CIA 2010 covert communication websites – Ciro Santilli (@cirosantilli)

CIA 2010 covert communication websites – Ciro Santilli (@cirosantilli)


The existence of the websites emerged in various stages, some of which may refer to this network or to other closely related communications failure since the published information is sometimes not clear enough.
May 21, 2011: various Iranian news outlets reported that:

30 individual suspected of spying for the US were arrested and 42 CIA operatives were identified in connection with the network.

The network, which was set up by a considerable number of seasoned CIA operatives in several countries, attempted to trick citizens into spying for them under the guise of issuing visa, helping with permanent residency, and making job and study offers.

Iranian sources include:The news were picked up and repeated by Western outlets on the same day e.g.:At this point there were still no clear indications that the recruitment had been made with websites, however later revelations would later imply that.

December 2014: McClathy DC reported on “Intelligence, defense whistleblowers remain mired in broken system” that CIA contractor John A. Reidy had started raising concerns about the security of a communication systems used by the CIA and other sources mention that he started this in 2008[ref] The focus of the article is how he was then ignored and silenced for raising these concerns, which later turned out to be correct and leading to an intelligence catastrophe that started in 2010.[ref][ref][ref]web.archive.org/web/20150101173203/ This appears to have come out after a heavily redacted appeal by Reidy against the CIA from October 2014 came into McClathy’s possession.[ref] While Reidy’s disclosures were responsible and don’t give much away, given the little that they disclose it feels extremely likely that they were related to the same system we are interested in. Even heavily redacted, the few unredacted snippets of the appeal are pure gold and give a little bit of insight into the internal workings of the CIA. Some selections:

As our efforts increased, we started to notice anomalies in our operations and conflicting intelligence reporting that indicated that several of our operations had been compromised. The indications ranged from [ redacted ] to sources abruptly and without reason ceasing all communications with us.

These warning signs were alarming due to the fact that our officers were approaching sources using [operational technique] (ledger item 16)

When our efforts began, ultimate operational authority rested with us. The other component provided the finances for the operation while we gave the operational guidance and the country specific knowledge.

knew we had a massive intelligence failure on our hands. All of our assets [ redacted ] were in jeopardy.

All of this information was collected under the project cryptonym [cryptonym] (ledger item 52)

Meanwhile throughout 2010, I started to hear about catastrophic intelligence failures in the government office I formally worked for. More than one government employee reached out to me and notified me that the “nightmare scenario” I had described and tried to prevent had transpired. I was told that in upwards of 70% of our operations had been compromised.

August 2018: Foreign Policy reported at “Botched CIA Communications System Helped Blow Cover of Chinese Agents” that:

It was considered one of the CIA’s worst failures in decades: Over a two-year period starting in late 2010, Chinese authorities systematically dismantled the agency’s network of agents across the country, executing dozens of suspected U.S. spies. But since then, a question has loomed over the entire debacle. How were the Chinese able to roll up the network?

and:

U.S. intelligence officers were also able to identify digital links between the covert communications system and the U.S. government itself, according to one former official—links the Chinese agencies almost certainly found as well. These digital links would have made it relatively easy for China to deduce that the covert communications system was being used by the CIA. In fact, some of these links pointed back to parts of the CIA’s own website, according to the former official.

Although no clear mention of websites is made in that article, the fact that there were “links” back to the CIA website strongly suggests that the communication was done through websites.

The report also reveals that there was a temporary “interim system” that new sources would use while they were being vetted, but that it used the same style of system as the main system. It would be cool if we managed to identify which sites are interim or not somehow:

When CIA officers begin working with a new source, they often use an interim covert communications system—in case the person turns out to be a double agent.
This interim, or “throwaway,” system, an encrypted digital program, allows for remote communication between an intelligence officer and a source, but it is also separated from the main communications system used with vetted sources, reducing the risk if an asset goes bad.
Although they used some of the same coding, the interim system and the main covert communication platform used in China at this time were supposed to be clearly separated.
The usage of of Google dorking is then mentioned:

In fact, the Iranians used Google to identify the website the CIA was using to communicate with agents.

It seems to us that this would have been very difficult on the generically themed websites that we have found so far. This suggests the existence of a separate recruitment website network, perhaps the one reported in 2011 by Iran offering VISAs. It would be plausible that such network could link back to the CIA and other government websites. Recruited agents would only then later use the comms network to send information back. The target countries may have first found the recruitment network, and then injected double agents into it, who later came to know about the comms network. TODO: it would be awesome to find some of those recruitment websites!

Another very interesting mention is the platform had been over extended beyond its original domain application, which is in part why things went so catastrophically bad:

Former U.S. officials said the internet-based platform, which was first used in war zones in the Middle East, was not built to withstand the sophisticated counterintelligence efforts of a state actor like China or Iran. “It was never meant to be used long term for people to talk to sources,” said one former official. “The issue was that it was working well for too long, with too many people. But it was an elementary system.”

December 2018: a followup Yahoo News article “At the CIA, a fix to communications system that left trail of dead agents remains elusive” gives an interesting internal organizational overview of the failed operation:

As a result, many who are directly responsible for working with sources on the ground within the CIA’s Directorate of Operations are furious

The fiascos in Iran and China continue to be sticking points between the Directorate of Operations and the CIA’s Directorate of Science and Technology (DS&T) — the technical scientists. “There is a disconnect between the two directorates,” said one former CIA official. “I’m not sure that will be fixed anytime soon.”

Entire careers in the CIA’s Office of Technical Service — the part of DS&T directly responsible for developing covert communications systems — were built on these internet-based systems, said a former senior official. Raising concerns about them was “like calling someone’s baby ugly,” said this person.

Much as in the case of Reidy, it is partly because of such internal dissatisfaction that so much has come out to the press, as agents feel that they have nowhere else to turn to.

The most important thing that this article gave were screenshots of nine websites, including the domain names of two of them: iraniangoals.com and iraniangoalkicks.com:

In addition, some sites bore strikingly similar names. For example, while Hosseini was communicating with the CIA through Iraniangoals.com, a site named Iraniangoalkicks.com was built for another informant. At least two dozen of the 350-plus sites produced by the CIA appeared to be messaging platforms for Iranian operatives, the analysts found.

The “350-plus” number is a bit random, given that their own analysts stated a much higher 885 in their report.

The article also reveals the critical flaw of the system; the usage of sequential IPs:

Online records they analyzed reveal the hosting space for these front websites was often purchased in bulk by the dozen, often from the same internet providers, on the same server space. The result was that numerical identifiers, or IP addresses, for many of these websites were sequential, much like houses on the same street.

It also mentions that other countries besides Iran and Chine were also likely targeted:
One of the most important information given in that report is the large number of sites found, 885, and the fact that they are available on Wayback Machine:The million dollar question is “which website did they use” and “how much does it cost if anything” since our investigation has so far had to piece together a few different hacky sources but didn’t spend any money. And a lot of money could be poured into this, e.g. DomainTools which might contain one of the largest historical databases seems to start at 15k USD / 1000 queries. One way to try and deduce which website they used is to look through their other research, e.g.:
They describe the most common subject matters and language of the websites:
They also give the dates range in which the system was active, which is very helpful for better targeting our searches:

The bulk of the websites that we discovered were active at various periods between 2004 and 2013.

And then a bomb, they claim to have found information regarding specific officers:This basically implies that they must have either

  • found some communication layer level identifier, e.g. domain name registration HTTPS certificate certificate because it is impossible to believe that real agent names would have been present on the website content itself!
  • or they may be instead talking about a separate recruitment network which offered the VISAs which we conjecture might have existed but currently have no examples of, and which might conceivably contain real embassy contacts

We have so for not yet found any such clear references to real individuals.

Chris, get fucked.

Thankfully however, either by carelessness or intentionally, this was easy to do by inspecting the address of the screenshots provided. For example, one of the URLs was:

https://www.reuters.com/investigates/special-report/assets/usa-spies-iran/screencap-activegaminginfo.com.jpg?v=192516290922

which corresponds to activegaminginfo.com.

The next step was to use our knowledge of the sequential IP flaw to look for more neighbor websites to the nine we knew of.
This was not so easy to do because the websites are down and so it requires historical data. But for our luck we found viewdns.info which allowed for 200 free historical queries (and they seem to have since removed this hard limit and moved to only throttling), leading to the discovery or some or our own new domains!
This gave us a larger website sample size in the order of the tens, which allowed us to better grasp more of the possible different styles of website and have a much better idea of what a good fingerprint would look like.

The next major and difficult step would be to find new IP ranges.

This was and still is a hacky heuristic process for us, but we’ve had the most success with the following methods:
Finally, at the very end of our pipeline, we were left with a a few hundred domains, and we just manually inspected them one by one as far as patience would allow it to confirm or discard the.
This section contains some of the most interesting and a few representative screenshots of the websites found.
Here are the websites likely targeting democracies based on their language and content found so far, defining a democracy as a country with score 7.0 or more in the Democracy index 2010:

  • France (6: affairesdumonde.com, guide-daventure.com, lesummumdelafinance.com, football-de-luxe.com, romulusactualites.com, suparakuvi.com)
  • Germany(2: dedrickonline.com, neighbour-news.com)
  • Italy (2: attivitaestremi.com, garanziadellasicurezza.com, podisticamondiale.com)
  • Spain (3: armashoy.com, montanismoaventura.com, ordenpolicial.com)
  • Brazil (2: noticiasmusica.net, vejaaeuropa.com)
  • South Korea (1: economicnewsbuzz.com)
  • Poland (1: boxingstop.net)

In English, so more deniable:”Almost democracies”:Ciro couldn’t help but feel as if looking through the Eyes of Sauron himself!

Snowden’s 2013 revelations particularly shocked USA “allies” with the fact that they were being spied upon, and as of the 2020’s, everybody knows this and has “stopped caring”, and or moved to end-to-end encryption by default. This is beautifully illustrated in the Snowden when Snowden talks about his time in Japan working for Dell as an undercover NSA operative:

NSA wanted to impress the Japanese. Show them our reach. They loved the live video from drones. This is Pakistan right now . They were not as excited about that we wanted their help to spy on the Japanese population. They said it was against their laws.
And we did not stop there. Once we had their communications we continued with the physical infrastructure. We sneaked into small programs in their power grids, dams, hospitals. The idea was that if Japan one day was not our allies we could turn off the lights.
Another noteworthy scene from that movie is Video 1. “Aptitude test on communication networks scene from the 2016 Snowden film”, where a bunch of new CIA recruits are told that:

Each of you is going to build a covert communications network in your home city [i.e. their fictitious foreign target location written on each person’s desk such as Berlin, Istanbul and Bangkok, not necessarily where they were actually born], you’re going to deploy it, backup your site, destroy it, and restore it again.

This section contains a list of all the websites that we consider belong to the network beyond reasonable doubt.
This section is about possible real-world information leaks found in the HTML of the pages. Domain DNS metadata may of course expose more, and is more likely to do so, this section is only about in-page findings, notably in the HTML.
We haven found much so far, but the ones we have are curious.
A similar thing happened to alljohnny.com
A few separate websites have an archive with the same pid parameter:

fightwithoutrules.com/20131220205811/?pid=2POQ7BC1G/index.html
half-court.net/20131223165013/?pid=2POQ7BC1G/index.html
health-men-today.com/20131223002237/?pid=2POQ7BC1G/index.html
intlnewsdaily.com/20131221121441/?pid=2POQ7BC1G/index.html
intoworldnews.com/20131217193621/?pid=2POQ7BC1G/index.html

It is unclear what it means. All of them contain something like:







Error. Page cannot be displayed. Please contact your service provider for more details. (11)

so looks like an archival artifact only.

This section tries to explain how the discoveries were made in more detail.

Some of the subsections are quite readable, while others are mostly data dumps and work logs, so bear with us.
Oleg Shakirov later discovered that the Carson one had its domain written right on the screenshot, as part of a watermark present on the original website itself. Therefore the URLs of all the websites were in one way or another essentially given on the article.
The full list of domains from screenshots is:
From The Reuters websites and others we’ve found, we can establish see some clear stylistic trends across the websites which would allow us to find other likely candidates upon inspection:

  • natural sounding, sometimes long-ish, domain names generally with 2 or 3 full words. Most in English language, but a few in Spanish, and very few in other languages like French.
  • shallow websites with a few tabs, many external links, sometimes many images, and few internal pages
  • common themes include:
  • .com and .net top-level domains, plus a few other very rare non .com .net TLDs, notably .info and .org
  • each one has one “communication mechanism file”: communication mechanisms
  • narrow page width like in the days of old, lots of images
  • split header images
  • some common pattern they follow in their news lists:

The most notable dissonance from the rest of the web is that there are no commercial looking website of companies, presumably because it was felt that it would be possible to verify the existence of such companies.

Most domains are the only domain for its IP, i.e. the websites are mostly private hosted. However we have later found many exceptions to this general indicator, so it should not be used as a strong exclusion rule.
It would be fun to actually reverse search into one of their stock image provider’s original images. Ones we’ve found:
Some possibly interesting searches include:

  • list all HTML comments, maybe something spicy was left over:
Varios of the non-English websites seem to have comments translating the content e.g.:

./noticiasmusica.net/20101230165001/index.html:

Alguns dos Melhores Sites Nacionais

This feels like it could be the translation helping the technical webdev team know what is what.

Some URLs existed both in HTML and .php extension, or were converted at some point:

allworldstatistics.com/20110207151941/comprehensivesources.html
allworldstatistics.com/20130818155225/comprehensivesources.php
A few of the PHP urls have weird IDs in them like omktf, juqwt and qlaqft:

./middle-east-newstoday.com/20100829004127/omktf/uirl.php?ok=461128
./newsandsportscentral.com/20100327130237/juqwt/eubcek.php?pe=747155
./pondernews.net/20100826031745/lldwg/qlaqft.php?fc=281298

we wonder what they mean.

As per:

grep . */index.html | grep 'binary file matches'

a few of the HTMLs are interpreted by grep as being binary:

grep: china-destinations.org/index.html: binary file matches
grep: classicalmusicboxonline.com/index.html: binary file matches
grep: driversinternationalgolf.com/index.html: binary file matches
grep: familyhealthonline.net/index.html: binary file matches
grep: grubbersworldrugbynews.com/index.html: binary file matches
grep: hai-pow.com/index.html: binary file matches
grep: hi-tech-today.com/index.html: binary file matches
grep: networkofnews.com/index.html: binary file matches
grep: nigeriastar.net/index.html: binary file matches
grep: noticias-caracas.com/index.html: binary file matches
grep: theentertainbiz.com/index.html: binary file matches
grep: thefilmcentre.com/index.html: binary file matches
grep: theinternationalgoal.com/index.html: binary file matches
grep: wildbirds-seasia.com/index.html: binary file matches
grep: worldedgenews.com/index.html: binary file matches
We started grepping with:and to just get the titles alone for visual inspection:

grep -ahi '' */index.html | sed -r 's/^\s*<title>//;s/<\/title>.*//'
Some mildly interesting facts include:

  • opensourcenewstoday.com is titled just as “Title”
    opensourcenewstoday.com/index.html:Title
  • a few sites are titled “Untitled Document” e.g.:
    media-coverage-now.com/index.html:Untitled Document
    newsandsportscentral.com/index.html:  Untitled Document
    newsincirculation.com/index.html:Untitled Document
    newsworldsite.com/index.html:Untitled Document
    primetimemovies.net/index.html:Untitled Document
    unganadormundial.com/index.html:Untitled Document

    This may have been the default title in Adobe Dreamweaver.

