{"id":809,"date":"2020-05-10T19:30:53","date_gmt":"2020-05-10T19:30:53","guid":{"rendered":"https:\/\/osintme.com\/?p=809"},"modified":"2020-05-11T15:47:52","modified_gmt":"2020-05-11T15:47:52","slug":"a-guide-to-investigating-scam-text-messages-and-websites-fake-revenue-online-page","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2020\/05\/10\/a-guide-to-investigating-scam-text-messages-and-websites-fake-revenue-online-page\/","title":{"rendered":"A guide to investigating scam text messages and websites &#8211; fake Revenue Online page"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"809\" class=\"elementor elementor-809\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-04f73d3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"04f73d3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2dfc2e7\" data-id=\"2dfc2e7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-95bb2d7 elementor-widget elementor-widget-text-editor\" data-id=\"95bb2d7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Today a reader contacted me with a suspicious text message they received from a purported Irish Revenue Online Service (ROS) number.<\/p><p>Sometimes even a cursory examination can reveal the true nature of these scams and no technical skills at all are required to determine that a text message containing a URL can be dangerous.<\/p><p>Let&#8217;s have a look.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fbce336 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fbce336\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fecd348\" data-id=\"fecd348\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-93cce52 elementor-widget elementor-widget-image\" data-id=\"93cce52\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"572\" height=\"727\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/phishing-link-text-message.jpg?fit=572%2C727&amp;ssl=1\" class=\"attachment-medium_large size-medium_large wp-image-811\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/phishing-link-text-message.jpg?w=572&amp;ssl=1 572w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/phishing-link-text-message.jpg?resize=236%2C300&amp;ssl=1 236w\" sizes=\"(max-width: 572px) 100vw, 572px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-07c429a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"07c429a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8746edd\" data-id=\"8746edd\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-30d0436 elementor-widget elementor-widget-text-editor\" data-id=\"30d0436\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Straight away, there are a number of giveaways here:<\/p><ol><li><strong>The phone number<\/strong> &#8211; this is a US phone number, as indicated by the +1 country code.<\/li><li><strong>The URL link<\/strong> &#8211; here we have a URL shortened using <a href=\"https:\/\/free-url-shortener.rb.gy\/\">this free service<\/a>. The legitimate reason for shortening URLs is to make really long links appear neater. It is very unlikely that ROS would use a URL shortener. In this case, the intention of the scammer was to hide the true URL of his website&#8230;<\/li><li>&#8230;which in this case has been <strong>partially revealed<\/strong> by the phone&#8217;s text messaging software.<\/li><\/ol><p>\u00a0<\/p><p>If you are using the Revenue Online Service, you will know that the real ROS login link is:<\/p><p><a href=\"https:\/\/www.ros.ie\/myaccount-web\">https:\/\/www.ros.ie\/myaccount-web<\/a><\/p><p>So this is clearly a scam.<\/p><p>But let us dig deeper.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b295ae3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b295ae3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4be6885\" data-id=\"4be6885\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9d338cc elementor-widget elementor-widget-heading\" data-id=\"9d338cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">1. Prepare your virtual environment<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0fc5edb elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0fc5edb\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-32fe014\" data-id=\"32fe014\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e1aa01b elementor-widget elementor-widget-text-editor\" data-id=\"e1aa01b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Before conducting any field research on malicious URLs, which at some point will inevitably require you to visit the rogue website, you must ensure that you protect your own system from potential compromise.<\/p><p>Even when investigating potential phishing links you cannot be sure that this is the only threat vector.<\/p><p>You don&#8217;t know if the website is free from malware that you might inadvertently install on your machine via a drive-by download.<\/p><p>Any standard virtual machine will do for this purpose. More information on what steps to take when preparing your virtual environment can be found <a href=\"https:\/\/osintme.com\/index.php\/2019\/10\/12\/osint-me-setup-part-2-software\/\">here<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9339400 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9339400\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d4607aa\" data-id=\"d4607aa\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-386892f elementor-widget elementor-widget-image\" data-id=\"386892f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"957\" height=\"552\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2019\/10\/VM.jpg?fit=957%2C552&amp;ssl=1\" class=\"attachment-large size-large wp-image-150\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2019\/10\/VM.jpg?w=957&amp;ssl=1 957w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2019\/10\/VM.jpg?resize=300%2C173&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2019\/10\/VM.jpg?resize=768%2C443&amp;ssl=1 768w\" sizes=\"(max-width: 