoslab.com
* kasbaui.touhami.2013@gmail.com
7 004
The actor behind these attempts is likely user 'Valkiryie' from the hacking forum Cracked. He is also known by the name 'Cepheus12'. 👀
7 004
3️⃣ A tweet from that account links to a username with the same real name and postal code "Matheo59680".
And that account is actually following us on Twitter. After tweeting about it, Matheo blocked us.
7 004
2️⃣ Of course his Computer was also infected in the past, and we have an actual screenshot.
He is also known by the username "slaide7". It so happens there is a French speaking Twitter account "slaide7".
Our lawyers will take over from here, and make sure those credit card fraud victims are enabled to have recourse. ⚖️👨🏻⚖️
7 004
In related news to the thread from last week about 2 🇫🇷 actors:
Another 🇫🇷 individual, Matheo Maufroy, thought it is a good idea to commit (attempted) credit card fraud using 20 (!) stolen credit cards on our site.
Another quick 🧵⤵️
1️⃣
He thought by using the temporary email provider 10minutemail[.]net (generated "fgr96384@zcrcd.com") he would get away using stolen credit cards (poor grandmas!).
His real email is "matheo-59680@hotmail.fr" and he is born 1996, living in Ferrière-la-Grande/France.
Note how his ZIP code 59680 is in his email address (it is also in his passwords).
7 004
We are literally watching in real time some actors trying to exploit our API. Latest attempt from IP 66.222.178.77.
We save all those logs and share with law enforcement as appropriate.
7 004
Update: The operator apologized via the cloned site.
We accept the apology and refrain from further actions.
7 004
4️⃣ Evidence suggests that outside of violating our Terms of Service, our Copyright, our Trademark, both Amqterasu and ChaKkaL also engaged in criminal activity including identity theft, fraud, unlawful access to a computer system, among others.
Conclusion / (we keep repeating ourselves in such investigations):
👆🏻 Maybe attempting to hack a security company isn't the best idea.
Our lawyers will take it from here.
7 004
3️⃣ Who is the second individual 'ChaKkaL'?
Genius was also infected, and was found via IX.
His email is chakkal.yo@gmail.com. He has a PayPal account with it.
His Twitter handle is "thechakkal".
All these details are being shared with French law enforcement.
Real name of ChaKkaL is Julien Kempf.
He is a student of monbureaunumerique[.]fr.
7 004
2️⃣ The first actor 'Amqterasu' registered an account with the email mostwantedfor1@gmail.com and French IP 77.205.47.20 (very close to the other one). Also associated accounts jqnviersquad2@gmail.com and canuanthony12.03@gmail.com.
This reveals an actual screenshot of this actors Computer. The IP address there matches the provider (SFR).
The result in IX reveals his user names "Jqnvier" and "Anthony" as well as yet another email, MostWantedFor2@gmail.com.
Jqnvier matches with the email "jqnviersquad2@gmail.com" he used for his other IX account. It all matches this individual.
And we got a person name "Anthony Canu" (who knows if that's an alias or not) with a French address and yet another email address monique.canu@gmail.com.
7 004
1️⃣ This unauthorized pseudo clone says "By Amqterasu and ChaKkaL" in the description. They added some cheap JS code.
The embedded API key registered via French IP 77.205.47.50 on 2022-04-12 via the spam email dadsunjqnvier22@unip.edu.pl.
xintel[.]fr was registered ... yesterday!
It uses privacy whois (a legal letter is being sent to the hoster).
7 004
Violating our trademark, copyright, and Terms of Service, someone created a cloned UI xintel[.]fr and embeds an API key. Note the color change, and reverse logo, but removal of our Copyright notice.
Let's uncover who is behind it.
An uncovering 🧵⬇️
7 004
Update to the #Ethereum address indexing:
Reindexing revealed there are only 1.525 Ethereum addresses in our 'Darknet #Tor' bucket.
Compared to 1.991.778 #Bitcoin addresses in the same bucket.
We are now applying our Ethereum address indexing algorithm across all of our data sources.
7 004
Our search results and data sources are categorized into bucket. Here is the list which may be useful when using our API for filtering:
https://blog.intelx.io/2022/05/05/list-of-buckets/