  • some others have empty title:
    aeronet-news.com/index.html:
    al-rashidrealestate.com/index.html:             <title/>
    arabicnewsunfiltered.com/index.html:<title/>
    dailynewsandsports.com/index.html:<title/>
    electronictechreviews.com/index.html:<title/>
    indirectfreekick.com/index.html:<title/>
    iran-newslink-today.com/index.html:<title/>
    iraniangoals.com/index.html:<title/>
    kickitnews.com/index.html:<title/>
    mediocampodefutbol.com/index.html:<title/>
    middle-east-newstoday.com/index.html:      <title/>
    mygadgettech.com/index.html:<title/>
    sayaara-auto.com/index.html:<title/>
    techwatchtoday.com/index.html:<title/>
    the-open-book-online.com/index.html:<title/>
    thenewsofpakistan.com/index.html:<title/>
    theworld-news.net/index.html:<title/>
    todaysengineering.com/index.html:<title/>
    todaysnewsreports.net/index.html:<title/>
    worldnewsandent.com/index.html:<title/></code></pre></div></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/html-title-element/_14">some others are titled just “index” or a variant of it:<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/html-title-element/_15" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>all-sport-headlines.com/index.html:<title>index
    europeannewsflash.com/index.html:Index
    fgnl.net/index.html:Index Page
    iraniangoalkicks.com/index.html:index
    just-the-news.com/index.html:index
    mide-news.com/index.html:index
    mytravelopian.com/index.html:Index
    noticiasdelmundolatino.com/index.html:index
    pakcricketgrd.com/index.html:  index
    pangawana.com/index.html:index
    sportsnewsfinder.com/index.html:index
    thenewseditor.com/index.html:index
    turkishnewslinks.com/index.html:index2
    wahidfutbol.com/index.html:index
    webscooper.com/index.html:index
    webworldsports.com/index.html:index
  • a few don’t have </code> at all:<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/html-title-element/_17" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>b2bworldglobal.com/index.html bailandstump.com/index.html businessexchangetoday.com/index.html commercialspacedesign.com/index.html court-masters.com/index.html flyingtimeline.com/index.html marketflows.net/index.html nouvellesetdesrapports.com/index.html senderosdemontana.com/index.html sixty2media.com/index.htm</code></pre></div></div></li></ul></div><p>It is impossible to tell if these were oversights, or intentional to simulate common web development quircks. But they are cute in any case.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_1" wp_automatic_readability="10.35">One promising way to find more of those would be with IP searches, since it was stated in the Reuters article that the CIA made the terrible mistake of using several contiguous IP blocks for those website. What a phenomenal OPSEC failure!!!</div><p>Our current results indicate that the typical IP range is about 30 IPs wide.</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_5" wp_automatic_readability="5.5428015564202">E.g. searching: viewdns.info/iphistory and considering only hits from 2011 or earlier we obtain:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_6"><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_7">capture-nature.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_10">activegaminginfo.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_13">iraniangoals.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_17">rastadirect.net</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_20">iraniangoalkicks.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_23">headlines2day.com<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_24"><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_25">118.139.174.1 – Singapore – Web Hosting Service – 2013-06-30. Source: viewdns.info</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_26">184.168.221.91 2013-08-12T06:17:39. Source: 2013 DNS Census grep</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_27">fightwithoutrules.com<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_28"><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_29">204.11.56.25 – British Virgin Islands – Confluence Networks Inc – 2013-09-26</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_30">208.91.197.19 – British Virgin Islands – Confluence Networks Inc – 2013-05-20</li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_31">212.4.17.38 – Milan – Italy – MCI Worldcom Italy Spa – 2012-03-03</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_32">fitness-dawg.com<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_33"><li id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_34">219.90.62.243 – Taiwan – Verizon Taiwan Co. Limited – 2012-01-11</li></ul></div></li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_36" wp_automatic_readability="7.4385964912281">Ciro then tried some of the other IPs, and soon hit gold.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ip-range-search/_39" wp_automatic_readability="5.7857142857143">Summaries of the IP range exploration done so far follows, combined data from all databases above.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_2" wp_automatic_readability="7.8677685950413">Here we list of suspected domains for which the correct IP was apparently not found since there are no neighbouring hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_3" wp_automatic_readability="14.375">These are suspicious, and suggest either that we didn’t obtain the correct reverse IP, or a change in CIA methodology from an older time at which they were not yet using the obscene IP ranges.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_4" wp_automatic_readability="14.12987012987">For example, in the case of inews-today.com, 2013 DNS Census gave one IP 193.203.49.212, but then viewdns.info gave another one 66.175.106.146 which fit into an existing IP range, and which assumed to be the correct IP of interest.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_6" wp_automatic_readability="7.3125">It is also possible that some of them are simply false positives so they should be taken with a grain of salt. Further reverse engineering e.g. of comms or HTML analysis might be able to exclude some of them.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_7" wp_automatic_readability="14.331210191083">It is interesting to note that Reuters seems to have featured disproportionately many hits from that range, one wonders why that happened. It is possible that they chose these because they actually didn’t have any nearby hits to give away less obvious information, though they did pick some from the ranges as wel.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_8" wp_automatic_readability="9.646017699115">In what follows we list the domains with possible reverse IPs and what was explored so far for each. We consider IPs not in a range to be uncertain, and that instead their domains might have been previously in a range which we</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_9" wp_automatic_readability="5.5410082768999">dailynewsandsports.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_10"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_11">216.119.129.94. rdns source: viewdns.info “location”: “United States”, “owner”: “A2 Hosting, Inc.”, “lastseen”: “2012-04-13”. Tested viewdns.info range: 216.119.129.85 – 216.119.129.86, 216.119.129.89 – 216.119.129.99, ran out of queries for 87 and 88<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_12"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_13">216.119.129.90: eastdairies.com 2011-04-04. Promising name and date, but no archives alas.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_14">216.119.129.97: miideaco.com 2016-02-01</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_15">216.119.129.114 Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches, also present on viewdns.info but at a later date from previous “location”: “United States”, “owner”: “A2 Hosting, Inc.”, “lastseen”: “2013-11-29”. Tested viewdns.info range: 216.119.129.109 – 216.119.129.119<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_16"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_17">216.119.129.110: dommoejmechty.com.ua. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_18">216.119.129.111: dailybeatz.com: Legit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_19">216.119.129.113:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_20"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_21">audreygeneve.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_22">reyzheng.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_23">jacintorey.com</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_24">216.119.129.114: dailynewsandsports.com. hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_25">216.119.129.115: afxchange.com legit/broken</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_26">216.119.129.116: danafunkfinancial.com: legit</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_27">208.73.33.194 on securitytrails.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_64">football-enthusiast.com:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_65"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_66">212.4.18.14: Tested viewdns.info range: 212.4.18.1 – 212.4.18.29. This is a curious case, rather close to 212.4.18.129 sightseeingnews.com, but not quite in the same range apparently. Viewdns.info also agrees on its history with only “212.4.18.14”, “location” : “Milan – Italy”, “owner” : “MCI Worldcom Italy Spa”, “lastseen” : “2013-06-30” of interest.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-without-nearby-ip-hits/_118" wp_automatic_readability="4.1372549019608">farsi-newsandweather.com:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/possible-hits/_1" wp_automatic_readability="8.0176211453744">Likely hits possible but whose archives is too broken to be easily certain. If:were to ever be found, these would be considered hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/possible-hits/_52" wp_automatic_readability="4.3356643356643">todaysolar.com. This might just be legit, but keeping it around just in case.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_1" wp_automatic_readability="7.4479768786127">62.22.60.49: telecom-headlines.com. UUNET in Spain. Found with: visual inspection of full 2013 DNS Census virtual host cleanup list just before worldnewsnetworking.com. Tested viewdns.info range: 62.22.60.34 – 62.22.60.66</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_2"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_3">62.22.60.33: newsperk.com. Almost certainly a hit. Stylistically perfect, rss-item. But no comms not found. Ennerving! 2011. English. Egypt. news. Later legitimately reused.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_4">62.22.60.34: freeslideshow.net. Legit? Attempting to open any HTML archives leads to an infinite page load loop, e.g. 2010. A subpage however exists: web.archive.org/web/20101230001640/ and appears legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_5">62.22.60.40: travel-passage.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_6">62.22.60.42: newsupdatesite.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_7">62.22.60.46: flyingtimeline.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_8">62.22.60.47: globalemergenceadvisorsbkserver.com. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_9">62.22.60.48: currentcommunique.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_10">62.22.60.49: telecom-headlines.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_11">62.22.60.52: collectedmedias.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_12">62.22.60.54: romulusactualites.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_13">62.22.60.55: thefilmcentre.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_14">62.22.60.56: traveltimenews.com. Hit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_53" wp_automatic_readability="8.0169050715215">63.131.229.12 cyberreportagenews.com. ADHOST in Coeur d’Alene – United States. Tested viewdns.info range: 63.131.228.248 – 63.131.229.30</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_54"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_55">63.131.229.2: fightskillsresource.com. Hit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_56">63.131.229.4: unitedterritorynews.com. Hit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_57">63.131.229.9: show-dustry.com. Hit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_58">63.131.229.10: afghanpoetry.net. Hit. Also at 74.254.12.166 in another range.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_59">63.131.229.11: mythriftytrip.com. Hit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_60">63.131.229.12: cyberreportagenews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_61">63.131.229.13: sunrise-news.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_62">63.131.229.15: cricketnewsforindia.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_63">63.131.229.16:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_67">63.131.229.18: itnl-xchange.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_68">63.131.229.20:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_69"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_70">fixashion.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_71">a few others</li></ul></div></li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_94" wp_automatic_readability="7.9062636881297">65.61.127.163 capture-nature.com. ADHOST in Greenacres – United States. whois.arin.net/rest/net/NET-65-61-96-0-1/pft?s=65.61.127.163: Net Range: 65.61.96.0 – 65.61.127.255. Organization. Name: TierPoint, LLC. Tested viewdns.info range: 65.61.127.149 –</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_95"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_96">65.61.127.46: anahuacchamber.com 2012-12-22T14:59:01</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_97">65.61.127.117: medicaresupplementalinsurance.com, 2013-08-21T09:49:41. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_98">65.61.127.121: counter-images.com 2013-08-22T11:14:44: web.archive.org/web/20110208173132/ Empty.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_99">65.61.127.125 zaphound.com 2013-08-21T02:25:40. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_100">65.61.127.130: ambitions.org 2013-08-22T01:43:40. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_101">65.61.127.161: european-footballer.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_102">65.61.127.163: capture-nature.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_103">65.61.127.164: futbolistico.net. 2012-02-20T03:25:33. Legit. web.archive.org/web/20130509004058/http://futbolistico.net/</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_104">65.61.127.165: travelconnectionsonline.com. Ciro initially though this might be a hit. But upon Googling it, there’s now a mirror at: travelconn.tripod.com/. Combined with the lack of a standard communications mechanism and the 2001 copyright, maybe it isn’t a hit after all</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_105">65.61.127.166: globalnewsbulletin.com: Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_106">65.61.127.167: internationalwhiskylounge.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_107">65.61.127.168: the-golden-rule.info 2013-09-20T02:13:52. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_108">65.61.127.169: crossovernews.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_109">65.61.127.170: newsidori.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_110">65.61.127.171: nrgconsultingandnews.com. Hit. 2013-08-13T18:45:05</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_111">65.61.127.172: premierstriker.com. Hit. 2012-01-11</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_112">65.61.127.174: dedrickonline.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_113">65.61.127.175: altworldnews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_114">65.61.127.176: american-historyonline.com. Hit. 2011-09-08</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_115">65.61.127.177: material-science.org. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_116">65.61.127.178: tee-shot.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_117">65.61.127.180: screencentral.info. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_118">65.61.127.181: worldnewsandtravel.com. Hit. 2011-11-13</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_119">65.61.127.182: pangawana.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_120">65.61.127.183: cutabovenews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_121">65.61.127.184: worldwildlifeadventure.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_122">65.61.127.186: explorealtmeds.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_123">65.61.127.194: 16 domains, so unclear.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_127">65.61.127.200: cdl-link.com (ipinf.ru). Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_128">65.61.127.222: asianwhitecoffee.com 2012-07-16T09:21:05 web.archive.org/web/20110903080036/ Could be legit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_129" wp_automatic_readability="8.1428571428571">66.45.179.205 noticiasporjanua.com. ADHOST in Edmonds – United States. Found with: 2013 DNS Census virtual host cleanup. Tested viewdns.info range: 66.45.179.187 – 66.45.179.223</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_130"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_131">66.45.179.187: mail03.gatesfoundation.org. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_132">66.45.179.192: thegraceofislam.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_133">66.45.179.193: arabicnewsunfiltered.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_134">66.45.179.194: raulsonsglobalnews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_135">66.45.179.195: aryannews.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_136">66.45.179.199: attivitaestremi.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_137">66.45.179.200: foodwineandsuch.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_138">66.45.179.201: hitthepavementnow.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_139">66.45.179.203: noticiascontinental.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_140">66.45.179.205: noticiasporjanua.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_141">66.45.179.206: podisticamondiale.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_142">66.45.179.207: reflectordenoticias.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_143">66.45.179.208: havenofgamerz.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_144">66.45.179.209: vejaaeuropa.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_145">66.45.179.210: sa-michigan.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_146">66.45.179.211: absolutebearing.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_147">66.45.179.212: grandretirement.net. No archives. cqcounter.com/whois/www/grandretirement.net.html blank image.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_148">66.45.179.213: myportaltonews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_149">66.45.179.214: investmentintellect.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_150">66.45.179.215: nigeriastar.net 2012-03-12. Hit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_171" wp_automatic_readability="5.2106424717999">66.104.173.186 myworldlymusic.com. XO-AS15 in United States. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 66.104.173.158 – 66.104.173.194</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_172"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_173">66.104.173.161: fanatic-pc-gamers.com. domainsbyproxy.com. 2013: Welcome to the US Petabox. cqcounter.com/whois/www/fanatic-pc-gamers.com.html somewhat in-style with large “Login to our Members Forum” message and copyright 2005.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_174">66.104.173.163: runakonews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_175">66.104.173.164: shoppingadventure.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_176">66.104.173.165: entertaining-ly.com. Hit. Network Solutions, LLC for Matthew Sorrell. tools.whoisxmlapi.com/reverse-whois-search hits:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_185">66.104.173.166: zubeenews.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_186">66.104.173.169: smart-financeology.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_187">66.104.173.173: remarkably has two potential hits, both shown in viewdns.info, and one of them was also in the 2013 DNS Census.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_191">66.104.173.175: media-coverage-now.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_192">66.104.173.176: jbc-online-news.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_193">66.104.173.177: webscooper.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_194">66.104.173.178: dk-dcinvestment.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_195">66.104.173.179: newsforthetech.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_196">66.104.173.180: stara-turistick.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_197">66.104.173.181: playbackpolitics.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_198">66.104.173.182: snapnewsfront.net. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_199">66.104.173.183: ingenuitytrendz.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_200">66.104.173.184: armashoy.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_201">66.104.173.185: baocontact.com. Hit. Godaddy for a “Denise Welch”:<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_202" wp_automatic_readability="10"><div wp_automatic_readability="15"><pre><code>"name": "Denise Welch", "organization": null, "street": "Box 288", "city": "Macdona", "state": "Texas", "postalCode": "78054", "country": "UNITED STATES",</code></pre></div></div><p>tools.whoisxmlapi.com/reverse-whois-search has 151 results, some inspections:Reducing a bit searching for Macdona as city gives only 19 hits:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_224">66.104.173.186: myworldlymusic.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_225">66.104.173.189: hitpoint-gaming.com. Hit. Network Solutions, LLC + perfect privacy.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_248" wp_automatic_readability="8.1823076923077">66.175.106.148 activegaminginfo.com. UUNET in United States. whois.arin.net/rest/net/NET-66-175-106-128-1/pft?s=66.175.106.148: Net Range: 66.175.106.128 – 66.175.106.159. Customer Name: DIAMOND-COLESON. Tested viewdns.info range: 66.175.106.131 – 66.175.106.178</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_249"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_250">66.175.106.10: nationalchecktrust.com. Legit?</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_251">66.175.106.134: paddlescoop.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_252">66.175.106.137: kessingerssportsnews.com. Hit. Network Solutions: Latimer, Daniel<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_253" wp_automatic_readability="11"><div wp_automatic_readability="17"><pre><code>"name": "Latimer, Daniel|ATTN KESSINGERSSPORTSNEWS.COM|care of Network Solutions", "organization": null, "street": "PO Box 459", "city": "PA", "state": "US", "postalCode": "18222", "country": "UNITED STATES",</code></pre></div></div><p>12 hits for name but nothing else looks promissing:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_267">66.175.106.138: factorforcenews.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_268">66.175.106.140: aroundthemiddleeast.com. No Wayback Machine hits. Last resolved: 2012-06-29. cqcounter.com/whois/www/aroundthemiddleeast.com.html not found.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_269">66.175.106.142: kanata-news.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_270">66.175.106.143: thecricketfan.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_271">66.175.106.146: inews-today.com. Initially found with 2013 DNS Census virtual host cleanup heuristic keyword searches which gave IP address 193.203.49.212. But that has no nearby hits. 66.175.106.146 was later found on viewdns.info, and slotted into this other existing IP range.<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_272"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_273">193.203.49.211 datingso.com: legit? Russian dating website</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_274">193.203.49.212 inews-today.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_275">193.203.49.223 zatysi.net: legit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_276">193.203.49.226 kinotopik.com: legit? Russian</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_277">193.203.49.229 rotor-volgograd.com. Legit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_278">193.203.49.233 ordercytotec.com. Broken. cqcounter.com/whois/www/ordercytotec.com.html not found.</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_279">66.175.106.147: starwarsweb.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_280">66.175.106.148: activegaminginfo.com. Hit. Network Solutions, LLC for Elizabeth Corral. tools.whoisxmlapi.com/reverse-whois-search reverse search “Corral, Elizabeth” only has that hit</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_281">66.175.106.149: feedsdemexicoyelmundo.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_282">66.175.106.150: noticiasmusica.net. Hit. Network Solutions, LLC for Megan See. tools.whoisxmlapi.com/reverse-whois-search only this hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_283">66.175.106.155: atomworldnews.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_284">66.175.106.158: nouvellesetdesrapports.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_285">66.175.106.166: exchange.katzbarron.com. Legit. Reverse IP source: 2012 Internet Census</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_286">66.175.106.183: mail.lfdatacenter.com. No archives.