957px) 100vw, 957px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Virtual environment from Virtual Box<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4c5f263 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4c5f263\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-802dfbd\" data-id=\"802dfbd\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1629dfb elementor-widget elementor-widget-heading\" data-id=\"1629dfb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">2. Phone number OSINT<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-debb239 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"debb239\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b6e952d\" data-id=\"b6e952d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e84bf90 elementor-widget elementor-widget-text-editor\" data-id=\"e84bf90\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The first point of focus should be the phone number &#8211; after all, this was the delivery method of the malicious link to the user.<\/p><p>Good place to start is Google, plain search first, then including search operators:<\/p><p><strong>&#8220;+12568417086&#8221; OR &#8220;256-8417086&#8243; OR &#8221; 1 2568417086&#8243;<\/strong><\/p><p><strong>intext:&#8221;+12568417086&#8243;<\/strong><\/p><p><strong>allintext:&#8221;+12568417086&#8243;<\/strong><\/p><p><strong>site:&#8221;&lt;<em>whatever site you search<\/em>&gt;&#8221; intext:&#8221;+12568417086&#8243;<\/strong><\/p><p>These methods might or might not yield the desired results, which will also vary in accuracy and details.<\/p><p>Phone lookup websites come and go. Searching for EU-based phone numbers has been hampered since the introduction of the GDPR. However, searching for non-EU numbers on specific websites might still be effective.<\/p><p>I searched for the phone number on the following sites (with no results, sadly):<\/p><p><a href=\"https:\/\/sync.me\/\">https:\/\/sync.me\/<\/a><\/p><p><a href=\"https:\/\/www.truecaller.com\/search\">https:\/\/www.truecaller.com\/search<\/a><\/p><p><a href=\"https:\/\/spamcalls.net\/en\/\">https:\/\/spamcalls.net\/en\/<\/a><\/p><p><a href=\"https:\/\/800notes.com\/\">https:\/\/800notes.com\/<\/a><\/p><p><a href=\"https:\/\/www.unknownphone.com\/\">https:\/\/www.unknownphone.com\/<\/a><\/p><p><a href=\"https:\/\/whocallsme.com\/\">https:\/\/whocallsme.com\/<\/a><\/p><p><a href=\"https:\/\/www.anywho.com\/reverse-phone-lookup\">https:\/\/www.anywho.com\/reverse-phone-lookup<\/a><\/p><p><a href=\"https:\/\/www.zabasearch.com\/\">https:\/\/www.zabasearch.com\/<\/a><\/p><p><a href=\"https:\/\/www.spydialer.com\/\">https:\/\/www.spydialer.com\/<\/a><\/p><p><a href=\"http:\/\/www.phonelookuper.com\">http:\/\/www.phonelookuper.com<\/a><\/p><p>This list is by no means exhaustive, there are dozens more reverse phone lookup sites.<\/p><p>The ones that did yield some results included:<\/p><p><a href=\"https:\/\/www.whitepages.com\/phone\/1-256-841-7086\">https:\/\/www.whitepages.com\/phone\/1-256-841-7086<\/a><\/p><p><a href=\"https:\/\/www.411.com\/phone\/1-256-841-7086\">https:\/\/www.411.com\/phone\/1-256-841-7086<\/a><\/p><p><a href=\"https:\/\/www.revealname.com\/256-841-7086\">https:\/\/www.revealname.com\/256-841-7086<\/a><\/p><p><a href=\"https:\/\/www.numlookup.com\/\">https:\/\/www.numlookup.com\/<\/a><\/p><p>The revealname and numlookup websites both offered an additional snippet of information that allowed me to pivot into a more specific direction.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-11e6152 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"11e6152\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-67457a3\" data-id=\"67457a3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-dbbc7b5 elementor-widget elementor-widget-image\" data-id=\"dbbc7b5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"322\" height=\"209\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/twilio-number-US.png?fit=322%2C209&amp;ssl=1\" class=\"attachment-large size-large wp-image-820\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/twilio-number-US.png?w=322&amp;ssl=1 322w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/twilio-number-US.png?resize=300%2C195&amp;ssl=1 300w\" sizes=\"(max-width: 322px) 100vw, 322px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c392430 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c392430\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-dec5d22\" data-id=\"dec5d22\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f28929d elementor-widget elementor-widget-text-editor\" data-id=\"f28929d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Twilio is a Voice over IP (VoIP) provider and its business model is to create a bridge between the traditional and cellular telephony and the Internet.<\/p><p>More details on how it works <a href=\"https:\/\/www.twilio.com\/blog\/what-does-twilio-do#it-all-starts-with-the-phone-number\">here<\/a>.<\/p><p>As a Twilio customer you can buy a virtual phone number and use it as if you&#8217;re using your own real mobile, with the exception that Twilio provides a degree of separation and an extra layer of privacy.<\/p><p>This is what the scammer availed of in this case.<\/p><p>To conduct look-ups with Twilio, you need to have an account with them. You can avail of a free trial, which will also give you some free credits towards look-ups.