"value":"Late last month, multiple news outlets reported that unspecified law enforcement officials had seized the servers for Leakedsource.com, perhaps the largest online collection of usernames and passwords leaked or stolen in some of the worst data breaches \u00e2\u20ac\u201d including billions of credentials for accounts at top sites like LinkedIn, Myspace, and Yahoo.\r\n\r\nIn a development that could turn out to be deeply ironic, it seems that the real-life identity of LeakedSource\u00e2\u20ac\u2122s principal owner may have been exposed by many of the same stolen databases he\u00e2\u20ac\u2122s been peddling."
},
{
"category":"Network activity",
"comment":"That one of the administrators of LeakedSource also was the admin of abusewith[dot]us, a site unabashedly dedicated to helping people hack email and online gaming accounts.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"domain",
"uuid":"58a4ab25-5620-4843-a08b-4f0602de0b81",
"value":"abusewith.us"
},
{
"category":"Attribution",
"comment":"The administrator of Abusewith[dot]us is a hacker who uses the nickname \u00e2\u20ac\u0153Xerx3s.\u00e2\u20ac\u009d",
"comment":"My source told me he\u00e2\u20ac\u2122d recently chatted with Xerx3s using the Jabber address Xerx3s has long used prior to the creation of LeakedSource",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"jabber-id",
"uuid":"58a4abf1-be0c-45a3-8225-46a802de0b81",
"value":"xerx3s@chatme.im"
},
{
"category":"Attribution",
"comment":"This is in reference to a pseudonym Xerx3s frequently used, \u00e2\u20ac\u0153Jeremy Wade.\u00e2\u20ac\u009d",
"comment":"According to a \u00e2\u20ac\u0153reverse WHOIS\u00e2\u20ac\u009d record search ordered through Domaintools.com, that email address is tied to two domain names registered in 2015: abusing[dot]rs, and cyberpay[dot]info.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"domain",
"uuid":"58a4accf-329c-4e54-a738-4d2d02de0b81",
"value":"cyberpay.info"
},
{
"category":"Network activity",
"comment":"According to a \u00e2\u20ac\u0153reverse WHOIS\u00e2\u20ac\u009d record search ordered through Domaintools.com, that email address is tied to two domain names registered in 2015: abusing[dot]rs, and cyberpay[dot]info.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"domain",
"uuid":"58a4acd0-2518-4778-8b62-4ff702de0b81",
"value":"abusing.rs"
},
{
"category":"Social network",
"comment":"paid $5 to cover a subscription for a user named \u00e2\u20ac\u0153jeremywade;\u00e2\u20ac\u009d",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad1d-fce0-4d78-baf6-ee8502de0b81",
"value":"eadeh_andrew@yahoo.com"
},
{
"category":"Social network",
"comment":"The leaked Panicstresser database shows the Jeremywade account was tied to the email address xdavros@gmail.com, and that the account was created in July 2012.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad3c-36ec-4ebe-bd84-414e02de0b81",
"value":"xdavros@gmail.com"
},
{
"category":"Payload delivery",
"comment":"According to a large number of forum postings, it appears that whoever used the xdavros@gmail.com address also created several variations on that address, including alexdavros@gmail.com, davrosalex3@yahoo.com, davrosalex4@yahoo.com, as well as themarketsales@gmail.com.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad74-e4f8-4838-b874-a3a102de0b81",
"value":"xdavros@gmail.com"
},
{
"category":"Payload delivery",
"comment":"According to a large number of forum postings, it appears that whoever used the xdavros@gmail.com address also created several variations on that address, including alexdavros@gmail.com, davrosalex3@yahoo.com, davrosalex4@yahoo.com, as well as themarketsales@gmail.com.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad75-2a18-47a9-a804-a3a102de0b81",
"value":"alexdavros@gmail.com"
},
{
"category":"Payload delivery",
"comment":"According to a large number of forum postings, it appears that whoever used the xdavros@gmail.com address also created several variations on that address, including alexdavros@gmail.com, davrosalex3@yahoo.com, davrosalex4@yahoo.com, as well as themarketsales@gmail.com.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad76-f960-48f3-9370-a3a102de0b81",
