Krypt3ia

(Greek: κρυπτεία / krupteía, from κρυπτός / kruptós, “hidden, secret things”)

LOOK MORTY! I’M A DANGEROUS PAGE MORTY!

with 2 comments

 

Still the page is marked as bad yet no malware can be shown to live here.

Written by Krypt3ia

2017/10/02 at 13:16

Posted in Uncategorized

Who’s Molesting Your Corpse?: Necrophilia and Snuff In The Darknet & Clearnet

leave a comment »

Vault of Sex and the Dead

Just when you thought I could delve no more deeply into the darknet I bring you this….

RIGHT! Well, since my deep dive into the world of cannibalism, I began to look at the other links out there to other paraphilia’s on offer in the darknet and once again to the clearnet. Today’s menu consists of Necrophilia and Snuff, which is quite the taboo really and something you would expect to be in the so called Darknet. In as much as what is indexed currently out there in the darknet there are a total of two sites that really cater to these two particular bents. The first being the one you see above in the screen shot. This one requires bitcoin payment just to see the content but you can get a taste by clicking on their samples.

Sex & The Dead

 

Sex & The Dead

What seems to be on offer here is a melange of snuff films and images that are staged mixed with actual gore photos culled from the clearnet and other places I suspect. Generally, it is all pretty vile and all rather violent which then in tandem with the data concerning how much money their bitcoin wallet has ($3140.76) one wonders just how many people are buying this service and how many are here just for the day or are return customers. The nominal fee to gain entry is (0.027 BTC) which is presently ($112.06) per entry fee. So, let’s tally that one up shall we?

Lesee, carry the one….

That’s thirty users of this site. Thirty people have paid over one hundred dollars to get into this site with bitcoin and wank to this stuff.

*shiver*

Oh and look someone just bought access on the 25th of this month!

So someone has at least some pocket money it seems from this little darknet adventure. I guess it all depends on how much you put into it though eh? I mean, how much is the hosting per month? Are you hosting this yourself? Web design seems to be not so much something they care about so no real expense there. Overall, this site seems to be a going concern because it is affordable and maybe has some content these thirty people want. I do wonder just how many though are seriously “using” the content as opposed to how many investigative entities bought access to “investigate” criminal activity. I suppose we could take all those bitcoin wallets and do some mining to see if anyone made some OPSEC mistakes but meh.

The second site in the darknet has a theme in that it is called “Japanese Lady Extermination” and they live up to that name with a lot of Asian/Japanese content. Between you, me, and the lamp post, we all know that the Japanese have some particular, well, shall we call them tastes in porn? On first look this site has much more content and the design is a bit better but is it a hub for this activity? How many people use it? Well, it seems that this one is the high price callgirl of the darknet in that they want some big bucks to get in on the action.

Dig this, they have two options for access. One is for a month of access which they want 0.6 bitcoins and the other for three months which costs a whopping 1.2 bitcoins! That translates into the one month access being $2493.34 and the three month plan being $5026.27! Now that is steep for access to some lady killin and if you have sticker shock so to do all the would be customers of this site as well. In looking at the wallets for the plans both have nothing in them. There are no transactions at all for both so this is a bust for the lady killers owners it seems.

Three months

One month

Three month wallet

Zilch

Nada

 

One month wallet

 

It seems to me that Japanese Lady Killin just ain’t a money making concern so far. Of course it seems that a lot of this content could be gotten via the clearnet and a vendor in Japan willing to ship a DVD so there is that. So that brings me to the conclusion that the darknet is not that scary and dark when you really take a look into it. Nope, what’s much more scary is the prevalence of this kind of thing on the clearnet available to all and easily gotten to by mistyping a URL. When I began Googling for links the first one that came up was darksites.net which is another site designed by our friends at Geocities.

My god.

…The horror.

The domain was created in 2000 so that probably answers the question right there. Why upgrade the site when you have a good thing going right? The site has a couple names attached over time from the WHOIS history and one of them goes back to a “Michael Guy” which has info out there. Just another rabbit hole one could go down to ask why? WHY? But I will continue on with the sites contents.

