OSINT Round-Up of Russia-Based High-Profile Cybercriminals

0
September 18, 2023


In my line of work in specific when doing research and analysis I always stick to a common concept which has to do with the fact that “everything that can be found has already been found somewhere online”. Sticking to this basic methodology the only thing an individual or a researcher has to do is to look up the facts including all the relevant and necessary technical information on the individual or case they’re working on and basically come up with a proper analysis relying on publicly obtainable and publicly accessible information on their topic of interest.

In this rather long OSINT analysis article I’ll do a OSINT roundup of Russia-based high-profile ransomware cybercriminals with the idea to share my research and analysis on the topic and potentially assist other researchers and vendors including U.S Law Enforcement on its way to properly track down and monitor and prosecute these cybercriminals.

\I’ll begin this analysis with an emphasis and actual OSINT research and analysis on the Conti Ransomware Group in the context of demonstrating what real-time OSINT is which a pretty good and decent methodology that I’ve been relying and using over the years which works.

It all began with an internally leaked and made publicly accessible Conti Ransomware Gang’s internal communication where a security researcher or a set of security researchers appear to have compromised their internal server and have been collecting conversation logs between the cybercriminals which they later on made publicly accessible on Twitter in a specific for the purpose account that basically included direct download links to their internal communication.

From an OSINT perspective the first thing a researcher should do is to do their best to obtain access to these conversation logs and attempt to preserve them for current and future use which is something that I did almost immediately considering the possibility to monitor and track down who the actual individuals behind this massive ransomware campaign are.

The results? I’ve managed to successfully identify some of key individuals behind the Conti Ransomware Gang in terms of top management where my believe is that although it was a hired or outsourced “know-how” in the beginning quickly matured into a cybercrime enterprise where everyone who wanted to could join on a “franchise” based model and just do their work and earn fraudulently and maliciously obtained revenue from legitimate companies who are having their networks compromised and sensitive data and information made publicly accessible or basically encrypted in a way making it impossible for the actual organization and company to use.

What is the Conti ransomware gang up to in terms of top management? It appears that the gang’s top management in a way is involved in the fashion industry with the idea that some of the screenshots that I obtained and processed and analyzed which were leaked internally in the form of exchange of URLs between the gang’s members lead me to believe that the gang is involved in either investing in fashion brands or actually working on such with several successful public OSINT analyses on the topic where I’ve managed to identify some of the fashion brands behind the Conti Ransomware Gang’s top management and my goal here is to present the actual findings with the idea to bring this fact to more light in the context of providing information on the activity of the Conti Ransomware Gang’s top management members.



So basically once I came across their internal leaked communication made publicly accessible on Twitter I immediately aimed to obtain access to the leaked internal information of the Conti ransomware gang and preserve it before it goes online so that I can later on work with it and successfully produce the analysis including all the screenshots managed and operated by the Conti ransomware gang and here’s how I did it.

Basically once I obtained access to their internal leaked communication which was made publicly accessible I data mined the internal leaked communication looking for personally identifiable email address accounts and related URLs with success which is where I automatically visited these URLs which I data mined in the Conti ransomware gang’s internal leaked communication and basically grabbed all the live URLs information which is where the analysis and the screenshots including the actual report come from which I produced and have been working on to produce exclusively for fellow researchers and vendors including U.S Law Enforcement in order to assist everyone on their way to properly track down monitor and prosecute.

Sample Internally Leaked URLs Courtesy of the Conti Ransomware Gang Obtained Using Public Sources

There are several other fashion brand themed screenshots which I also managed to obtain which appear to be directly related to the Conti ransomware gang.

Here are some of the “upcoming brands” courtesy of the Conti Ransomware Gang obtained using real-time OSINT and relying on their internally leaked communications proving the gang including its top management is into fashion brands and the industry:

Here’s some personally identifiable information on some of the brands using OSINT and public sources of information:

Leylo

Top Management Includes:

tel:+79126331303

Мария Сергеевна Ермолаева/Maria Ermolaeva (Chudnova)

Birthday: 5 July

hxxp://vk.com/id7326657

Maria Ermolaeva

Birthday: 5 July

г. Екатеринбург, ул. Репина, 95, офис 116

Телефон: +7 (912) 633–13–03

Е-mail: info@leylo.ru

leyloekb@gmail.com

hxxp://leylo.ru/

Danil Ermolaev

hxxp://vk.com/id4874860

Birthday: 7 August 1989

Sample Top Management Photos and Personally Identifiable Information of the Conti Ransomware Gang’s charity fund:

Tamila Kerimova

Conti Ransomware Gang’s Top Management Team

hxxp://impulse-life.ru

Tamila Kerimova

— Birthday: 4 April 1986

— hxxp://vk.com/id6515862

— Planet for beauty and development

— hxxp://irinaverhusha.com

Тел: +7 926 536–63–68

Email: impulse.life2020@gmail.com

Sample Internally Leaked Screenshots Courtesy of the Conti Ransomware Gang:

Sample Conti Ransomware Gang’s Internal Leaked Screenshots

Sample Related Internally Leaked Screenshots Courtesy of the Conti Ransomware Gang:

Sample Conti Ransomware Gang’s Internal Leaked Screenshots




Sample Conti Ransomware Gang’s Internal Leaked XMPP/Jabber Account IDs:

LiamNeeson@jabber.ru

arb_reserved@ubuntu-jabber.de

battletoad@jabbim.sk

begemot_sun@jabber.ru

crazy_digger@jabber.ru

gfh6776@jabb.im

ivanalert@jabber.ru

landslide@jabb.im

new_henry@jabber.cz

scopehope@jabb.im

ugly@1jabber.com

valerius2k@jabber.ru

vdx17@jabber.ru

337788@exploit.im

asteradminn@sure.im

benalen@exploit.im

bio@yax.im

crunch@exploit.im

daiverjm@exploit.im

dmanager@exploit.im

fuckUSAhahaha@exploit.im

fuckusa@exploit.im

gfh6776@jabb.im

goldcoin@exploit.im

jackiedugn@exploit.im

landslide@jabb.im

martiniden123@exploit.im

mr_loki@exploit.im

posi_tron@exploit.im

pravdazanami@exploit.im

rob0660@conversations.im

scopehope@jabb.im

soulst@exploit.im

time_t@exploit.im

trqa23rt@exploit.im

volhvb@exploit.im

yastreb@exploit.im

SamCodeSign@xmpp.jp

alieelu@xmpp.jp

baton@xmpp.jp

batono@xmpp.jp

benalien@xmpp.jp

cosm123@xmpp.jp

graddds@xmpp.jp

guliver@xmpp.sh

liamliam@xmpp.jp

ohmygod728@xmpp.jp

Denis Gennadievich Kulkov

Personal Photo of Denis Gannadievich Kulkov


Among the actual domains known to be part of the Try2Check cybercriminals enterprise include:

hxxp://try2services[.]pm

hxxp://try2services[.]cm

hxxp://try2services[.]vc

including the following domain:

hxxp://just-buy[.]it

including the following two ICQ numbers 855377 and 555724 and let’s don’t forget his personal email address accounts obtained using public sources which are polkas@bk.ru nordexin@ya.ru

and it doesn’t get any better than this as we’ve got a pretty good and informative domain portfolio registered by the same individual based on public information sharing the same domain registration details such as for instance hxxp://worldissuer[.]biz which actually are:

hxxp://cloud-mine[.]me

hxxp://gpucloud[.]org

hxxp://hyperhost[.]info

hxxp://miservers[.]info

hxxp://carterdns[.]com

hxxp://reshipping[.]us

hxxp://keyserv[.]org

hxxp://antmining[.]biz

hxxp://investmentauditor[.]com

hxxp://sunnylogistics[.]us

hxxp://try2services[.]cm

hxxp://greatwallhost[.]net

hxxp://jaqjckugrfffqa[.]com

hxxp://numberoneforyou[.]net

hxxp://getprofitnow[.]biz

hxxp://avsdefender[.]com

hxxp://spyware-defender[.]com

hxxp://beta-dns[.]net

hxxp://mpm-profit-method[.]com

hxxp://public-dns[.]us — related including this

hxxp://adobe-update[.]net — Email: krownymaradonna@onionmail.org related domains known to have been involved in the campaign include — hxxp://amazon-clouds[.]com; hxxp://microsoft-clouds[.]net; hxxp://telenet-cloud[.]com; hxxp://vmware-update[.]com



hxxp://kwitri[.]net

hxxp://dcm-trade[.]com

hxxp://karoospin[.]biz

hxxp://fastvps[.]biz

Evgeniy Mikhaylovich Bogachev

Sample Personal Photos of Evgeniy Mikhaylovich Bogachev:


Slavik’s IM and personal email including responding IP:

bashorg@talking.cc — 112.175.50.220

Personal Address:

Lermontova Str. Anapa, Russian Federation

Instant Messaging account:

lucky12345@jabber.cz

Related name servers:

ns.humboldtec.cz — 88.86.102.49

ns2.humboldtec.cz — 188.165.248.173

Related domains part of a C&C phone-back location:

hxxp://slaviki-res1.com

hxxp://slavik1.com — 91.213.72.115

hxxp://slavik2.com

hxxp://slavik3.com

Slavik’s primary email:

luckycats2008@yahoo.com

Slavik’s ICQ numbers:

ICQ — 42729771

ICQ — 312456

Related emails known to have participated in the campaign:

alexgarbar-chuck@yahoo.com

bollinger.evgeniy@yandex.ru

charajiang16@gmail.com

Related domains known to have participated in the campaign:

hxxp://visitcoastweekend.com — 103.224.182.253; 70.32.1.32; 192.184.12.62; 141.8.224.93; 69.43.160.163

hxxp://incomeet.com — 192.186.226.71; 66.199.248.195

hxxp://work.businessclub.so

Real Name: Galdziev Chingiz

Related domains known to have participated in the campaign:

hxxp://fizot.org

hxxp://fizot.com — 50.63.202.35; 184.168.221.33

hxxp://poymi.ru — 109.206.190.54

Related name servers known to have participated in the campaign:

ns1.fizot.com — 35.186.238.101

ns2.fizot.com

Related domain including an associated email using the same name server:

hxxp://averfame.org — harold@avereanoia.org

Google Analytics ID: UA-3816538

Related domains known to have participated in the campaign:

hxxp://awmproxy.com

hxxp://pornxplayer.com

Related emails known to have participated in the campaign:

fizot@mail.ru

xtexgroup@gmail.com

xtexcounter@bk.ru

Related domains known to have responded to the same malicious and fraudulent IP — 178.162.188.28:

hxxp://dnevnik.cc

hxxp://xvpn.ru

hxxp://xsave.ru

hxxp://anyget.ru

hxxp://nezayti.ru

hxxp://proproxy.ru

hxxp://hitmovies.ru

hxxp://appfriends.ru

hxxp://naraboteya.ru

hxxp://naraboteya.ru

hxxp://awmproxy.com

hxxp://zzyoutube.com

hxxp://pornxplayer.com

hxxp://awmproxy.net

hxxp://checkerproxy.net

Related domains known to have participated in the campaign:

hxxp://fizot.livejournal.com/

hxxp://russiaru.net/fizot/

Instant Messaging Account:

ICQ — 795781

Related personally identifiable information of Galdziev Chingiz:

hxxp://phpnow.ru

ICQ — 434929

Email: info@phpnow.ru

Related domains known to have participated in the campaign:

hxxp://filmv.net

hxxp://finance-customer.com

hxxp://firelinesecrets.com

hxxp://fllmphpxpwqeyhj.net

hxxp://flsunstate333.com

Related individuals known to have participated in the campaign:

Slavik, Monstr, IOO, Nu11, nvidiag, zebra7753, lexa_Mef, gss, iceIX, Harderman, Gribodemon, Aqua, aquaSecond, it, percent, cp01, hct, xman, Pepsi, miami, miamibc, petr0vich, Mr. ICQ, Tank, tankist, Kusunagi, Noname, Lucky, Bashorg, Indep, Mask, Enx, Benny, Bentley, Denis Lubimov, MaDaGaSka, Vkontake, rfcid, parik, reronic, Daniel, bx1, Daniel Hamza, Danielbx1, jah, Jonni, jtk, Veggi Roma, D frank, duo, Admin2010, h4x0rdz, Donsft, mary.J555, susanneon, kainehabe, virus_e_2003, spaishp, sere.bro, muddem, mechan1zm, vlad.dimitrov, jheto2002, sector.exploits

Related Instant Messaging accounts and emails known to have participated in the campaign:

iceix@secure-jabber.biz

shwark.power.andrew@gmail.com

johnlecun@gmail.com

gribodemon@pochta.ru,

glazgo-update-notifier@gajim.org

gribo-demon@jabber.ru

aqua@incomeet.com

miami@jabbluisa.com

um@jabbim.com

hof@headcounter.org

theklutch@gmail.com

niko@grad.com

Johnny@guru.bearin.donetsk.au

petr0vich@incomeet.com

mricq@incomeet.com

T4ank@ua.fm

tank@incomeet.com

getreadysafebox.ru

john.mikleymaiI.com

aIexeysafinyahoo.corn

rnoscow.berlin@yahoo.com

cruelintention@email.ru,

bind@ernail.ru

firstmen17@rarnbler.ru

benny@jabber.cz

airlord1988@gmail.com

bxl@hotmail.com

i_amhere@hotmail.fr

daniel.h.b@universityofsutton.com

princedelune@hotmail.fr

bxl_@msn.com

danibxl@hotmail.fr

danieldelcore@hotmail.com.

d.frank@jabber.jp

d.frank@0nl1ne.at

duo@jabber.cn

fering99@yahoo.com

secustar@mail.ru

h4x0rdz@hotmail.com

Donsft@hotmail.com

mary.j555@hotmail.com

susanneon@googlemail.com

kainehabe@hotmail.com

virus_e_2003@hotmail.com

spanishp@hotmail.com

sere.bro@hotmail.com

lostbuffer@hotmail.com

lostbuffer@gmail.com

vlad.dimitrov@hotmail.com

jheto2002@gmail.com

sector.exploits@gmail.com

Aleksei Belan

Sample Personal Photo of Aleksei Belan

Sample domains known to have been involved in the campaign:

Sample personally identifiable email address accounts known to have been involved in the campaign:

moy.yawik@gmail.com

moy-yawik@bk.ru

Sample known responding IPs known to have been involved in the campaign include:

77.221.159.235

62.76.182.72

62.76.190.68

185.50.25.13

104.18.41.143

198.54.117.212

104.18.40.143

Mykhaylo Sergiyovich Rytikov


Sample Personal Photo of Mykhaylo Sergiyovich Rytikov

Known domains affiliated with AbdAllah Internet Hizmetleri:

hxxp://tiket[.]cc

hxxp://abdulla[.]cc

hxxp://privateforum[.]cn — upomajuliya745@gmail.com; xpj88kf@gmail.com; 316411856@qq.com


Related known domains affiliated with AbdAllah Internet Hizmetleri:

hxxp://ns1[.]srv4u[.]biz

hxxp://bulletproof-service[.]com — Email: support@hosting-offshore.biz — 202.83.212.250

hxxp://tarahost[.]net — Email: konstantin@karyaev.com — 89.108.73.93

Related domains known to have been registered by the same domain registrant:

hxxp://all-mafia[.]net

hxxp://shampanskoe[.]info

hxxp://mashost[.]org

hxxp://flexi-domains[.]com

hxxp://5pagess[.]net

hxxp://extrasoft[.]biz

hxxp://golovolomka[.]info

hxxp://optical-coatings[.]info

hxxp://polevoi[.]info

hxxp://belorussia[.]info

hxxp://3alab[.]com

hxxp://prezervativ[.]org

hxxp://brodyaga[.]net

hxxp://skramedia[.]com

hxxp://tarafree[.]com

hxxp://mp3-mmf[.]com

hxxp://myproga[.]net

hxxp://extrahost[.]su

hxxp://garanthost[.]com

hxxp://grand-host[.]net

hxxp://technormativ[.]info

hxxp://xp-hosting[.]net

hxxp://kredits[.]cn

hxxp://tarahost[.]biz

hxxp://tarahost[.]org

hxxp://optical-coatings-design[.]info

hxxp://extrasoft-outsourcing[.]info

hxxp://pm-tost[.]net

hxxp://pm-sotovik[.]net

hxxp://pm-ranlix[.]net

hxxp://pm-holland[.]net

hxxp://swlu[.]info

hxxp://valdiss[.]info

hxxp://karyaev[.]com

hxxp://x450[.]info

hxxp://grand-host[.]biz

hxxp://flexi-classifieds[.]com

hxxp://flexi-sitebuilder[.]com

hxxp://flexi-projects[.]com

hxxp://bloggast[.]info

hxxp://pereezd-pro[.]info

hxxp://eduaction[.]info

hxxp://wmnakovalnya[.]com

hxxp://retro80x[.]com

hxxp://tarafree[.]net

hxxp://skramedia[.]org

hxxp://oldactors[.]net

hxxp://tarahost[.]net

hxxp://janimation[.]net

hxxp://tarahost[.]com

hxxp://skramedia[.]biz

hxxp://vv-want[.]info

hxxp://skramedia[.]net

hxxp://olimp-sport[.]com

hxxp://youhouse[.]biz

hxxp://kroleki[.]com

hxxp://extrasoft-projects[.]info

hxxp://zelenaya[.]com

hxxp://cazinowm[.]com

hxxp://extrasoft-outsourcing[.]net

Related domains known to have been involved with AbdAllah Internet Hizmetleri:

hxxp://magic-jackpot-cas[.]com

hxxp://euro-vip-casino[.]com

hxxp://royal-casino-vip[.]com

hxxp://sexrusfuck[.]com

hxxp://royal-cas-vip[.]com

hxxp://2400-usd-casino[.]com

hxxp://royalcasino-vip[.]com

hxxp://2400usd-casino[.]net

hxxp://eurocasino-vip[.]com

hxxp://sinlife[.]cn

hxxp://byron-consulting-group[.]com

hxxp://28–07[.]com

hxxp://28–07[.]net

hxxp://job-consults[.]org

hxxp://837–86[.]org

hxxp://expressdeal[.]biz

hxxp://cron[.]li

hxxp://crons[.]cc

hxxp://cronos[.]mn

hxxp://crinc[.]mn

hxxp://crinc[.]li

hxxp://ultrasmoke[.]cn

hxxp://supersmoke[.]cn

hxxp://globalsmoke[.]cn

hxxp://937–86[.]org

hxxp://cronco[.]li

hxxp://tradegroup-ha[.]com

hxxp://ha-tradegroup[.]com

hxxp://crinc[.]jp

hxxp://tradegroup-ha[.]net

hxxp://investmentcron[.]cn

hxxp://glb-soft[.]com

hxxp://croninv[.]cc

hxxp://cronis[.]cn

hxxp://crons[.]ac

hxxp://cronn[.]eu

hxxp://dkebooks[.]com

hxxp://cronoi[.]cc

hxxp://jieod[.]com

hxxp://midgejs[.]com

hxxp://crin[.]ac

hxxp://aoejf[.]com

hxxp://yseac[.]com

hxxp://kaserid[.]com

hxxp://crin[.]cc

hxxp://jekdoe[.]com

hxxp://ujeose[.]com

hxxp://masiwer[.]com

hxxp://reusiwe[.]com

hxxp://kaoeds[.]com

hxxp://iwoser[.]com

hxxp://planet0day[.]biz

hxxp://xeirod[.]com

hxxp://neusoas[.]com

hxxp://geoepd[.]com

hxxp://efuyr[.]com

hxxp://ziude[.]com

hxxp://polsenstanford[.]com

hxxp://heyud[.]com

hxxp://woqkr[.]com

hxxp://seiudr[.]com

hxxp://aosier[.]com

hxxp://dueor[.]com

hxxp://crins[.]ac

hxxp://verbespecially[.]com

hxxp://fivejoy[.]com

hxxp://riverwomen[.]com

hxxp://trianglesentence[.]com

hxxp://floorside[.]com

hxxp://developtail[.]com

hxxp://womanfinish[.]com

hxxp://alwaysfell[.]com

hxxp://differcollect[.]com

hxxp://goodalso[.]com

hxxp://kingbrought[.]com

hxxp://findcharacter[.]com

hxxp://chanceexpect[.]com

hxxp://beardictionary[.]com

hxxp://forwardfield[.]com

hxxp://tinydown[.]com

hxxp://jobwhether[.]com

hxxp://numeralcity[.]com

hxxp://cronin[.]jp

hxxp://equalcatch[.]com

hxxp://streamwho[.]com

hxxp://selectmonth[.]com

hxxp://propercame[.]com

hxxp://grewsoil[.]com

hxxp://townslip[.]com

hxxp://stationheavy[.]com

hxxp://charactereven[.]com

hxxp://milk0soft[.]com

hxxp://goldverb[.]com

hxxp://windowlisten[.]com

hxxp://bqgqnfc[.]cn

hxxp://wrbhnuw[.]cn

hxxp://a9da6[.]org

hxxp://04ccc408[.]org

hxxp://bdb7beb6[.]org

hxxp://scalespread[.]com

hxxp://thencloud[.]com

hxxp://figurespoke[.]com

hxxp://fullfraction[.]com

hxxp://propertytall[.]com

hxxp://beautyfig[.]com

hxxp://hadover[.]com

hxxp://followsalt[.]com

hxxp://staysay[.]com

hxxp://herexcept[.]com

hxxp://thanscore[.]com

hxxp://humanthus[.]com

hxxp://branchfelt[.]com

hxxp://areacountry[.]com

hxxp://meetduring[.]com

hxxp://movestood[.]com

hxxp://stillverb[.]com

hxxp://suggesteye[.]com

hxxp://preparebut[.]com

hxxp://hurrysound[.]com

hxxp://cookcompare[.]com

hxxp://0daycod[.]biz

hxxp://europeansmoke[.]cn

hxxp://sprybog[.]net

hxxp://taybaol[.]com

hxxp://polsenstanford[.]com

hxxp://bconsgroup[.]com

GRU’s Unit 74455 “NotPetya”


Sample screenshots of the GRU’s Unit 74455 “NotPetya” malware gang obtained using public sources:





Igor Dehtyarchuk

Sample Personal Photo of Igor Dehtyarchuk

Sample emails known to have been involved in the campaign include:

abuse@shopsn.su

dimetr801@mail.ru

admin@4server.su

ssg.apple77@gmail.com


Sample domains known to have been involved in the campaign include:

hxxp://4server.su

hxxp://csgoacc.ru

hxxp://marketsales.su

hxxp://zarmo.su

hxxp://4domains.su

hxxp://ebayshop.su

hxxp://globus-base.su

hxxp://broshop.su

hxxp://deer.su

hxxp://shopsn.su

hxxp://cjmarket.net

hxxp://vkaccounts.com

hxxp://cheapaccounts.su

hxxp://ytuber.su

hxxp://vds4u.su

hxxp://4host.su

hxxp://tgshop.su

hxxp://xn — 227-qdd4dec.xn — p1acf

hxxp://4dedic.su

hxxp://time-hack.su

hxxp://4ns.su

Sample screenshot:

Oleksandr Vitalyevich Ieremenko


Sample Personal Photo of Oleksandr Vitalyevich Ieremenko

Handle: Zl0m; Lamarez; Ded.MCz; l@m@rEz

Email: lamarez@mail.ru; uaxakep@gmail.com — xeljanzusa.com — 62.109.25.228 (hxxp://www.secureworks.com/research/point-of-sale-malware-threats); 62.109.1.69

Commpany: 2016 Кзерокс

Phone: +7 951 366 17 17

ICQ: 123424

Web Money: 258807111393

Related URLs:

hxxp://ageline.ru/lamarez.php

hxxp://k0x.ru/md5.salt.tx

hxxp://k0x.ru/_bot.exe — 82.146.60.59

hxxp://k0x.ru/black_energy_31337_/stat.php

hxxp://k0x.ru/siicywu36dswh/addddos.php

hxxp://xtoolz.ru

hxxp://cup.su

hxxp://xwarez.us

hxxp://kinoafisha.ua/news/lamarez-was-here

hxxp://post-tracker.ru

hxxp://zr.ru

hxxp://business-gazeta.ru

hxxp://proshkolu.ru

hxxp://opengost.ru

hxxp://krokha.ru

hxxp://eurolab.ua

hxxp://newsdon.info

hxxp://dirt.ru

hxxp://anime-zone.ru

hxxp://rus.kg

hxxp://badger.ru

hxxp://fedpress.ru

hxxp://carsguru.net

hxxp://findfood.ru

hxxp://beboss.ru

hxxp://vidal.ru

hxxp://reghelp.ru

hxxp://rabotagrad.ru

hxxp://proshkolu.ru

hxxp://muztorg.ru

hxxp://mirf.ru

hxxp://medgorodok.ru

hxxp://dobrota.ru

hxxp://cooksa.ru

hxxp://consmed.ru

hxxp://buro247.ru

hxxp://3dmir.ru

hxxp://novorus.info

hxxp://kidbe.ru

hxxp://eknigi.org

hxxp://2×2.su

Exante LTD — XNT Ltd. — exante.eu

Danil Potekhin

Sample personal Web site: hxxp://agressivex.com

Sample personal email: potekhinl4@bk.ru

Sample MD5 known to have participated in the campaign:

MD5: ecb347518230e54c773646075e2cc5ea269dcf8304ad102cee4aae75524e4736

Happy research!

Continue reading →

Sample Breach Forums Personally Identifiable Cybercriminal Email Address Accounts

0
September 17, 2023

Dear blog readers,

The following is a personally identifiable email address compilation known to belong to known members of the Breach Forums cybercrime-friendly forum community which I've decided to share with the idea to assist researchers vendors and organizations including U.S Law Enforcement on its way to properly track down and monitor and prosecute the cybercriminals behind these campaigns.