"value":"davrosalex3@yahoo.com"
},
{
"category":"Payload delivery",
"comment":"According to a large number of forum postings, it appears that whoever used the xdavros@gmail.com address also created several variations on that address, including alexdavros@gmail.com, davrosalex3@yahoo.com, davrosalex4@yahoo.com, as well as themarketsales@gmail.com.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad76-e768-42cb-adfc-a3a102de0b81",
"value":"davrosalex4@yahoo.com"
},
{
"category":"Social network",
"comment":"According to a large number of forum postings, it appears that whoever used the xdavros@gmail.com address also created several variations on that address, including alexdavros@gmail.com, davrosalex3@yahoo.com, davrosalex4@yahoo.com, as well as themarketsales@gmail.com.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"email-src",
"uuid":"58a4ad77-03ac-41bb-be33-a3a102de0b81",
"value":"themarketsales@gmail.com"
},
{
"category":"Attribution",
"comment":"The Gmail account xdavros@gmail.com was used to register at least four domain names almost six years ago in 2011. Two of those domains \u00e2\u20ac\u201d daily-streaming.com and tiny-chats.com \u00e2\u20ac\u201d were originally registered to a \u00e2\u20ac\u0153Nick Davros\u00e2\u20ac\u009d at 3757 Dunes Parkway, Muskegon, Mich. The other two were registered to a Nick or Alex Davros at 868 W. Hile Rd., Muskegon, Mich. All four domain registration records included the phone number +12313430295.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"text",
"uuid":"58a4ae60-4610-45b8-b00c-403c02de0b81",
"value":"+12313430295"
},
{
"category":"Network activity",
"comment":"were originally registered to a \u00e2\u20ac\u0153Nick Davros\u00e2\u20ac\u009d at 3757 Dunes Parkway, Muskegon, Mich. The other two were registered to a Nick or Alex Davros at 868 W. Hile Rd., Muskegon, Mich.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"domain",
"uuid":"58a4aeac-1c24-4d98-ac30-47fe02de0b81",
"value":"daily-streaming.com"
},
{
"category":"Network activity",
"comment":"were originally registered to a \u00e2\u20ac\u0153Nick Davros\u00e2\u20ac\u009d at 3757 Dunes Parkway, Muskegon, Mich. The other two were registered to a Nick or Alex Davros at 868 W. Hile Rd., Muskegon, Mich.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"domain",
"uuid":"58a4aead-f9bc-43f8-be16-48e102de0b81",
"value":"tiny-chats.com"
},
{
"category":"Payload delivery",
"comment":"Farsight reports that the address 68.41.238.208 maps back to three different dynamic IP domains,",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"filename",
"uuid":"58a4af01-36f0-43f2-8bf1-4a0302de0b81",
"value":"jwade69.no-ip.biz"
},
{
"category":"Payload delivery",
"comment":"Farsight reports that the address 68.41.238.208 maps back to three different dynamic IP domains,",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487187734",
"to_ids":false,
"type":"filename",
"uuid":"58a4af02-62a0-4692-8613-48ae02de0b81",
"value":"wadewon.no-ip.biz"
},
{
"category":"Payload delivery",
"comment":"Farsight reports that the address 68.41.238.208 maps back to three different dynamic IP domains,",
"comment":"two email addresses connected to domains associated with the Jeremy Wade alias \u00e2\u20ac\u201d matt96sk@yahoo.com and skythekiddy@yahoo.com \u00e2\u20ac\u201d are tied to Facebook accounts for Michigan residents who both list Alex Davros among their Facebook friends.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1487188059",
"to_ids":false,
"type":"email-src",
"uuid":"58a4b05b-b628-4a3f-bf37-4bc002de0b81",
"value":"matt96sk@yahoo.com"
},
{
"category":"Payload delivery",
"comment":"two email addresses connected to domains associated with the Jeremy Wade alias \u00e2\u20ac\u201d matt96sk@yahoo.com and skythekiddy@yahoo.com \u00e2\u20ac\u201d are tied to Facebook accounts for Michigan residents who both list Alex Davros among their Facebook friends.",