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_287" wp_automatic_readability="7.0560859188544">66.237.236.247 comunidaddenoticias.com. XO-AS15 in United States. Tested viewdns.info range: 66.237.236.222 – 66.237.236.254</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_288"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_289">66.237.236.227: newsandmusicminute.com. Hit. Network Solutions, LLC for:<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_290" wp_automatic_readability="10.5"><div wp_automatic_readability="16"><pre><code>"name": "Alger, Jennifer", "organization": null, "street": "PO Box 459", "city": "Drums", "state": "PA", "postalCode": "18222", "country": "UNITED STATES",</code></pre></div></div><p>tools.whoisxmlapi.com/reverse-whois-search search for “Alger, Jennifer” has four domain:but more interestingly this address is the same as other hits: activegameinfo.com and noticiasmusica.net! “PO Box 459” anywhere search has 10k+ domains and so does Drums so not helping.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_296">66.237.236.229: pearls-playlist.com 2011-11-13. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_297">66.237.236.230: beyondthefringe.info 2013-01-02. Hit. GoDaddy.com for<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_298" wp_automatic_readability="11.5"><div wp_automatic_readability="18"><pre><code>"registrantContact": { "name": "Nathan Stock", "organization": null, "street": "PO Box 61654", "city": "Savannah", "state": "Georgia", "postalCode": "31420", "country": "UNITED STATES", "email": "nathanstock@earthlink.net", "telephone": "19129206355",</code></pre></div></div><p>no hits for that name of reversed.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_299">66.237.236.231: primetimemovies.net 2011-06-22. Hit. No whois records.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_300">66.237.236.235: persephneintl.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_301">66.237.236.236: directoalgrano.net 2012-01-23. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_302">66.237.236.240: actualizaciondebeisbol.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_303">66.237.236.243: mygadgettech.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_304">66.237.236.247: comunidaddenoticias.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_305">66.237.236.249: sumerjaseahora.com. Hit. domainsbyproxy.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_326" wp_automatic_readability="8.8437617085051">72.34.53.174 technologytodayandtomorrow.com. IHNET in United States. This IP is special. This IP is somehow closely linked to the “Mass Deface III” pastebin as it seems to have been hosted by Condor hosting. They also have many old sites, and links to Russia which is apparently where this was hosted.</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_327"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_328">viewdns.info/iphistory/?domain=technologytodayandtomorrow.com<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_329"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_330">68.178.232.100 United States AS-26496-GO-DADDY-COM-LLC 2011-11-13 virtual</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_331">72.34.53.174 United States IHNET 2011-09-08. Tested viewdns.info range: 72.34.53.164 72.34.53.184 viewdns.info/reverseip/?t=1&host=72.34.53.174 went through all of them;<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_332"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_333">hits<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_334"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_335">electronictechreviews.com 2011-09-08 domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_336">recursosdenoticias.com 2012-06-29 domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_337">todaysnewsandweather-ru.com 2012-01-11 domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_338">myonlinegamesource.com 2012-01-11 Godaddy:<div class="code" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_339" wp_automatic_readability="10"><div wp_automatic_readability="15"><pre><code>"name": "Brandon Stiltner", "organization": null, "street": "1200 Brookstone Centre Pkwy", "city": "Columbus", "state": "Georgia", "postalCode": "31904", "country": "UNITED STATES",</code></pre></div></div><p>has two domains:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_343">mytravelopian.com 2011-04-04 domainsbyproxy.com</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_344">possible hits<br />* intloil.org 2012-04-27. 2011, Possible hit, a bit off style, but possibly because too broken. rss-item. Copyright 2005. Present at pastebin.com/CTXnhjeSp (now lost without archives I’m an idiot). cqcounter.com/whois/www/intloil.org.html from 2011 somewhat in style but interestingly also similarly broken. The “Login” button leads to another domain: “condorsecure.com”: web.archive.org/web/20110721052801/ which is megaweird and is what is mentioned in the “Mass Deface III” pastebin. domainsbyproxy.com. A similar thing happens in europeantravelcafe.com but to another domain.<br />* islamicnewsonline.com 2013-03-23. No archives in date range. cqcounter.com/whois/www/islamicnewsonline.com.html not found, sad</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_345">not hits</li></ul></div></li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_356">securitytrails.com/domain/technologytodayandtomorrow.com/history/a same</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_417" wp_automatic_readability="3.7479166666667">173.208.81.2 LEASEWEB-USA-CHI in Lombard – United States:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_418"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_419">weblognewsinfo.com:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_432">newsincirculation.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_467" wp_automatic_readability="5.4679715302491">199.85.212.118 just-kidding-news.com. ATT-INTERNET4 in United States.</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_468"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_469">199.85.212.118 rdns source: 2013 DNS Census virtual host cleanup heuristic keyword searches, dnshistory.org (2009-09-23 -> 2011-01-25) and viewdns.info: “location”: “United States”, “owner”: “VIMRO, LLC”, “lastseen”: “2012-01-11”. Tested viewdns.info range: 199.85.212.95 – 199.85.212.128. Not sure worth it given the many 2013 DNS Census misses surrounding.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_495">68.178.232.100: see rastadirect.net. rdns source: viewdns.info: “location”: “United States”, “owner”: “GoDaddy.com, LLC”, “lastseen”: “2012-06-29”</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_496">209.85.45.84. Tested viewdns.info range: 209.85.45.74 – 209.85.45.94.<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_497"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_498">209.85.45.2: dz8.dailyrazor.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_499">209.85.45.2: jr4consulting.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_500">209.85.45.41: guitarzza.com. No archives of time.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_501">209.85.45.46: evergraindecking.com. No archives of time.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_502">209.85.45.114: mauritiuspropertyconsultant.com. Legit/ broken.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_503">209.85.45.160: bieltvedt.net. No archives of time.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_504">209.85.45.160: golfstats.dk. No archives.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_505">209.85.45.225: infokus.ca</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_506">209.85.45.225: mail.tomlatham.net</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_507">209.85.45.225: mail.tomlatham.org</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_508">209.85.45.239: flavacationcenter.com</li></ul></div></li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_509" wp_automatic_readability="8.3194706994329">204.176.38.143 noticiassofisticadas.com. UUNET in United States. Found with: 2013 DNS Census virtual host cleanup. Tested viewdns.info range: 204.176.38.125 – 204.176.38.154</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_510"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_511">204.176.38.130: i-pressnews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_512">204.176.38.132: turkishnewslinks.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_513">204.176.38.134: photographyarecord.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_514">204.176.38.135: breakingthewicket.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_515">204.176.38.136: politicalworldtoday.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_516">204.176.38.137: hi-tech-today.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_517">204.176.38.138: continental-business-news.com. TODO. rss-item, split images. 2011. Cannot find comms. Also header and footer are not limited width which is unusual. Further HTML similarity reversing would be needed.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_518">204.176.38.139: bigscreenbattles.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_519">204.176.38.141: rakotafootball.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_520">204.176.38.142: senderosdemontana.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_521">204.176.38.143: noticiassofisticadas.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_522">204.176.38.144: techno-today.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_523">204.176.38.145: tickettonews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_524">204.176.38.146: dps-digitalphotosharing.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_525">204.176.38.147: theputtingreen.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_526">204.176.38.149: sportsnewstodayar.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_527">204.176.38.150: kairuafricanews.com. Hit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_528" wp_automatic_readability="7.1950092421442">204.176.39.115 globalprovincesnews.com. UUNET in United States. Tested viewdns.info range: 204.176.39.93 – 204.176.39.124</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_543" wp_automatic_readability="3.5040967616075">207.150.191.68 technologypresstoday.com. Saudi Telecom Company JSC in Saudi Arabia.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_604" wp_automatic_readability="6.9718309859155">208.93.112.105 fastnews-online.com. TULIP-SYSTEMS in United States. Checked viewdns.info range: 208.93.112.90 – 208.93.112.155</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_618" wp_automatic_readability="5.7371134020619">208.254.38.39 todaysengineering.com. COLO-PREM-VZB in United States.</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_619"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_620">Tested viewdns.info range: 208.254.38.9 – 208.254.38.86. Weirdly empty, doesn’t even show the domain iteslf!</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_624">68.178.232.100: source: securitytrails.com. 2009-11-24 – 2009-12-11, GoDaddy.com, LLC</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_625" wp_automatic_readability="7.656976744186">208.254.40.117 worldnewsandent.com. COLO-PREM-VZB in United States. whois.arin.net/rest/net/NET-208-192-0-0-1/pft?s=208.254.40.117: Net Range 208.192.0.0 – 208.255.255.255. Tested viewdns.info range: 208.254.40.92 – 208.254.40.135</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_626"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_627">208.254.40.96: sixty2media.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_628">208.254.40.99: newspoliticssource.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_629">208.254.40.110 musical-fortune.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_630">208.254.40.113: ashoka-gemstones.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_631">208.254.40.117: worldnewsandent.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_632">208.254.40.124: riskandrewardnews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_633">208.254.40.129: mailb.casella.com. Legit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_634" wp_automatic_readability="7.307596513076">208.254.42.205 driversinternationalgolf.com. COLO-PREM-VZB in United States. Tested viewdns.info range: 208.254.42.178 – 208.254.42.233.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_655" wp_automatic_readability="7.6733490566038">210.80.75.55 philippinenewsonline.net. UUNET in Australia. Tested viewdns.info range: 210.80.75.30 – 210.80.75.67</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_656"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_657">210.80.75.35: aroundtheworldnews.net. No archives. ipinf.ru/domains/210.80.75.33/ disagrees and places it at .33.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_658">210.80.75.36: e-commodities.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_659">210.80.75.37: trekkingtoday.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_660">210.80.75.41: multinews-33.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_661">210.80.75.42: movimientodenticias.com. No archives. cqcounter.com/whois/www/movimientodenticias.com.html blank.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_662">210.80.75.43: gulfandmiddleeastnews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_663">210.80.75.44: whirlybirdinflight.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_664">210.80.75.45: kings-game.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_665">210.80.75.46: topglobalnewsdaily.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_666">210.80.75.49: recipe-dujour.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_667">210.80.75.53: sportsman-elite.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_668">210.80.75.55: philippinenewsonline.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_669">210.80.75.56: technewsforme.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_670">210.80.75.59: goldeportesnoticias.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_671">210.80.75.68: gigabyte-usa.com. Legit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_679" wp_automatic_readability="9.633355393779">212.4.17.38 fightwithoutrules.com. UUNET in Cassano d’Adda – Italy. whois.arin.net/rest/net/NET-208-192-0-0-1/pft?s=208.254.40.117. Net Range: 208.192.0.0 – 208.255.255.255. Organization: Name: Verizon Business. Tested viewdns.info range: see 212.4.16.* above</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_680"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_681">212.4.17.38: fightwithoutrules.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_682">212.4.17.41: newtechfrontier.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_683">212.4.17.43: smart-travel-consultant.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_684">212.4.17.46: atentlaloc.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_685">212.4.17.53: newsresolution.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_686">212.4.17.56: lesummumdelafinance.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_687">212.4.17.56: thepinnacleoffinance.com. No Wayback machine archives. cqcounter.com/whois/www/thepinnacleoffinance.com.html blank.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_688">212.4.17.61: tech-stop.org. Archive: 2011. Feels likely. No commons found. .org hit? Has subdomain “gear.tech-stop.org” according to 2013 DNS Census, which suggests CGI comms, but no links to it</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_689">212.4.17.98: topbillingsite.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_690">212.4.17.122: b2bworldglobal.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_691">212.4.17.125: worldaroundyunnan.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_692">212.4.17.160: localtoglobalnews.com. Hit.</li></ul></div><p>There were also some other reverse IP hits for fightwithoutrules.com, but no CIA websites there:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_693"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_694">204.11.56.25 – British Virgin Islands – Confluence Networks Inc – 2013-09-26. Many domains.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_695">208.91.197.19 – British Virgin Islands – Confluence Networks Inc – 2013-05-20. Many domains.</li></ul></div><p>Other hits:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_696"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_697">208.91.197.132. rdns source: viewdns.info: “location” : “British Virgin Islands”, “owner” : “Confluence Networks Inc”, “lastseen” : “2013-09-26”. So this is after the previous one, unlikely to be correct.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_698">205.178.189.131. source: securitytrails.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_726" wp_automatic_readability="7.6236033519553">212.209.79.40 hydradraco.com. UUNET in Sweden. Found with: visual inspection of full 2013 DNS Census virtual host cleanup list just after globalbaseballnews.com. Tested viewdns.info range: 212.209.79.35 – 212.209.79.63</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_727"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_728">212.209.79.34: fgnl.net. Hit. securitytrails.com provides IP history:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_729"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_730">212.209.79.34: 2008-09-01 – 2010-04-19.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_731">212.4.18.133: 2010-04-19 – 2019-06-19. Tested viewdns.info range: 212.4.18.122 – 212.4.18.148</li></ul></div><p>both under MCI Communications Services, Inc. d/b/a Verizon Business.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_732">212.209.79.37: fitness-sources.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_733">212.209.79.40: hydradraco.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_734">212.209.79.41: noticiasdelmundolatino.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_735">212.209.79.42: suparakuvi.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_736">212.209.79.44: myigadgets.net. Unclear. 2010. tech. Contains some helpers to: iGoogle. This page is very interesting. and quite different from the others, as it contains highly specialized functionality. No known comms found. The choice of homepage languages is also very suspicious: Arabic, Farsi, French, Chinese and Spanish.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_737">212.209.79.46: cetusdelph.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_738">212.209.79.47: willtoworship.com. Hit. domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_739">212.209.79.48: themvconnection.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_740">212.209.79.51: pi-resources.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_741">212.209.79.52: newel-adserver.com. Redirects to newel.com which is legit. cqcounter.com/whois/www/newel-adserver.com.html blank.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_742">212.209.79.53: ourscubaworld.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_743">212.209.79.58: tech-love-home.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_744">212.209.79.60: first-solo-aviation.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_745">212.209.79.61: china-destinations.org. Hit.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_764" wp_automatic_readability="4.095">216.93.248.194 esmundonoticias.com. TWDX in Chelmsford – United States.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_805" wp_automatic_readability="7.0919234856536">216.105.98.152: modernarabicnews.com. SAVVY-NET in United States. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 216.105.98.125 – 216.105.98.167</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_806"><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_807">216.105.98.118:</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_811">216.105.98.132: europeantravelcafe.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_812">216.105.98.134: fuenteneta.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_813">216.105.98.135: ilat-news.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_814">216.105.98.136: etherealinspirations.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_815">216.105.98.137: the-news-zone.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_816">216.105.98.138: photozoomnews.com. No archives. cqcounter.com/whois/www/photozoomnews.com.html empty</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_817">216.105.98.139: cultura-digital.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_818">216.105.98.140: uaeshoppingspree.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_819">216.105.98.141: jabarifootball.com. No archives. “Jabari” is a Swahili/Arabic name<sup class="ref">[ref]</sup>. cqcounter.com/whois/www/jabarifootball.com.html not found.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_820">216.105.98.142: globalreview-ar.com. No archives. Shame, could have been our first Argentinian site. cqcounter.com/whois/www/globalreview-ar.com.html empty.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_821">216.105.98.144: garanziadellasicurezza.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_822">216.105.98.145: montanismoaventura.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_823">216.105.98.146: large-format-news.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_824">216.105.98.147: nepalnewsbrief.com. Hit. dnshistory.org marks it as having IP 2010-03-10 -> 2010-08-15 216.169.148.94 <sup class="ref">[ref]</sup>. This range does feel a bit different from the others, too many broken archives, and relatively early ones too. Explored viewdns.info range: 216.169.148.84 – 216.169.148.104, empty for period. domainsbyproxy.com.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_825">216.105.98.148: teclafinance.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_826">216.105.98.149: entreman.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_827">216.105.98.152: modernarabicnews.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_828">216.105.98.153: global-headlines.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_829">216.105.98.154: everythingcricket.org. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_830">216.105.98.156: familyhealthonline.net. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_831">216.105.98.157: delacorne.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_832">216.105.98.158: econfutures.com. Hit.</li><li id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_833">216.105.98.161: kstcloud.com. No archives. cqcounter.com/whois/www/kstcloud.com.html not found</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/hits-with-nearby-ip-hits/_834" wp_automatic_readability="6.9662337662338">219.90.61.123 journeystravelled.com. UUNET in Taiwan. Tested viewdns.info range: 219.90.61.100 – 219.90.61.133</div><p><b><span title="Tags" class="fa-solid-900 icon"></span> Tagged</b></p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/find-missing-hits-in-ip-ranges/_1" wp_automatic_readability="5.6184210526316">All IP ranges have some holes in them for which we don’t have a domain name.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/find-missing-hits-in-ip-ranges/_2" wp_automatic_readability="6.7572815533981">It is because there was nothing there, or just because we don’t have a good enough reverse IP database?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/find-missing-hits-in-ip-ranges/_4" wp_automatic_readability="5.6274509803922">Censys is another option that would be good to try.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/find-missing-hits-in-ip-ranges/_5" wp_automatic_readability="5.90625">Putting 140 USD into WhoisXMLAPI to get all whois histories of interest for possible reverse searches would also be of interest.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/how-did-alexa-find-the-domains/_1" wp_automatic_readability="26.53164556962">It can’t be HTML crawl because presumably there wouldn’t have been links to those websites? Presumably this is why Common Crawl doesn’t seem to have any hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/how-did-alexa-find-the-domains/_2" wp_automatic_readability="26.947368421053">So they must have had some kind of DNS A record database?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/how-did-alexa-find-the-domains/_3" wp_automatic_readability="30.884615384615">Or would IPv4 sweep have worked, without the <code>Host</code> header with the CIA’s setup?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/how-did-alexa-find-the-domains/_4" wp_automatic_readability="29.29347826087">The same question also applies to the 2013 DNS Census. It has less hits, but still has many.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/how-did-alexa-find-the-domains/_5" wp_automatic_readability="30.745098039216">Whatever they did, we are so so glad that they did!</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/are-there-org-hits/_6" wp_automatic_readability="6.6646706586826">Others that had been previously found in IP ranges but without clear comms:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/are-there-org-hits/_7"><li id="cirosantilli/cia-2010-covert-communication-websites/are-there-org-hits/_8">65.61.127.177: material-science.org</li><li id="cirosantilli/cia-2010-covert-communication-websites/are-there-org-hits/_9">212.4.17.61: tech-stop.org</li><li id="cirosantilli/cia-2010-covert-communication-websites/are-there-org-hits/_10">74.116.72.244 arborstribune.org</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/are-there-org-hits/_11" wp_automatic_readability="9.6031746031746">.org is very rare, and has been excluded from some of our search heuristics. That was a shame, but likely not much was missed.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/data-sources/_1" wp_automatic_readability="9.1907514450867">This is a dark art, and many of the sources are shady as fuck! We often have no idea of their methodology. Also no source is fully complete. We just piece up as best we can.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/reuters-article/_2">www.reuters.com/investigates/special-report/usa-spies-iran</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/reuters-article/_3">This is our primary data source, the first article that pointed out a few specific CIA websites which then served as the basis for all of our research.