Sample personally identifiable email address accounts of known Breach Forums members include:
bfweep[.]proton.me
elforumadept[.]proton.me
mybbjunkxd[.]protonmail.com
cry4mebb[.]proton.me
nathavm[.]proton.me
opsopsops123[.]proton.me
kokotc[.]proton.me
meowza.mlplove[.]proton.me
megadabbz[.]protonmail.com
rhapsody3[.]proton.me
mixoleetou51[.]protonmail.com
x153[.]protonmail.com
cooncooncooncooncooncooncoon[.]proton.me
drugsarefree[.]protonmail.com
ciphergold[.]proton.me
unknownUser23[.]protonmail.com
Mafiosoyouth[.]proton.me
domainreportaa[.]protonmail.com
entrymeowmeow[.]proton.me
nicetryniggerkek[.]protonmail.com
an0n.pr1v[.]proton.me
C0rpix[.]protonmail.com
spumoni529[.]proton.me
researcher8293[.]proton.me
ImNotHere97[.]protonmail.com
yasinstinkt[.]proton.me
bestlonely[.]protonmail.com
nox-nicht[.]protonmail.com
mamamia.omega[.]protonmail.com
fbiareus[.]proton.me
raidblocker[.]proton.me
K.MRXx7[.]protonmail.com
xxxtenlive9[.]proton.me
wdwamfrpaws[.]proton.me
ByteNinja956[.]proton.me
verykindgentleman[.]proton.me
larrayjin[.]proton.me
moonman.rape.cloudflare[.]protonmail.com
debtaccount[.]proton.me
synpastehacked[.]protonmail.com
palleskov[.]proton.me
jigsaw_19546[.]proton.me
Pk268[.]proton.me
manhattanchinadoll[.]protonmail.com
belledelphinesbathwater[.]proton.me
lulzpirate[.]protonmail.com
alek1092[.]proton.me
Spoofythewhale[.]proton.me
nomorepedos[.]protonmail.com
max_gliz[.]proton.me
dk430safr2[.]proton.me
actordf043k[.]proton.me
exljeqhkmfzhwcxwdp[.]proton.me
codmus[.]protonmail.com
bytecorporation[.]proton.me
0xmastermind[.]proton.me
wizard9591432[.]proton.me
hellokittyqt[.]proton.me
adriansamuraiu1[.]protonmail.com
russianboy29[.]protonmail.com
Govdzctf[.]proton.me
4.lsis[.]proton.me
user_breach[.]proton.me
petermacdonald13[.]protonmail.com
iszxqaa[.]proton.me
0xproplayer[.]protonmail.com
cutty78[.]proton.me
spy03we021eo[.]proton.me
shellrean[.]proton.me
byaujayzvgnnusyrxa[.]protonmail.com
opticom-net-ec[.]protonmail.com
dollaria[.]proton.me
ankitbinary[.]protonmail.com
s3cgr0n[.]proton.me
bonobe4826p[.]proton.me
moxybbs[.]protonmail.com
throwaaaa[.]proton.me
tht_me[.]proton.me
xr1x[.]proton.me
breaches[.]proton.me
thespore[.]protonmail.com
z3ek[.]proton.me
lampss45[.]proton.me
luminouscascade[.]proton.me
althal[.]protonmail.com
mssssom[.]protonmail.com
gaberenewal[.]proton.me
loserssquad[.]proton.me
why99999[.]proton.me
lololtrolol[.]protonmail.com
datapurchaser[.]proton.me
puppybreached[.]proton.me
imgroot000[.]proton.me
mHzqslgnQOjfwusjQcTUKbwk[.]protonmail.com
ralyleebit00[.]proton.me
68312eyiqwuy3186[.]protonmail.com
veryscarysite[.]protonmail.com
Techt0m[.]protonmail.com
le21ren[.]proton.me
BradenRoute66[.]protonmail.com
Atonable[.]proton.me
iniqus[.]proton.me
crackwh0re[.]protonmail.com
penguinbrew[.]proton.me
unit828200[.]proton.me
Questman124[.]protonmail.com
johnsmith10000[.]protonmail.com
teqdh[.]proton.me
hunsy001[.]proton.me
alphawonder[.]proton.me
bzroka[.]proton.me
itshug[.]proton.me
anthraxsec[.]protonmail.com
parusan1337[.]proton.me
Oreo0384[.]proton.me
smartsol888[.]proton.me
pausanbel[.]proton.me
mougreikacrommei[.]proton.me
darkdemon6[.]proton.me
JamesGarrod7[.]protonmail.ch
marcus_dravic[.]proton.me
longliveasap[.]protonmail.com
r00t1988[.]protonmail.ch
Iam4uSweety[.]protonmail.com
384969392[.]proton.me
exp878[.]proton.me
globaldatabases[.]proton.me
0xwh[.]proton.me
densortetelefon[.]protonmail.com
f41rs[.]proton.me
alpinecow_email[.]proton.me
teleport92344[.]proton.me
whdhiduj[.]proton.me
goamericago[.]proton.me
paidjemz[.]protonmail.com
0xarkin[.]protonmail.com
darkcsaitama[.]proton.me
morok0[.]proton.me
examservice[.]proton.me
Johnny.Manseau[.]proton.me
299918dj[.]proton.me
aesinner[.]proton.me
AlbertAnokhin777[.]proton.me
0xFF1E071F[.]protonmail.com
intrusior[.]proton.me
allyourbasearebelongtobreached[.]proton.me
oculus3210[.]proton.me
expgods[.]proton.me
fnat1cal[.]proton.me
fuckyouadmins[.]protonmail.com
hgghjhgh[.]proton.me
julius302[.]protonmail.com
krispykremedonutslilyumyum[.]proton.me
stephditto[.]proton.me
0xrfg8fr[.]proton.me
jawarib[.]proton.me
Turqjesus[.]proton.me
mrchsh0[.]proton.me
seeder21[.]protonmail.com
viplds[.]protonmail.com
binray_x64[.]proton.me
ImPOlowN[.]proton.me
eewwewtgr[.]proton.me
BinaryGhost101[.]proton.me
huntinghalo[.]proton.me
AlistaGrob[.]proton.me
Profitlogs[.]protonmail.com
wowston75[.]proton.me
fixthathatx[.]protonmail.com
thenazgul234[.]protonmail.com
hamahbalif[.]proton.me
ms7cr[.]proton.me
paragon56[.]protonmail.com
onoderapunpun1997[.]proton.me
ssqwessssqwe[.]proton.me
mariamhadid139[.]proton.me
robot57357[.]proton.me
ruselllane0[.]proton.me
dostoyevskiy[.]protonmail.com
x_xaammx[.]proton.me
Marble_cig11[.]protonmail.com
trusted_mediator[.]proton.me
0xwhoami01[.]proton.me
zimablue0920[.]protonmail.com
Tutinoti[.]proton.me
xIblackhunterIx[.]proton.me
abdfurkan[.]proton.me
gasmaskgus[.]proton.me
yFLTY[.]proton.me
lol[.]protonmail.com
hydrogen404[.]proton.me
marseu68[.]protonmail.com
d4rkness00[.]protonmail.com
Wayne.Barbers[.]proton.me
dsifapit[.]proton.me
lykioo[.]protonmail.com
rata[.]protonmail.com
scopkqwpokqwpoqpokwwwwwwwwww[.]proton.me
freached[.]proton.me
jackrumm[.]protonmail.ch
WonkaWillie75[.]protonmail.com
exploitbender[.]protonmail.com
ollebal[.]proton.me
iamthealch3mist[.]proton.me
r1ddikulu5[.]protonmail.com
kokopolisd1[.]proton.me
aaaaaaaaaaaaaaaaaaaaaaaaxxxxxxxxxxx[.]proton.me
Z4n4h0r1F4ck[.]proton.me
q32q[.]protonmail.com
MEkpZdmhPs[.]proton.me
pompaman34[.]proton.me
breached.here[.]protonmail.com
fontfan1144[.]proton.me
mobster2399[.]proton.me
adispy[.]protonmail.com
0peratorSuiss3[.]protonmail.com
cyanarcana[.]protonmail.com
Lacerta332[.]proton.me
anomadeut17[.]protonmail.com
tomiashari[.]proton.me
chiccy[.]proton.me
hair3[.]protonmail.com
asdjkhasdfjkhesfkjsefiuhsefiuhqwf[.]proton.me
notSpamerImLamer[.]proton.me
nonamenone1[.]protonmail.com
accbuyer[.]protonmail.com
perfectings[.]protonmail.com
zzzbf[.]proton.me
skyeyes59[.]proton.me
OlegPopov180[.]proton.me
m841337[.]proton.me
choochoo.train13[.]protonmail.com
0pearatorDansk3[.]proton.me
breached69[.]protonmail.com
d4ddyduty[.]proton.me
nevermindless111[.]proton.me
waocc[.]proton.me
dellpolar[.]protonmail.com
qmflegend[.]proton.me
xy0ke[.]proton.me
humanproxy666[.]protonmail.com
secretleakbuyer[.]proton.me
docbuyer[.]proton.me
Poppedsomexanax[.]proton.me
anashu3[.]proton.me
ScrimWasTaken[.]proton.me
thecartelteam[.]protonmail.com
cqygfxgfst3233[.]protonmail.com
gbl004d[.]proton.me
tomas.mutrel[.]proton.me
sa2osec[.]protonmail.com
mandala1920[.]protonmail.com
nameni[.]protonmail.com
adahou[.]proton.me
kimmkayy8[.]proton.me
kirakiranon[.]proton.me
nitin7618verma[.]protonmail.com
squll[.]protonmail.com
laddukuma76[.]proton.me
KristinaIzvekova[.]proton.me
pakligg[.]protonmail.com
maligator.breachforums[.]proton.me
sinancoskun208[.]protonmail.com
chill38409[.]proton.me
Lightko[.]protonmail.com
anodine22[.]proton.me
mommothowl123[.]protonmail.com
professional1337[.]protonmail.com
sk0nz1t[.]protonmail.com
olekka4[.]proton.me
robowhiz[.]proton.me
wakatchaka[.]protonmail.com
Twilight6888[.]proton.me
datsuli[.]proton.me
mr_lordx_new[.]proton.me
vladi22ss33[.]proton.me
mzxndsmnb[.]proton.me
0mada[.]protonmail.com
ShiShiShi1[.]proton.me
wecanchop[.]proton.me
dreamerbf[.]proton.me
asmdsma552[.]proton.me
tcn88xv[.]proton.me
dopaminebf[.]proton.me
a8b6e[.]protonmail.com
noilnotso[.]protonmail.com
sarah.taylor99[.]protonmail.com
honvetek[.]proton.me
lolcalhost[.]proton.me
nastybillion[.]protonmail.com
brut3k1t[.]proton.me
sheikh.muhajir05[.]proton.me
bfnest0r[.]proton.me
verzogerteverleugnung[.]proton.me
7UnLXhD4nkdYcMCb5dfM[.]proton.me
saaaaaalaaaaaanaaa[.]proton.me
ultrapeachy[.]protonmail.com
proxyfoxy26[.]protonmail.com
34585[.]protonmail.com
tg134134[.]proton.me
slxyin[.]protonmail.com
yajija[.]proton.me
nasr_rlgz[.]proton.me
smokeup3759[.]proton.me
imvxgue[.]protonmail.com
johnnybravo4you[.]protonmail.com
Bronzii420[.]proton.me
samosadude[.]protonmail.com
snufflesss[.]proton.me
sanukai[.]protonmail.com
G1ld3d[.]proton.me
gubjldamin[.]protonmail.com
teodorius[.]protonmail.com
ripley.xeno[.]proton.me
otamaro[.]proton.me
wowfca[.]protonmail.com
man1fest89[.]proton.me
ougefouwrg[.]protonmail.com
ardemti[.]proton.me
charcoal213[.]protonmail.com
fzeouhvapiaphg[.]protonmail.com
ssjtrX0[.]protonmail.com
uglystory[.]proton.me
m1rdz4_Set0[.]protonmail.com
netcat1993[.]proton.me
kxdr535[.]protonmail.com
ajeje112233[.]proton.me
Mendung_Ireng[.]protonmail.com
shewuz[.]protonmail.com
bookread920[.]proton.me
ugaugaXsp[.]proton.me
forwarddejv[.]proton.me
kota-0009[.]proton.me
ClipperAuthum86[.]proton.me
gambling.spur[.]proton.me
cuddlybear[.]proton.me
reilopisne[.]protonmail.com
abc313235[.]protonmail.com
dabi23[.]protonmail.com
byt3r00t[.]proton.me
wowwowowoowow[.]proton.me
kernelsec[.]protonmail.com
unshipped[.]protonmail.com
yanayana20[.]protonmail.com
zumi.anette[.]protonmail.com
reznicivan[.]proton.me
ApplePieIceCreamLover[.]proton.me
masqueradezer0[.]proton.me
therandomnull[.]protonmail.com
thinning5013[.]proton.me
Uschreiner[.]protonmail.com
ajuki[.]proton.me
OSHEE20[.]proton.me
maraud3r[.]protonmail.com
4mruu[.]proton.me
4lt3r3g000[.]proton.me
bhihmaridlas[.]proton.me
ForrestGumpWasTaken[.]proton.me
r49n4r0k[.]protonmail.ch
anon4fd8reg6[.]proton.me
cherry_bloom11[.]protonmail.com
elf_unix[.]proton.me
amznv1p3r[.]proton.me
sean.fann1ng[.]protonmail.com
ven0mv[.]protonmail.com
raidfomatad[.]protonmail.com
kenzo156[.]protonmail.com
jackson.westwind[.]protonmail.com
Larry.Liechtenstein[.]proton.me
asthrok[.]proton.me
shinjuro[.]protonmail.com
carnagecookie[.]proton.me
0rssal[.]proton.me
exceptwice[.]proton.me
sabiopervertido[.]protonmail.com
doratomiu[.]proton.me
mijita88[.]proton.me
whokem[.]proton.me
adilson2380[.]protonmail.com
telkomshit[.]proton.me
monkeyotp[.]proton.me
acdefg[.]protonmail.ch
realelon[.]proton.me
54ax[.]protonmail.com
xcviking[.]protonmail.com
n6db23s[.]proton.me
frogmaster101[.]proton.me
RetardMango[.]proton.me
cavernousmawe123[.]proton.me
JohnGottiFromBreached[.]proton.me
kewqaltd[.]proton.me
near0007[.]protonmail.com
MrWeed0x69[.]proton.me
breachgold[.]proton.me
faqwe789[.]proton.me
cattleshit865943[.]proton.me
goldyhunters[.]proton.me
breachxyz123[.]proton.me
zerofeds[.]proton.me
doomCrawler[.]protonmail.com
HA11ofD00M[.]protonmail.com
AllWeatherSpecialAgent[.]proton.me
braturhrere[.]proton.me
BlackCherryCarKey[.]proton.me
WholeFoodsRecordCard[.]proton.me
anonymousscaryhacker[.]proton.me
capture_ca[.]proton.me
ofj39t[.]proton.me
kalienso[.]protonmail.com
rando186[.]proton.me
Lolin99[.]protonmail.com
fs0c131y[.]protonmail.com
ir0nm3n0101[.]proton.me
gloft[.]protonmail.com
cyber.astro931[.]proton.me
kaktus.paz[.]proton.me
wickedeevee[.]proton.me
fleetbarber1337[.]proton.me
mydreamisww3[.]proton.me
monsieurlex[.]proton.me
bicycle002[.]proton.me
BugHunterFromBreached[.]proton.me
offsec[.]proton.me
mrmojorasin[.]protonmail.com
garoldp[.]proton.me
THEBIGPAPI666[.]proton.me
5meowmeowkittycat[.]proton.me
n9h3ch0_2935[.]proton.me
ayoumo[.]protonmail.com
b4binks.py[.]proton.me
020monkey[.]protonmail.com
lighthouse099[.]proton.me
z5bra[.]protonmail.com
xsandereli[.]protonmail.com
nightsh3ll[.]protonmail.com
Alloha79[.]proton.me
kongrong9[.]proton.me
Sora.Togo[.]protonmail.ch
cyanbun1986[.]proton.me
zxczbedcx[.]proton.me
skmei1337[.]proton.me
yaliaojiahaomatwd[.]proton.me
trabznnspor[.]proton.me
YRNAfromFNC[.]proton.me
sdadfef[.]proton.me
misa.cordero[.]protonmail.com
inoreader6[.]proton.me
cartiiiierrz[.]protonmail.com
jafkkre3[.]proton.me
lucythenewcat[.]proton.me
goatkiss[.]protonmail.com
qfx0[.]protonmail.com
abvfrd[.]protonmail.com
inchwohrm[.]protonmail.com
goresecto[.]proton.me
yrzxzhk[.]proton.me
ryuokada19191[.]proton.me
lockon.noir80[.]protonmail.com
oneoneoneandzero[.]protonmail.com
exploitin2023[.]proton.me
sparkmedia[.]protonmail.com
b33_f0ur[.]protonmail.com
rqwffasaffsaa[.]proton.me
Frederikgaming11x[.]proton.me
jimmbobb123[.]protonmail.com
spy032kds9adk[.]proton.me
kenoraichi[.]protonmail.com
0xRemax[.]proton.me
Smeagoll1[.]proton.me
sec1338[.]protonmail.com
dgtarget49aaattt[.]proton.me
oldhuntr3[.]proton.me
2ysur[.]protonmail.com
omegatiger57[.]protonmail.com
arabicspy03[.]protonmail.com
whiskyboy1405[.]proton.me
bebrajopa1[.]proton.me
catcwo[.]proton.me
arabicspy01[.]protonmail.com
astrosp[.]proton.me
libert213[.]proton.me
LulzToor[.]protonmail.com
C4i0[.]protonmail.com
offensive-info[.]protonmail.com
mauricegprice[.]protonmail.com
jaddsalloum[.]proton.me
mamatereza[.]proton.me
binks90[.]protonmail.com
nullptr_t_xd[.]protonmail.com
Eh2madhatter[.]protonmail.com
sinhe278[.]proton.me
Funtik_2[.]proton.me
Mithosss[.]protonmail.com
DanthSmith[.]proton.me
mike2.flame[.]proton.me
parkedflow[.]proton.me
toryeah[.]proton.me
cosmicapelord[.]proton.me
exposed.vc1[.]proton.me
saojo_asd[.]protonmail.com
volkiaa[.]protonmail.com
danielbrain111[.]protonmail.com
kakzanov[.]protonmail.com
toastpwned[.]proton.me
chinamandan[.]proton.me
228e7c64[.]proton.me
xexira7850[.]proton.me
zorndeslammes[.]protonmail.com
walkingzombie69[.]proton.me
leebee2233[.]proton.me
tracy.andrus[.]protonmail.com
kawaiichandesu[.]protonmail.com
adrian.piko[.]proton.me
iamnopiracy[.]protonmail.com
gama0x3a[.]protonmail.com
hotbitefood[.]proton.me
norevell[.]proton.me
databulk[.]protonmail.com
thomasbarrow20[.]proton.me
tonihawk[.]protonmail.com
freedompro1024[.]protonmail.com
saur1nh[.]proton.me
19intelbroker[.]proton.me
escudopikespeak[.]proton.me
kr0wl4n[.]protonmail.com
crmfhewnjfw[.]proton.me
abella.grand[.]protonmail.com
d0nutSpecial777[.]protonmail.com
49xp[.]protonmail.com
Karambalam[.]protonmail.com
8cash[.]protonmail.com
wswsms[.]proton.me
cocomelonpizza[.]proton.me
useruusseer123[.]proton.me
H4rDw4Y[.]proton.me
neverlate11[.]protonmail.com
1488hnz[.]proton.me
ch13f.k133f[.]protonmail.ch
whosayyours[.]proton.me
markflaus[.]protonmail.com
Fe784n94[.]protonmail.com
floofbunny22[.]protonmail.com
kalinka1175[.]proton.me
spermus3243434343[.]proton.me
lonelilpublic[.]proton.me
enqusx[.]proton.me
offsecfree420[.]proton.me
xn0ne[.]proton.me
mr_snek_guy[.]protonmail.com
kiotoyt5130[.]protonmail.com
srskr3w[.]protonmail.com
breachforumsdotvc[.]proton.me
notahoneypot124[.]protonmail.com
f5w4ltqgqz[.]proton.me
ab3232321[.]proton.me
addidix[.]proton.me
satorikraft[.]protonmail.com
ilikeonion[.]proton.me
pr0m3teuz[.]proton.me
akame0x41[.]proton.me
sazadadev[.]proton.me
zonedinmyblood[.]proton.me
wearethejoker[.]protonmail.com
hadespro1[.]proton.me
cokesyrup3000[.]proton.me
jerry02cherry[.]protonmail.com
witox7[.]proton.me
pandapan0001[.]protonmail.com
hates3curity12[.]proton.me
toohigh1[.]proton.me
Nbcbilling[.]proton.me
protonaccountemailnow[.]protonmail.com
halofan1016[.]protonmail.com
killingops[.]proton.me
icyyvulpix[.]proton.me
plugyy[.]proton.me
wdymbesafe[.]proton.me
taiga52[.]protonmail.com
si_peaxe[.]proton.me
russiancontact[.]proton.me
taskmanag3r[.]proton.me
ivebeenbreached[.]proton.me
