<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>fake Facebook page - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/fake-facebook-page/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Tue, 19 Sep 2023 20:34:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>fake Facebook page - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>Phishing message on Facebook mimicking Meta to target many businesses in Austria</title>
		<link>https://www.osintafrica.net/phishing-message-on-facebook-mimicking-meta-to-target-many-businesses-in-austria/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phishing-message-on-facebook-mimicking-meta-to-target-many-businesses-in-austria</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Thu, 02 Mar 2023 18:11:49 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[fake Facebook page]]></category>
		<category><![CDATA[Socail Network Registry 1011999162]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=609</guid>

					<description><![CDATA[<p>On the 1 March 2023, i connected on my Facebook page and found a strange...</p>
<p>The post <a href="https://www.osintafrica.net/phishing-message-on-facebook-mimicking-meta-to-target-many-businesses-in-austria/">Phishing message on Facebook mimicking Meta to target many businesses in Austria</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;">On the </span><span style="color: #000000;">1 March 2023, i connected on my Facebook page and found a strange notification from the page &#8220;Socail Network Registry 1011999162&#8221; . I clicked on the notification and found out the message below.</span></p>
<p><a href="https://www.facebook.com/Socail-Network-Registry-1011999162-117752521246073/">https://www.facebook.com/Socail-Network-Registry-1011999162-117752521246073/</a></p>
<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="alignnone size-full wp-image-610" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing.png?resize=640%2C312&#038;ssl=1" alt="" width="640" height="312" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing.png?w=658&amp;ssl=1 658w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing.png?resize=300%2C146&amp;ssl=1 300w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">As a Cyber Security and OSINT lover, i was wondering why Meta will publish such message on a third party. </span></p>
<p><span style="color: #000000;">I checked the page creation date and found out that the page is created on the 01.03.2012,the same date that the message was sent, which was alarming for me.</span></p>
<p><span style="color: #000000;">As you read above, the message is tricking users to click on a link to reactivate their account because the page was reported for identify theft.</span></p>
<p><span style="color: #000000;">The message contains an URL on which you should click to reactivate your account.</span></p>
<p><span style="color: #000000;">I took the user and verify from </span><a href="https://www.browserling.com/browse/win/7/chrome/109/https%3A%2F%2Ftinyurl.com%2Fha6tp4fb-infirmscantinuss">Browserling &#8211; Live interactive cross-browser testing</a></p>
<p>&nbsp;</p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone wp-image-611" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-2.png?resize=600%2C444&#038;ssl=1" alt="" width="600" height="444" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-2.png?w=987&amp;ssl=1 987w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-2.png?resize=300%2C222&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-2.png?resize=768%2C568&amp;ssl=1 768w" sizes="(max-width: 600px) 100vw, 600px" /></p>
<p>&nbsp;</p>
<p><span style="color: #000000;">The image above, shows a fake Facebook page logo and registration to trick people to enter their credential. The intention is probably stealing the credential and ask money later to recover the account.</span></p>
<p><span style="color: #000000;">The actor behind the page sends the same notification to many third parties located in Austria including my page as well.</span></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-full wp-image-612" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-3.png?resize=640%2C697&#038;ssl=1" alt="" width="640" height="697" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-3.png?w=661&amp;ssl=1 661w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/phishing-3.png?resize=275%2C300&amp;ssl=1 275w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">I checked the URL on Virus Total and got the following information:</span></p>
<p><a href="https://www.virustotal.com/gui/url/1d43e62c0c1d4ed58919330306f534648b04650adc7f87047d204b55cbf0068e">https://www.virustotal.com/gui/url/1d43e62c0c1d4ed58919330306f534648b04650adc7f87047d204b55cbf0068e</a></p>
<p><span style="color: #000000;">The domain was submitted 2 hours ago. The final URL is available, so I checked the final URL and I got another useful information:</span></p>
<p><a href="https://whois.domaintools.com/infirmscantinus-458691.space">Whois Lookup Captcha (domaintools.com)</a></p>
<p><span style="color: #000000;">The domain was created on the 2023-03-01.</span></p>
<p><span style="color: #000000;">At this point, we can be pretty sure that the domain is a phishing domain to trick people to click on the link to enter their credential.</span></p>
<p><span style="color: #000000;">Be always careful before entering your credential and do not forget to use 2FA to secure your account</span></p>
<p>&nbsp;</p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img loading="lazy" decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/phishing-message-on-facebook-mimicking-meta-to-target-many-businesses-in-austria/">Phishing message on Facebook mimicking Meta to target many businesses in Austria</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">609</post-id>	</item>
	</channel>
</rss>