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/reuters-article/_4" wp_automatic_readability="21.44502617801">We take the truth of this article as an axiom. And then all we claim is that all other websites found were made by the same people due to strong shared design principles of the such websites.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine/_5" wp_automatic_readability="8.8636363636364">The Common Crawl project attempts in part to address this lack of querriability, but we haven’t managed to extract any hits from it.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning/_2" wp_automatic_readability="12.12676056338">This allows to filter down 10 thousands of possible domains in a few hours. But 100s of thousands would be too much. This is because you have to query exactly one URL at a time, and they possibly rate limit IPs. But no IP blacklisting so far after several hours, so it’s not that bad.</div><p>From then on, you can just manually inspect for hist on your browser.</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_9" wp_automatic_readability="9.1868131868132">Since archive is so abysmal in its data access, e.g. a Google BigQuery would solve our issues in seconds, we have to come up with creative ways of getting around their IP throttling.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_10" wp_automatic_readability="6.5434782608696">The CIA doesn’t play fair. They’re actually the exact opposite of fair. So neither shall we.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_12" wp_automatic_readability="8.9294117647059">This should allow a full sweep of the 4.5M records in 2013 DNS Census virtual host cleanup in a reasonable amount of time. After JAR/SWF/CGI filtering we obtained 5.8k domains, so a reduction factor of about 1 million with likely very few losses. Not bad.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_13" wp_automatic_readability="17.174050632911">5.8k is still a bit annoying to fully go over however, so we can also try to count CDX hits to the domains and remove anything with too many hits, since the CIA websites basically have very few archives:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_14" wp_automatic_readability="10.5"><div wp_automatic_readability="16"><pre><code>cd 2013-dns-census-a-novirt-domains.txt.cdx ./cdx-tor.sh -d out.post domain-list.txt cd out.post.cdx cut -d' ' -f1 out | uniq -c | sort -k1 -n | awk 'match($2, /([^,]+),([^)]+)/, a) {printf("%s.%s %d\n", a[2], a[1], $1)}' > out.count</code></pre></div></div><p>This gives us something like:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_15" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>12654montana.com 1 aeronet-news.com 1 atohms.com 1 av3net.com 1 beechstreetas400.com 1</code></pre></div></div><p>sorted by increasing hit counts, so we can go down as far as patience allows for!</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_16" wp_automatic_readability="6.86">New results from a full CDX scan of 2013-dns-census-a-novirt.csv:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_17"><li id="cirosantilli/cia-2010-covert-communication-websites/wayback-machine-cdx-scanning-with-tor-parallelization/_18">219.90.61.123 journeystravelled.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/js-cdx-scanning/_1" wp_automatic_readability="10.838235294118">JAR, SWF and CGI-bin scanning by path only is fine, since there are relatively few of those. But .js scanning by path only is too broad.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/js-cdx-scanning/_2" wp_automatic_readability="18.734831460674">One option would be to filter out by size, an information that is contained on the CDX. Let’s check typical ones:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/js-cdx-scanning/_3" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>grep -f <(jq -r '.[]|select(select(.comms)|.comms|test("\\.js"))|.host' ../media/cia-2010-covert-communication-websites/hits.json) out | out.jshits.cdx sort -n -k7 out.jshits.cdx</code></pre></div></div><p>Ignoring some obvious unrelated non-comms files visually we get a range of about 2732 to 3632:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/js-cdx-scanning/_4" wp_automatic_readability="8"><div wp_automatic_readability="11"><pre><code>net,hollywoodscreen)/current.js 20110106082232 text/javascript 200 XY5NHVW7UMFS3WSKPXLOQ5DJA34POXMV 2732 com,amishkanews)/amishkanewss.js 20110208032713 text/javascript 200 S5ZWJ53JFSLUSJVXBBA3NBJXNYLNCI4E 3632</code></pre></div></div><p>This ignores the obviously atypical JavaScript with SHAs from iranfootballsource, and the particularly small old menu.js from cutabovenews.com, which we embed into cia-2010-covert-communication-websites/cdx-post-js.sh.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/js-cdx-scanning/_5" wp_automatic_readability="7.5245901639344">The size helps a bit, but it’s not insanely good unfortunately, only about 3x, these are some common JS sizes right there!</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/viewdns-info/_3" wp_automatic_readability="5.7142857142857">Accounts used so far: 6 (1500 reverse IP checks).</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/viewdns-info/_4" wp_automatic_readability="9.8051948051948">Their historic DNS and reverse DNS info was very valuable, and served as Ciro’s the initial entry point to finding hits in the IP ranges given by Reuters.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/viewdns-info/_6" wp_automatic_readability="9.8550724637681">Since this source is so scarce and valuable, we have been quite careful to note down all the domain and IP ranges that have been explored.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/viewdns-info/_11" wp_automatic_readability="5.74">For domain to IP queries from the API you should use “iphistory” viewdns.info/api/docs/ip-history.php:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/viewdns-info/_12" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>curl 'https://api.viewdns.info/iphistory/?domain=todaysengineering.com&apikey=$APIKEY&output=json'</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/domaintools/_1" wp_automatic_readability="8.5153846153846">TODO can they do historical reverse IP or not? I.e. determine which domains were hosted on a given IP at a given date in the past?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dns-census-2013/_3" wp_automatic_readability="7.7096774193548">Hit overlap:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/dns-census-2013/_4" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>jq -r '.[].host' ../media/cia-2010-covert-communication-websites/hits.json ) | xargs -I{} sqlite3 aiddcu.sqlite "select * from t where d = '{}'"</code></pre></div></div><p>Domain hit count when we were at 279 hits: 142 hits, so about half of the hits were present.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dns-census-2013/_5" wp_automatic_readability="9.0196078431373">The timing of the database is perfect for this project, it is as if the CIA had planted it themselves!</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_1" wp_automatic_readability="8.3259911894273">We’ve noticed that often when there is a hit range:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_2"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_3">there is only one IP for each domain</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_4">there is a range of about 20-30 of those</li></ul></div><p>and that this does not seem to be that common. Let’s see if that is a reasonable fingerprint or not.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_5" wp_automatic_readability="8.4347826086957">Note that although this is the most common case, we have found multiple hits that viewdns.info maps to the same IP.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_6" wp_automatic_readability="13.506711409396">First we create a table <code>u</code> (<code>unique</code>) that only have domains which are the only domain for an IP, let’s see by how much that lowers the 191 M total unique domains:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_7" wp_automatic_readability="8"><div wp_automatic_readability="11"><pre><code>time sqlite3 u.sqlite 'create table t (d text, i text)' time sqlite3 av.sqlite -cmd "attach 'u.sqlite' as u" "insert into u.t select min(d) as d, min(i) as i from t where d not like '%.%.%' group by i having count(distinct d) = 1"</code></pre></div></div><p>The <code>not like '%.%.%'</code> removes subdomains from the counts so that CGI comms are still included, and <code>distinct</code> in <code>count(distinct</code> is because we have multiple entries at different timestamps for some of the hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_8" wp_automatic_readability="10.573275862069">Let’s start with the 208 subset to see how it goes:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_9" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>time sqlite3 av.sqlite -cmd "attach 'u.sqlite' as u" "insert into u.t select min(d) as d, min(i) as i from t where i glob '208.*' and d not like '%.%.%' and (d like '%.com' or d like '%.net') group by i having count(distinct d) = 1"</code></pre></div></div><p>OK, after we fixed bugs with the above we are down to 4 million lines with unique domain/IP pairs and which contains all of the original hits! Almost certainly more are to be found!</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_10" wp_automatic_readability="8.0504587155963">This data is so valuable that we’ve decided to upload it to: archive.org/details/2013-dns-census-a-novirt.csv Format:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_11" wp_automatic_readability="11.5"><div wp_automatic_readability="18"><pre><code>8,chrisjmcgregor.com 11,80end.com 28,fine5.net 38,bestarabictv.com 49,xy005.com 50,cmsasoccer.com 80,museemontpellier.net 100,newtiger.com 108,lps-promptservice.com 111,bridesmaiddressesshow.com</code></pre></div></div><p>The numbers of the first column are the IPs as a 32-bit integer representation, which is more useful to search for ranges in.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_12" wp_automatic_readability="8.2611940298507">To make a histogram with the distribution of the single hostname IPs:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_13" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>#!/usr/bin/env bash bin=$((2**24)) sqlite3 2013-dns-census-a-novirt.sqlite -cmd '.mode csv' >2013-dns-census-a-novirt-hist.csv <<eof select="" i="" sum="" from="" floor="" as="" count="" cnt="" t="" group="" by="" union="" generate_series="" eof="" gnuplot="" terminal="" svg="" size="" output="" datafile="" separator="" tics="" scale="" key="" xrange="" title="" of="" ips="" with="" a="" single="" hostname="" xlabel="" first="" byte="" ylabel="" using="" labels=""/></code></pre></div></div><p>Which gives the following useless noise, there is basically no pattern:</p><div class="figure"><figure id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup/_14"><div class="float-wrap"></div></figure></div></div><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_2" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>grep -e news -e noticias -e nouvelles -e world -e global</code></pre></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_3">iran + football:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_4"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_5">iranfootballsource.com: the third hit for this area after the two given by Reuters! Epic.</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_6" wp_automatic_readability="9.7596153846154">3 easy hits with “noticias” (news in Portuguese or Spanish”), uncovering two brand new ip ranges:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_7"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_8">66.45.179.205 noticiasporjanua.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_9">66.237.236.247 comunidaddenoticias.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_10">204.176.38.143 noticiassofisticadas.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_11" wp_automatic_readability="6.8803418803419">Let’s see some French “nouvelles/actualites” for those tumultuous Maghrebis:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_12"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_13">216.97.231.56 nouvelles-d-aujourdhuis.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_14">news + world:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_15"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_16">210.80.75.55 philippinenewsonline.net</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_17">news + global:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_18"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_19">204.176.39.115 globalprovincesnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_20">212.209.74.105 globalbaseballnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_21">212.209.79.40: hydradraco.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_22" wp_automatic_readability="8.2220338983051">OK, I’ve decided to do a complete Wayback Machine CDX scanning of <code>news</code>… Searching for <code>.JAR</code> or <code>https.*cgi-bin.*\.cgi</code> are killers, particularly the .jar hits, here’s what came out:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_23"><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_24">62.22.60.49 telecom-headlines.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_25">62.22.61.206 worldnewsnetworking.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_26">64.16.204.55 holein1news.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_27">66.104.169.184 bcenews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_28">69.84.156.90 stickshiftnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_29">74.116.72.236 techtopnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_30">74.254.12.168 non-stop-news.net</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_31">193.203.49.212 inews-today.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_32">199.85.212.118 just-kidding-news.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_33">207.210.250.132 aeronet-news.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_34">212.4.18.129 sightseeingnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_35">212.209.90.84 thenewseditor.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_36">216.105.98.152 modernarabicnews.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_40" wp_automatic_readability="8.8676470588235">“headline”: only 140 matches in 2013-dns-census-a-novirt.csv and 3 hits out of 269 hits. Full inspection without CDX led to no new hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_41" wp_automatic_readability="11.447368421053">“today”: only 3.5k matches in 2013-dns-census-a-novirt.csv and 12 hits out of 269 hits, TODO how many on those on 2013-dns-census-a-novirt? No new hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-virtual-host-cleanup-heuristic-keyword-searches/_42" wp_automatic_readability="14.451219512195">“world”, “global”, “international”, and spanish/portuguese/French versions like “mondo”, “mundo”, “mondi”: 15k matches in 2013-dns-census-a-novirt.csv. No new hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_1" wp_automatic_readability="6.8478260869565">Let’ see if there’s anything in records/mx.xz.</div><p>mx.csv is 21GB.</p><p>They do have <code>"</code> in the files to escape commas so:</p><p>then:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_7" wp_automatic_readability="9"><div wp_automatic_readability="13"><pre><code># uniq not amazing as there are often two or three slightly different records repeated on multiple timestamps, but down to 11 GB python3 mx.py | uniq > mx-uniq.csv sqlite3 mx.sqlite 'create table t(d text, m text)' # 13 GB time sqlite3 mx.sqlite ".import --csv --skip 1 'mx-uniq.csv' t" # 41 GB time sqlite3 mx.sqlite 'create index td on t(d)' time sqlite3 mx.sqlite 'create index tm on t(m)' time sqlite3 mx.sqlite 'create index tdm on t(d, m)' # Remove dupes. # Rows: 150m time sqlite3 mx.sqlite <<eof delete="" from="" t="" where="" rowid="" not="" in="" select="" min="" group="" by="" d="" m="" eof="" gb="" time="" sqlite3="" mx.sqlite="" vacuum=""/></code></pre></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_8">Let’s see what the hits use:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_9" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code>awk -F, 'NR>1{ print $2 }' ../media/cia-2010-covert-communication-websites/hits.csv | xargs -I{} sqlite3 mx.sqlite "select distinct * from t where d = '{}'"</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_10" wp_automatic_readability="20.039501039501">At around 267 total hits, only 84 have MX records, and from those that do, almost all of them have exactly:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_11" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>smtp.secureserver.net mailstore1.secureserver.net</code></pre></div></div><p>with only three exceptions:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_12" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>dailynewsandsports.com|dailynewsandsports.com inews-today.com|mail.inews-today.com just-kidding-news.com|just-kidding-news.com</code></pre></div></div><p>We need to count out of the totals!</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_13" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>sqlite3 mx.sqlite "select count(*) from t where m = 'mailstore1.secureserver.net'"</code></pre></div></div><p>which gives, ~18M, so nope, it is too much by itself…</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_14" wp_automatic_readability="7.6639175257732">Let’s try to use that to reduce <code>av.sqlite</code> from 2013 DNS Census virtual host cleanup a bit further:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_15" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>time sqlite3 mx.sqlite '.mode csv' "attach 'aiddcu.sqlite' as 'av'" '.load ./ip' "select ipi2s(av.t.i), av.t.d from av.t inner join t as mx on av.t.d = mx.d and mx.m = 'mailstore1.secureserver.net' order by av.t.i asc" > avm.csv</code></pre></div></div><p>where <code>avm</code> stands for <code>av</code> with <code>mx</code> pruning. This leaves us with only ~500k entries left. With one more figerprint we could do a Wayback Machine CDX scanning scan.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_16" wp_automatic_readability="6.6146788990826">Let’s check that we still have most our hits in there:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-mx-records/_17" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code>grep -f <(awk -F, 'NR>1{print $2}' /home/ciro/bak/git/media/cia-2010-covert-communication-websites/hits.csv) avm.csv</code></pre></div></div><p>At 267 hits we got 81, so all are still present.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_1" wp_automatic_readability="7.6521739130435">ns.csv is 57 GB. This file is too massive, working with it is a pain.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_4" wp_automatic_readability="10.736248236953">Let’s just scan it once real quick to start with, since likely nothing will come of this venue:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_5" wp_automatic_readability="8"><div wp_automatic_readability="11"><pre><code>grep -f <(awk -F, 'NR>1{print $2}' ../media/cia-2010-covert-communication-websites/hits.csv) nsu.csv | tee nsu-hits.csv cat nsu-hits.csv | csvcut -c 2 | sort | awk -F. '{OFS="."; print $(NF-1), $(NF)}' | sort | uniq -c | sort -k1 -n</code></pre></div></div><p>As of 267 hits we get:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_6" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code> 1 a2hosting.com 1 amerinoc.com 1 ayns.net 1 dailyrazor.com 1 domainingdepot.com 1 easydns.com 1 frienddns.ru 1 hostgator.com 1 kolmic.com 1 name-services.com 1 namecity.com 1 netnames.net 1 tonsmovies.net 1 webmailer.de 2 cashparking.com 55 worldnic.com 86 domaincontrol.com</code></pre></div></div><p>so yeah, most of those are likely going to be humongous just by looking at the names.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_7" wp_automatic_readability="7.4368421052632">The smallest ones by far from the total are: frienddns.ru with only 487 hits, all others quite large or fake hits due to CSV. Did a quick Wayback Machine CDX scanning there but no luck alas.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_8" wp_automatic_readability="6.9279588336192">Let’s check the smaller ones:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_9" wp_automatic_readability="15.5"><div wp_automatic_readability="26"><pre><code>inews-today.com,2013-08-12T03:14:01,ns1.frienddns.ru source-commodities.net,2012-12-13T20:58:28,ns1.namecity.com -> fake hit due to grep e-commodities.net dailynewsandsports.com,2013-08-13T08:36:28,ns3.a2hosting.com just-kidding-news.com,2012-02-04T07:40:50,jns3.dailyrazor.com fightwithoutrules.com,2012-11-09T01:17:40,sk.s2.ns1.ns92.kolmic.com fightwithoutrules.com,2013-07-01T22:46:23,ns1625.ztomy.com half-court.net,2012-09-10T09:49:15,sk.s2.ns1.ns92.kolmic.com half-court.net,2013-07-07T00:31:12,ns1621.ztomy.com</code></pre></div></div><p>Doubt anything will come out of this.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_10" wp_automatic_readability="6.2536764705882">Let’s do a bit of counting out of the total:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_11" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>grep domaincontrol.com ns.csv | awk -F, '{print $1}' | uniq | wc</code></pre></div></div><p>gives ~20M domain using <code>domaincontrol</code>. Let’s see how many domains are in the first place:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2013-dns-census-ns-records/_12" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>awk -F, '{print $1}' ns.csv | uniq | wc</code></pre></div></div><p>so it accounts for 1/4 of the total.</p></div><p>dnshistory.org contains historical domain -> mappings.</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_2" wp_automatic_readability="32.083333333333">We have not managed to extract much from this source, they don’t have as much data on the range of interest.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_3" wp_automatic_readability="35.335793357934">But they do have some unique data at least, perhaps we should try them a bit more often, e.g. they were the only source we’ve seen so far that made the association: headlines2day.com -> 212.209.74.126 which places it in the more plausible globalbaseballnews.com IP range.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_4" wp_automatic_readability="23.144578313253">TODO can it do IP to domain? Or just domain to IP? Asked on their Discord: discord.com/channels/698151879166918727/968586102493552731/1124254204257632377. Their banner suggests that yes:</p><div><blockquote id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_5"><p>With our new look website you can now find other domains hosted on the same IP address, your website neighbours and more even quicker than before.</p></blockquote></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_6">Owner replied, you can’t:</p><div><blockquote id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_7"><p>At the moment you can only do this for current not historical records</p></blockquote></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_8" wp_automatic_readability="29.526315789474">This is a shame, reverse IP here could be quite valuable.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_9" wp_automatic_readability="24.995024875622">In principle, we could obtain this data from search engines, but Google doesn’t track that entire website well, e.g. no hits for <code>site:dnshistory.org "62.22.60.48"</code> presumably due to heavy IP throttling.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/dnshistory-org/_10" wp_automatic_readability="26.948148148148">Homepage dnshistory.org/ gives date starting in 2009:and it is true that they do have some hits from that useful era.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/securitytrails-com/_1" wp_automatic_readability="10.694189602446">They appear to piece together data from various sources. This is the most complete historical domain -> IP database we have so far. They don’t have hugely more data than viewdns.info, but many times do offer something new. It feels like the key difference is that their data goes further back in the critical time period a bit.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/securitytrails-com/_2" wp_automatic_readability="10.38202247191">TODO do they have historical reverse IP? The fact that they don’t seem to have it suggests that they are just making historical reverse IP requests to a third party via some API?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/securitytrails-com/_4" wp_automatic_readability="6.5625">But searching the IP 62.22.60.55 is empty and there’s no historical data option?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/securitytrails-com/_5" wp_automatic_readability="7.4413407821229">Account creation blacklists common email providers such as gmail to force users to use a “corporate” email address. But using random domains like <code>ciro@cirosantilli.com</code> works fine.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/securitytrails-com/_6" wp_automatic_readability="6.4909090909091">Their data seems to date back to 2008 for our searches.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_5">Hello world:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_6" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>select * from "ccindex"."ccindex" limit 100;</code></pre></div></div><p>Data scanned: 11.75 MB</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_7">Sample first output line:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_8" wp_automatic_readability="8"><div wp_automatic_readability="11"><pre><code># 2 url_surtkey org,whwheelers)/robots.txt url url_host_name whwheelers.org url_host_tld org url_host_2nd_last_part whwheelers url_host_3rd_last_part url_host_4th_last_part url_host_5th_last_part url_host_registry_suffix org url_host_registered_domain whwheelers.org url_host_private_suffix org url_host_private_domain whwheelers.org url_host_name_reversed url_protocol https url_port url_path /robots.txt url_query fetch_time 2021-06-22 16:36:50.000 fetch_status 301 fetch_redirect content_digest 3I42H3S6NNFQ2MSVX7XZKYAYSCX5QBYJ content_mime_type text/html content_mime_detected text/html content_charset content_languages content_truncated warc_filename crawl-data/CC-MAIN-2021-25/segments/1623488519183.85/robotstxt/CC-MAIN-20210622155328-20210622185328-00312.warc.gz warc_record_offset 1854030 warc_record_length 639 warc_segment 1623488519183.85 crawl CC-MAIN-2021-25 subset robotstxt</code></pre></div></div><p>So <code>url_host_3rd_last_part</code> might be a winner for CGI comms fingerprinting!