Krypt3ia

(Greek: κρυπτεία / krupteía, from κρυπτός / kruptós, “hidden, secret things”)

Archive for the ‘DARKNET’ Category

The Darknet As Medium for Proof of Life K&R Deals AKA OpFOQ

leave a comment »

Last week someone pointed out a story about how the Qatari government or relatives of some Qatari’s that had been kidnapped on a falcon hunt had started a darknet site and a fund in bitcoins for information on their whereabouts and return. This story intrigued me so I went looking for the site and someone on Twitter kindly pointed to it and the twitter feed with the address. I went to the site and took a look at it and then started looking at the larger picture of who the Qatari’s hired to do this as well. What follows are my thoughts on using a darknet site like this for proof of life and or transactions like this as well as the company that the Qatari’s turned to to do it for them. Of note is that this attempt was closed down as soon as the story came out in the press so that is an added twist but given the things I have seen it makes total sense why a little light on the subject would make the “company” hired by Qatar to close shop and run away.

Qatari’s abducted falconing

Global Strategies Council Inc:

As reports online had mentioned, the “company”  Global Strategies Council, was given 2 million dollars up front for work attempting to get proof of life for the abducted falconers. I decided to look further than the reporters (at least as much as they reported) and found some interesting things concerning this alleged company and the person(s) involved in it. First off, the company is so stealth that you have to really dig a fair bit to get to the guts of what it is. Even then, you really do not get much detail on who is in the company, who works there, and what it does exactly. The hinge seems to be on this “shoe salesman” or “Shoe Mogul” if you will, Miltos Goudamanis and no, it is not Militas as you see in the reports in the news. His real name is Miltos and he has a rather obscure past, unless you just go with the shoe angle.

Miltos is evidently the international sales guy for “Naughty Monkey” shoes, a crappy ass site that sells shoes and poorly for a number of years attached to Cyprus. Now, one lately hear Cyprus and think first off of money laundering and banks and so did I. I checked the Panama papers and he is not in there but generally everything is pretty sketch around this guy. Naughty Monkey is the most solid hit for this guy that you can backtrace, so now one has to ask how does the Greek Al Bundy get to the point of dealing with international terrorists and asking for an advance of 2 million dollars to set up darknet sites eh? That question kept ringing in my ears as I dug deeper into the inception zone.

If you look at all the data above in the screen shots you can see that this guy has no real experience with military or national affairs so how does he suddenly become a director or chair at this Global think tank? Furthermore how does a guy who makes less than 10G’s a year is getting a net of 499k?

Blink blink…

SHOES MUST BE SELLING LIKE NO TOMORROW!

This is starting to smell like some rotting carcass in the San Diego sun….

So yeahhhh, this “company” this think tank specializing in… In what? Well, fuckall really, is being run out of this condo it seems in San Diego according to all the records I could find. In fact the phone number to the place also matches with a land line for the area. Not one thing about this company says it has offices in Washington DC at all. Even though their site makes all kinds of DC imagery and allusions to connections therein… Obliquely that is.

Saaaaaaaayyyyyyyy.. is that office condo space zoned for this kind of fuckery?

Looking at their site you have to just ask yourself after reading it all; “Is this Enron?” because they seemed not able to tell you exactly what they did either and look what happened there huh? There are no employees, no experts listed on their rolls and certainly very little on Miltos as to his history or education for these kinds of things. If I were the Qatari’s I would be asking the guy who hooked this all up what cut of that two million he got. I am just gonna lay it out here in plain language;

  1. Company site is poorly made and has no real data
  2. No employees
  3. No history
  4. Two million up front and we get proof of life!
  5. PROFIT!

This all screams scam and when the whole operation was shut down I think we all got the same feeling about it huh? How are the Qatari families feeling about this? Is this guy just an opportunist shoe hawker or is there more? So far as I can tell this guy has been trying for years to get USGOV work and hasn’t been able to land anything. So a little grift for a cool two million and a cheap darknet site/twitter account is easy peezy.