Domain Name: DARKSITES.NET
Registry Domain ID: 20065601_DOMAIN_NET-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: http://www.enom.com
Updated Date: 2017-02-18T07:42:12Z
Creation Date: 2000-02-17T20:13:39Z
Registry Expiry Date: 2018-02-17T20:13:39Z
Registrar: eNom, Inc.
Registrar IANA ID: 48
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Name Server: DNS1.REGISTRAR-SERVERS.COM
Name Server: DNS2.REGISTRAR-SERVERS.COM
DNSSEC: unsigned

 

Darksites

Darksites

Darksites

Darksites

This site is the clearing house of all things deviant. All your desires can be sated with this list of things.

There are things I have never heard of here…

Like the whole cannibal thing I reported on before, all of this could just be fantasy and acting or it could lead to actual committing of crimes. As we saw on the cannibal sites it was all fun and games until someone got really eaten by that whacky German guy right? I am not trying to say that these desires are bad or dirty but the paraphilia’s could lead one down the wrong path if they go too far or are unbalanced to start with. In the case of Miewes in Germany he had been fascinating about eating people since he was eight years old. At what point do kinks turn into actual crimes? Now add to this that the clearnet seems to be the biggest purveyor of this fantasy fuel free on the net (or for a nominal fee) one has to start wondering just how many people have stepped over that line after becoming addicted to this kind of content.

I also have to look at the psychology of being exposed to this stuff and becoming hooked on it. You become inured to it and it becomes pedestrian, then you need more of it to sate yourself and perhaps even things that are even further outside the norms just to feel the thrill? I have read such things in treatises by psychiatrists in the past, so now instead of having to really do the leg work and go somewhere to get the content you can just Google it up. Think about the pathology here…

Interesting stuff.

Anyway, the other outcome from my foray into this dark world is that the darknet is not really so dark. Well, at least where it concerns this stuff, the clearnet has it beat by a mile in amounts and ease of access. And this is one of the things I started down this path wanting to get out there. Other than the voyeuristic aspects here, I wanted to take a plain look at the oft spookily talked about darknet and defuse the hype. It’s not that scary and it isn’t that hard to get into no matter what Hollywood would like you to think. Nope, it’s just another space for people to do things they probably shouldn’t with a cool name.

But hey, at least in the darknet I found a manual on how to Necrophilia…

Woo!

K.

Written by Krypt3ia

2017/09/28 at 18:01

Posted in DARKNET, Paraphilias

What’s eating you?: On-line Cannibalism in the darknet and clearnet

leave a comment »

 

There are so many mis-perceptions about the “Darknet” out there but when you really start to dig right down into the bone and sinew of it you start to see that it really isn’t so dark and certainly not as spooky as one might see on CSI Cyber. I for one have had a yen lately for a serving of cannibalism content on the darknet and boy I was kinda let down by the deep dark nopesauce that I found. See, when you look into the darknet and it blinks back you know you have come to the end of the line and it is time to go back to the clearnet for some real horror.

So yeah, I was messing about in the darknet with my spider looking for some marbled fleshy goodness that I had heard was available out there on the clearnet. You know how you Google something and the usual tinfoil alien type of search results come up? Well the same can be said for things like necrophilia and all the other paraphilias out there. The spiders turned up only one site that had cannibalism in there as a subject so I went there. The site is titled “Japanese Lady Extermination” and it is true to its name in content.There’s a lot of Japanese lady killin going on in there on film and yeah, no, I am gonna opt out of the bitcoin purchases there. No, what I wanted was full on cannibalism for realz and I was bound and determined to find it!

I finally found a link in the darknet to a clearnet Reddit site that had the url to an archived version of “The Cannibal Cafe Forum” a now defunct site that was archived by the nascent “Wayback Machine” at archive.org. Now this site was stood up in 2001 (May 2nd was the spider) and it served up a board feature for those who wanted to roll play cannibalism …Maybe? I am not quite sure on how many of these “Fine Young Cannibals” were serious about their desires and how many weren’t, well, except for the one case where the guy actually killed and ate the other guy!

…but now I am getting a head of myself….