</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_9">Naive one for one index:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_10" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>select * from "ccindex"."ccindex" where url_host_registered_domain = 'conquermstoday.com' limit 100;</code></pre></div></div><p>have no results… data scanned: 5.73 GB</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_11" wp_automatic_readability="10.711286089239">Let’s see if they have any of the domain hits. Let’s also restrict by date to try and reduce the data scanned:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_12" wp_automatic_readability="8.5"><div wp_automatic_readability="12"><pre><code>select * from "ccindex"."ccindex" where fetch_time < TIMESTAMP '2014-01-01 00:00:00' AND url_host_registered_domain IN ( 'activegaminginfo.com', 'altworldnews.com', ... 'topbillingsite.com', 'worldwildlifeadventure.com' )</code></pre></div></div><p>Humm, data scanned: 60.59 GB and no hits… weird.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_13" wp_automatic_readability="6.0421052631579">Sanity check:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_14" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code>select * from "ccindex"."ccindex" WHERE crawl="CC-MAIN-2013-20" AND subset="warc" AND url_host_registered_domain IN ( 'google.com', 'amazon.com' )</code></pre></div></div><p>has a bunch of hits of course. Data scanned: 212.88 MB, <code>WHERE</code> <code>crawl</code> and <code>subset</code> are a must! Should have read the article first.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_15" wp_automatic_readability="6.8066298342541">Let’s widen a bit more:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/common-crawl/_16" wp_automatic_readability="9.5"><div wp_automatic_readability="14"><pre><code>select * from "ccindex"."ccindex" WHERE crawl IN ( 'CC-MAIN-2013-20', 'CC-MAIN-2013-48', 'CC-MAIN-2014-10' ) AND subset="warc" AND url_host_registered_domain IN ( 'activegaminginfo.com', 'altworldnews.com', ... 'worldnewsandent.com', 'worldwildlifeadventure.com' )</code></pre></div></div><p>Still nothing found… they don’t seem to have any of the URLs of interest?</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_2" wp_automatic_readability="11.518518518519">We could not find anything useful in it so far, but there is great potential to use this tool to find new IP ranges based on properties of existing IP ranges. Part of the problem is that the dataset is huge, and is split by top 256 bytes. But it would be reasonable to at least explore ranges with pre-existing known hits…</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_3" wp_automatic_readability="8.8793103448276">We have started looking for patterns on <code>66.*</code> and <code>208.*</code>, both selected as two relatively far away ranges that have a number of pre-existing hits. 208 should likely have been 212 considering later finds that put several ranges in 212.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_4">tcpip_fp:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_5"><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_6">66.104.<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_7"><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_8">66.104.175.41: grubbersworldrugbynews.com: 1346397300 SCAN(V=6.01%E=4%D=1/12%OT=22%CT=443%CU=%PV=N%G=N%TM=387CAB9E%P=mipsel-openwrt-linux-gnu),ECN(R=N),T1(R=N),T2(R=N),T3(R=N),T4(R=N),T5(R=N),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_9">66.104.175.48: worlddispatch.net: 1346816700 SCAN(V=6.01%E=4%D=1/2%OT=22%CT=443%CU=%PV=N%DC=I%G=N%TM=1D5EA%P=mipsel-openwrt-linux-gnu),SEQ(SP=F8%GCD=3%ISR=109%TI=Z%TS=A),ECN(R=N),T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=),T1(R=N),T2(R=N),T3(R=N),T4(R=N),T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_10">66.104.175.49: webworldsports.com: 1346692500 SCAN(V=6.01%E=4%D=9/3%OT=22%CT=443%CU=%PV=N%DC=I%G=N%TM=5044E96E%P=mipsel-openwrt-linux-gnu),SEQ(SP=105%GCD=1%ISR=108%TI=Z%TS=A),OPS(O1=M550ST11NW6%O2=M550ST11NW6%O3=M550NNT11NW6%O4=M550ST11NW6%O5=M550ST11NW6%O6=M550ST11),WIN(W1=1510%W2=1510%W3=1510%W4=1510%W5=1510%W6=1510),ECN(R=N),T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=),T1(R=N),T2(R=N),T3(R=N),T4(R=N),T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_11">66.104.175.50: fly-bybirdies.com: 1346822100 SCAN(V=6.01%E=4%D=1/1%OT=22%CT=443%CU=%PV=N%DC=I%G=N%TM=14655%P=mipsel-openwrt-linux-gnu),SEQ(TI=Z%TS=A),ECN(R=N),T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=),T1(R=N),T2(R=N),T3(R=N),T4(R=N),T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_12">66.104.175.53: info-ology.net: 1346712300 SCAN(V=6.01%E=4%D=9/4%OT=22%CT=443%CU=%PV=N%DC=I%G=N%TM=50453230%P=mipsel-openwrt-linux-gnu),SEQ(SP=FB%GCD=1%ISR=FF%TI=Z%TS=A),ECN(R=N),T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=),T1(R=N),T2(R=N),T3(R=N),T4(R=N),T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_13">66.175.106<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_14"><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_15">66.175.106.150: noticiasmusica.net: 1340077500 SCAN(V=5.51%D=1/3%OT=22%CT=443%CU=%PV=N%G=N%TM=38707542%P=mipsel-openwrt-linux-gnu),ECN(R=N),T1(R=N),T2(R=N),T3(R=N),T4(R=N),T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li><li id="cirosantilli/cia-2010-covert-communication-websites/internet-census-2012/_16">66.175.106.155: atomworldnews.com: 1345562100 SCAN(V=5.51%D=8/21%OT=22%CT=443%CU=%PV=N%DC=I%G=N%TM=5033A5F2%P=mips-openwrt-linux-gnu),SEQ(SP=FB%GCD=1%ISR=FC%TI=Z%TS=A),ECN(R=Y%DF=Y%TG=40%W=1540%O=M550NNSNW6%CC=N%Q=),T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=),T2(R=N),T3(R=N),T4(R=N),T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=),T6(R=N),T7(R=N),U1(R=N),IE(R=N)</li></ul></div></li></ul></div></div><p>Hostprobes quick look on two ranges:</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_2">208.254.40:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_3" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>... similar down 208.254.40.95 1334668500 down no-response 208.254.40.95 1338270300 down no-response 208.254.40.95 1338839100 down no-response 208.254.40.95 1339361100 down no-response 208.254.40.95 1346391900 down no-response 208.254.40.96 1335806100 up unknown 208.254.40.96 1336979700 up unknown 208.254.40.96 1338840900 up unknown 208.254.40.96 1339454700 up unknown 208.254.40.96 1346778900 up echo-reply (0.34s latency). 208.254.40.96 1346838300 up echo-reply (0.30s latency). 208.254.40.97 1335840300 up unknown 208.254.40.97 1338446700 up unknown 208.254.40.97 1339334100 up unknown 208.254.40.97 1346658300 up echo-reply (0.26s latency). ... similar up 208.254.40.126 1335708900 up unknown 208.254.40.126 1338446700 up unknown 208.254.40.126 1339330500 up unknown 208.254.40.126 1346494500 up echo-reply (0.24s latency). 208.254.40.127 1335840300 up unknown 208.254.40.127 1337793300 up unknown 208.254.40.127 1338853500 up unknown 208.254.40.127 1346454900 up echo-reply (0.23s latency). 208.254.40.128 1335856500 up unknown 208.254.40.128 1338200100 down no-response 208.254.40.128 1338749100 down no-response 208.254.40.128 1339334100 down no-response 208.254.40.128 1346607900 down net-unreach 208.254.40.129 1335699900 up unknown ... similar down</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_4" wp_automatic_readability="6.8205128205128">Suggests exactly 127 – 96 + 1 = 31 IPs.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_5">208.254.42:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_6" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>... similar down 208.254.42.191 1334522700 down no-response 208.254.42.191 1335276900 down no-response 208.254.42.191 1335784500 down no-response 208.254.42.191 1337845500 down no-response 208.254.42.191 1338752700 down no-response 208.254.42.191 1339332300 down no-response 208.254.42.191 1346499900 down net-unreach 208.254.42.192 1334668500 up unknown 208.254.42.192 1336808700 up unknown 208.254.42.192 1339334100 up unknown 208.254.42.192 1346766300 up echo-reply (0.40s latency). 208.254.42.193 1335770100 up unknown 208.254.42.193 1338444900 up unknown 208.254.42.193 1339334100 up unknown ... similar up 208.254.42.221 1346517900 up echo-reply (0.19s latency). 208.254.42.222 1335708900 up unknown 208.254.42.222 1335708900 up unknown 208.254.42.222 1338066900 up unknown 208.254.42.222 1338747300 up unknown 208.254.42.222 1346872500 up echo-reply (0.27s latency). 208.254.42.223 1335773700 up unknown 208.254.42.223 1336949100 up unknown 208.254.42.223 1338750900 up unknown 208.254.42.223 1339334100 up unknown 208.254.42.223 1346854500 up echo-reply (0.13s latency). 208.254.42.224 1335665700 down no-response 208.254.42.224 1336567500 down no-response 208.254.42.224 1338840900 down no-response 208.254.42.224 1339425900 down no-response 208.254.42.224 1346494500 down time-exceeded ... similar down</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_7" wp_automatic_readability="6.825">Suggests exactly 223 – 192 + 1 = 31 IPs.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_8" wp_automatic_readability="6.8372093023256">Let’s have a look at the file <code>68</code>: outcome: no clear hits like on 208. One wonders why.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_9" wp_automatic_readability="7.3125">It does appears that long sequences of ranges are a sort of fingerprint. The question is how unique it would be.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_10" wp_automatic_readability="6.9154929577465">First:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_11" wp_automatic_readability="8.5"><div wp_automatic_readability="12"><pre><code>n=208 time awk '$3=="up"{ print $1 }' $n | uniq -c | sed -r 's/^ +//;s/ /,/' | tee $n-up-uniq t=$n-up-uniq.sqlite rm -f $t time sqlite3 $t 'create table tmp(cnt text, i text)' time sqlite3 $t ".import --csv $n-up-uniq tmp" time sqlite3 $t 'create table t (i integer)' time sqlite3 $t '.load ./ip' 'insert into t select str2ipv4(i) from tmp' time sqlite3 $t 'drop table tmp' time sqlite3 $t 'create index ti on t(i)'</code></pre></div></div><p>This reduces us to 2 million IP rows from the total possible 16 million IPs.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_12" wp_automatic_readability="6.5643153526971">OK now just counting hits on fixed windows has way too many results:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_13" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code>sqlite3 208-up-uniq.sqlite "\ SELECT * FROM ( SELECT min(i), COUNT(*) OVER ( ORDER BY i RANGE BETWEEN 15 PRECEDING AND 15 FOLLOWING ) as c FROM t ) WHERE c > 20 and c < 30 "</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_14" wp_automatic_readability="6.2846715328467">Let’s try instead consecutive ranges of length exactly 31 instead then:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_15" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>sqlite3 208-up-uniq.sqlite <<eof select="" f="" t="" as="" c="" from="" min="" max="" i="" row_number="" over="" by="" grp="" group="" order="" where="" eof=""/></code></pre></div></div><p>271. Hmm. A bit more than we’d like…</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_16" wp_automatic_readability="7">Another route is to also count the ups:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_17" wp_automatic_readability="9.5"><div wp_automatic_readability="14"><pre><code>n=208 time awk '$3=="up"{ print $1 }' $n | uniq -c | sed -r 's/^ +//;s/ /,/' | tee $n-up-uniq-cnt t=$n-up-uniq-cnt.sqlite rm -f $t time sqlite3 $t 'create table tmp(cnt text, i text)' time sqlite3 $t ".import --csv $n-up-uniq-cnt tmp" time sqlite3 $t 'create table t (cnt integer, i integer)' time sqlite3 $t '.load ./ip' 'insert into t select cnt as integer, str2ipv4(i) from tmp' time sqlite3 $t 'drop table tmp' time sqlite3 $t 'create index ti on t(i)'</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_18" wp_automatic_readability="6.9477611940299">Let’s see how many consecutives with counts:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_19" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>sqlite3 208-up-uniq-cnt.sqlite <<eof select="" f="" t="" as="" c="" from="" min="" max="" i="" row_number="" over="" by="" grp="" where="" cnt="">= 3) GROUP BY grp ORDER BY i ) where c > 28 and c < 32 EOF</eof></code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_20" wp_automatic_readability="8.9456193353474">Let’s check on 66:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_21" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>grep -e '66.45.179' -e '66.45.179' 66</code></pre></div></div><p>not representative at all… e.g. several convfirmed hits are down:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-hostprobes/_22" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code>66.45.179.215 1335305700 down no-response 66.45.179.215 1337579100 down no-response 66.45.179.215 1338765300 down no-response 66.45.179.215 1340271900 down no-response 66.45.179.215 1346813100 down no-response</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_1" wp_automatic_readability="6.9848484848485">Let’s check relevancy of known hits:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_2" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>grep -e '208.254.40' -e '208.254.42' 208 | tee 208hits</code></pre></div></div><p>Output:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_3" wp_automatic_readability="10"><div wp_automatic_readability="15"><pre><code>208.254.40.95 1355564700 unreachable 208.254.40.95 1355622300 unreachable 208.254.40.96 1334537100 alive, 36342 208.254.40.96 1335269700 alive, 17586 .. 208.254.40.127 1355562900 alive, 35023 208.254.40.127 1355593500 alive, 59866 208.254.40.128 1334609100 unreachable 208.254.40.128 1334708100 alive from 208.254.32.214, 43358 208.254.40.128 1336596300 unreachable</code></pre></div></div></div><p>The rest of 208 is mostly unreachable.</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_5" wp_automatic_readability="17"><div wp_automatic_readability="29"><pre><code>208.254.42.191 1335294900 unreachable ... 208.254.42.191 1344737700 unreachable 208.254.42.191 1345574700 Icmp Error: 0,ICMP Network Unreachable, from 63.111.123.26 208.254.42.191 1346166900 unreachable ... 208.254.42.191 1355665500 unreachable 208.254.42.192 1334625300 alive, 6672 ... 208.254.42.192 1355658300 alive, 57412 208.254.42.193 1334677500 alive, 28985 208.254.42.193 1336524300 unreachable 208.254.42.193 1344447900 alive, 8934 208.254.42.193 1344613500 alive, 24037 208.254.42.193 1344806100 alive, 20410 208.254.42.193 1345162500 alive, 10177 ... 208.254.42.223 1336590900 alive, 23284 ... 208.254.42.223 1355555700 alive, 58841 208.254.42.224 1334607300 Icmp Type: 11,ICMP Time Exceeded, from 65.214.56.142 208.254.42.224 1334681100 Icmp Type: 11,ICMP Time Exceeded, from 65.214.56.142 208.254.42.224 1336563900 Icmp Type: 11,ICMP Time Exceeded, from 65.214.56.142 208.254.42.224 1344451500 Icmp Type: 11,ICMP Time Exceeded, from 65.214.56.138 208.254.42.224 1344566700 unreachable 208.254.42.224 1344762900 unreachable</code></pre></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_6">Let’s try with 66. First there way too much data, 9 GB, let’s cut it down:</div><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_7" wp_automatic_readability="7"><div wp_automatic_readability="9"><pre><code>n=66 time awk '$3~/^alive,/ { print $1 }' $n | uniq -c | sed -r 's/^ +//;s/ /,/' | tee $n-up-uniq-c</code></pre></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_8">OK down to 45 MB, now we can work.</div><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_9" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>grep -e '66.45.179' -e '66.104.169' -e '66.104.173' -e '66.104.175' -e '66.175.106' '66-alive-uniq-c' | tee 66hits</code></pre></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_10" wp_automatic_readability="6.9195402298851">Nah, it’s full of holes:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/2012-internet-census-icmp-ping/_11" wp_automatic_readability="10"><div wp_automatic_readability="15"><pre><code>4,66.45.179.187 12,66.45.179.188 2,66.45.179.197 1,66.45.179.202 2,66.45.179.205 2,66.45.179.206 1,66.45.179.207</code></pre></div></div><p>won’t be able to find new ranges here.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/tb0hdan-domains/_1" wp_automatic_readability="34.094827586207">Domain list only, no IPs and no dates. We haven’t been able to extract anything of interest from this source so far.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/tb0hdan-domains/_2" wp_automatic_readability="30.855263157895">Domain hit count when we were at 69 hits: only 9, some of which had been since reused. Likely their data collection did not cover the dates of interest.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_2" wp_automatic_readability="27.759633409706">When you Google most of the hit domains, many of them show up on “expired domain trackers”, and above all Chinese expired domain trackers for some reason, notably e.g.:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_3" wp_automatic_readability="19.09962406015"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_4" wp_automatic_readability="32.976913730255"><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_6">First known working day: <code>2011-07-29</code>.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_7" wp_automatic_readability="19.351851851852">Scraping script: cia-2010-covert-communication-websites/hupo.sh. Scraping does about 1 day every 5 minutes relatively reliably, so about 36 hours / year. Not bad.</div><p>Results are stored under <code>tmp/humo/<day/></code>.</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_9" wp_automatic_readability="33.089820359281">Check for hit overlap:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_10" wp_automatic_readability="31.5"><div wp_automatic_readability="8"><pre><code>grep -Fx -f <( jq -r '.[].host' ../media/cia-2010-covert-communication-websites/hits.json ) cia-2010-covert-communication-websites/tmp/hupo/*</code></pre></div></div><p>The hits are very well distributed amongst days and months, at least they did a good job hiding these potential timing fingerprints. This feels very deliberately designed.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_11" wp_automatic_readability="34.098360655738">There are lots of hits. The data set is very inclusive. Also we understand that it must have been obtains through means other than Web crawling, since it contains so many of the hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_12" wp_automatic_readability="28.745762711864">Nice output format for scraping as the HTML is very minimal</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_13" wp_automatic_readability="12.581497797357">They randomly changed their URL format to remove the space before the .com after 2012-02-03:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_17" wp_automatic_readability="18.649595687332">Some of their files are simply missing however unfortunately, e.g. neither of the following exist:webmasterhome.cn did contain that one however: domain.webmasterhome.cn/com/2012-07-01.asp. Hmm. we might have better luck over there then?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_21" wp_automatic_readability="31.435665914221">2018-11-19 is corrupt in a new and wonderful way, with a bunch of trailing zeros:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_22" wp_automatic_readability="31.5"><div wp_automatic_readability="8"><pre><code>wget -O hupo-2018-11-19 ' hd hupo-2018-11-19</code></pre></div></div><p>ends in:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_23" wp_automatic_readability="32"><div wp_automatic_readability="9"><pre><code>000ffff0 74 75 64 69 65 73 2e 63 6f 6d 0d 0a 70 31 63 6f |tudies.com..p1co| 00100000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| * 0018a5e0 00 00 00 00 00 00 00 00 00 |.........|</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_24" wp_automatic_readability="19.493670886076">More generally, several files contain invalid domain names with non-ASCII characters, e.g. 2013-01-02 contains <code>365<d3>л<fa><c2><cc>.com</cc></c2></fa></d3></code>. Domain names can only contain ASCII charters: stackoverflow.com/questions/1133424/what-are-the-valid-characters-that-can-show-up-in-a-url-host Maybe we should get rid of any such lines as noise.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_25" wp_automatic_readability="32.017857142857">Some files around 2011-09-06 start with an empty line. 2014-01-15 starts with about twenty empty lines. Oh and that last one also has some trash bytes the end <code><b7><b5><bb><d8/></bb></b5></b7></code>. Beauty.</div></li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_26" wp_automatic_readability="33.926446727961"><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_28">First known working day: <code>2011-08-18</code>.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_29" wp_automatic_readability="32.777777777778">Also heavily IP throttled, and a bit more than hupo apparently.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_30">Scraper cia-2010-covert-communication-websites/webmastercn.sh.</div><p>Also has some randomly missing dates like hupo.com, though different missing ones from hupo, so they complement each other nicely.</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_32" wp_automatic_readability="18.147909967846">Some of the URLs are broken and don’t inform that with HTTP status code, they just replace the results with some Chinese text 无法找到该页 (The requested page could not be found):</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_37" wp_automatic_readability="36.122733612273">Several URLs just return length 0 content, e.g.:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_38" wp_automatic_readability="33"><div wp_automatic_readability="11"><pre><code>curl -vvv * Trying 125.90.93.11:80... * Connected to domain.webmasterhome.cn (125.90.93.11) port 80 (#0) > GET /com/2015-10-31.asp HTTP/1.1 > Host: domain.webmasterhome.cn > User-Agent: curl/7.88.1 > Accept: */* > < HTTP/1.1 200 OK < Date: Sat, 21 Oct 2023 15:12:23 GMT < Server: Microsoft-IIS/6.0 < X-Powered-By: ASP.NET < Content-Length: 0 < Content-Type: text/html < Set-Cookie: ASPSESSIONIDCSTTTBAD=BGGPAONBOFKMMFIPMOGGHLMJ; path=/ < Cache-control: private < * Connection #0 to host domain.webmasterhome.cn left intact</code></pre></div></div><p>It is not fully clear if this is a throttling mechanism, or if the data is just missing entirely.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_39" wp_automatic_readability="32.359550561798">Starting around 2018, the IP limiting became very intense, 30 mins / 1 hour per URL, so we just gave up. Therefore, data from 2018 onwards does not contain webmasterhome.cn data.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_40" wp_automatic_readability="32.646017699115">Starting from <code>2013-05-10</code> the format changes randomly. This also shows us that they just have all the HTML pages as static files on their server. E.g. with:we see:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_42" wp_automatic_readability="31"><div wp_automatic_readability="7"><pre wp_automatic_readability="4"><code wp_automatic_readability="2">2013-05-09:<pre style="font-family:Verdana, Arial, Helvetica, sans-serif; "><strong>2013<c4><ea>05<d4><c2>09<c8>յ<bd><c6>ڹ<fa><bc><ca><d3><f2><c3><fb/></c3></f2></d3></ca></bc></fa></c6></bd></c8></c2></d4></ea></c4></strong><br/>0-3y.com 2013-05-10:<pre><strong>2013<c4><ea>05<d4><c2>10<c8>յ<bd><c6>ڹ<fa><bc><ca><d3><f2><c3><fb/></c3></f2></d3></ca></bc></fa></c6></bd></c8></c2></d4></ea></c4></strong></pre><p></code></div></div></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_43">justdropped.com: e.g. www.justdropped.com/drops/010112com.html. First known working day: <code>2006-01-01</code>. Unthrottled.</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_44">yoid.com: e.g.: yoid.com/bydate.php?d=2016-06-03&a=a. First known workding day: <code>2016-06-01</code>.</li></ul></div><p>This suggests that scraping these lists might be a good starting point to obtaining “all expired domains ever”.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_45">Data comparison:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_46"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_47" wp_automatic_readability="16.290275761974"><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_48" wp_automatic_readability="16.441102756892">2012-01-01Looking only at the <code>.com</code>:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_53"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_54">webmastercn has just about ten extra ones than justdropped, the rest is exactly the same</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_55">justdropped has some extra and some missing from hupo</li></ul></div><p>The lists are quite similar however.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_56">Considering toplevels:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_57"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_58">hupo has several toplevels that webmastercn does not have, e.g. .org and many others</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_59">justdropped only covers exactly 6 tlds: <code>.us</code>, <code>.org</code>, <code>.net</code>, <code>.info</code>, <code>.com</code> and <code>.biz</code>. The <code>.com</code> lists are very similar to hupo + webmastercn. But it has a lot more non-<code>.com</code> domains apparently.