About that darknet site….

Darknet Site:

The idea behind this site was to allow the hostage takers a medium to connect with the alleged “middle man” Miltos, to get in touch as well as maybe open source this thing so that anyone with information could leave a tip. Now, on the face of it this may be something of use if you keep it really down low and release that information only to the hostage takers right? I mean you leave this on the darknet and then publish it in the paper you are only gonna get trolls right?

I went to the site and checked it out. It was a clone of the global leaks site (using their frame) and you could create an ID and drop information there. You could log back in and see what responses came from Miltos and his crew but when I looked there were no other info drops that I could see. I signed up and got a number just to see how it would work.

Basically this was ill thought out and deployed so once again I think fly by night and not really meant to gather real intel on the status of the poor Qatari’s who have been jacked. Of course, it is now all shut down according to the Twitter account for the “Op” so so much for gathering information of proof of life for the families of those Qatari’s huh? I will keep an eye on the site to see when it comes down but generally I suspect it will just sit there on some rented space littering the darknet for years.

Thoughts on Darknet as Medium for Ransom:

Aside from thinking that this whole thing was just a grift by this guy Militos and his wife, the notion of using a site in the darknet as a means of proof of life is iffy at best. I should think that the terrorists or whoever that took these people is not surfing the darknet in the first place and would just as easily pick up a sat-phone or regular phone and call the Qatari government with their demands. These arcane measures just isn’t their shtick man.

For that matter just use a cutout gmail account and PGP huh? What the fuck! This whole debacle is just an exercise in how to pull off a short con on a lot of families looking for answers about their lost loved ones. If I were Qatar, I would be asking this Ali Hani about his connections to this Greek guy in San Diego tootsuite man. I am sure the money is spent already anyway…

Oh and as for the hacker angle of “OOOH SCARY HACKERS IN THE DARKNET MAKE SITE” cut the shit media! Anyone with half a brain can stand up a site in the darknet so cut it the fuck out. There was nothing spectacular here other than the lede that looked good for clickbait.

Now.. About those lost Qatari’s….

K.

Written by Krypt3ia

2017/04/17 at 17:09

Posted in DARKNET

Black Edge on the Darknet?

leave a comment »

Black Edge

I was trawling the darknet as you all know I like to do and came across a site I had seen once before and bookmarked but never got back to. The site http://b34xhb2kjf3nbuyk.onion “The Stock Insiders” is a php site that claims to be an insider trading site seeking users who will provide insider information for the collective to profit from. Now I will admit that I have been watching Billions and I am also reading “Black Edge” so this site finally struck a chord with me and I decided to mirror it and take a look inside. The following post is the sum total of what I found and some thoughts on the idea in the first place. …I am sure you all will be amused.

The Idea:

Right, well the darknet is supposed to be super secret and encrypted if you believe all of the reporters out there who cover it with conspiratorially raised brows. It only stands to reason that some enterprising joker would go and set up a site like this to trade in illegal insider information yes? Well obviously yes because here it is! As you can see from the screenshot above they are making no bones about it, they want to have players here who can provide solid insider information so as to make trades illegally and make oodles of money! Of course there are problems with that idea and I will be going into those here. Sure they make caveats about the legalities but they also claim that the server is not physically in the US and the whole server is “encrypted” which, ugh, come on people! Crypto is only as good as the system being shut down and the type of crypto being used.

….But I digress…

Now let’s talk about the intricacies of insider information and it’s use. You see, it is not that easy to obtain good insider information in the first place and secondly, using it has to be carried out carefully so as to not tip the SEC and other investigative bodies to your use of it to profit right? So by trying to open source this on the darknet is kinda scary in more than a few ways to my mind. I mean, who are these people? How do you vet them and their information they are passing? How do you not know you are being baited by a Fed or some moron in the first place? Then, how do you make the trades and profit without a trail and maybe even the potential for being ratted out if things go badly? I just keep coming up with all these scenarios where things go poorly from this idea. Personally, the notion of this site is half baked in my mind but hey, this could just be a honeytrap right?

