Historical OSINT - Profiling a Portfolio of Fake Visa Application Scam Domains

February 07, 2019
It's been a while since I last posted a quality update profiling a versatile currently circulating malicious and fraudulent spam campaign profiling and highlighting the fraudulent and malicious activities of the cybercriminals behind the campaign.

In this post I'll profile a currently circulating Fake Visa Application fraudulent campaign enticing users into submitting their personal details for the purpose of obtaining a fake and rogue visa.

Related emails known to have participated in the campaign:
vizagold2010@mail.ru
qwerty_ok@bigmir.net
vizacom10@bigmir.net
Abrakadabra011@yandex.ua
alexboy40@meta.ua
vizacom09@bigmir.net
bestagancy@rambler.ru
vizagold2010@mail.ru
vizagold2010@gmail.com
vizacom01@ua.fm
Vizacom01@gmail.com
Vizacom01@ukr.net
Vizacom01@qip.ru
visas_com@ukr.net
Visas.com2010@gmail.com
infinite-visas@rambler.ru
unforeseen2010@hotmail.com
shengen_visas@ukr.net
shengenvisas@gmail.com
shengenvisas@rambler.ru
shengenvisas@bigmir.net

Stay tuned for an updated set of malicious and fraudulent Fake Visa Application domain portfolio to be published anytime soon.

About Dancho Danchev

Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com