</li></ul></div></div></li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_60" wp_automatic_readability="30.982658959538">We’ve made the following pipelines for hupo.com + webmasterhome.cn merging:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_61" wp_automatic_readability="32"><div wp_automatic_readability="9"><pre><code>./hupo.sh & ./webmastercn.sh & ./justdropped.sh & wait ./justdropped-post.sh ./hupo-merge.sh # Export as small Google indexable files in a Git repository. ./hupo-repo.sh # Export as per year zips for Internet Archive. ./hupo-zip.sh # Obtain count statistics: ./hupo-wc.sh</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_62" wp_automatic_readability="32">Count unique domains in the repos:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_63" wp_automatic_readability="31"><div wp_automatic_readability="7"><pre><code>( echo */*/*/* | xargs cat ) | sort -u | wc</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_64" wp_automatic_readability="16.866295264624">The extracted data is present at:Soon after uploading, these repos started getting some interesting traffic, presumably started by security trackers going “bling bling” on certain malicious domain names in their databases:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_88"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_89">GitHub trackers:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_90"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_91">admin-monitor.shiyue.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_92">anquan.didichuxing.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_93">app.cloudsek.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_94">app.flare.io</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_95">app.rainforest.tech</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_96">app.shadowmap.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_97">bo.serenety.xmco.fr 8 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_98">bts.linecorp.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_99">burn2give.vercel.app</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_100">cbs.ctm360.com 17 2</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_101">code6.d1m.cn</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_102">code6-ops.juzifenqi.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_103">codefend.devops.cndatacom.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_104">dlp-code.airudder.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_105">easm.atrust.sangfor.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_106">ec2-34-248-93-242.eu-west-1.compute.amazonaws.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_107">ecall.beygoo.me 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_108">eos.vip.vip.com 1 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_109">foradar.baimaohui.net 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_110">fty.beygoo.me</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_111">hive.telefonica.com.br 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_112">hulrud.tistory.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_113">kartos.enthec.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_114">soc.futuoa.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_115">lullar-com-3.appspot.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_116">penetration.houtai.io 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_117">platform.sec.corp.qihoo.net</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_118">plus.k8s.onemt.co 4 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_119">pmp.beygoo.me 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_120">portal.protectorg.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_121">qa-boss.amh-group.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_122">saicmotor.saas.cubesec.cn</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_123">scan.huoban.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_124">sec.welab-inc.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_125">security.ctrip.com 10 3</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_126">siem-gs.int.black-unique.com 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_127">soc-github.daojia-inc.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_128">spigotmc.org 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_129">tcallzgroup.blueliv.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_130">tcthreatcompass05.blueliv.com 4 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_131">tix.testsite.woa.com 2 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_132">toucan.belcy.com 1 1</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_133">turbo.gwmdevops.com 18 2</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_134">urlscan.watcherlab.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_135">zelenka.guru. Looks like a Russian hacker forum.</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_136">LinkedIn profile views:</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_139" wp_automatic_readability="32">Check for overlap of the merge:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_140" wp_automatic_readability="31.5"><div wp_automatic_readability="8"><pre><code>grep -Fx -f <( jq -r '.[].host' ../media/cia-2010-covert-communication-websites/hits.json ) cia-2010-covert-communication-websites/tmp/merge/*</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_141" wp_automatic_readability="27.036437246964">Next, we can start searching by keyword with Wayback Machine CDX scanning with Tor parallelization with out helper cia-2010-covert-communication-websites/hupo-cdx-tor.sh, e.g. to check domains that contain the term “news”:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_142" wp_automatic_readability="31"><div wp_automatic_readability="7"><pre><code>./hupo-cdx-tor.sh mydir 'news|global' 2011 2019</code></pre></div></div><p>produces per-year results for the regex term <code>news|global</code> between the years under:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_143" wp_automatic_readability="31"><div wp_automatic_readability="7"><pre><code>tmp/hupo-cdx-tor/mydir/2011 tmp/hupo-cdx-tor/mydir/2012</code></pre></div></div><p>OK lets:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_144" wp_automatic_readability="31"><div wp_automatic_readability="7"><pre><code>./hupo-cdx-tor.sh out 'news|headline|internationali|mondo|mundo|mondi|iran|today'</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_145" wp_automatic_readability="28.759493670886">Other searches that are not dense enough for our patience:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_147" wp_automatic_readability="30.994475138122">OMG <code>news</code> search might be producing some golden, golden new hits!!! Going full into this. Hits:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_148"><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_149">thepyramidnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_150">echessnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_151">tickettonews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_152">airuafricanews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_153">vuvuzelanews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_154">dayenews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_155">newsupdatesite.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_156">arabicnewsonline.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_157">arabicnewsunfiltered.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_158">newsandsportscentral.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_159">networkofnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_160">trekkingtoday.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/expired-domain-trackers/_161">financial-crisis-news.com</li></ul></div><p>and a few more. It’s amazing.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/club-domain-cn/_1" wp_automatic_readability="23.92523364486">TODO what does this Chinese forum track? New registrations? Their focus seems to be domain name speculation</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/club-domain-cn/_2" wp_automatic_readability="23.22633744856">Some of the threads contain domain dumps. We haven’t yet seen a scrapable URL pattern, but their data goes way back and did have various hits. The forum seems to have started in 2006: club.domain.cn/forum.php?mod=forumdisplay&fid=41&page=10127</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/club-domain-cn/_3" wp_automatic_readability="23.538461538462">club.domain.cn/forum.php?mod=viewthread&tid=241704 “【国际域名拟删除列表】2007年06月16日” is the earliest list we could find. It is an expired domain list.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/mass-deface-iii-pastebin/_5" wp_automatic_readability="16.413098236776">This pastebin contained a few new hits, in addition to some pre-existing ones. Most of the hits them seem to be linked to the IP 72.34.53.174, which presumably is a major part of the fingerprint found by CYBERTAZIEX, though unsurprisingly methodology is unclear. As documented, the domains appear to be linked to a “Condor hosting” provider, but it is hard to find any information about it online.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/mass-deface-iii-pastebin/_6" wp_automatic_readability="9.645390070922">From the title, it would seem that someone hacked into Condor and defaced all of its sites, including unknowingly some CIA ones which is LOL.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/mass-deface-iii-pastebin/_7" wp_automatic_readability="5.6617647058824">Ciro Santilli checked every single non-subdomain domain in the list.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/mass-deface-iii-pastebin/_10" wp_automatic_readability="4.030518819939">www.zone-h.com lists some of the domains. They also seem to have intended to have snapshots of the defaces but we can’t see them which is sad:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ipinf-ru/_5" wp_automatic_readability="8.6896551724138">But they do reverse IP, and they show which nearby reverse IPs have hits on the same page, for free, which is great!</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ipinf-ru/_6" wp_automatic_readability="8.4552845528455">Shame their ordering is purely alphabetical, doesn’t properly order the IPs so it is a bit of a pain, but we can handle it.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ipinf-ru/_8" wp_automatic_readability="11.046357615894">The data here had a little bit of non-overlap from other sources. 4 new confirmed hits were found, plus 4 possible others that were left as candidates.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cqcounter/_9" wp_automatic_readability="6.6111111111111">Unfortunately I can’t find a reverse IP search method.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cqcounter/_10" wp_automatic_readability="11.430188679245">And perhaps due to having lots of CAPTCHAs, Google doesn’t seem to index that website very well… it even has a tiny screenshot! And it also shows some more metadata beyond IP, e.g. HTTP response headers, which notably contain stuff like <code>Server: Apache-Coyote/1.1</code>.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cqcounter/_11" wp_automatic_readability="5.9433962264151">They seem to have an exceptionally complete database.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cqcounter/_13" wp_automatic_readability="5.475">They also have some random localized versions:These can be useful if your IP gets blacklisted on the main site because you were checking too many sites.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_2" wp_automatic_readability="7.7537091988131">There are four main types of communication mechanisms found:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_4" wp_automatic_readability="4.8913043478261"><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_8" wp_automatic_readability="7.8387096774194">JAR is the most common comms, and one of the most distinctive, making it a great fingerprint.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_9" wp_automatic_readability="7.3443396226415">Several of the JAR files are named something like either:as if to pose as Internet speed testing tools? The wonderful subtleties of the late 2000s Internet are a bit over our heads.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_14" wp_automatic_readability="13.176470588235">All JARs are directly under root, not in subdirectories, and the basename usually consist of one word, though sometimes two camel cased.</div></li><li id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_15">JavaScript file. There are two subtypes:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_16"><li id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_17">JavaScript with SHAs. Rare. Likely older. Way more fingerprintable.</li><li id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_18">JavaScript without SHAs. They have all been obfuscated slightly different and compressed. But the file sizes are all very similar from 8kB to 10kB, and they all look similar, so visually it is very easy to detect a match with good likelyhood.</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_19" wp_automatic_readability="4.2238966630786"><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_20" wp_automatic_readability="15.990697674419">Adobe Flash swf file. In all instances found so far, the name of the SWF matches the name of the second level domain exactly, e.g.:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_21" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>http://tee-shot.net/tee-shot.swf</code></pre></div></div><p>While this is somewhat of a fingerprint, it is worth noting that is was a relatively commonly used pattern. But it is also the rarest of the mechanisms. This is a at a dissonance with the rest of the web, which circa 2010 already had way more SWF than JAR apparently.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_22" wp_automatic_readability="6.87374749499">Some of the SWF websites have archives for empty <code>/servlet</code> pages:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_23" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>./bailsnboots.com/20110201234509/servlet/teammate/index.html ./currentcommunique.com/20110130162713/servlet/summer/index.html ./mynepalnews.com/20110204095758/servlet/SnoopServlet/index.html ./mynepalnews.com/20110204095403/servlet/release/index.html ./www.hassannews.net/20101230175421/servlet/jordan/index.html ./zerosandonesnews.com/20110209084339/servlet/technews/index.html</code></pre></div></div><p>which makes us think that it is a part of the SWF system.</p></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_24">CGI comms</li></ul></div><p>These have short single word names with some meaning linked to their website.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/communication-mechanism/_25" wp_automatic_readability="15.403755868545">Because the communication mechanisms are so crucial, they tend to be less varied, and serve as very good fingerprints. It is not ludicrous, e.g. identical files, but one look at a few and you will know the others.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_1" wp_automatic_readability="7.4716981132075">We’ve come across a few shallow and stylistically similar websites on suspicious ranges with this pattern.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_2" wp_automatic_readability="8.974358974359">No JS/JAR/SWF comms, but rather a subdomain, and an HTTPS page with .cgi extension that leads to a login page. Some names seen for this subdomain:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_4"><code>secure.</code>: most common</li><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_5"><code>ssl.</code>: also common</li><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_6">various other more creative ones linked to the website theme itself, e.g.:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_7"><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_8">musical-fortune.net has a backstage.musical-fortune.net</li></ul></div></li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_9" wp_automatic_readability="11.375722543353">The question is, is this part of some legitimate tooling that created such patterns? And if so which? Or are they actual hits with a new comms mechanism not previously seen?</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_10" wp_automatic_readability="6.841628959276">The fact that:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_11"><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_12">hits of this type are so dense in the suspicious ranges</li><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_13">they are so stylistically similar between on another</li><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms/_14">citizenlabs specifically mentioned a “CGI” comms method</li></ul></div><p>suggests to Ciro that they are an actual hit.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms-variant/_1" wp_automatic_readability="5.2783505154639">Later on, we’ve also come across some stylistic hits in IP ranges with apparent slight variations of the CGI comms pattern:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms-variant/_2"><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms-variant/_3">no .cgi, but also http on subdomain:</li><li id="cirosantilli/cia-2010-covert-communication-websites/cgi-comms-variant/_10">no subdomain, no https, no .cgi</li></ul></div><p>Since these are so rare, it is still a bit hard to classify them for sure, but they are of great interest no doubt, as as we start to notice these patterns more tend to come if it is a thing.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_2" wp_automatic_readability="3.4326359832636">crt.sh appears to be a good way to look into this:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_4">backstage.musical-fortune.net:</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_8">clients.smart-travel-consultant.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_12">members.it-proonline.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_16">members.metanewsdaily.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_20">miembros.todosperuahora.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_24">secure.altworldnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_28">secure.driversinternationalgolf.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_32">secure.freshtechonline.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_36">secure.globalnewsbulletin.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_40">secure.negativeaperture.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_44">secure.riskandrewardnews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_48">secure.theworld-news.net</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_49">secure.topbillingsite.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_50">secure.worldnewsandent.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_51">ssl.beyondnetworknews.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_52">ssl.newtechfrontier.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_53">www.businessexchangetoday.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/ssl-certificate/_54">heal.conquermstoday.com</li></ul></div><p>They all appear to use either of:</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_1" wp_automatic_readability="9.4871794871795">TODO it would be cool to have a look at the JARs and see if they have anything in common that makes for a good fringerprint. Would not help find new ones, but would help to confirm possible hits.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_2" wp_automatic_readability="6.3660714285714">web.archive.org/web/20110208072027/ unzips to:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_3" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>. ./c ./c/b ./c/b/b.class ./c/b/c.class ./c/b/d.class ./c/b/a ./c/b/a/a.class ./c/b/a/b.class ./c/b/a/c.class ./c/b/a/d.class ./c/a ./c/a/a.class ./c/a/b.class ./c/a/c.class ./b ./b/a ./b/a/a ./b/a/a/e.class ./b/a/a/f.class ./b/a/a/a.class ./b/a/a/b.class ./b/a/a/g.class ./b/a/a/c.class ./b/a/a/d.class ./META-INF ./META-INF/MANIFEST.MF ./a ./a/cre ./a/a ./a/a/b ./a/a/b/a.class ./a/a/a ./a/a/a/e.class ./a/a/a/applet.configs ./a/a/a/b ./a/a/a/b/e.class ./a/a/a/b/f.class ./a/a/a/b/b.class ./a/a/a/b/g.class ./a/a/a/b/c.class ./a/a/a/b/d.class ./a/a/a/b/a ./a/a/a/b/a/a.class ./a/a/a/b/a/b.class ./a/a/a/b/a/c.class ./a/a/a/c.class ./a/a/a/d.class ./a/a/a/a ./a/a/a/a/a.class</code></pre></div></div><p>so it is fully obfuscated.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_4"><code>./META-INF/MANIFEST.MF</code></p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_5" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>Manifest-Version: 1.0 Ant-Version: Apache Ant 1.7.1 Created-By: 1.5.0_17-b04 (Sun Microsystems Inc.)</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_10" wp_automatic_readability="6.0421052631579">A quick:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_11" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>find . -type f | xargs strings | sort -u</code></pre></div></div><p>does not reveal any obvious cryptography calls.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_14">web.archive.org/web/20110202185659/ is a bit different with tree:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_15" wp_automatic_readability="7.5"><div wp_automatic_readability="10"><pre><code>META-INF/MANIFEST.MF a/a.class b/a/a/a.class b/a/a/b.class b/a/a/c.class b/a/b/a.class b/a/b/b.class b/a/b/c.class b/a/b/d.class b/a/b/e.class b/a/bw.properties b/a/c.class c/a/a/a.class c/a/a/b.class c/a/a/c.class c/a/a/d.class c/a/b.class c/a/c.class c/a/d.class c/a/e.class c/b/a.class c/b/b.class c/b/c.class</code></pre></div></div><p>and:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/jar-reverse-engineering/_16" wp_automatic_readability="6.5"><div wp_automatic_readability="8"><pre><code>META-INF/MANIFEST.MF Manifest-Version: 1.0 Ant-Version: Apache Ant 1.6.5 Created-By: 1.5.0_12-b04 (Sun Microsystems Inc.)</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/javascript-with-shas/_1" wp_automatic_readability="7.4788114953726">There are two types of JavaScript found so far. The ones with SHA and the ones without. There are only 2 examples of JS with SHA:Both files start with precisely the same string:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/javascript-with-shas/_7" wp_automatic_readability="14.5"><div wp_automatic_readability="24"><pre><code>var ms="\u062F\u0631\u064A\u0627\u0641\u062A\u06CC",lc="\u062A\u0647\u064A\u0647 \u0645\u062A\u0646",mn="\u0628\u0631\u062F\u0627\u0632\u0634 \u062F\u0631 \u062C\u0631\u064A\u0627\u0646 \u0627\u0633\u062A...\u0644\u0637\u0641\u0627 \u0635\u0628\u0631 \u0643\u0646\u064A\u062F",lt="\u062A\u0647\u064A\u0647 \u0645\u062A\u0646",ne="\u067E\u0627\u0633\u062E",kf="\u062E\u0631\u0648\u062C",mb="\u062D\u0630\u0641",mv="\u062F\u0631\u064A\u0627\u0641\u062A\u06CC",nt="\u0627\u0631\u0633\u0627\u0644",ig="\u062B\u0628\u062A \u063A\u0644\u0637. \u062C\u0647\u062A \u062A\u062C\u062F\u064A\u062F \u062B\u0628\u062A \u0635\u0641\u062D\u0647 \u0631\u0627 \u0628\u0627\u0632\u0622\u0648\u0631\u06CC \u06A9\u0646\u064A\u062F",hs="\u063A\u064A\u0631 \u0642\u0627\u0628\u0644 \u0627\u062C\u0631\u0627. \u062E\u0637\u0627 \u062F\u0631 \u0627\u062A\u0651\u0635\u0627\u0644",ji="\u063A\u064A\u0631 \u0642\u0627\u0628\u0644 \u0627\u062C\u0631\u0627. \u062E\u0637\u0627 \u062F\u0631 \u0627\u062A\u0651\u0635\u0627\u0644",ie="\u063A\u064A\u0631 \u0642\u0627\u0628\u0644 \u0627\u062C\u0631\u0627. \u062E\u0637\u0627 \u062F\u0631 \u0627\u062A\u0651\u0635\u0627\u0644",gc="\u0633\u0648\u0627\u0631 \u06A9\u0631\u062F\u0646 \u062A\u06A9\u0645\u064A\u0644 \u0634\u062F",gz="\u0645\u0637\u0645\u0626\u0646\u064A\u062F \u06A9\u0647 \u0645\u064A\u062E\u0648\u0627\u0647\u064A\u062F \u067E\u064A\u0627\u0645 \u0631\u0627 \u062D\u0630\u0641 \u06A9\u0646\u064A\u062F\u061F"</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/javascript-with-shas/_8">Good fingerprint present in all of them:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/javascript-with-shas/_9" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>throw new Error("B64 D.1");};if(at[1]==-1){throw new Error("B64 D.2");};if(at[2]==-1){if(f<ay.length new="" error="" d.3="" if="" d.4=""/></code></pre></div></div></div><p>Googling most domains gives only very few results, and most of them are just useless lists of expired domains. Skipping those for now.</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/google-searches-for-known-domains-and-ips/_2" wp_automatic_readability="23.913043478261">Googling <code>"dedrickonline.com"</code> has a git at www.webwiki.de/dedrickonline.com# Furthermore, it also contains the IP address “65.61.127.174” under the “Technik” tab!</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/google-searches-for-known-domains-and-ips/_3" wp_automatic_readability="30.954773869347">Unfortunately that website appears to be split by language? E.g. the English version does not contain it: www.webwiki.com/dedrickonline.com, which would make searching a bit harder, but still doable.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/google-searches-for-known-domains-and-ips/_4">But if we can Google search those IPs there, we might just hit gold.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/google-searches-for-known-domains-and-ips/_5">IP search did work! www.webwiki.de/65.61.127.174</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/google-searches-for-known-domains-and-ips/_6" wp_automatic_readability="31.396226415094">But doesn’t often/ever work unfortunately for others.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/google-searches-for-known-domains-and-ips/_7" wp_automatic_readability="24.136518771331">Searching on github.com: github.com/DrWhax/cia-website-comms by Jurre van Bergen from September 2022 contains some of the links to some of the ones reported by Reuters including some of their JARs, presumably for reversing purposees. Pinged him at: github.com/DrWhax/cia-website-comms/issues/1</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/breakthroughs/_1" wp_automatic_readability="3.2551440329218">Some less-trivial breakthroughs:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_1" wp_automatic_readability="27.836431226766">Grepping the 2013 DNS Census first by overused CGI comms subdomains <code>secure.</code> and <code>ssl.</code> leaves 200k lines. Grepping for the overused “news” led to hits:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_2"><li id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_3">secure.worldnewsandent.com,2012-02-13T21:28:15,208.254.40.117</li><li id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_4">ssl.beyondnetworknews.com,2012-02-13T20:10:13,66.104.175.40</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_10" wp_automatic_readability="26.262975778547">OK, after the initial successes in <code>secure.