Alright, let’s assume it is legit, how do you really go about this? Well, you start off by getting members and then testing them by asking for legit insider info to trade on so they will be allowed in as “full members” ya know, like becoming a made man ehhhhh? Ok, so I am say “jpompo6” (oh yeah wait till you get to the bottom of this here post!) and I want in. I have to create an account, then go through the vetting process by passing data to the “root” account (yes, I did say root!! wink wink nudge nudge!) on a sweet sweet insider stock tip and hope upon hope that I am accepted into the inner sanctum. One of two outcomes will happen:

  1. I wait, and I wait, and nothing happens.
  2. I hear back that I am a made man and HOO HA! I can then get into the inner sanctum and start reading all the juicy posts and making trades on them! WIN!

Unfortunately I had no real insider info to pass and, well, I am not an idiot so I did not go further than setting up a dummy account on this site. Instead I started looking at the site itself and gathering whatever intelligence I could to do a little OSINT on the users that I could see.

…And boy did I see things-n-stuff.

Membership Rules:

Anywho, the community has rules and those rules are listed below. I do sincerely love the first rule of INSIDER TRADING CLUB which is YOU MUST BE AN HONEST GENTLEMAN! Now that is some deep derp there kids. You are telling me that you want honest gents in this here illegal enterprise of insider trading informatics on the darknets? NO. WAY. The other rules pretty much follow the rules of Fight Club, don’t talk about Fight Club, Don’t fuck with Fight Club, yadda yadda yadda. The more I read the rules the more cognitive dissonance I have about the whole thing really. I do like the whole you have to keep reporting in new leads every 90 days in accordance with the SEC practice of 10-q reporting hahaha.

Say, is there a profit sharing plan here? How are the health benefits? Do I get a 401K here? Honestly, this whole model is good when you are in the real world and you are face to face with people you have developed a rapport with, not some shmuck who may be a Fed on the darknet kids. In reading the Black Edge book you can see how much of the intelligence is gathered on companies, usually you have paid sources or sources you do favors for quid pro quo and there is an understanding that if you fuck me you fuck yourself. The whole idea that I am just gonna take some inside info from the darknet and apply it to large trades on the market is a bit much for me to believe. Now maybe if you wanted to communicate data like this with known and trusted people in the darknet using encrypted comms maybe I would buy that but this site just seems to be to either be a honeytrap or a scam looking for suckers to put their legit inside info out there for a quick pump and dump.

But that’s just me…

OPSEC FAIL:

So yeah, you have this site out there and you promise all the super secret DARKNET black magic. You tell people that the data is secure and then you say “But.. You have to be careful” everyone is gonna take that to heart right? Well, almost everyone… Ok some people… Ok ok ok maybe one person. In the case of this site there was a “props” page that I found that listed users who they wanted to thank. For the most part the user names were innocuous enough to not go anywhere with an OSINT search regimen. However, there was one guy who seemed to not comprehend the idea of OPSEC.

The user JPOMPO6 who is listed in the thanks page seems to really not get the whole idea of not re-using online handles. This guy seems to have used his handle for everything online on this site and “root” likes him enough to give em props. A simple Google search for the ID drops a ton of hits that show this guy to might be Joe Pompo a CPA from upstate New York. Now given that the handle is exactly the same as the Twitter handle he uses and then further more that he is a CPA, well, I kinda think this is our man but I have to say for the record and for all you lawyers out there; (I Googled some shit and this MAY BE the guy, I am not saying IT IS THE GUY but JEEBUS it really does kinda all fit) so please, don’t sue me because I made a logical leap.