<\/p><p>Twilio look-ups cost:<\/p><ul><li><span class=\"td table-data text-align-right col-sm-4 \">$0.01 per Caller Name you look up<\/span><\/li><li><span class=\"td table-data text-align-right col-sm-4 \">$0.005 per Carrier details you look up<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-999bf38 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"999bf38\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-84872dc\" data-id=\"84872dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5e93d88 elementor-widget elementor-widget-image\" data-id=\"5e93d88\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"680\" height=\"376\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/twilio-lookup.png?fit=680%2C376&amp;ssl=1\" class=\"attachment-large size-large wp-image-821\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/twilio-lookup.png?w=680&amp;ssl=1 680w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/twilio-lookup.png?resize=300%2C166&amp;ssl=1 300w\" sizes=\"(max-width: 680px) 100vw, 680px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">.<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-494ea77 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"494ea77\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-121cb48\" data-id=\"121cb48\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a8a0bde elementor-widget elementor-widget-text-editor\" data-id=\"a8a0bde\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In this case we have hit a dead end. No further information is available on Twilio.<\/p><p>Law enforcement officers investigating a scam like this could explore this further and request additional subscriber information from Twilio under a court warrant \/ subpoena, such as the IP address used to create this account, email address, personal information (if any), payment details on record, and so on.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-74a1179 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"74a1179\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1186edb\" data-id=\"1186edb\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cc107b5 elementor-widget elementor-widget-heading\" data-id=\"cc107b5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">3. Dealing with the shortened URLs<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6724db7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6724db7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1c73576\" data-id=\"1c73576\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e1daf73 elementor-widget elementor-widget-text-editor\" data-id=\"e1daf73\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>I would always advise extreme caution before clicking on any shortened URL &#8211; the link can lead absolutely anywhere and it&#8217;s not immediately clear what the destination might be.<\/p><p>Luckily there are several methods for unshortening these URLs.<\/p><p>Many shortened links can be explored by simply adding a <strong>&#8216;+&#8217;<\/strong> symbol at the end of the shortened URL in the your browser&#8217;s URL tab. This will work majority of the time, but it depends on the compatibility of the URL shortening service.<\/p><p>Note that instead of the &#8216;+&#8217; symbol, in order to unshorten your link some of these services require different symbols, like:<\/p><ul><li>a hyphen &#8216;-&#8216;;<\/li><li>a question mark &#8216;?&#8217;<\/li><li>a tilde &#8216;~&#8217;<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1358428 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1358428\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c8910f6\" data-id=\"c8910f6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3dbd97c elementor-widget elementor-widget-text-editor\" data-id=\"3dbd97c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>So in the case of our shortened malicious URL the unshortened result is:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1c430b8 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1c430b8\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7ba5afb\" data-id=\"7ba5afb\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-dd904f7 elementor-widget elementor-widget-image\" data-id=\"dd904f7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"764\" height=\"484\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/unshortened-URL.jpg?fit=764%2C484&amp;ssl=1\" class=\"attachment-large size-large wp-image-837\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/unshortened-URL.jpg?w=764&amp;ssl=1 764w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/unshortened-URL.jpg?resize=300%2C190&amp;ssl=1 300w\" sizes=\"(max-width: 764px) 100vw, 764px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f26c521 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f26c521\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6216eac\" data-id=\"6216eac\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-19b0251 elementor-widget elementor-widget-text-editor\" data-id=\"19b0251\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In this case the service used to shorten our link was Rebrandly &#8211; the URL shortening platform that offers plenty of additional statistics pertinent to that link, such as the number of total clicks, browsers, devices, social media referrals and more.<\/p><p>You can browse the detailed stats on user interactions with this particular link <a href=\"https:\/\/app.rebrandly.com\/public\/links\/share?href=rb.gy\/aatdqg\">here<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b28ffe6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b28ffe6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a19fba6\" data-id=\"a19fba6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b5705b4 elementor-widget elementor-widget-text-editor\" data-id=\"b5705b4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Other ways to investigate shortened URLs include installing a dedicated browser extension or going directly to online resources that will do the job for you, with varying degrees of details.