</code>, we went a bit more data intensive:New results: only one…</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_16"><li id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_17">208.254.42.205 secure.driversinternationalgolf.com,2012-02-13T10:42:20,</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/secure-subdomain-search-on-2013-dns-census/_18" wp_automatic_readability="26.189189189189">After 2013 DNS Census virtual host cleanup heuristic keyword searches we later understood why there were so few hits here: the 2013 DNS Census didn’t capture the <code>secure.</code> subdomains of many domains it had for some reason. Shame, because if it had, this method would have yielded many more results.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/oleg-shakirov-s-findings/_3" wp_automatic_readability="8.758064516129">He then proceeded to give Carson and 5 other domains in private communication. His name is given here with his consent. His advances besides not being blind were Yandexing for some of the known hits which led to pages that contained other hits:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/oleg-shakirov-s-findings/_7" wp_automatic_readability="9.9846153846154">Unfortunately, these methods are not very generalizable, and didn’t lead to a large number of other hits. But every domain counts!</div><div class="figure"><figure id="cirosantilli/cia-2010-covert-communication-websites/image-2004-wayback-machine-archive-of-alljohnny-com" wp_automatic_readability="0.83928571428571"><div class="float-wrap"><img data-lazyloaded="1" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MTEiIGhlaWdodD0iNzE3IiB2aWV3Qm94PSIwIDAgODExIDcxNyI+PHJlY3Qgd2lkdGg9IjEwMCUiIGhlaWdodD0iMTAwJSIgc3R5bGU9ImZpbGw6I2NmZDRkYjtmaWxsLW9wYWNpdHk6IDAuMTsiLz48L3N2Zz4=" width="811" height="717" decoding="async" data-src="https://raw.githubusercontent.com/cirosantilli/media/master/cia-2010-covert-communication-websites/screenshots/alljohnny.com.jpg" loading="lazy"/></div><figcaption wp_automatic_readability="1.6785714285714"><span class="caption-prefix">Figure 1. </span></p><p>2004 Wayback Machine archive of alljohnny.com</p><p>.</figcaption></figure></div><p>What follows is the previous</p><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/searching-for-carson/_4" wp_automatic_readability="7.0020746887967">Some text visible on the Reuters screenshot:It is unclear however if this text is plaintext or part of a an image.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/searching-for-carson/_15" wp_automatic_readability="3.4846787479407">Some failed attempts, either dry guesses or from DNS grepping dataset searches:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_1">Scrapped justdropped data, patched:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_2" wp_automatic_readability="18"><div wp_automatic_readability="31"><pre><code>+++ b/cia-2010-covert-communication-websites/cdx-post.sh @@ -1,7 +1,7 @@ #!/usr/bin/env bash # Post process the output of cdx.sh to enrich IDs even further, and reconstruct easier to Web Archive inspect domain names. -grep -P -e '([^,)]+)\)\/\1\.swf|\)/[^/]+.jar|([^,)]+),([^,)]+),([^,)]+)\)/cgi-bin/[^/]+\.cgi' "$1" | - sed -r 's/\).*//' | awk -F, '{ printf("%s.%s\n", $2, $1) }' | uniq -c | awk '$1 == 1{ print $2 }' | tee $1.post +grep -P -e '([^,)]+)\)\/\1\.swf|\)/[^/]+.jar|([^,)]+),([^,)]+),([^,)]+)\)/cgi-bin/[^/]+\.cgi' "$1"| + sed -r 's/\).*//' | awk -F, '{ printf("%s.%s\n", $2, $1) }' | uniq -c | awk '{ print $2 }' | tee $1.post</code></pre></div></div><p>and then:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_3" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>./hupo-cdx-tor.sh out 'news|headline|internationali|mondo|mundo|mondi|iran|today' 2006 2022</code></pre></div></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_200" wp_automatic_readability="5.8325242718447">2010. Suspicious. But no clear fingrenprint. Also not as shallow as others. Also Joomla based which would be novel.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_263">sandstormnews.com 2011, SWF Arabic. <code>ul.rss-items > li.rss-item</code>, split header</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_272">zerosandonesnews.com 2011. SWF Split header, <code>ul.rss-items > li.rss-item</code></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/work-log/_293" wp_automatic_readability="5.9183673469388">mynepalnews.com, split header images, <code>ul.rss-items > li.rss-item</code>, Unarchived jar:</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_1" wp_automatic_readability="5.8553459119497">Summary: this is just a red herring. Wakatime owner likely registered the domains just after this article was published as a publicity stunt. Fair play though.</div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_14" wp_automatic_readability="5.8557692307692">Running e.g.</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_15" wp_automatic_readability="6"><div wp_automatic_readability="7"><pre><code>curl -vvv dedrickonline.com</code></pre></div></div><p>gives:</p><div class="code" id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_16" wp_automatic_readability="7.7322834645669"><div wp_automatic_readability="10.63188976378"><pre><code>* Trying 162.255.119.197:80... * Connected to dedrickonline.com (162.255.119.197) port 80 (#0) > GET / HTTP/1.1 > Host: dedrickonline.com > User-Agent: curl/7.88.1 > Accept: */* > < HTTP/1.1 301 Moved Permanently < Date: Mon, 12 Jun 2023 20:30:19 GMT < Content-Type: text/html; charset=utf-8 < Content-Length: 55 < Connection: keep-alive < Location: < X-Served-By: Namecheap URL Forward < Server: namecheap-nginx < Moved Permanently. * Connection #0 to host dedrickonline.com left intact</code></pre></div></div><p>so we see that he must have setup redirection with Namecheap as mentioned at: www.namecheap.com/support/knowledgebase/article.aspx/385/2237/how-to-redirect-a-url-for-a-domain/</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_17">Let’s also try DNS history</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_18"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_19">whoisrequest.com/history/:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_20"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_21">dedrickonline.com: registered: 1 Nov, 2010, dropped: 24 Nov, 2013</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_22">activegaminginfo.com : registered: 1 Feb, 2010, dropped: 1 Apr, 2012</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_23">tools.whoisxmlapi.com/whois-history-search<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_24"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_25">dedrickonline.com:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_26"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_27">CIA (registrar: Godaddy, registrant name: domainsbyproxy.com)<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_28"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_29">Created Date: October 27, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_30">Updated Date: October 28, 2013 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_31">Expires Date: October 27, 2014 00:00:00 UTC</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_32">Alan (namecheap):<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_33"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_34">Created Date: June 11, 2023 09:59:25 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_35">Expires Date: June 11, 2024 09:59:25 UTC</li></ul></div></li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_36">activegaminginfo.com:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_37"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_38">CIA (Network Solutions, registrant name: LLC. Corral, Elizabeth|ATTN ACTIVEGAMINGINFO.COM|care of Network Solutions)<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_39"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_40">Created Date: January 26, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_41">Updated Date: November 27, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_42">Expires Date: January 26, 2012 00:00:00 UTC</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_43">Alan:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_44"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_45">Created Date: June 11, 2023 09:59:40 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_46">Expires Date: June 11, 2024 09:59:40 UTC</li></ul></div></li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_47">iraniangoalkicks.com:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_48"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_49">CIA (registrar: Godaddy, registrant name: domainsbyproxy.com)<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_50"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_51">Created Date: April 9, 2007 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_52">Updated Date: March 2, 2011 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_53">Expires Date: April 9, 2011 00:00:00 UTC</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_54">Alan:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_55"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_56">Created Date: June 11, 2023 09:59:20 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_57">Expires Date: June 11, 2024 09:59:20 UTC</li></ul></div></li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_58">iraniangoals.com:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_59"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_60">CIA (registrar: Godaddy, registrant name: domainsbyproxy.com):<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_61"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_62">Created Date: March 6, 2008 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_63">Updated Date: March 7, 2011 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_64">Expires Date: March 6, 2014 00:00:00 UTC</li></ul></div></li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_65">Reuters:<div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_66"><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_67">Created Date: September 29, 2022 11:16:09 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_68">Updated Date: September 29, 2022 11:16:09 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/wakatime-redirects/_69">Expires Date: September 29, 2023 11:16:09 UTC</li></ul></div></li></ul></div></li></ul></div></li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_1" wp_automatic_readability="5.6111111111111">whoisxmlapi WHOIS history April 11, 2011:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_2"><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_3">Created Date: March 6, 2008 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_4">Updated Date: March 7, 2011 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_5">Expires Date: March 6, 2014 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_6">Registrant Name: domainsbyproxy.com.</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_7">Registrant Organization: Domains by Proxy, Inc.</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_8">Registrant Street: 15111 N. Hayden Rd., Ste 160,</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_9">Registrant City: Scottsdale</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_10">Registrant State/Province: Arizona</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_11">Registrant Postal Code: 85260</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_12">Registrant Country: UNITED STATES</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_13">Name servers: NS29.WORLDNIC.COM|NS30.WORLDNIC.COM</li></ul></div><p>Folowed by reuters registration in 2022.</p></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_14">whoisrequest.com/history/ mentions:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_15"><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_16">1 Apr, 2008: Domain created*, nameservers added. Nameservers:</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_17">ns1.webhostingpad.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoals-com/_18">ns2.webhostingpad.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_1">whoisxmlapi WHOIS history March 23, 2011:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_2"><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_3">Created Date: April 9, 2007 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_4">Updated Date: March 2, 2011 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_5">Expires Date: April 9, 2011 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_6">Registrant Name: domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_7">Name servers: dns1.registrar-servers.com|dns2.registrar-servers.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_8" wp_automatic_readability="7.2">whoisrequest.com/history/ mentions:<br />1 May, 2007: Domain created*, nameservers added. Nameservers:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_9"><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_10">ns1.qwknetllc.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/iraniangoalkicks-com/_11">ns2.qwknetllc.com</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_2">whoisxmlapi WHOIS history March 22, 2011:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_4">Registrar Name: NETWORK SOLUTIONS, LLC.</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_5">Created Date: January 26, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_6">Updated Date: November 27, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_7">Expires Date: January 26, 2012 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_8">Registrant Name: Corral, Elizabeth|ATTN ACTIVEGAMINGINFO.COM|care of Network Solutions</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_9">Registrant Street: PO Box 459</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_10">Registrant City: PA</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_11">Registrant State/Province: US</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_12">Registrant Postal Code: 18222</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_13">Registrant Country: UNITED STATES</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_14">Administrative Name: Corral, Elizabeth|ATTN ACTIVEGAMINGINFO.COM|care of Network Solutions</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_15">Administrative Street: PO Box 459</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_16">Administrative City: Drums</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_17">Administrative State/Province: PA</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_18">Administrative Postal Code: 18222</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_19">Administrative Country: UNITED STATES</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_20">Administrative Email: xc2mv7ur8cw@networksolutionsprivateregistration.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_21">Administrative Phone: 5707088780</li><li id="cirosantilli/cia-2010-covert-communication-websites/activegameinfo-com/_22">Name servers: NS23.DOMAINCONTROL.COM|NS24.DOMAINCONTROL.COM</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_2" wp_automatic_readability="6.6262626262626">whoisxmlapi WHOIS record on April 28, 2011</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_4">Registrar Name: GODADDY.COM, INC</li><li id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_5">Created Date: February 9, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_6">Updated Date: February 9, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_7">Expires Date: February 9, 2015 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_8">Registrant Name: domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/feedsdemexicoyelmundo-com/_9">Name servers: NS55.DOMAINCONTROL.COM|NS56.DOMAINCONTROL.COM</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_2" wp_automatic_readability="6.6086956521739">whoisxmlapi WHOIS record on September 13, 2011</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_4">Registrar Name: NETWORK SOLUTIONS, LLC</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_5">Created Date: February 17, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_6">Updated Date: February 17, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_7">Expires Date: February 17, 2015 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_8">Registrant Name: See, Megan|ATTN NOTICIASMUSICA.NET|care of Network Solutions</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_9">Registrant Street: PO Box 459</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_10">Registrant City: PA</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_11">Registrant State/Province: US</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_12">Registrant Postal Code: 18222</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_13">Registrant Country: UNITED STATES</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_14">Administrative Contact</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_15">Administrative Name: See, Megan|ATTN NOTICIASMUSICA.NET|care of Network Solutions</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_16">Administrative Street: PO Box 459</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_17">Administrative City: Drums</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_18">Administrative State/Province: PA</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_19">Administrative Postal Code: 18222</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_20">Administrative Country: UNITED STATES</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_21">Administrative Email: hf3eg77c4nn@networksolutionsprivateregistration.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_22">Administrative Phone: 5707088780</li><li id="cirosantilli/cia-2010-covert-communication-websites/noticiasmusica-net/_23">Name Servers: NS45.WORLDNIC.COM|NS46.WORLDNIC.COM</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_2" wp_automatic_readability="6.75">whoisxmlapi WHOIS record on April 17, 2011</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_3"><li id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_4">Created Date: April 9, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_5">Updated Date: April 9, 2010 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_6">Expires Date: April 9, 2012 00:00:00 UTC</li><li id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_7">Registrant Name: domainsbyproxy.com</li><li id="cirosantilli/cia-2010-covert-communication-websites/atomworldnews-com/_8">Name servers: NS33.DOMAINCONTROL.COM|NS34.DOMAINCONTROL.COM</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/backlinks/_21">Pings by self:</p><div class="list"><ul id="cirosantilli/cia-2010-covert-communication-websites/backlinks/_22"><li id="cirosantilli/cia-2010-covert-communication-websites/backlinks/_23">2025-03-13:</li><li id="cirosantilli/cia-2010-covert-communication-websites/backlinks/_27">2025-03-31 going to find random interested people on Twitter:</li><li id="cirosantilli/cia-2010-covert-communication-websites/backlinks/_46">2025-05-05:</li></ul></div></div><div class="p" id="cirosantilli/cia-2010-covert-communication-websites/backlinks/_65">Notable reactions to the websites themselves</div></div><p><br /> <br /><a href="https://ourbigbook.com/cirosantilli/cia-2010-covert-communication-websites" target="_blank" rel="noopener">Source link </a></p><div class="fpm_end"></div></div><footer class="entry-footer"> <span class="tags-links">Tagged: <a href="https://techelevate.us/tag/cia/" rel="tag">CIA</a> <a href="https://techelevate.us/tag/ciro/" rel="tag">Ciro</a> <a href="https://techelevate.us/tag/cirosantilli/" rel="tag">cirosantilli</a> <a href="https://techelevate.us/tag/communication/" rel="tag">Communication</a> <a href="https://techelevate.us/tag/covert/" rel="tag">covert</a> <a href="https://techelevate.us/tag/santilli/" rel="tag">Santilli</a> <a href="https://techelevate.us/tag/websites/" rel="tag">Websites</a></span></footer><nav class="navigation post-navigation" aria-label="Posts"><h2 class="screen-reader-text">Post navigation</h2><div class="nav-links"><div class="nav-previous"><a href="https://techelevate.us/2025/05/26/pizza-bandit-combines-gears-of-war-and-overcooked-for-a-tasty-shooter-slice-ign/" rel="prev"><span class="nav-subtitle"><i class="fas fa-angle-double-left"></i>Previous:</span> <span class="nav-title">Pizza Bandit Combines Gears of War and Overcooked for a Tasty Shooter Slice – IGN</span></a></div><div class="nav-next"><a href="https://techelevate.us/2025/05/26/how-to-stop-ai-depicting-iphones-in-bygone-eras/" rel="next"><span class="nav-subtitle">Next:<i class="fas fa-angle-double-right"></i></span> <span class="nav-title">How to Stop AI Depicting iPhones in Bygone Eras</span></a></div></div></nav></div><div id="comments" class="comments-area"><div id="respond" class="comment-respond"><h3 id="reply-title" class="comment-reply-title">Leave a Reply <small><a rel="nofollow" id="cancel-comment-reply-link" href="/2025/05/26/cia-2010-covert-communication-websites-ciro-santilli-cirosantilli/#respond" style="display:none;">Cancel reply</a></small></h3><form action="https://techelevate.us/wp-comments-post.php" method="post" id="commentform" class="comment-form" novalidate><p class="comment-notes"><span id="email-notes">Your email address will not be published.</span> <span class="required-field-message">Required fields are marked <span class="required">*</span></span></p><p class="comment-form-comment"><label for="comment">Comment <span class="required">*</span></label><textarea id="comment" name="comment" cols="45" rows="8" maxlength="65525" required></textarea></p><p class="comment-form-author"><label for="author">Name <span class="required">*</span></label> <input id="author" name="author" type="text" value="" size="30" maxlength="245" autocomplete="name" required /></p><p class="comment-form-email"><label for="email">Email <span class="required">*</span></label> <input id="email" name="email" type="email" value="" size="30" maxlength="100" aria-describedby="email-notes" autocomplete="email" required /></p><p class="comment-form-url"><label for="url">Website</label> <input id="url" name="url" type="url" value="" size="30" maxlength="200" autocomplete="url" /></p><p class="comment-form-cookies-consent"><input id="wp-comment-cookies-consent" name="wp-comment-cookies-consent" type="checkbox" value="yes" /> <label for="wp-comment-cookies-consent">Save my name, email, and website in this browser for the next time I comment.</label></p><p class="form-submit"><input name="submit" type="submit" id="submit" class="submit" value="Post Comment" /> <input type='hidden' name='comment_post_ID' value='4820' id='comment_post_ID' /> <input type='hidden' name='comment_parent' id='comment_parent' value='0' /></p></form></div></div></article><div class="single-related-posts-section-wrap layout--list"><div class="single-related-posts-section"> <a href="javascript:void(0);" class="related_post_close"> <i class="fas fa-times-circle"></i> </a><h2 class="newsmatic-block-title"><span>Related News</span></h2><div class="single-related-posts-wrap"><article post-id="post-4914" class="post-4914 post type-post status-publish format-standard has-post-thumbnail hentry category-internet-web tag-agents tag-designers tag-developers tag-strategists"><figure class="post-thumb-wrap "><div class="post-thumbnail"> <img data-lazyloaded="1" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9Ijc5OSIgdmlld0JveD0iMCAwIDEyMDAgNzk5Ij48cmVjdCB3aWR0aD0iMTAwJSIgaGVpZ2h0PSIxMDAlIiBzdHlsZT0iZmlsbDojY2ZkNGRiO2ZpbGwtb3BhY2l0eTogMC4xOyIvPjwvc3ZnPg==" width="1200" height="799" post-id="4914" fifu-featured="1" data-src="https://i2.wp.com/webdesignerdepot-wp.s3.us-east-2.amazonaws.com/2025/05/22153511/1-11.jpg?w=1200&resize=1200,0&ssl=1" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="AI Agents for Designers, Developers, and UX Strategists: What You Need to Know Now" title="AI Agents for Designers, Developers, and UX Strategists: What You Need to Know Now" title="AI Agents for Designers, Developers, and UX Strategists: What You Need to Know Now" decoding="async" /></div></figure><div class="post-element"><h2 class="post-title"><a href="https://techelevate.us/2025/05/30/ai-agents-for-designers-developers-and-ux-strategists-what-you-need-to-know-now/">AI Agents for Designers, Developers, and UX Strategists: What You Need to Know Now</a></h2><div class="post-meta"> <span class="byline"> <span class="author vcard"><a class="url fn n author_name" href="https://techelevate.us/author/ellonjohns/">ellonjohns</a></span></span><span class="post-date posted-on published"><a href="https://techelevate.us/2025/05/30/ai-agents-for-designers-developers-and-ux-strategists-what-you-need-to-know-now/" rel="bookmark"><time class="entry-date published updated" datetime="2025-05-30T03:32:13+00:00">3 hours ago</time></a></span> <a href="https://techelevate.us/2025/05/30/ai-agents-for-designers-developers-and-ux-strategists-what-you-need-to-know-now/#comments"><span class="post-comment">0</span></a></div></div></article><article post-id="post-4893" class="post-4893 post type-post status-publish format-standard has-post-thumbnail hentry category-internet-web tag-css tag-csstricks tag-order tag-reading"><figure class="post-thumb-wrap "><div class="post-thumbnail"> <img data-lazyloaded="1" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjYwMCIgdmlld0JveD0iMCAwIDEyMDAgNjAwIj48cmVjdCB3aWR0aD0iMTAwJSIgaGVpZ2h0PSIxMDAlIiBzdHlsZT0iZmlsbDojY2ZkNGRiO2ZpbGwtb3BhY2l0eTogMC4xOyIvPjwvc3ZnPg==" width="1200" height="600" post-id="4893" fifu-featured="1" data-src="https://i0.wp.com/css-tricks.com/wp-content/uploads/2022/06/books-code.