That this character under the handle jpompo6 is on this site does not in fact mean that they have traded insider information at all. In fact, I cannot see any postings by this user so it is not for me to say. All I can say is that a user who has the same handle as the Twitter user and that user has the name Joe Pompo exists is, well, there you have it… If this is the same guy then oops, your OPSEC sucks and the site’s admonishments were lost on you. One wonders what other OPSEC fails there must be inside the site, ya know, like using your corporate email or your one personal email as the contact for this site.

Oh my…..

Programming and Administration:

As if the OPSEC thing wasn’t bad enough, when the site was looked at from a security perspective things went from bad to worse. The site is leaking information, it was set up poorly and likely can be hacked if it hasn’t already. The mere fact that the root account is the one making all the posts here is scary as administrating php sites goes. However, when looking at the directory tree there was a lot left open. With all this hanging out I kinda really have my doubts about the security of the site don’t you? I personally would run away, change my name, and burn everything with my old name on it if I had traded anything of any import on this site kids.

So what have we learned today? Well, we learned that insider trading is best left to professionals and done in secret places other than the darknet I think. While the idea of insider trading is appealing to some, it is really going to fuck only you in the end when the feds come for you. Honestly, I think a better alternative is to just do OSINT and find data that has been accidentally leaked by companies and then make your trades, and as I understand it that is kinda grey area right? I mean no one told you the info, you did not pay for it, you happened upon it right? In the present day state of the internet there is so much information that is out there on mis-configured servers and the like that you could likely use that to day trade your way to riches right?

End of the day, stay away from these scam sites in the darknet kids… Unless federal prison appeals or being totally taken by fraudsters.

K.

PS.. Props to @chkefa for the heads up on jpompo6!

Written by Krypt3ia

2017/04/13 at 19:50

Posted in BlackEdge, DARKNET

Darknet Numbers Pages Proof of Concept

leave a comment »

screenshot-from-2016-10-25-15-57-20

 

Numbers Station:

So with all the kerfuffle over crypto I decided to give everyone a big fuck you and do something low-tek just to mess with the narrative. Right, so you all know what numbers stations are right? Well, I decided that it was time that the internet have one all it’s own but not on the clearnet no sir-ee! I wanted a darknet spooky spooky impenetrable super scary numbers station! So I began to hatch a dastardly nation state level of fuckery that surely will have the gubment all  up in arms over my crypto darknet wizardry! I set up a site and I communicated with some people secretly and securely and no one was the wiser. Not one federal agency that I know of saw the site, no scripted scouring of the darknet cached my page that I am aware of (and I asked) and generally, I just pulled off the new age of tradecraft that the KGB should be jealous of!

Here’s how I did it.

Proof of Concept

The Plan

As I was thinking about a means of communication using the darknet to avoid prying eyes and to do so securely I came to the conclusion that I sure could use PGP and some email service out there but gee, lately those have been pwn3d too so fuck that. Instead I wanted to be more old skewl and opted for two way comms through OTP and a static page that could live on the darknet at periods of the day and night of my choosing with those I want to communicate with in the know as to timetables with, well, a timetable. Commonly on the air Numbers stations beacon at specific times of the day and week so this is kind of the same thing. So I set to making a highly portable TOR capable platform that I could take with me and connect to WIFI at hotels, bars, cafe’s, rando people’s houses etc. I could effectively have a transient site that would be hard to track and harder to narrow down where it lives because it is not in some rack somewhere stationary and waiting to be deanonymized and pwn3d.

20161025_155936

I opted for a netbook that I had laying around after doing the math on a Raspberry Pi. It was far cheaper to use an old old netbook I had than go spend money on a pi and it was just as portable. Once I got the laptop up and running on backbox, I then installed the TOR system and configured it for having it’s own hidden site. I then installed lighthttpd and created a very small stripped down page of text and color which I then hid the encoded text in the black space. No need to be all fancy here and it was a flourish anyway. It doesn’t have to be pretty to work and yet this lightweight site and the server it was on allowed me to communicate well enough while the whole thing was secure from being hacked. I had testing run on it and the tester was unable to own the box nor the site.