Forums_Double[.]proton.me
neotoad[.]protonmail.com
supplier5556[.]proton.me
1337pwnz[.]proton.me
dantewin[.]proton.me
lopsidedninjago[.]proton.me
itsforresearch7355608[.]proton.me
black_goldmine[.]protonmail.com
st_r6996[.]proton.me
0xsn0wy[.]proton.me
xnaxicx[.]protonmail.com
SY6houl[.]protonmail.com
8l0ck[.]proton.me
ooo6nh4zhee[.]proton.me
RoyGBive[.]proton.me
Pomdb150[.]proton.me
haxaman[.]proton.me
DieNicely[.]proton.me
redzik0[.]proton.me
22pxe[.]protonmail.com
evertonperes[.]protonmail.com
roberthaschberg[.]protonmail.com
ejhd412[.]protonmail.com
bhamchoubey[.]protonmail.com
stagerfriend[.]protonmail.com
legendaryservices[.]protonmail.com
CarbonVeil[.]proton.me
dummywojak[.]proton.me
isayar17[.]protonmail.com
drivethrough.mcdonalds[.]proton.me
FalangistasGroup[.]proton.me
luaplayer000[.]protonmail.com
sonus1975[.]protonmail.com
Jimmycarrey[.]proton.me
234wsdfasdjkfhasdk[.]proton.me
kasem545[.]proton.me
alexcracked[.]protonmail.com
asdfasdrferasd3r4we[.]proton.me
Unblessed2808[.]proton.me
ringplayer84[.]proton.me
clean1337[.]protonmail.com
eeeeex5[.]proton.me
smellylikepoop12345[.]proton.me
Danielposadabogota[.]proton.me
agents4777[.]proton.me
lmy46475[.]protonmail.com
ss_ddbl[.]proton.me
leticia_brandao_18[.]proton.me
pedroalcantara1[.]proton.me
needyeevee[.]proton.me
moomincrew[.]protonmail.com
Un_M2M[.]protonmail.com
jklpq[.]protonmail.com
Sl3pt0n[.]proton.me
warneraaa[.]proton.me
vbnet[.]protonmail.ch
darthyodax[.]protonmail.com
selshevneren[.]proton.me
riley7007[.]proton.me
ubergetaway[.]proton.me
skid_hunter1[.]protonmail.com
grapefruit22[.]protonmail.com
ScriptMaestro[.]protonmail.com
stormyseaz[.]protonmail.com
quasenada5[.]protonmail.com
Cyenlacex[.]proton.me
Captainshiv[.]proton.me
honeypotenjoyer[.]protonmail.com
punky84[.]protonmail.com
BreathingFine123[.]proton.me
gringoalberhein[.]proton.me
multideplaty[.]protonmail.com
cuentaforocoches2[.]proton.me
something172853[.]proton.me
Hamicka[.]proton.me
fedundercover[.]protonmail.com
nopz0x90[.]proton.me
sdkuuusss[.]protonmail.com
myanmarxist[.]protonmail.com
affiliatecheese[.]proton.me
oxxxdaddy[.]proton.me
forocoches1[.]protonmail.com
fluffyyyy69[.]proton.me
valentina23aa[.]protonmail.com
anubisegyptiangod[.]protonmail.com
duduspam45[.]proton.me
osbreach[.]proton.me
amywhitte[.]proton.me
v1t0r_028[.]protonmail.com
calypsopwd[.]proton.me
personality.vc[.]proton.me
jakethedog420[.]protonmail.com
leal_langlais[.]proton.me
aaaaz123567[.]proton.me
asdaw4rtdf[.]proton.me
viphaxx[.]proton.me
fredfuchs01[.]protonmail.com
0xN3KF[.]proton.me
test5300[.]protonmail.com
alluringsonderr[.]proton.me
ulzhQMHicz[.]proton.me
noobguy7172[.]proton.me
exquisiten[.]proton.me
jayiscorrupt[.]protonmail.com
0xz3ld4[.]protonmail.com
breachforumvc[.]proton.me
lotbs1012[.]proton.me
lucia.rivas2000[.]proton.me
11231123w[.]proton.me
zxjia[.]protonmail.com
ogsinful[.]proton.me
ramonpaxten[.]protonmail.com
shourodityopaul[.]proton.me
0xCr0w[.]protonmail.com
thisismee79[.]proton.me
nicklancer[.]protonmail.com
KoY4N7SwWj3Th9vphAJ49ctkQiaq[.]proton.me
heimam[.]proton.me
hurk.churk[.]proton.me
andrejmanning32[.]protonmail.com
pbrito[.]protonmail.ch
usa911911[.]proton.me
aaravpatel345[.]proton.me
ferminpietrowiczuh[.]protonmail.com
nihaoahhh[.]protonmail.com
DanthGSmith[.]proton.me
prot245543[.]protonmail.com
n0thingser[.]proton.me
retreat2105[.]proton.me
eggmanwow[.]proton.me
amalgam0506[.]protonmail.com
lukly69[.]proton.me
smokingperp4daddy[.]proton.me
vrsq[.]proton.me
sg432[.]proton.me
areuid[.]proton.me
Joellperry[.]proton.me
sightunseen[.]protonmail.com
spix98[.]protonmail.com
stevewozniac[.]proton.me
4m3rr0r[.]protonmail.com
VirtualModz[.]proton.me
anteriseiste33[.]proton.me
Apotato369[.]proton.me
ruza.dodek8[.]proton.me
biharibabuofficial[.]proton.me
justarand0mmail[.]proton.me
ontario.eth[.]proton.me
jobaca44[.]proton.me
io32ppm[.]protonmail.com
reapercreapster1[.]proton.me
janedoe12358162[.]proton.me
nirgn[.]protonmail.com
dhawiklwad[.]protonmail.com
pangu.alpha[.]proton.me
godkingkevin[.]proton.me
abrahamjay010[.]protonmail.com
thedarksnakeoffi[.]protonmail.com
dfadfasdfasdf1[.]proton.me
vettimail[.]protonmail.com
wiskyy[.]proton.me
HadesSayyaf[.]proton.me
bloobox[.]protonmail.com
f-22proton[.]protonmail.com
bistaz[.]proton.me
m00nstarr[.]proton.me
lmbtq[.]proton.me
roidlimeskies[.]protonmail.com
tail.grand[.]protonmail.com
lala4lune[.]proton.me
fullmoonday[.]protonmail.com
dem0nonearth[.]protonmail.com
Mastschwein361[.]proton.me
lighter133[.]protonmail.com
0xpepperduck[.]proton.me
tichalatom[.]proton.me
JJJJJJenny[.]protonmail.com
ne024[.]proton.me
66badger66[.]proton.me
jarviseatme[.]proton.me
robinbettink[.]protonmail.com
RoastedMarshmellos[.]proton.me
b0nak0v[.]protonmail.com
furminator100[.]proton.me
hyuogen[.]proton.me
neutroniumcore[.]proton.me
redkite808[.]protonmail.com
marcowthe[.]protonmail.com
zeBPWDZ11qJMpnS2[.]proton.me
vanjkatz[.]proton.me
jamesdunn19[.]proton.me
itchyscratchy1[.]protonmail.com
forum.mantheman[.]proton.me
gems345[.]proton.me
nashnash120[.]proton.me
gonofu_55200[.]protonmail.com
nikicigi[.]proton.me
notahoneypotxd[.]proton.me
kalnaut[.]proton.me
gamabumalka[.]proton.me
brandee_white[.]proton.me
f0ck123123asd[.]protonmail.com
alkinooscostaou1[.]protonmail.com
baobab32[.]proton.me
takaruyu[.]proton.me
Scarface3306[.]protonmail.com
qsignature[.]protonmail.com
d0ntspamme[.]proton.me
wheypr0tein[.]proton.me
Spectre01[.]protonmail.com
GarfieldDrip0[.]proton.me
alanqqp[.]proton.me
jasd5674[.]proton.me
igorgrach[.]protonmail.com
rickjames6969[.]protonmail.com
petrucci_overlord19[.]protonmail.com
fckallthe3agency[.]proton.me
majorptr[.]proton.me
for_simple_man[.]proton.me
lalolilus[.]protonmail.com
matthew.sparrow[.]protonmail.com
00Sora[.]protonmail.com
richbossman[.]proton.me
schreibert.robin[.]proton.me
ELGatoDeBato[.]proton.me
b1ng0pwn[.]proton.me
fukudachan[.]proton.me
r9z9cr7[.]protonmail.com
prod.cxr[.]protonmail.com
R0lex1080[.]protonmail.com
clairefoster90[.]proton.me
danablack69[.]proton.me
console11[.]protonmail.com
postcypher84[.]proton.me
ltrt999[.]proton.me
aj_cyberscoop[.]proton.me
gottaloveit1337[.]proton.me
anonhackerlegion[.]proton.me
LosnakSec[.]proton.me
zTGZERGVZ[.]proton.me
web24solutions[.]protonmail.com
provekaninen[.]protonmail.com
steventramless[.]protonmail.com
caddett[.]protonmail.com
Ritoha[.]proton.me
BrooklynB00gie[.]protonmail.com
sillyyyyyyy[.]proton.me
chibby3434[.]protonmail.com
ra1nbowd[.]proton.me
teamseras[.]proton.me
topbhop[.]protonmail.com
salsaaapje[.]proton.me
steven5151[.]proton.me
user1238121[.]proton.me
h4wkin9[.]protonmail.com
calimush[.]proton.me
panchos[.]protonmail.com
confirmedretard3[.]proton.me
hackerman22[.]proton.me
MaloneFaz[.]protonmail.com
gh0stking1[.]proton.me
Danaye.Githens[.]proton.me
iomegax00[.]protonmail.com
luca.francesconi[.]proton.me
freemeoutus[.]protonmail.com
londonview123[.]proton.me
kelincilucul[.]proton.me
bicratfuck[.]proton.me
isy4hrose[.]proton.me
d1lb3rt[.]proton.me
d432sg4[.]proton.me
CYGEEKPWN[.]proton.me
netraveeye2000[.]protonmail.com
gdfsds3[.]proton.me
aaaaatop[.]proton.me
TKW2019[.]proton.me
latestcyberman[.]proton.me
177954[.]proton.me
electron.2006[.]protonmail.com
pastralik[.]proton.me
daem0n0[.]proton.me
bobthefrogg[.]proton.me
sonofthor123[.]proton.me
nigvgd[.]proton.me
zezebreachforums[.]proton.me
adeqweq[.]protonmail.com
kmarx123[.]protonmail.com
breachforums01[.]proton.me
WebPlowler[.]proton.me
kerjabro[.]proton.me
68696e68[.]protonmail.com
eshadow.my[.]proton.me
wangguoy[.]protonmail.com
csirtccfr[.]protonmail.com
salpha[.]proton.me
makersmark29[.]protonmail.com
usaShare333[.]proton.me
fuckingmykatawa[.]protonmail.com
89031743067[.]protonmail.com
minsersager[.]proton.me
yuhannaz[.]proton.me
realraymondhoward[.]proton.me
wallexerdam[.]proton.me
s4lph4[.]proton.me
chriswtf[.]protonmail.com
iMrDark[.]protonmail.com
promisingmaster[.]proton.me
gaytillyard[.]proton.me
yesviolets[.]protonmail.com
baphometfella[.]proton.me
support.toolsstore[.]protonmail.com
petersmett[.]proton.me
onelastriddler[.]proton.me
zhuanzhiyangwei888[.]proton.me
Kea_Deceit[.]proton.me
crazy42000[.]protonmail.com
EazyAI[.]proton.me
martinscp007[.]proton.me
dimitrirascalov1[.]proton.me
pupkin24[.]protonmail.com
Theli3[.]proton.me
ladyspenzer[.]proton.me
tmptestbf[.]proton.me
outgoingrequest[.]protonmail.com
NewEmailIsForPossibleDBLeaks[.]proton.me
l4stc4r3ss[.]proton.me
plumberz[.]proton.me
prozzzzz23[.]proton.me
cyb3rpUnK777[.]protonmail.ch
doghugger1349[.]proton.me
TxTxxTxT[.]proton.me
junkssh[.]proton.me
dasrunadi[.]proton.me
kwest93[.]proton.me
serfdomgalore[.]protonmail.com
sadperson1993[.]proton.me
theOwl.SA[.]proton.me
hi57741[.]protonmail.com
PatrickDevan202[.]proton.me
u000e4[.]protonmail.com
anonymousleads[.]proton.me
realsmo[.]proton.me
iusedtobehappy[.]protonmail.com
mubarakhab[.]protonmail.com
hivemindprivacy[.]proton.me
ali_goto786[.]protonmail.com
aveurs[.]proton.me
xciiw[.]proton.me
YummyGhost[.]protonmail.com
ch.c.786[.]proton.me
whitenoise404[.]proton.me
Jwesmolan[.]proton.me
psyberdata[.]proton.me
papulus7384[.]proton.me
neetgineer[.]proton.me
alohaaloha12312[.]protonmail.com
breachsforum-vc[.]proton.me
thistempme[.]proton.me
shinyflakes009[.]protonmail.com
MosVokaRock[.]proton.me
ocarinabattle123[.]proton.me
rainytokyo[.]proton.me
k8ge[.]proton.me
wl52hz[.]proton.me
valepwn[.]protonmail.com
15mdb3[.]proton.me
Birutinha69[.]proton.me
bixolo8376[.]proton.me
bxcdrkafe[.]protonmail.com
cipherto[.]proton.me
angry.cal[.]proton.me
utilizador69420[.]proton.me
test2023202323[.]proton.me
fbsibrq488[.]proton.me
dbtg3h2fk6[.]proton.me
xyhfxii886[.]proton.me
deltinix[.]protonmail.com
taiketsu31770[.]proton.me
theodore.martin1[.]protonmail.com
sanitersaniter[.]proton.me
doyouknowhat123[.]proton.me
MBA-FR[.]proton.me
777GOG[.]proton.me
xr3phx[.]proton.me
UN-USA1995[.]proton.me
ponponpongeus[.]proton.me
arcad1a88[.]protonmail.com
Heisenberg-DDOS[.]proton.me
DDOS.ccc[.]proton.me
Curse4819[.]proton.me
bunnyonaspree[.]proton.me
wearenotsureaboutit[.]proton.me
funiinc[.]proton.me
idkutu[.]proton.me
yourh4ck3r[.]proton.me
Richard_pr130ause[.]proton.me
olexyn[.]protonmail.com
makeron232[.]protonmail.com
vittens[.]proton.me
armorwtf[.]proton.me
immmm[.]protonmail.com
lolwhut321[.]proton.me
Icreatemultiple[.]proton.me
sdfgysertgdfg[.]proton.me
kjkljilyhksfd[.]proton.me
Beroepassistent[.]proton.me
cyph3rzer0[.]protonmail.com
599066[.]protonmail.com
adriansharp720[.]proton.me
milevamaric_einsten[.]proton.me
mullman765[.]proton.me
m4n4m3r[.]protonmail.com
0DiXsg20jSyVb6[.]proton.me
valhalla0x0[.]proton.me
p0stm0rtemleaks23[.]proton.me
fqifufilme[.]proton.me
ric1337[.]protonmail.ch
dbrick84[.]protonmail.com
bn0de1337[.]proton.me
marshaoyo[.]proton.me
trppalol[.]proton.me
wangluombg[.]proton.me
carpediem06789[.]protonmail.com
bountytest[.]proton.me
thinkforurself123[.]proton.me
OscarHdz33[.]proton.me
cicek0800[.]proton.me
sunakeye[.]protonmail.com
l34ks4s4l3[.]proton.me
kn7sJo8WVcOQ[.]protonmail.com
f0rs4g3t34m[.]proton.me
send2cyber[.]proton.me
s3v3nd4ys[.]proton.me
farrowsec[.]proton.me
98kdbs[.]proton.me
maxlundh91[.]protonmail.com
shifthi[.]protonmail.com
lingtingbingfing[.]proton.me
jhgunnar[.]proton.me
g4byg0l[.]proton.me
LoganSE[.]protonmail.ch
HhineySunters[.]proton.me
swankyhankypanky[.]proton.me
mynameisrobertpaulson2[.]proton.me
kauranga7[.]proton.me
nakoru[.]protonmail.com
evildelta[.]proton.me
visialp2013[.]protonmail.com
ElopusMySlopus[.]proton.me
invalid_password[.]protonmail.com
qd8mhvar636uxa23[.]proton.me
doneforthemdone[.]proton.me
0day23[.]protonmail.com
thegreenmile2[.]protonmail.com
pacific49901[.]proton.me
bozosokozo[.]proton.me
breachedforums[.]protonmail.com
uvuyu[.]proton.me
vanderhall[.]protonmail.com
bottomsixersf[.]proton.me
dontfindmepls[.]proton.me
uhcuqshczisio[.]protonmail.com
ayman.oussamou[.]proton.me
breadisnotfree[.]proton.me
kissforsex[.]proton.me
Danielbrian111[.]protonmail.com
AliIbnLaAhad[.]proton.me
levikingerson[.]proton.me
ihaveaveryhardlifeman[.]proton.me
Yu69RC3C5S7dJpcS[.]proton.me
compl3xpassword[.]proton.me
afdannuzul[.]proton.me
Bearac211[.]proton.me
bettercallmessi123[.]proton.me
cibertido[.]protonmail.com
fatalXflawX[.]proton.me
galatasaray161[.]proton.me
u6darmLxnzESEDzmF6xj[.]proton.me
jmoomedaaf[.]proton.me
fisha_medorow[.]proton.me
tamirciciragii[.]proton.me
finnyiky[.]proton.me
BuckJohnson1984[.]proton.me
kjhgodflvkjsdfsaofs[.]proton.me
qpo8080[.]proton.me
iusedtobehappyy[.]proton.me
TommyCashes[.]protonmail.com
Mamamiakepaso[.]proton.me
gskldfnksbfj[.]proton.me
totigag[.]protonmail.com
anon-beastmastery[.]protonmail.com
nik1940[.]protonmail.com
urbansystem398[.]proton.me
lili2021lili2021[.]proton.me
itartinas[.]proton.me
kulapulu[.]proton.me
ruzcat[.]proton.me
sobatguruns[.]proton.me
aguxile[.]proton.me
mikegeigei[.]proton.me
bangwashswigjagonhag[.]proton.me
vegamenkar[.]proton.me
m.peintech[.]protonmail.ch
broadgesture[.]protonmail.com
Minerblood[.]protonmail.com
Noone4real[.]proton.me
712374325345[.]proton.me
22girls1cup[.]proton.me
nullf0und[.]proton.me
jamboah[.]proton.me
royaliser002[.]protonmail.com
spotifybiggestfan[.]proton.me
bravo00[.]protonmail.com
johnruckus.my[.]protonmail.com
bfaccount01[.]protonmail.com
works247[.]proton.me
facceebook[.]protonmail.com
sp1n[.]protonmail.com
blackcaper[.]proton.me
yeseterdayoncemore618[.]proton.me
nonchalant333[.]proton.me
rredr10[.]protonmail.com
pufroeba32[.]proton.me
user3342[.]protonmail.com
GreenMalwareTeam[.]protonmail.com
dedcodegit[.]proton.me
itstuffofhell[.]proton.me
zzzbbcab1165[.]proton.me
S8mple[.]proton.me
Xolezel[.]protonmail.com
jurnal83[.]protonmail.com
ortijdf83fk4[.]proton.me
KillFemboys[.]proton.me
rob3447[.]proton.me
Goseak[.]proton.me
axllabs[.]protonmail.com
sfDferwgzsae[.]proton.me
01Kevin0110[.]proton.me
jiggypuff4[.]proton.me
adderall2077[.]proton.me
mythpat0909[.]proton.me
ano.afspreken[.]protonmail.com
mrdgill[.]proton.me
maps1990[.]proton.me
Tyronzz[.]proton.me
0xcyberpanther[.]protonmail.com
jamal22191[.]proton.me
livesimply06[.]proton.me
xred07[.]protonmail.com
gud3tama[.]proton.me
CCS1122gg[.]proton.me
poolverine24[.]protonmail.com
flosfow[.]proton.me
5x156[.]proton.me
v3rgitsklok[.]proton.me
satyriha[.]proton.me
boeufmijote[.]proton.me
Military.VTC[.]protonmail.ch
MichaelSinopoli[.]proton.me
randomed1[.]proton.me
alnabeargm[.]protonmail.com
justhereforthesauce[.]proton.me
canerbasaran[.]protonmail.com
morpheus1337[.]protonmail.com
JimmyIeong[.]proton.me
durdasirde[.]protonmail.com
AnonymousTermations[.]proton.me
odtulu[.]proton.me
Nbirdmann[.]protonmail.com
stainedrain[.]proton.me
laowang202211[.]proton.me
amriu[.]proton.me
mystuffyt[.]proton.me
stdpi[.]proton.me
dajori1509[.]proton.me
apog331intt[.]proton.me
nawliet[.]protonmail.ch
wttr[.]protonmail.com
darvinsass[.]proton.me
whoisevensky[.]proton.me
rokk37[.]proton.me
edccvb[.]proton.me
asriux9935[.]proton.me
idktpure[.]proton.me
sneek28[.]proton.me
fu58fj4[.]proton.me
Pashata89[.]proton.me

