A comprehensive framework for analyzing messaging-based scam campaigns, with advanced behavioral pattern detection and automation indicators.
This framework provides tools and methodologies for analyzing messaging-based scam campaigns, with capabilities for:
- Temporal pattern analysis
- Automation detection
- Behavioral risk assessment
- Campaign-wide analytics
- Threat Type: SMS-based government impersonation scam
- Target Demographic: Pennsylvania residents
- Attribution: Philippines-based criminal organization
- Infrastructure: Fraudulent domain mimicking official government sites
- Status: Operation disrupted (domain offline)
- Source: iMessage database extraction and analysis
- Tools: Custom SQLite analysis scripts, sentiment analysis
- Scope: Communication pattern analysis and threat identification
- Domain Analysis: Infrastructure investigation of fraudulent sites
- Telecom Intelligence: International phone number attribution
- OSINT: Open source intelligence gathering
- Operational Security Assessment: OPSEC failure identification
- Geographic Attribution: Philippines-based operations
- Capability Assessment: Professional-grade criminal network
- Phone Number: +639127911810 (Globe Telecom, Philippines)
- Fraudulent Domain: pa.gov-jad.vip (now offline)
- Target Vector: SMS-to-web redirection attack
- Payment Processing: Integrated fraudulent financial systems
- β Professional social engineering techniques
- β Geographic and demographic targeting
- β Multi-stage attack methodology
- β OPSEC failures (international numbers, legal terminology errors)
dmv_scam_analysis/
βββ README.md # This file
βββ analysis/
β βββ technical_report.md # Detailed technical analysis
β βββ threat_actor_profile.md # Threat actor intelligence
β βββ timeline_analysis.md # Attack timeline reconstruction
βββ evidence/
β βββ indicators_of_compromise.md # IOCs and technical indicators
β βββ communication_analysis.md # Message content analysis
β βββ infrastructure_analysis.md # Domain and network analysis
βββ scripts/
β βββ message_extractor.py # iMessage database analysis tool
β βββ threat_visualizer.py # Advanced data visualization suite
β βββ sentiment_analyzer.py # Threat detection automation
β βββ ioc_validator.py # IOC verification toolkit
βββ reports/
β βββ executive_summary.md # High-level findings
β βββ law_enforcement_report.md # LE intelligence package
β βββ public_awareness_guide.md # Community protection guide
βββ visualizations/
β βββ visualization_index.html # Interactive visualization gallery
β βββ risk_dashboard.html # Multi-panel risk assessment dashboard
β βββ threat_network.html # Interactive infrastructure network
β βββ executive_dashboard.html # Executive KPI dashboard
β βββ threat_timeline.png # Campaign timeline analysis
β βββ detection_analytics.png # Detection effectiveness metrics
βββ documentation/
β βββ methodology.md # Analysis methodology
β βββ visualizations.md # Data visualization documentation
β βββ tools_used.md # Technical toolkit documentation
β βββ lessons_learned.md # Post-analysis insights
βββ requirements.txt # Python dependencies
βββ venv/ # Virtual environment (excluded from git)
- Database Analysis: SQLite database extraction and parsing
- Communication Forensics: Message content and metadata analysis
- Timeline Reconstruction: Event sequence mapping
- OSINT Collection: Open source intelligence gathering
- Infrastructure Analysis: Domain and network investigation
- Attribution Assessment: Geographic and organizational attribution
- Interactive Dashboards: Plotly-based dynamic threat assessment dashboards
- Statistical Visualization: Risk scoring, trend analysis, and pattern recognition charts
- Network Mapping: Threat infrastructure relationship visualization
- Executive Reporting: High-level KPI dashboards with gauge and indicator widgets
- Timeline Analysis: Multi-dimensional temporal threat progression mapping
- Python Development: Custom analysis tools and automation
- Data Processing: Large-scale message parsing and analysis
- Pattern Recognition: Automated threat detection algorithms
- Technical Writing: Detailed analysis documentation
- Executive Briefings: High-level summary preparation
- Multi-Audience Reporting: LE, technical, and public formats
This section contains tools and scripts for analyzing DMV-related scams and fraudulent activities.