Once the testing was over I let the site run. It was up and down per specific times and communication was made using a second site on the darknet where people could post to a pasteit where we could have coded signals (basically; understood and complying) so that the communications stream would be innocuous enough using code words. You could use images on chan’s or the old trope of putting up an ad for something and even having more code in the text of that if you wanna get fancy and all.

The Tools

  • Net top laptop
  • Backbox linux distro
  • TOR
  • Lighthttpd
  • One Time Pads (plenty of places on the net to create them)
  • Timetable for uptime and downtime for comms
  • Assets to communicate with

The Tradecraft

Using this method of secret communication one could plan out all kinds of badness if they wanted to. Having a stealth site that is transient too also allows for more security but as always the people are the weak point. If an asset is caught then the means of communication is blown. Just like the analog counterparts (AM/SW Numbers Stations) this type of communication could go on untouched and unbroken for a long time because of the frequency changes, the IP address changes, and mobility of the asset. Just imagine if the analog version of Numbers Stations were actually not just in some building but in a backpack eh?

The hardest part of all of this is that you have to train your assets to use OTP and to have proper OPSEC. It can be done though, so this is a viable means of secret communication that is low tek enough yet high tek enough for the average person to easily carry out if they are determined to. It would bypass all the email shenanigans as well as texts, calls, chats, that can be intercepted by warrants to companies like Apple and AT&T. After all, how hard is it today to get a distro of linux on a box, install TOR, set up a hidden site, and start using OTP?

Wait… Ok maybe it is a little hard.

Still doable though… I mean it worked for me and my “assets”

Enjoy kids!

K.

Written by Krypt3ia

2016/10/25 at 20:41

Posted in 1984, Crypto, DARKNET

YES YOU TOO CAN BUY A 1 KILOTONNE SUITCASE NUKE IN THE DARK NET! (Ok no not really)

leave a comment »

screenshot-from-2016-09-21-09-04-22

So I was surfing the darknets as is my wont to do every morning to see what the kids are up to and this site popped up that claimed they had Russian nulcear hardware for sale. What else is a guy like me to do with a site like this than to say FUCK YEAH! LEMME IN AND LEMME BUY SOME! I did the sign up process (Of course I signed up all super sekret like using the name SPECTRE) and immediately took a look at the wares! These guys have a few options on their “products” page and gee, it was hard to choose from the offerings as they are all super cool.

screenshot-from-2016-09-21-09-34-06My account (SPECTRE)

screenshot-from-2016-09-21-09-08-29

As you can see I have three options for types of nukes and how they would be deployed. I opted for the “Suitcase Nuke” because who hasn’t wanted one of those right? AM I RIGHT? I am right right? Anyway, the other options are a land based “Iskander” system (like the one in Spies Like Us) or a Sub based “Bulava” missile evidently already deployed and laying in wait off the coast of somewhere within a weeks distance according to the details. Each of these options has only regional capacity and the suitcase nuke is the most portable so there is that… Anywho, I forged forward and decided that $50 MILLION dollars was just ducky as prices go and that I could pony up the requisite bitcoins. (As seen below)

screenshot-from-2016-09-21-09-27-4150 million in bitcoins please!

screenshot-from-2016-09-21-09-28-10YES YES YES WHEN DO I TAKE DELIVERY ALREADY???

screenshot-from-2016-09-21-09-28-43

NOW, even though I did not see a bitcoin address here I JAMMED that enter button and eagerly awaited the response!

Wait, did I put in my bitcoin wallet?

SHIT!

FAIL!

GOD DAMMIT DARKNET!

CODE ERROR!

WHISKEY TANGO FOXTROT!

Ugh.. I am disappoint.

I have written a PGP encrypted, tersely worded email to their helpdesk…

Dammit. Guess I will have to go order some Polonium 210 or Red Mercury in Silk Road III or is it like VII now?