Related personally identifiable email address accounts of Breach Forums members:
weej[.]tuta.io
jigsaw11[.]tutanota.com
walter_brian[.]tutanota.com
priestituta[.]gmail.com
mufy[.]tuta.io
karamellakto[.]tutanota.com
blarg[.]tuta.io
Forsaken87[.]tutanota.com
ratbag[.]tutanota.com
wwewes[.]tutanota.com
dude6969[.]tutanota.com
chasethedragon69[.]tutanota.com
breachforumsttiyshn[.]tutanota.com
4wayswing[.]tuta.io
frederick832[.]tutanota.com
vinnyannoyia[.]tutanota.com
zeropio[.]tutanota.com
bitchy[.]tuta.io
robowhiz[.]tutanota.com
z_ghent[.]tutanota.com
wavie[.]tuta.io
raping[.]tuta.io
sneakypete33[.]tutanota.com
Ernieball[.]tutanota.com
masterdata[.]tutanota.com
ax1l[.]tutanota.com
ramb002[.]tutanota.com
bytemafia[.]tuta.io
xerosest[.]tuta.io
bashed[.]tuta.io
asnegejusotutaip[.]gmail.com
thotiana24[.]tutanota.com
kala420[.]tutanota.com
tbackflower[.]tutanota.com
yohankoshy[.]tutanota.com
sashahalas[.]tutanota.com
keeferga[.]tutanota.com
BourbonCream1995[.]tutanota.com
progon[.]tuta.io
stuxnot[.]tutanota.com
cloudknight86[.]tutanota.com
4e4eneca[.]tuta.io
dealxtreme[.]tutanota.com
tejo[.]tuta.io
jstarq2[.]tutanota.com
qazrfvujm[.]tutanota.com
366ovu9qbgq0wss78vt254o2[.]tutanota.com
M3t4w0rm32[.]tutanota.com
browingmark[.]tutanota.com
whitewalker777[.]tutanota.com
woyaohuifuzhanghao[.]tuta.io
bjoshua[.]tuta.io
kstop7[.]tutanota.com
bayganyo[.]tutanota.com
hashcats[.]tuta.io
8urp420[.]tutanota.com
krumi[.]tutanota.com
xcist[.]tutanota.com
fbii[.]tuta.io
bfjohn[.]tutanota.com
Euclid_[.]tuta.io
ppxp[.]tuta.io
kittypot[.]tutanota.com