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="What We Know (So Far) About CSS Reading Order | CSS-Tricks" title="What We Know (So Far) About CSS Reading Order | CSS-Tricks" title="What We Know (So Far) About CSS Reading Order | CSS-Tricks" decoding="async" /></div></figure><div class="post-element"><h2 class="post-title"><a href="https://techelevate.us/2025/05/29/what-we-know-so-far-about-css-reading-order-css-tricks/">What We Know (So Far) About CSS Reading Order | CSS-Tricks</a></h2><div class="post-meta"> <span class="byline"> <span class="author vcard"><a class="url fn n author_name" href="https://techelevate.us/author/ellonjohns/">ellonjohns</a></span></span><span class="post-date posted-on published"><a href="https://techelevate.us/2025/05/29/what-we-know-so-far-about-css-reading-order-css-tricks/" rel="bookmark"><time class="entry-date published updated" datetime="2025-05-29T10:51:34+00:00">20 hours ago</time></a></span> <a href="https://techelevate.us/2025/05/29/what-we-know-so-far-about-css-reading-order-css-tricks/#comments"><span class="post-comment">0</span></a></div></div></article><article post-id="post-4875" class="post-4875 post type-post status-publish format-standard has-post-thumbnail hentry category-internet-web tag-scalability tag-site tag-sitepoint tag-smart tag-starts tag-structure tag-wordpress"><figure class="post-thumb-wrap "><div class="post-thumbnail"> <img data-lazyloaded="1" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjYzMCIgdmlld0JveD0iMCAwIDEyMDAgNjMwIj48cmVjdCB3aWR0aD0iMTAwJSIgaGVpZ2h0PSIxMDAlIiBzdHlsZT0iZmlsbDojY2ZkNGRiO2ZpbGwtb3BhY2l0eTogMC4xOyIvPjwvc3ZnPg==" width="1200" height="630" post-id="4875" fifu-featured="1" data-src="https://i0.wp.com/uploads.sitepoint.com/wp-content/uploads/2025/05/1748249724Why-WordPress-Scalability-Starts-with-Smart-Site-Structure-from-Day-One.jpg?w=1200&resize=1200,0&ssl=1" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Why WordPress Scalability Starts with Smart Site Structure — SitePoint" title="Why WordPress Scalability Starts with Smart Site Structure — SitePoint" title="Why WordPress Scalability Starts with Smart Site Structure — SitePoint" decoding="async" loading="lazy" /></div></figure><div class="post-element"><h2 class="post-title"><a href="https://techelevate.us/2025/05/28/why-wordpress-scalability-starts-with-smart-site-structure-sitepoint/">Why WordPress Scalability Starts with Smart Site Structure — SitePoint</a></h2><div class="post-meta"> <span class="byline"> <span class="author vcard"><a class="url fn n author_name" href="https://techelevate.us/author/ellonjohns/">ellonjohns</a></span></span><span class="post-date posted-on published"><a href="https://techelevate.us/2025/05/28/why-wordpress-scalability-starts-with-smart-site-structure-sitepoint/" rel="bookmark"><time class="entry-date published updated" datetime="2025-05-28T18:10:00+00:00">2 days ago</time></a></span> <a href="https://techelevate.us/2025/05/28/why-wordpress-scalability-starts-with-smart-site-structure-sitepoint/#comments"><span class="post-comment">0</span></a></div></div></article><article post-id="post-4857" class="post-4857 post type-post status-publish format-standard has-post-thumbnail hentry category-internet-web tag-data tag-findings tag-insights tag-magazine tag-smashing"><figure class="post-thumb-wrap "><div class="post-thumbnail"> <img data-lazyloaded="1" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjY3NSIgdmlld0JveD0iMCAwIDEyMDAgNjc1Ij48cmVjdCB3aWR0aD0iMTAwJSIgaGVpZ2h0PSIxMDAlIiBzdHlsZT0iZmlsbDojY2ZkNGRiO2ZpbGwtb3BhY2l0eTogMC4xOyIvPjwvc3ZnPg==" width="1200" height="675" post-id="4857" fifu-featured="1" data-src="https://i2.wp.com/files.smashing.media/articles/data-vs-findings-vs-insights-ux/data-vs-findings-vs-insights-ux.jpg?w=1200&resize=1200,0&ssl=1" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Data Vs. Findings Vs. Insights In UX — Smashing Magazine" title="Data Vs. Findings Vs. Insights In UX — Smashing Magazine" title="Data Vs. Findings Vs. Insights In UX — Smashing Magazine" decoding="async" loading="lazy" /></div></figure><div class="post-element"><h2 class="post-title"><a href="https://techelevate.us/2025/05/28/data-vs-findings-vs-insights-in-ux-smashing-magazine/">Data Vs. Findings Vs. Insights In UX — Smashing Magazine</a></h2><div class="post-meta"> <span class="byline"> <span class="author vcard"><a class="url fn n author_name" href="https://techelevate.us/author/ellonjohns/">ellonjohns</a></span></span><span class="post-date posted-on published"><a href="https://techelevate.us/2025/05/28/data-vs-findings-vs-insights-in-ux-smashing-magazine/" rel="bookmark"><time class="entry-date published updated" datetime="2025-05-28T01:29:26+00:00">2 days ago</time></a></span> <a href="https://techelevate.us/2025/05/28/data-vs-findings-vs-insights-in-ux-smashing-magazine/#comments"><span class="post-comment">0</span></a></div></div></article></div></div></div></div></div><div class="secondary-sidebar"><aside id="secondary" class="widget-area"><section id="block-1" class="widget widget_block widget_search"><form role="search" method="get" action="https://techelevate.us/" class="wp-block-search__button-outside wp-block-search__text-button wp-block-search" ><label class="wp-block-search__label" for="wp-block-search__input-1" >Search</label><div class="wp-block-search__inside-wrapper " ><input class="wp-block-search__input" id="wp-block-search__input-1" placeholder="" value="" type="search" name="s" required /><button aria-label="Search" class="wp-block-search__button wp-element-button" type="submit" >Search</button></div></form></section><section id="block-2" class="widget widget_block"><div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Posts</h2><ul class="wp-block-latest-posts__list wp-block-latest-posts"><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/wecreat-vision-pro-45w-review-greater-than-the-sum-of-its-parts/">WeCreat Vision Pro 45W review: Greater than the sum of its parts</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/accelerating-silicon-carbide-sic-manufacturing-with-big-data-platforms/">Accelerating silicon carbide (SiC) manufacturing with big data platforms</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/nintendo-switch-2-pre-order-updates-ahead-of-the-june-5-launch-date/">Nintendo Switch 2 pre-order updates ahead of the June 5 launch date</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/a-coding-guide-for-building-a-self-improving-ai-agent-using-googles-gemini-api-with-intelligent-adaptation-features/">A Coding Guide for Building a Self-Improving AI Agent Using Google’s Gemini API with Intelligent Adaptation Features</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/ai-agents-for-designers-developers-and-ux-strategists-what-you-need-to-know-now/">AI Agents for Designers, Developers, and UX Strategists: What You Need to Know Now</a></li></ul></div></div></section><section id="block-3" class="widget widget_block"><div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Recent Comments</h2><div class="no-comments wp-block-latest-comments">No comments to show.</div></div></div></section><section id="block-4" class="widget widget_block"><div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Archives</h2><ul class="wp-block-archives-list wp-block-archives"><li><a href='https://techelevate.us/2025/05/'>May 2025</a></li><li><a href='https://techelevate.us/2025/04/'>April 2025</a></li><li><a href='https://techelevate.us/2025/03/'>March 2025</a></li><li><a href='https://techelevate.us/2025/02/'>February 2025</a></li><li><a href='https://techelevate.us/2025/01/'>January 2025</a></li><li><a href='https://techelevate.us/2024/12/'>December 2024</a></li></ul></div></div></section><section id="block-5" class="widget widget_block"><div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow"><h2 class="wp-block-heading">Categories</h2><ul class="wp-block-categories-list wp-block-categories"><li class="cat-item cat-item-4"><a href="https://techelevate.us/artificial-intelligence-ai/">Artificial Intelligence (AI)</a></li><li class="cat-item cat-item-1"><a href="https://techelevate.us/consumer-electronics/">Consumer Electronics</a></li><li class="cat-item cat-item-8"><a href="https://techelevate.us/cybersecurity/">Cybersecurity</a></li><li class="cat-item cat-item-7"><a href="https://techelevate.us/emerging-technologies/">Emerging Technologies</a></li><li class="cat-item cat-item-3"><a href="https://techelevate.us/gadgets-reviews/">Gadgets & Reviews</a></li><li class="cat-item cat-item-6"><a href="https://techelevate.us/gaming-technology/">Gaming Technology</a></li><li class="cat-item cat-item-26"><a href="https://techelevate.us/hardware/">Hardware</a></li><li class="cat-item cat-item-5"><a href="https://techelevate.us/internet-web/">Internet & Web</a></li><li class="cat-item cat-item-2"><a href="https://techelevate.us/software-apps/">Software & Apps</a></li></ul></div></div></section></aside></div></div></div></main></div><footer id="colophon" class="site-footer dark_bk"><div class="main-footer boxed-width"><div class="footer-inner newsmatic-container"><div class="row"><div class="footer-widget column-three"><section id="newsmatic_widget_title_widget-1" class="widget widget_newsmatic_widget_title_widget"><h2 class="newsmatic-widget-title align--left"> <span>Tech <sub>Elevate</sub></span></h2></section><section id="block-7" class="widget widget_block"><div style="height:2px" aria-hidden="true" class="wp-block-spacer"></div></section><section id="block-8" class="widget widget_block widget_text"><p style="font-size:15px;letter-spacing:0px">From cutting-edge innovations and product reviews to expert opinions and how-to guides, our site delivers valuable information to help readers understand the complexities of the digital world. Explore diverse topics, discover new tech ideas, and elevate your knowledge with Tech Elevate.<br><br></p></section><section id="block-8" class="widget widget_block widget_text"><p style="font-size:15px;letter-spacing:0px">From cutting-edge innovations and product reviews to expert opinions and how-to guides, our site delivers valuable information to help readers understand the complexities of the digital world. Explore diverse topics, discover new tech ideas, and elevate your knowledge with Tech Elevate.<br><br></p></section></div><div class="footer-widget column-three"><section id="newsmatic_widget_title_widget-2" class="widget widget_newsmatic_widget_title_widget"><h2 class="newsmatic-widget-title align--left"> <span>Useful <sub>Links</sub></span></h2></section><section id="block-10" class="widget widget_block widget_categories"><ul class="wp-block-categories-list wp-block-categories"><li class="cat-item cat-item-4"><a href="https://techelevate.us/artificial-intelligence-ai/">Artificial Intelligence (AI)</a> (244)</li><li class="cat-item cat-item-1"><a href="https://techelevate.us/consumer-electronics/">Consumer Electronics</a> (188)</li><li class="cat-item cat-item-8"><a href="https://techelevate.us/cybersecurity/">Cybersecurity</a> (244)</li><li class="cat-item cat-item-7"><a href="https://techelevate.us/emerging-technologies/">Emerging Technologies</a> (244)</li><li class="cat-item cat-item-3"><a href="https://techelevate.us/gadgets-reviews/">Gadgets & Reviews</a> (242)</li><li class="cat-item cat-item-6"><a href="https://techelevate.us/gaming-technology/">Gaming Technology</a> (246)</li><li class="cat-item cat-item-26"><a href="https://techelevate.us/hardware/">Hardware</a> (243)</li><li class="cat-item cat-item-5"><a href="https://techelevate.us/internet-web/">Internet & Web</a> (244)</li><li class="cat-item cat-item-2"><a href="https://techelevate.us/software-apps/">Software & Apps</a> (247)</li></ul></section></div><div class="footer-widget column-three"><section id="newsmatic_widget_title_widget-3" class="widget widget_newsmatic_widget_title_widget"><h2 class="newsmatic-widget-title align--left"> <span>Latest <sub>News</sub></span></h2></section><section id="block-11" class="widget widget_block widget_recent_entries"><ul class="wp-block-latest-posts__list wp-block-latest-posts"><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/wecreat-vision-pro-45w-review-greater-than-the-sum-of-its-parts/">WeCreat Vision Pro 45W review: Greater than the sum of its parts</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/accelerating-silicon-carbide-sic-manufacturing-with-big-data-platforms/">Accelerating silicon carbide (SiC) manufacturing with big data platforms</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/nintendo-switch-2-pre-order-updates-ahead-of-the-june-5-launch-date/">Nintendo Switch 2 pre-order updates ahead of the June 5 launch date</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/a-coding-guide-for-building-a-self-improving-ai-agent-using-googles-gemini-api-with-intelligent-adaptation-features/">A Coding Guide for Building a Self-Improving AI Agent Using Google’s Gemini API with Intelligent Adaptation Features</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/ai-agents-for-designers-developers-and-ux-strategists-what-you-need-to-know-now/">AI Agents for Designers, Developers, and UX Strategists: What You Need to Know Now</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/30/switch-2-leaker-explains-how-he-got-the-console-early-and-why-hes-not-afraid-of-nintendo/">Switch 2 Leaker Explains How He Got The Console Early And Why He’s Not Afraid Of Nintendo</a></li><li><a class="wp-block-latest-posts__post-title" href="https://techelevate.us/2025/05/29/wwdc-2025-what-we-expect-apple-to-reveal-including-new-ios-macos-apple-intelligence-and-more/">WWDC 2025: What we expect Apple to reveal including new iOS, macOS, Apple Intelligence and more</a></li></ul></section></div></div></div></div><div class="bottom-footer"><div class="newsmatic-container"><div class="row"><div class="bottom-inner-wrapper"><div class="site-info"> Tech Elevate 2024-2028 all rights reserved. Powered By <a href="https://blazethemes.com/">BlazeThemes</a>.</div><div class="bottom-menu"><div class="menu-bottom-menu-container"><ul id="bottom-footer-menu" class="menu"><li id="menu-item-401" class="menu-item menu-item-type-post_type menu-item-object-page menu-item-401"><a href="https://techelevate.us/about-us/">About Us</a></li><li id="menu-item-400" class="menu-item menu-item-type-post_type menu-item-object-page menu-item-400"><a href="https://techelevate.us/contact-us/">Contact Us</a></li><li id="menu-item-399" class="menu-item menu-item-type-post_type menu-item-object-page menu-item-399"><a href="https://techelevate.us/disclaimer/">Disclaimer</a></li><li id="menu-item-397" class="menu-item menu-item-type-post_type menu-item-object-page menu-item-397"><a href="https://techelevate.us/privacy-policy/">Privacy Policy</a></li><li id="menu-item-398" class="menu-item menu-item-type-post_type menu-item-object-page menu-item-398"><a href="https://techelevate.us/terms-condition/">Terms & Condition</a></li></ul></div></div></div></div></div></div></footer><div id="newsmatic-scroll-to-top" class="align--right"> <span class="icon-holder"><i class="fas fa-angle-up"></i></span></div></div> <script id="newsmatic-theme-js-extra" type="litespeed/javascript">var newsmaticObject={"_wpnonce":"cf1509d0dc","ajaxUrl":"https:\/\/techelevate.us\/wp-admin\/admin-ajax.php","stt":"1","stickey_header":"","livesearch":""}</script> <script id="fifu-json-ld-js-extra" type="litespeed/javascript">var fifuJsonLd={"url":"https:\/\/raw.githubusercontent.com\/cirosantilli\/media\/master\/cia-2010-covert-communication-websites\/2013-dns-census-a-novirt-hist.svg"}</script> <script type="litespeed/javascript">!function(){window.advanced_ads_ready_queue=window.advanced_ads_ready_queue||[],advanced_ads_ready_queue.push=window.advanced_ads_ready;for(var d=0,a=advanced_ads_ready_queue.length;d<a;d++)advanced_ads_ready(advanced_ads_ready_queue[d])}();</script><script type="litespeed/javascript">var rocket_beacon_data={"ajax_url":"https:\/\/techelevate.us\/wp-admin\/admin-ajax.php","nonce":"ded9727ec2","url":"https:\/\/techelevate.us\/2025\/05\/26\/cia-2010-covert-communication-websites-ciro-santilli-cirosantilli","is_mobile":!1,"width_threshold":1600,"height_threshold":700,"delay":500,"debug":null,"status":{"atf":!0},"elements":"img, video, picture, p, main, div, li, svg, section, header, span"}</script><script data-no-optimize="1">!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?module.exports=e():"function"==typeof define&&define.amd?define(e):(t="undefined"!=typeof globalThis?globalThis:t||self).LazyLoad=e()}(this,function(){"use strict";function e(){return(e=Object.assign||function(t){for(var e=1;e<arguments.length;e++){var n,a=arguments[e];for(n in a)Object.prototype.hasOwnProperty.call(a,n)&&(t[n]=a[n])}return t}).apply(this,arguments)}function i(t){return e({},it,t)}function o(t,e){var n,a="LazyLoad::Initialized",i=new t(e);try{n=new CustomEvent(a,{detail:{instance:i}})}catch(t){(n=document.createEvent("CustomEvent")).initCustomEvent(a,!1,!1,{instance:i})}window.dispatchEvent(n)}function l(t,e){return t.getAttribute(gt+e)}function c(t){return l(t,bt)}function s(t,e){return function(t,e,n){e=gt+e;null!==n?t.setAttribute(e,n):t.removeAttribute(e)}(t,bt,e)}function r(t){return s(t,null),0}function u(t){return null===c(t)}function d(t){return c(t)===vt}function f(t,e,n,a){t&&(void 0===a?void 0===n?t(e):t(e,n):t(e,n,a))}function _(t,e){nt?t.classList.add(e):t.className+=(t.className?" ":"")+e}function v(t,e){nt?t.classList.remove(e):t.className=t.className.replace(new RegExp("(^|\\s+)"+e+"(\\s+|$)")," ").replace(/^\s+/,"").replace(/\s+$/,"")}function g(t){return t.llTempImage}function b(t,e){!e||(e=e._observer)&&e.unobserve(t)}function p(t,e){t&&(t.loadingCount+=e)}function h(t,e){t&&(t.toLoadCount=e)}function n(t){for(var e,n=[],a=0;e=t.children[a];a+=1)"SOURCE"===e.tagName&&n.push(e);return n}function m(t,e){(t=t.parentNode)&&"PICTURE"===t.tagName&&n(t).forEach(e)}function a(t,e){n(t).forEach(e)}function E(t){return!!t[st]}function I(t){return t[st]}function y(t){return delete t[st]}function A(e,t){var n;E(e)||(n={},t.forEach(function(t){n[t]=e.getAttribute(t)}),e[st]=n)}function k(a,t){var i;E(a)&&(i=I(a),t.forEach(function(t){var e,n;e=a,(t=i[n=t])?e.setAttribute(n,t):e.removeAttribute(n)}))}function L(t,e,n){_(t,e.class_loading),s(t,ut),n&&(p(n,1),f(e.callback_loading,t,n))}function w(t,e,n){n&&t.setAttribute(e,n)}function x(t,e){w(t,ct,l(t,e.data_sizes)),w(t,rt,l(t,e.data_srcset)),w(t,ot,l(t,e.data_src))}function O(t,e,n){var a=l(t,e.data_bg_multi),i=l(t,e.data_bg_multi_hidpi);(a=at&&i?i:a)&&(t.style.backgroundImage=a,n=n,_(t=t,(e=e).class_applied),s(t,ft),n&&(e.unobserve_completed&&b(t,e),f(e.callback_applied,t,n)))}function N(t,e){!e||0<e.loadingCount||0<e.toLoadCount||f(t.callback_finish,e)}function C(t,e,n){t.addEventListener(e,n),t.llEvLisnrs[e]=n}function M(t){return!!t.llEvLisnrs}function z(t){if(M(t)){var e,n,a=t.llEvLisnrs;for(e in a){var i=a[e];n=e,i=i,t.removeEventListener(n,i)}delete t.llEvLisnrs}}function R(t,e,n){var a;delete t.llTempImage,p(n,-1),(a=n)&&--a.toLoadCount,v(t,e.class_loading),e.unobserve_completed&&b(t,n)}function T(o,r,c){var l=g(o)||o;M(l)||function(t,e,n){M(t)||(t.llEvLisnrs={});var a="VIDEO"===t.tagName?"loadeddata":"load";C(t,a,e),C(t,"error",n)}(l,function(t){var e,n,a,i;n=r,a=c,i=d(e=o),R(e,n,a),_(e,n.class_loaded),s(e,dt),f(n.callback_loaded,e,a),i||N(n,a),z(l)},function(t){var e,n,a,i;n=r,a=c,i=d(e=o),R(e,n,a),_(e,n.class_error),s(e,_t),f(n.callback_error,e,a),i||N(n,a),z(l)})}function G(t,e,n){var a,i,o,r,c;t.llTempImage=document.createElement("IMG"),T(t,e,n),E(c=t)||(c[st]={backgroundImage:c.style.backgroundImage}),o=n,r=l(a=t,(i=e).data_bg),c=l(a,i.data_bg_hidpi),(r=at&&c?c:r)&&(a.style.backgroundImage='url("'.concat(r,'")'),g(a).setAttribute(ot,r),L(a,i,o)),O(t,e,n)}function D(t,e,n){var a;T(t,e,n),a=e,e=n,(t=It[(n=t).tagName])&&(t(n,a),L(n,a,e))}function V(t,e,n){var a;a=t,(-1<yt.indexOf(a.tagName)?D:G)(t,e,n)}function F(t,e,n){var a;t.setAttribute("loading","lazy"),T(t,e,n),a=e,(e=It[(n=t).tagName])&&e(n,a),s(t,vt)}function j(t){t.removeAttribute(ot),t.removeAttribute(rt),t.removeAttribute(ct)}function P(t){m(t,function(t){k(t,Et)}),k(t,Et)}function S(t){var e;(e=At[t.tagName])?e(t):E(e=t)&&(t=I(e),e.style.backgroundImage=t.backgroundImage)}function U(t,e){var n;S(t),n=e,u(e=t)||d(e)||(v(e,n.class_entered),v(e,n.class_exited),v(e,n.class_applied),v(e,n.class_loading),v(e,n.class_loaded),v(e,n.class_error)),r(t),y(t)}function $(t,e,n,a){var i;n.cancel_on_exit&&(c(t)!==ut||"IMG"===t.tagName&&(z(t),m(i=t,function(t){j(t)}),j(i),P(t),v(t,n.class_loading),p(a,-1),r(t),f(n.callback_cancel,t,e,a)))}function q(t,e,n,a){var i,o,r=(o=t,0<=pt.indexOf(c(o)));s(t,"entered"),_(t,n.class_entered),v(t,n.class_exited),i=t,o=a,n.unobserve_entered&&b(i,o),f(n.callback_enter,t,e,a),r||V(t,n,a)}function H(t){return t.use_native&&"loading"in HTMLImageElement.prototype}function B(t,i,o){t.forEach(function(t){return(a=t).isIntersecting||0<a.intersectionRatio?q(t.target,t,i,o):(e=t.target,n=t,a=i,t=o,void(u(e)||(_(e,a.class_exited),$(e,n,a,t),f(a.callback_exit,e,n,t))));var e,n,a})}function J(e,n){var t;et&&!H(e)&&(n._observer=new IntersectionObserver(function(t){B(t,e,n)},{root:(t=e).container===document?null:t.container,rootMargin:t.thresholds||t.threshold+"px"}))}function K(t){return Array.prototype.slice.call(t)}function Q(t){return t.container.querySelectorAll(t.elements_selector)}function W(t){return c(t)===_t}function X(t,e){return e=t||Q(e),K(e).filter(u)}function Y(e,t){var n;(n=Q(e),K(n).filter(W)).forEach(function(t){v(t,e.class_error),r(t)}),t.update()}function t(t,e){var n,a,t=i(t);this._settings=t,this.loadingCount=0,J(t,this),n=t,a=this,Z&&window.addEventListener("online",function(){Y(n,a)}),this.update(e)}var Z="undefined"!=typeof window,tt=Z&&!("onscroll"in window)||"undefined"!=typeof navigator&&/(gle|ing|ro)bot|crawl|spider/i.test(navigator.userAgent),et=Z&&"IntersectionObserver"in window,nt=Z&&"classList"in document.createElement("p"),at=Z&&1<window.devicePixelRatio,it={elements_selector:".lazy",container:tt||Z?document:null,threshold:300,thresholds:null,data_src:"src",data_srcset:"srcset",data_sizes:"sizes",data_bg:"bg",data_bg_hidpi:"bg-hidpi",data_bg_multi:"bg-multi",data_bg_multi_hidpi:"bg-multi-hidpi",data_poster:"poster",class_applied:"applied",class_loading:"litespeed-loading",class_loaded:"litespeed-loaded",class_error:"error",class_entered:"entered",class_exited:"exited",unobserve_completed:!0,unobserve_entered:!1,cancel_on_exit:!0,callback_enter:null,callback_exit:null,callback_applied:null,callback_loading:null,callback_loaded:null,callback_error:null,callback_finish:null,callback_cancel:null,use_native:!1},ot="src",rt="srcset",ct="sizes",lt="poster",st="llOriginalAttrs",ut="loading",dt="loaded",ft="applied",_t="error",vt="native",gt="data-",bt="ll-status",pt=[ut,dt,ft,_t],ht=[ot],mt=[ot,lt],Et=[ot,rt,ct],It={IMG:function(t,e){m(t,function(t){A(t,Et),x(t,e)}),A(t,Et),x(t,e)},IFRAME:function(t,e){A(t,ht),w(t,ot,l(t,e.data_src))},VIDEO:function(t,e){a(t,function(t){A(t,ht),w(t,ot,l(t,e.data_src))}),A(t,mt),w(t,lt,l(t,e.data_poster)),w(t,ot,l(t,e.data_src)),t.load()}},yt=["IMG","IFRAME","VIDEO"],At={IMG:P,IFRAME:function(t){k(t,ht)},VIDEO:function(t){a(t,function(t){k(t,ht)}),k(t,mt),t.load()}},kt=["IMG","IFRAME","VIDEO"];return t.prototype={update:function(t){var e,n,a,i=this._settings,o=X(t,i);{if(h(this,o.length),!tt&&et)return H(i)?(e=i,n=this,o.forEach(function(t){-1!==kt.indexOf(t.tagName)&&F(t,e,n)}),void h(n,0)):(t=this._observer,i=o,t.disconnect(),a=t,void i.forEach(function(t){a.observe(t)}));this.loadAll(o)}},destroy:function(){this._observer&&this._observer.disconnect(),Q(this._settings).forEach(function(t){y(t)}),delete this._observer,delete this._settings,delete this.loadingCount,delete this.toLoadCount},loadAll:function(t){var e=this,n=this._settings;X(t,n).forEach(function(t){b(t,e),V(t,n,e)})},restoreAll:function(){var e=this._settings;Q(e).forEach(function(t){U(t,e)})}},t.load=function(t,e){e=i(e);V(t,e)},t.resetStatus=function(t){r(t)},Z&&function(t,e){if(e)if(e.length)for(var n,a=0;n=e[a];a+=1)o(t,n);else o(t,e)}(t,window.lazyLoadOptions),t});!function(e,t){"use strict";function a(){t.body.classList.add("litespeed_lazyloaded")}function n(){console.log("[LiteSpeed] Start Lazy Load Images"),d=new LazyLoad({elements_selector:"[data-lazyloaded]",callback_finish:a}),o=function(){d.update()},e.MutationObserver&&new MutationObserver(o).observe(t.documentElement,{childList:!0,subtree:!0,attributes:!0})}var d,o;e.addEventListener?e.addEventListener("load",n,!1):e.attachEvent("onload",n)}(window,document);</script><script data-no-optimize="1">var litespeed_vary=document.cookie.replace(/(?:(?:^|.*;\s*)_lscache_vary\s*\=\s*([^;]*).*$)|^.*$/,"");litespeed_vary||fetch("/wp-content/plugins/litespeed-cache/guest.vary.php",{method:"POST",cache:"no-cache",redirect:"follow"}).then(e=>e.json()).then(e=>{console.log(e),e.hasOwnProperty("reload")&&"yes"==e.reload&&(sessionStorage.setItem("litespeed_docref",document.referrer),window.location.reload(!0))});</script><script data-optimized="1" type="litespeed/javascript" data-src="https://techelevate.us/wp-content/litespeed/js/817f098d8c9e98df65a70b34a9d93312.js?ver=4da1f"></script><script>const litespeed_ui_events=["mouseover","click","keydown","wheel","touchmove","touchstart"];var urlCreator=window.URL||window.webkitURL;function litespeed_load_delayed_js_force(){console.log("[LiteSpeed] Start Load JS Delayed"),litespeed_ui_events.forEach(e=>{window.removeEventListener(e,litespeed_load_delayed_js_force,{passive:!0})}),document.querySelectorAll("iframe[data-litespeed-src]").forEach(e=>{e.setAttribute("src",e.getAttribute("data-litespeed-src"))}),"loading"==document.readyState?window.addEventListener("DOMContentLoaded",litespeed_load_delayed_js):litespeed_load_delayed_js()}litespeed_ui_events.forEach(e=>{window.addEventListener(e,litespeed_load_delayed_js_force,{passive:!0})});async function litespeed_load_delayed_js(){let t=[];for(var d in document.querySelectorAll('script[type="litespeed/javascript"]').forEach(e=>{t.push(e)}),t)await new Promise(e=>litespeed_load_one(t[d],e));document.dispatchEvent(new Event("DOMContentLiteSpeedLoaded")),window.dispatchEvent(new Event("DOMContentLiteSpeedLoaded"))}function litespeed_load_one(t,e){console.log("[LiteSpeed] Load ",t);var d=document.createElement("script");d.addEventListener("load",e),d.addEventListener("error",e),t.getAttributeNames().forEach(e=>{"type"!=e&&d.setAttribute("data-src"==e?"src":e,t.getAttribute(e))});let a=!(d.type="text/javascript");!d.src&&t.textContent&&(d.src=litespeed_inline2src(t.textContent),a=!0),t.after(d),t.remove(),a&&e()}function litespeed_inline2src(t){try{var d=urlCreator.createObjectURL(new Blob([t.replace(/^(?:<!--)?(.*?)(?:-->)?$/gm,"$1")],{type:"text/javascript"}))}catch(e){d="data:text/javascript;base64,"+btoa(t.replace(/^(?:<!--)?(.*?)(?:-->)?$/gm,"$1"))}return d}</script></body></html> <!-- Page optimized by LiteSpeed Cache @2025-05-30 06:42:23 --> <!-- Page cached by LiteSpeed Cache 7.1 on 2025-05-30 06:42:21 --> <!-- Guest Mode --> <!-- QUIC.cloud UCSS in queue --> <!-- This website is like a Rocket, isn't it? Performance optimized by WP Rocket. Learn more: https://wp-rocket.me -->