*snicker*

OK! So this board on (necrobabes.org) was stood or was run by someone calling themselves “Perro Loco” or the “Mad Dog” and they ran the show using an email address for their own domain of perroloco.net (see whois data below *wink*) which still exists today and in fact has spawned another site in the aftermath of the flame out of necrobabes circa 2003. As you can see from the screen shots below this site was pretty active and they had a bunch of links for services, offerings, and an application to become …well …uh …meat?

Livestock available

Application to be …Livestock

Films and animations

“Stockman” Association I guess you could join the “club”

Loco’s actual daughter who wanted to get into porn….

Another one to be served up

I can’t even make this shit up!

Click me…

Right, well looking at all those images you get a sense of what the flip was going on in there back in the day. It was all good, if you can call it that, until it went bad for Perro and his merry gang of paraphiliacs. I mean, never mind that he is serving up his own daughter in this thing and all of the cray cray “eat me” discourse that is fairly graphic but man these people had no idea what they were doing OPSEC wise either. I understand it was 2001 and really the net was new but boy oh boy did they leave a trail to their real identities here. If you decide to take a look at the archive note that their IP’s were captured for each post as well as they were offering up their email addresses that they CONTINUE TO USE! I have looked up several and located their real names and locations today.

<BLINK>

OY VEY!

</BLINK>

Now I am going to pause here for a moment to take all this in and maybe say a couple things about pathology and psychological illness…

Eh fuck it.

On to the CRAZIER CRAZY!

So yeah everything was just super great in the Cannibal clearnet back in 2001 until a certain character showed up on the board. His name was “Franky” and he was a German dude who wanted to eat someone and this was the hot spot for this kind of thing right? Well, maybe it was and maybe it wasn’t. I mean all these folks may actually have been just living out their fantasies right? Well Franky would have none of that, he was gonna chow down and he was gonna have a nice time at it provided he could “meat” someone at necrobabes.

Oddly enough you all may know of Franky through the IT Crowd. Does everyone remember the IT Crowd episode titled “I want to cook with you” ? Well, this parody is based on Franky, the German IT guy who put an ad out for someone to eat.

Go on, click the video, I know you wanna… I will be waiting below.

Franky

Young Boys

MOAR FRANKY

Frankalicious

Armin Meiwes

Franky, aka Armin Meiwes literally wanted to eat someone and had wanted to do so since he was eight years old. He met a poor sod on the cannibal site who agreed (Bernd Brandes) of whom he ate about 20kg of his flesh. You can read the grizzly bit below on how that happened and the whole article right here. It seems that Bernd was rather tasty and Miewes took his time with the rest saving it in the freezer for later. I am guessing that after Miewes was caught and the searches were begun it quickly became apparent that he had been on the necrobabes site. I kinda have to wonder at how they all took it on that site. I mean, they were all into the cannibal thing, they talked a good game but just how many of them were all McConaughey about it…

So the site pulls the cannibal board and sometime later the site kinda dies itself. Meanwhile your friendly neighborhood “loco” is like “I am gonna start my own site now man, I need me some cannibalism!” and get’s a new domain started. This site is supposed to be private and you have to email to get an invite. So, me being me, I decided to use a cutout and send an email in to get that freaky e-vite! I got turned down though, so I was disappoint! That is until I decided to use my super Google Fu and shit, he really hasn’t secured the site. You can see all the shit in there with a good Goog session and in the end there isn’t much traffic in there at all. I guess you can’t keep a good cannibal down but you can not sign up for his whacky site and just move on to other places right?

His site is still up and MAN is it GEOSHITTIES

DUDE DUDE DUDE NO MENTION OF DOLCETTEGIRLS?

Who is this Poizner cat?

The perro himself…

dolcettegirls.com

Inside dolcette

More boards and it’s all quiet

For more just use the Google Fu: site:dolcettgirls.com
Now you can just say well that guy is a bit whack and move on but once you start going down the rabbit hole on him you kinda just get sucked into the Nick Cage level shit in Eight Millimeter. Ancillary searches on this guy turned up some real crazy shit. I mean just look at that photo of him above here!

Holy Church of Dolcette?

WHAT THE?

I CAN’T!