Related personally identifiable email address accounts of Breach Forums members include:
deaddd[.]dnmx.org
squir[.]dnmx.org
criox[.]dnmx.org
jasafy842[.]dnmx.org
nulettoo[.]dnmx.org
talecyte[.]dnmx.org
shagneto[.]dnmx.org
c4tsya[.]dnmx.org
randomlygenerated[.]dnmx.org
gj49nds0dv1[.]dnmx.org
federalcat[.]dnmx.org
vincegiligan[.]dnmx.org
naisyaputridharma[.]dnmx.org
builder[.]dnmx.org
sz[.]dnmx.org
breachforums23[.]dnmx.org
r0318932[.]dnmx.org
backagain[.]dnmx.org
cFb9rShFu5ZB[.]dnmx.org
lordisha[.]dnmx.org
kangarootc[.]dnmx.org
xnico[.]dnmx.org
brettjs[.]dnmx.org
doctorreal[.]dnmx.org
sicarius69[.]dnmx.org
akarca[.]dnmx.org
hellokitty234891[.]dnmx.org
Tklmaster[.]dnmx.org
Tarepanda[.]dnmx.org
Indishell[.]dnmx.org
redux[.]dnmx.org
install[.]dnmx.org
metasnapchat[.]dnmx.org
Metaforce[.]dnmx.org
Ahmadxd[.]dnmx.org
Denisovich[.]dnmx.org
Rilakkumabear[.]dnmx.org
Jerrytom[.]dnmx.org
Roundearth[.]dnmx.org
Knight[.]dnmx.org
RoyalQueen[.]dnmx.org
Royalx[.]dnmx.org
Soulx[.]dnmx.org
DarknessX[.]dnmx.org
Ak47x[.]dnmx.org
Americax[.]dnmx.org
Crackedx[.]dnmx.org
123xd[.]dnmx.org
Cobrax[.]dnmx.org
Venomx[.]dnmx.org
deathxd[.]dnmx.org
4ttrs[.]dnmx.org
DarkxDeath[.]dnmx.org
DarkxKnight[.]dnmx.org
Evilx[.]dnmx.org
Hiccup[.]dnmx.org
Maleficent[.]dnmx.org
MiaK[.]dnmx.org
TopxG[.]dnmx.org
LuciferD[.]dnmx.org
shirokun[.]dnmx.org
Crackx[.]dnmx.org
DarkAli[.]dnmx.org
OnnichanUwU[.]dnmx.org
karatekid[.]dnmx.org
KhanB[.]dnmx.org
iame[.]dnmx.org
smartelog[.]dnmx.org
audiencele[.]dnmx.org
iw991ia[.]dnmx.org
damemphis[.]dnmx.org
GoogleX[.]dnmx.org
IBM[.]dnmx.org
breachedvc[.]dnmx.org
MicrosoftPVT[.]dnmx.org
FRS[.]dnmx.org
GunX[.]dnmx.org
KID[.]dnmx.org
Toothless[.]dnmx.org
TEN[.]dnmx.org
CoinX[.]dnmx.org
DemonXd[.]dnmx.org
Asadx[.]dnmx.org
VxPN[.]dnmx.org
MetaFacebook[.]dnmx.org
DOGx[.]dnmx.org
GrandTheftAuto[.]dnmx.org
Kingxpin[.]dnmx.org
TigerXd[.]dnmx.org
LostX[.]dnmx.org
Bing[.]dnmx.org
DiscordPVT[.]dnmx.org
YouTubePVT[.]dnmx.org
CID[.]dnmx.org
TheUFO[.]dnmx.org
DeadWarrior[.]dnmx.org
DeathWAR[.]dnmx.org
kilink[.]dnmx.org
alabmoah[.]dnmx.org
dejvbweiojdvbjwbid[.]dnmx.org
PoliceDepartment[.]dnmx.org
KingLEO[.]dnmx.org
KhanG[.]dnmx.org
MrBeastYT[.]dnmx.org
SusAf[.]dnmx.org
Man[.]dnmx.org
ImKSZ[.]dnmx.org
Mojang[.]dnmx.org
TeslaX[.]dnmx.org
HailHydra[.]dnmx.org
Eboy[.]dnmx.org
EboyAli[.]dnmx.org
NeganSmith[.]dnmx.org
REDS[.]dnmx.org
TheWalker[.]dnmx.org
PTI[.]dnmx.org
YukariX[.]dnmx.org
AssWipe[.]dnmx.org
Fury[.]dnmx.org
She[.]dnmx.org
Evex[.]dnmx.org
VEX[.]dnmx.org
BreachVC[.]dnmx.org
0293848811[.]dnmx.org
Assassin[.]dnmx.org
Ezio[.]dnmx.org
UnitedStates[.]dnmx.org
Asian[.]dnmx.org
Asiax[.]dnmx.org
Mammal[.]dnmx.org
RexT[.]dnmx.org
Avoslocker[.]dnmx.org
Rhino[.]dnmx.org
tz002mail[.]dnmx.org
Pythx[.]dnmx.org
xBoss[.]dnmx.org
mouly[.]dnmx.org
Mailmx[.]dnmx.org
CyberD[.]dnmx.org
MailG[.]dnmx.org
NixOS[.]dnmx.org
ShinyHunter[.]dnmx.org
cap[.]dnmx.org
Swordx[.]dnmx.org
egirl[.]dnmx.org
TheISIS[.]dnmx.org
TheBible[.]dnmx.org
TheVirus[.]dnmx.org
Shoutbox[.]dnmx.org
Force00[.]dnmx.org
babyl0n[.]dnmx.org
Thorodinson[.]dnmx.org
Continue reading →