Dr. K.

Written by Krypt3ia

2016/09/21 at 14:23

Posted in Amused, DARKNET

Meanwhile back in the Darknets…

leave a comment »

Screenshot from 2016-08-22 13-25-54

@flanvel sent me a link to the darknets with what he said “may” be a numbers station. Of course I had to look at that right away and they were absolutely right! The question is is this just a troll of some kind or is there something else at work? The site tutdwuh7mlji5we3.onion is a static page with four very large ogg files of what sounds like a series of what some claim as ten hours of numbers station like audio. I began the wget this morning and it is still going and I have yet to hear the whole thing but what I heard so far sounds like it starts with a Mexican numbers station from the diction/accent of the reader.

As the commentor on the Reddit says, there is no real way to tell what the deal is with this site because if truly a numbers station (one on the darknet at that) then the code will be random and from OTP so virtually uncrackable. However, it is an interesting notion to consider as I have recently, putting a static transient page on the darknet to use for covert communication through such means as OTP or maybe book code. A simple site with a simple block of text would all it would have to be and you are in bidniss right? In this case if this is a real numbers station at all then perhaps they are trying a signal to noise thing with one of those messages being the real one and the rest are just noisy red herrings. Interesting to ponder.

In any case this is worth a listen to those of you interested in spook world.

Enjoy,

Dr. K.

 

Written by Krypt3ia

2016/08/22 at 17:52

أخبار المسلمين akhbar almuslimin: Muslim News

leave a comment »

Screenshot from 2016-08-08 12-17-55

Yep, yet another Da’esh darknet site popped up this morning. This one is a rather bare bones effort that relies on free DynDNS, Tor2web and links back to things like WordPress and imgur and Cloudflare. The site came up and then went down after the kids from OpISIS came and went. The cloudflare though seemed to help as well as the tor2web linkage. As of this writing Cloudflare started to act up and the site was losing bits of itself as I was interrogating it for information.

Anyway, this site is pretty sparse design wise but has a lot of content to click. As you can see below it is low tek but the content is brand new. No mention of official ties but it has the flag in the tab as you can see. All of the links go to external clearnet sites for content so much of the work is being placed on the clearnet sites that the daeshbags upload shit to like mega and the like.

Screenshot from 2016-08-08 12-18-31Videos from Syria

 

Screenshot from 2016-08-08 12-21-37Dabiq 15 linked to clearnet dump

 

Screenshot from 2016-08-08 12-24-34Other mags

 

Screenshot from 2016-08-08 12-24-56Al Bayan radio streams

 

Screenshot from 2016-08-08 12-25-51Martyrs and usual propaganda crap

 

Screenshot from 2016-08-08 12-26-35Single page content links

 

Screenshot from 2016-08-08 14-00-25Page info

 

Overall, not much to write home about. The site I assume will be down and up for a while but this just shows you that the daeshbags are trying to get content in the darknet but they seem to be unable to host it all themselves on a single server. Until they can do this, then technically they will continue to be taken offline pretty easily by the kids.

I will be pulling all the metadata since I have already archived the site en toto with wget… More when I have it.

Dr. K.

 

–UPDATE–

I ran an onion scan on this site for all you kids.. Go.. play..

krypt3ia@krypt3ia:~/go$ sudo ./bin/onionscan http://ou7zytv3h2yaosqq.onion/
2016/08/10 12:59:25 Starting Scan of http://ou7zytv3h2yaosqq.onion/
2016/08/10 12:59:25 This might take a few minutes..