- PhoneInfoGA - Phone number investigation tool
- Usage:
phoneinfoga scan -n "+27618264263"
- Usage:
- Holehe - Email account finder across platforms
- Usage:
holehe suspicious@example.com
- Usage:
- Sherlock - Username lookup across social networks
- Usage:
sherlock username123
- Usage:
- Whois - Domain registration lookup
- Usage:
/opt/homebrew/opt/whois/bin/whois domain.com
- Usage:
- Nmap - Network scanning tool
- Usage:
nmap -F target.com
- Usage:
- ExifTool - Metadata extraction from files
- Usage:
exiftool suspicious_document.pdf
- Usage:
- Retry - Retry failed commands
- Usage:
retry -t 3 curl https://unreliable-site.com
- Usage:
- quick_lookup.sh - Analyze phone, email, or username
- url_analysis.sh - Analyze domain for scam indicators
- evidence_analysis.sh - Analyze file metadata and type
- Actionable intelligence for criminal investigation
- International cooperation coordination points
- Victim identification and protection guidance
- Public awareness campaign materials
- Scam identification training resources
- Prevention strategy documentation
- Threat intelligence sharing (IOCs)
- Methodology documentation for similar investigations
- OSINT techniques and tools demonstration
All analysis was conducted using:
- Sanitized Data: Personal information removed/anonymized
- Responsible Disclosure: Appropriate authority notification
- Legal Compliance: Analysis within authorized scope
- Victim Protection: No victim re-identification possible
π View Complete Visualization Suite
- Multi-panel interactive dashboard with risk scoring, geographic distribution, and threat actor capabilities
- Real-time filtering and hover tooltips for detailed analysis
- Executive-ready presentation with professional styling
- Interactive network diagram showing infrastructure relationships
- Color-coded entities (threat actors, infrastructure, targets)
- Dynamic positioning based on relationship proximity
- KPI gauges and indicators for campaign impact and mitigation status
- Progress tracking with milestone markers and trend analysis
- At-a-glance status assessment for leadership briefings
- Message activity frequency over campaign duration
- IOC discovery timeline with annotated investigation milestones
- Campaign phase identification and threat escalation patterns
- Detection method effectiveness with accuracy metrics
- Pattern confidence scoring and algorithm reliability
- Automation efficiency comparison (manual vs. automated)
- Risk score evolution throughout investigation
- Interactive: Plotly with HTML5/JavaScript
- Static: Matplotlib/Seaborn with high-resolution PNG output
- Professional: Corporate styling, responsive design, accessibility compliance
β
Data Science Skills: Statistical analysis, visualization design, interactive development
β
Executive Communication: Technical-to-business translation, KPI dashboards
β
Professional Presentation: Corporate-ready deliverables, multi-audience targeting
- Python 3.x: Analysis scripting and automation
- SQLite: Database analysis and extraction
- macOS Forensics: Native message database access
- OSINT Frameworks: Domain and infrastructure investigation
- Pandas: Data manipulation and analysis
- Matplotlib/Seaborn: Statistical visualization and charting
- Plotly: Interactive dashboard development
- NumPy: Numerical computing and statistical analysis
- TextBlob/NLTK: Natural language processing
- Requests: Web reconnaissance and verification
- Datetime: Timeline analysis and correlation
- Frontend: HTML5, CSS3, JavaScript (via Plotly)
- Backend: Python visualization libraries
- Output: High-res PNG (300 DPI), Interactive HTML
- Design: Professional styling, responsive layouts
This project demonstrates proficiency in:
- Digital Forensics: Real-world communication analysis
- Threat Intelligence: End-to-end intelligence lifecycle
- Malware Analysis: Social engineering campaign investigation
- Python Development: Custom security tool creation
- Technical Writing: Professional security documentation
- OSINT: Open source intelligence methodologies
- Threat Actors Identified: 1 criminal organization
- IOCs Generated: 4+ actionable indicators
- Analysis Timeframe: Campaign timeline reconstructed
- Intelligence Products: 3 tailored reports produced
- Automation Achieved: 90%+ of analysis automated
This analysis demonstrates capabilities relevant to:
- SOC Analyst: Threat detection and analysis
- Digital Forensics: Communication forensics and investigation
- Threat Intelligence: Analyst and researcher roles
- Incident Response: Campaign investigation and attribution
- Cybersecurity Consulting: Client threat assessment
For questions about methodology, collaboration opportunities, or professional inquiries:
- LinkedIn: [Your Professional Profile]
- Email: [Professional Contact]
- Portfolio: [Additional Security Projects]
This analysis was conducted for educational and cybersecurity research purposes. All data was obtained legally and ethically. Personal information has been sanitized to protect privacy while preserving analytical value. This work is intended to contribute to community protection and cybersecurity awareness.
No warranty is provided for the accuracy or completeness of this analysis. Use at your own discretion.