<\/p><p>Examples of these include:<\/p><p><a href=\"http:\/\/wheredoesthislinkgo.com\/\">http:\/\/wheredoesthislinkgo.com\/<\/a><\/p><p><a href=\"http:\/\/www.getlinkinfo.com\/\">http:\/\/www.getlinkinfo.com\/<\/a><\/p><p><a href=\"http:\/\/www.checkshorturl.com\/\">http:\/\/www.checkshorturl.com\/<\/a><\/p><p><a href=\"https:\/\/unshorten.it\/\">https:\/\/unshorten.it\/<\/a><\/p><p><a href=\"https:\/\/wheregoes.com\/\">https:\/\/wheregoes.com\/<\/a><\/p><p><a href=\"https:\/\/urlex.org\/\">https:\/\/urlex.org\/<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-36919a6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"36919a6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4a7a9a6\" data-id=\"4a7a9a6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2b5100a elementor-widget elementor-widget-image\" data-id=\"2b5100a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"763\" height=\"375\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/shortened-URL-expanded-with-Wheregoes.jpg?fit=763%2C375&amp;ssl=1\" class=\"attachment-large size-large wp-image-838\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/shortened-URL-expanded-with-Wheregoes.jpg?w=763&amp;ssl=1 763w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/shortened-URL-expanded-with-Wheregoes.jpg?resize=300%2C147&amp;ssl=1 300w\" sizes=\"(max-width: 763px) 100vw, 763px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">wheregoes.com<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9ccbb2a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9ccbb2a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6958b9b\" data-id=\"6958b9b\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0a6b8ff elementor-widget elementor-widget-heading\" data-id=\"0a6b8ff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">4. The malicious website<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5545c86 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5545c86\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3a22e4c\" data-id=\"3a22e4c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-600a021 elementor-widget elementor-widget-text-editor\" data-id=\"600a021\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Time to visit the malicious site itself &#8211; using the safe virtual machine.<\/p><p>The cursory look at the true URL tells us that this website is hosted on the Azure East US 2 server &#8211; a Microsoft cloud computing platform.<\/p><p>The whole website is just one single fake login page, designed to impersonate the real Revenue Online Services website.<\/p><p>This is what the fake page looks like and there we have both login pages compared side by side:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2efba74 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2efba74\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8475048\" data-id=\"8475048\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2ee64f0 elementor-widget elementor-widget-image\" data-id=\"2ee64f0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"604\" height=\"891\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-login-page.jpg?fit=604%2C891&amp;ssl=1\" class=\"attachment-large size-large wp-image-842\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-login-page.jpg?w=604&amp;ssl=1 604w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/fake-login-page.jpg?resize=203%2C300&amp;ssl=1 203w\" sizes=\"(max-width: 604px) 100vw, 604px\" \/>\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Fake login page for Revenue Online<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-34c3e84 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"34c3e84\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-cc86f7d\" data-id=\"cc86f7d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-158387d elementor-widget elementor-widget-image\" data-id=\"158387d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"770\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/real-vs-fake-ROS-login-page.jpg?fit=1024%2C770&amp;ssl=1\" class=\"attachment-large size-large wp-image-841\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/real-vs-fake-ROS-login-page.jpg?w=1222&amp;ssl=1 1222w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/real-vs-fake-ROS-login-page.jpg?resize=300%2C226&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/real-vs-fake-ROS-login-page.jpg?resize=1024%2C770&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/real-vs-fake-ROS-login-page.jpg?resize=768%2C578&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7a0b524 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7a0b524\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-61b7299\" data-id=\"61b7299\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-05f0483 elementor-widget elementor-widget-text-editor\" data-id=\"05f0483\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The only functionality the fake web page has is to harvest and store any login credentials a victim would populate into the text fields.<\/p><p>The stolen credentials could then be used to log in to the legitimate web page and steal any information within, leading to potential identity theft and almost certainly a wave of cyber attacks against the victim.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-817b81c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"817b81c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5f74d78\" data-id=\"5f74d78\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7054fa5 elementor-widget elementor-widget-text-editor\" data-id=\"7054fa5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Additional information can be obtained by conducting website OSINT.<\/p><p>One of my favourite tools for this is <a href=\"https:\/\/urlscan.io\/\">urlscan.io<\/a>, which I mentioned many times previously.