<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DNS OSA RECORD - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/dns-osa-record/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Thu, 31 Aug 2023 15:14:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>DNS OSA RECORD - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>Scammers are targeting the French fines authorities website</title>
		<link>https://www.osintafrica.net/scammers-are-targeting-the-french-fines-authorities-website/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=scammers-are-targeting-the-french-fines-authorities-website</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Thu, 31 Aug 2023 15:12:12 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[DNS OSA RECORD]]></category>
		<category><![CDATA[IOCs]]></category>
		<category><![CDATA[Iranian Locker Group]]></category>
		<category><![CDATA[online payment of fines issued by the French authorities]]></category>
		<category><![CDATA[SCAMMERS]]></category>
		<category><![CDATA[yakuzahn2.gmail.com]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=767</guid>

					<description><![CDATA[<p>The website https://www.amendes.gouv.fr is the only governmental website for online payment of fines issued by...</p>
<p>The post <a href="https://www.osintafrica.net/scammers-are-targeting-the-french-fines-authorities-website/">Scammers are targeting the French fines authorities website</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;">The</span> <span style="color: #000000;">website https://www.amendes.gouv.fr is the only governmental website for online payment of fines issued by the French authorities.</span></p>
<p><span style="color: #000000;">The website contains confidential, PII, financial information and others. In case of any data stolen or breached; it could cause several damages.</span></p>
<p><span style="color: #000000;">I found out many suspicious domains mimicking the website. The suspicious domains are located in different location through the world.</span></p>
<p><span style="color: #000000;">Let’s share with you the investigation.</span></p>
<p><span style="color: #000000;">Some suspicious domains:</span></p>
<p><strong><span style="color: #000000;">amende-gouv-login[.]fr</span></strong></p>
<p><span style="color: #000000;"><strong>amende-pv-service[.]com</strong></span></p>
<p><strong><span style="color: #000000;">antai-gouv-amendes[.]net</span></strong></p>
<p><strong><span style="color: #000000;">antais-gouv[.]com</span></strong></p>
<p><strong><span style="color: #000000;">xn--rglementamendes-bnb[.]fr Puny   réglementamendes[.]fr</span></strong></p>
<p><strong><span style="color: #000000;">servicesamendes[.]info</span></strong></p>
<p><strong><span style="color: #000000;">ksocampaign[.]com</span></strong></p>
<p><span style="color: #000000;">the domains mentioned above are some of the domains mimicking the online fines payment.</span></p>
<p><span style="color: #000000;">Among those domains, the domain <strong>ksocampaign[.]com</strong> paid my attention.</span></p>
<p><span style="color: #000000;">While investigating, I found the following email address “<strong>yakuzahn2.gmail.com</strong>” in the DNS OSA records which could be the administrator email address.</span></p>
<p><a href="https://securitytrails.com/domain/ksocampaign.com/dns">ksocampaign.com &#8211; Current DNS records and Full DNS Report (securitytrails.com)</a></p>
<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="alignnone size-full wp-image-768" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/security-trails.png?resize=640%2C263&#038;ssl=1" alt="" width="640" height="263" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/security-trails.png?w=1155&amp;ssl=1 1155w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/security-trails.png?resize=300%2C123&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/security-trails.png?resize=1024%2C421&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/security-trails.png?resize=768%2C316&amp;ssl=1 768w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p>&nbsp;</p>
<p><span style="color: #000000;">I took the email address and checked through Google search and the information below was found.</span></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-full wp-image-769" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/google-seach-IOC.png?resize=640%2C446&#038;ssl=1" alt="" width="640" height="446" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/google-seach-IOC.png?w=753&amp;ssl=1 753w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/google-seach-IOC.png?resize=300%2C209&amp;ssl=1 300w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">Like you see, the email address is associated to a website used to unlock the websites that were hacked by the Iranian Locker group.</span></p>
<p><a href="https://urlscan.io/result/f92f18f8-fdb9-4611-b250-c4ee24d42ed6/#summary">dhs.edu.bt &#8211; urlscan.io </a></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-full wp-image-770" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/Iranian-Locker-group.png?resize=640%2C331&#038;ssl=1" alt="" width="640" height="331" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/Iranian-Locker-group.png?w=875&amp;ssl=1 875w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/Iranian-Locker-group.png?resize=300%2C155&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/08/Iranian-Locker-group.png?resize=768%2C398&amp;ssl=1 768w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">At this point, we came to the following conclusion:</span></p>
<p><span style="color: #000000;">The domain <strong>ksocampaign[.]com</strong> might belong to the Iranian threat actor or the person behind the email address “yakuzahn2.gmail.com”.</span></p>
<p><span style="color: #000000;">The intention of the threat actor behind the phishing campaign or the threat actor mimicking the online payment website is to get the users credentials and credit cards information from the users.</span></p>
<p>&nbsp;</p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img loading="lazy" decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/scammers-are-targeting-the-french-fines-authorities-website/">Scammers are targeting the French fines authorities website</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">767</post-id>	</item>
	</channel>
</rss>