Sample Personally Identifiable Cybercriminal XMPP/Jabber Accounts

0
September 17, 2023

Dear blog readers,

The following compilation of XMPP/Jabber account IDs known to belong to cybercriminals which I obtained using public and proprietary sources including data mining aims to assist researchers vendors and organizations including U.S Law Enforcement on its way to properly track down and monitor including to prosecute the cybercriminals behind these campaigns.

Sample XMPP/Jabber accounts IDs known to belong to cybercriminals and known to have been involved in various campaigns include:

newjabber@jabbim.com

cash@allinione.com

slark@jix.im

sypress@wwh.so

soft-rdp@xmpp.jp

merchant.official@xabber.de

merchant.official@jabbim.com

driesdtt@in.koderoot.net

npaplav000k@strong.pm

npaplav000k@xmpp.jp

cashsir@xmpp.jp

luke@allinione.com

nsky@allinione.com

adm@allinione.com

mrgreen@allinione.com

tech@jabber.belnet.be

jsminamr@openmailbox.org

mrlapis@exploit.im

airman@jabber.ru

neshpiter@jabbim.com

joke@blah.im

westup@codingteam.net

big@myempire.me

z@allinione.com

cuclusclan@allinione.com

mrgr@im.osmose-am.net

maracana777@exploit.im

daydate@im.apinc.org

scratch@jabber.belnet.be

cubon@thesecure.biz

mate@creep.im

nauthstuff@exploit.im

dozer@jabb.im

luke@suchat.org

mainqmac@jabber.cz

nadmin@pro-fi.net

nspacetex@jabber.cz

supp01@jabberx.biz

supp08@xmpp.jp

supp17@exploit.im

supp37@cock.li

puusycat@jabber.ru

info@albfrrame.com

nsupport_miloff@exploit.im

nmilano1@default.rs

aizoo-adv@thesecure.biz

tmtforlifeqazbey@xmpp.jp

greenman@jabber.belnet.be

mikluchamaklai@jabb.im

chromehearts@jabber.ru

Continue reading →

Sample Personally Identifiable XMPP/Jabber Accounts of the Gozi/Ursnif Malware Gang Team Members

0
September 17, 2023

Digging a little bit deeper into my ongoing research into various personally identifiable information such as for instance email address accounts and XMPP/Jabber account IDs belonging to cybercriminals I've decided to share a compilation of XMPP/Jabber account IDs known to belong to the Gozi/Ursnif malware gang team members with the idea to assist researchers vendors and organizations including U.S Law Enforcement on its way to properly track down monitor and prosecute the cybercriminals behind these campaigns.

Sample XMPP/Jabber account IDs known to have been involved in the campaign include:

newjabber@jabbim.com

cash@allinione.com

slark@jix.im

sypress@wwh.so

soft-rdp@xmpp.jp

merchant.official@xabber.de

merchant.official@jabbim.com

driesdtt@in.koderoot.net

npaplav000k@strong.pm

npaplav000k@xmpp.jp

cashsir@xmpp.jp

luke@allinione.com

nsky@allinione.com

adm@allinione.com

mrgreen@allinione.com

tech@jabber.belnet.be

jsminamr@openmailbox.org

mrlapis@exploit.im

airman@jabber.ru

neshpiter@jabbim.com

joke@blah.im

westup@codingteam.net

big@myempire.me

z@allinione.com

cuclusclan@allinione.com

mrgr@im.osmose-am.net

maracana777@exploit.im

daydate@im.apinc.org

scratch@jabber.belnet.be

cubon@thesecure.biz

mate@creep.im

nauthstuff@exploit.im

dozer@jabb.im

luke@suchat.org

mainqmac@jabber.cz

nadmin@pro-fi.net

nspacetex@jabber.cz

supp01@jabberx.biz

supp08@xmpp.jp

supp17@exploit.im

supp37@cock.li

puusycat@jabber.ru

info@albfrrame.com

nsupport_miloff@exploit.im

nmilano1@default.rs

aizoo-adv@thesecure.biz

tmtforlifeqazbey@xmpp.jp

greenman@jabber.belnet.be

mikluchamaklai@jabb.im

chromehearts@jabber.ru

Continue reading →