<\/p><p>It revealed the website&#8217;s IP address as well as some further information which I highlighted below:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-18e7a5f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"18e7a5f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1e88ea4\" data-id=\"1e88ea4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bbe8717 elementor-widget elementor-widget-image\" data-id=\"bbe8717\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"922\" height=\"499\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/URL-scan-malicious-website.jpg?fit=922%2C499&amp;ssl=1\" class=\"attachment-large size-large wp-image-843\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/URL-scan-malicious-website.jpg?w=922&amp;ssl=1 922w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/URL-scan-malicious-website.jpg?resize=300%2C162&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/URL-scan-malicious-website.jpg?resize=768%2C416&amp;ssl=1 768w\" sizes=\"(max-width: 922px) 100vw, 922px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-83408df elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"83408df\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-98c7d12\" data-id=\"98c7d12\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-14539a1 elementor-widget elementor-widget-text-editor\" data-id=\"14539a1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Urlscan.io detected 5 structurally similar pages hosted on different IP addresses &#8211; something that was not obvious to us initially.<\/p><p>It seems that the scammers cloned the malicious website at least 4 more times and loaded it up using separate Microsoft Azure instances, while maintaining the same mode of operation.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3275e16 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3275e16\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7c1a269\" data-id=\"7c1a269\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d691a33 elementor-widget elementor-widget-image\" data-id=\"d691a33\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"297\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/more-scam-websites.jpg?fit=1024%2C297&amp;ssl=1\" class=\"attachment-large size-large wp-image-844\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/more-scam-websites.jpg?w=1168&amp;ssl=1 1168w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/more-scam-websites.jpg?resize=300%2C87&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/more-scam-websites.jpg?resize=1024%2C297&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/more-scam-websites.jpg?resize=768%2C223&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0724336 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0724336\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1e56bad\" data-id=\"1e56bad\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ea034be elementor-widget elementor-widget-text-editor\" data-id=\"ea034be\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Searching for the IP address with <a href=\"https:\/\/centralops.net\/co\/\">Central Ops<\/a> confirms that it indeed belongs to Microsoft.<\/p><p>More importantly, it gives us an avenue to take action against the scammer &#8211; by reporting all the sites to Microsoft and asking for their removal.<\/p><pre>To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to:\n<br \/>* https:\/\/cert.microsoft.com.  \n       \nFor SPAM and other abuse issues, such as Microsoft Accounts, please contact:\n<br \/>* abuse@microsoft.com.  <\/pre>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4815068 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4815068\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0a0c935\" data-id=\"0a0c935\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-67682a4 elementor-widget elementor-widget-text-editor\" data-id=\"67682a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This is exactly what I did in this case.\u00a0<\/p><p>All these websites have been taken down since I reported them, and more so, Google Safe Browsing has also classified both the shortened links and the true URLs as malicious.<\/p><p>So right now all the links have a very obvious safety warning displaying before one can continue on to the website &#8211; meaning that a Google Chrome user will receive ample warnings before they even have a chance of inadvertently handing over their credentials to the scammer.<\/p><p><strong>So, a small victory in a whack-a-mole never-ending war against online scams!<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f0f1b5b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f0f1b5b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0da998d\" data-id=\"0da998d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-229a6fb elementor-widget elementor-widget-image\" data-id=\"229a6fb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"651\" height=\"563\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/Google-chrome-malicious-warning.jpg?fit=651%2C563&amp;ssl=1\" class=\"attachment-large size-large wp-image-845\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/Google-chrome-malicious-warning.jpg?w=651&amp;ssl=1 651w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/05\/Google-chrome-malicious-warning.jpg?resize=300%2C259&amp;ssl=1 300w\" sizes=\"(max-width: 651px) 100vw, 651px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>A step by step guide to investigating scam text messages, phishing URL links and dodgy websites. I investigate a real Revenue Online Services scam that hit users in Ireland several days ago.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"off","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[93],"tags":[76,34,92,82,81,79],"class_list":["post-809","post","type-post","status-publish","format-standard","hentry","category-my-investigations","tag-cybercrime","tag-investigation","tag-microsoft","tag-phishing","tag-scam","tag-website"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=809"}],"version-history":[{"count":22,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/809\/revisions"}],"predecessor-version":[{"id":849,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/809\/revisions\/849"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}