————— OnionScan Report —————
High Risk Issues: 0
Medium Risk Issues: 0
Low Risk Issues: 0
Informational Issues: 4

Info: Missing X-Frame-Options HTTP header discovered!
Why this is bad: Provides Clickjacking protection. Values: deny – no rendering within a frame, sameorigin
– no rendering if origin mismatch, allow-from: DOMAIN – allow rendering if framed by frame loaded from DOMAIN
To fix, use X-Frame-Options: deny
Info: Missing X-XSS-Protection HTTP header discovered!
Why this is bad: This header enables the Cross-site scripting (XSS) filter built
into most recent web browsers. It’s usually enabled by default anyway,
so the role of this header is to re-enable the filter for this particular website if it was disabled by the user.
To fix, use X-XSS-Protection: 1; mode=block
Info:  Missing X-Content-Type-Options HTTP header discovered!
Why this is bad: The only defined value, “nosniff”, prevents browsers
from MIME-sniffing a response away from the declared content-type.
This reduces exposure to drive-by download attacks and sites serving user
uploaded content that, by clever naming, could be treated as executable or dynamic HTML files.
To fix, use  X-Content-Type-Options: nosniff
Info: Missing X-Content-Type-Options HTTP header discovered!
Why this is bad: Content Security Policy requires careful tuning and precise definition of the policy.
If enabled, CSP has significant impact on the way browser renders pages (e.g., inline
JavaScript disabled by default and must be explicitly allowed in policy).
CSP prevents a wide range of attacks, including Cross-site scripting and other cross-site injections.
To fix, use  Content-Security-Policy: default-src ‘self’
krypt3ia@krypt3ia:~/go$

 

Written by Krypt3ia

2016/08/08 at 20:44

Posted in Da'esh, DARKNET

Counterfeiting On The Darknet: USD4U

leave a comment »

Screenshot from 2016-07-13 15:06:11

USD4U

While traversing the darknets, as one does today, I came across a constellation of sites hawking counterfeit currency, particularly American twenty and hundred dollar bills. It is not uncommon to see counterfeit currency on offer on the darknet markets but in this case these were stand alone sites by a proud group of counterfeiters offering on the face of it, almost superbill quality notes. Stuff that has not been seen in a while since the take down of the DPRK’s efforts to not only manufacture currency for their own purposes, but also to potentially be used in a larger scheme of currency destabilization.

The notes in this case however, aren’t the old hundred dollar notes of yesterday but instead today’s counterfeit protected notes that the US rolled out in 2013 to the masses. With color as well as new inks that fluoresce, have metal in them, and hidden tech to stop fakes, the new bills were supposed to be incredibly hard to create. Well, it seems that these guys on the darknet have done a pretty good job at creating a passable facsimile as seen below;

11Their hundo

 

2Hundo front with markings of checking points/features

 

1Their hundo back

hundo features1

 

hundo features2

 

rs_560x415-131008091411-1024-3new-100.ls.10813Real hundo

Quality

That’s right kids, this can pass the UV light test, it has the fiber/metal strip, it has the holographs, and has the look of a real bill. In fact I have at least one alleged user who has passed the hundo’s at a local establishment without issue. Of course it is common practice to use smaller bills than this, some devil may care types will buy the hundreds and pass them in gas stations and other low end brick and mortar stores in hopes that the teller’s there will not know the difference nor have the technology to test the bill for authenticity.

Screenshot from 2016-07-14 07:14:01

So someone has been passing these already if you are to believe the Reddit post. I should think that it is quite possible and while I did not check out “mrexpat” to see if he is a shill, I know just by looking at the site and the language they use, they make a “quality” product. The site(s) are all by the same maker and or brand if you will. They call themselves USD4U and they are pretty brazen in their advertising including telling the client not to haggle with them, the price is the price! That price being as follows for varying denominations and weights;

Screenshot from 2016-07-14 15:40:32

Screenshot from 2016-07-14 15:40:47

Screenshot from 2016-07-14 15:40:56

Printing

As you can see they offer anything from ten dollar bills all the way up to the hundred dollar bills seen at the top. They are dealing only in Bitcoin and they offer FREE SHIPPING with an order over $250.00 and over. Of course now if you look at the prices they are pretty cheap for the main part. However, in larger operations it is not by the note but by the pound (weight) that you buy bills in with serious folks. These guys have the niceties as well of an “affiliate” program and an earnings program, which I am not sure exactly how that would work but ok…

Another interesting note is that they say they ship from the US, which makes me wonder a bit about these guys. For the most part my digging has shown that in their photos the players are Asian but that could just mean it is a Tong or another group doing this. They certainly though spent big bucks on the printing process and seem to be using quality materials as well to make these notes… So is this just a sideline or what? The brazen behaviour I alluded to above is that they have taken photo’s of their Flexo Printer that they “heavily modded” in order to make these bills.

5

4

For those not in the know, and do not want to go read more in the link above, a “Flexographic Printer” is a specialized piece of machinery that can print things on many types of material with rubber “plates” that can carry high rez scans. So, if you ever had print shop back in the day (as I did) you make a flexible plate and then run that on your media with the flexo and you can get crisp images with texture. Texture is a key here, see, when you just laser print a note you don’t have the right feel and you may not be able to run high fiber content paper through an inkjet in some cases. No, these are printed on cotton stock and have raised ink feel to them as well like the real deal.

(I know what you’re thinking here.. “What has he been up to?” No, I am not a counterfeiter… No really!.. Ask me at DEFCON and buy me a drink maybe I will tell you more…)

This modded rig as they call it can run jobs fast, multi color, and handle the iridescent ink that they need to make a passable note. I would have to really get my hands on a note to say more about the quality of the paper and the strip and all so I will just leave it there but were one to pass one of these at the local gas-n-sip without the little pen check, I am pretty sure you would walk away with change.

A Little Investigation

Anyway, looking at this site I decided to dig a bit and see if they done fucked up somewhere on the OPSEC. I ganked the sites down using WGET Torrify and checked for metadata etc. What I found was pretty much nothing to write home about. They have done a good job at securing the site and using ToR to obfuscate who they are but those photo’s just had me thinking they must have left some clues there. So I took a closer look at them.

Screenshot from 2016-07-14 06:45:33Asian Man 1

 

truck

Asian Man 2

Asian

Asian Man 3

number 6 1380684725

 

So yeah, Asians unloading the Flexo. Are they the owners? Are they minions? I really cannot say, but I will say that the Asian gangs have been known to be involved with this activity in the past as well as DPRK. Slick professional operations like this means to me that these guys have been at this for a while. Their versatility in making old and new bills, the use of the Flexo and the right materials… It all leads me to believe they are pro’s…

Or… It’s a trap!

The images though had no metadata to use so we have to go on the IMINT itself. The biggest tell to me is the number on the forklift. Someone may be able to get a lock on where this thing is sitting because they unloaded it in these photos in some industrial area and that machine did the work. A long shot really but hey, it is what it is right? That’s all the attribution I am willing to state here on this. Maybe Los Feds (USSS) can do a better job?

So What’s It All Mean?

Welp, I for one an impressed with what I see here. From a forgery perspective these guys have a legit *cough* act here. Yes yes yes, criminal but interesting! So many places on the darknet are just poorly put together craptastic sites with a barker at the front door yelling “BUY SHIT!” This though is more subtle, straight forward, in a crooked way, and merits the attention of both me and perhaps the federal authorities that handle such things as fake currency. They must be doing a good job because they also claim at the top to look out for a cloned site as well! Imitation being the most sincere form of flattery is it?

I also think it very telling that they offer no bitcoin wallet on the site as well. This to me says that they are being careful with the OPSEC, and frankly that is a smart play. You have to order with your email address and they will contact you. It could all just be a scam… It could be a sting operation… I am not going to go any further to find out though. I just surf the darkest parts of the darknets and chortle.

Oh darknet.. I lurv you!

Dr. K.

Written by Krypt3ia

2016/07/14 at 20:37

Posted in DARKNET