It seems like ol’ Perro wanted to have himself a cannibalistic religious org that could maybe be tax exempt? I can imagine that might be hard to get past the IRS, I mean, how are you gonna make that a religio… Wait.. Wafer and wine…

SHIT!

Whoa!

Anyway, Perro is still kicking around on the tubes and seems to have slowed down but where have all those cannibals gone since the necrobabes site went bye bye? Well, it isn’t to the darknet as far as I can tell from all my searches. Nope, it is once again the clearnet that hosts this kind of crazy and I found the new mother load by accident.

It seems all the kids are now at ForumJar which is a low end board much like the original necrobabes but this one is much more sedate and hidden. These people are offering themselves and looking for others to consume just like the old days so I guess you really can’t keep a cannibal down eh? These guys though seems to be a little more savvy about their security but even so, one I looked at is looking for a “chunky” female and offers a kik address to chat them up. I read this and just had a flash of Hannibal Lecter asking Starling if Bill’s ladies were “roomy”

New board

Secondary board

Take me!

“Chunky female”

Well, I guess it’s time to put the lotion on the skin…

Remember, this is what happens when I have idle hands kids. All in all, this is pretty twisted and it all lives mostly in the clearnet so don’t believe all the BOOGA BOOGA DARKNET shit you hear. The clearnet is maybe even more scary and when you think about it, kids today can just google this up and get an eye full.

…. Even if you have those filters on your router.

Heh.

K.

UPDATE: As if by some quirk of fate this turns up today in the news… 30 people eaten at least! http://www.independent.co.uk/news/world/europe/cannibal-couple-eat-30-people-russia-dmitry-baksheev-natalia-military-aviation-academy-krasnodar-a7967216.html

Written by Krypt3ia

2017/09/25 at 21:08

Posted in DARKNET

Equifax and Musicians

leave a comment »

Screenshot from Zerohedge

 

So here’s my thing; It isn’t about the fact she was a music major and had two degrees in that. What it is really all about is the fact that she had no discernible security experience in the time she was working in the position or before to make her qualified to handle the job. THIS IS THE ISSUE PEOPLE! It is not about that she had a degree in nothing to do with security. So please stop all the 140 character bullshit and get it through your thick heads that even if you have a degree in IT this does not make you qualified necessarily to handle a job in information security ok?

Now that the CSO’s and CISO’s linkedin pages are redacted you can’t see much of anything but before they took them down I looked and neither had the requisite experience that would make me consider them for a position as an executive in charge of insuring that the security of the company and more importantly, the security of the clients data was in capable hands. Look. let’s face it you can say that the exec is just there as an advocate or to manage Trust me though, if they have no experience in the arena either they listen to their guys in the field and implicitly trust them and advocate or they just are compliance monkeys of the worst order.

I have lived it and I have seen it throughout my career in security. So please stop all the fuckery about “I have a degree in animal science and woe is me I am unfit for security!”

BULLSHIT

If you have a degree or not, you have to have put in the hours of study and actually doing the things! If you haven’t then you are out of your depth and bad things will happen.

Just look at Equifax.

K.

Written by Krypt3ia

2017/09/20 at 15:14

Posted in FAIL, FUCKERY

The CYBER Wars

leave a comment »

We met in an old, drab, and odd Russian eatery cum bar this year. A matronly Russian woman made us order things from the menu as a young girl sang Russian kulturny songs on a cheap sound system in the back corner. I had come to talk to someone in the IC about “Cyber War” and hoped that our mutual experiences could give me an insight or direction for this post. After sitting with this person for about an hour I had to go but in that time I had several revelations from our discourse. This post is the culmination of that conversation and my further ruminations about the current state of “cyber warfare”

Firstly, the conversation that we had was very roundabout, going back to the dawn of the ARPANET and other systems but all the while with a bent on economics. This kind of threw me for a bit but I listened further and within that long and winding road two things became clear from this IC warriors career. All cyber war is really Information Warfare, and second that all information warfare has an economic component. These things had not really occurred to me in the past but the revelation made me think differently about all of it. Thinking about the economics certainly easily led to all the Chinese hacking and theft of IP surely, but on a macro scale all warfare has its economic drivers right? Someone wants the things you have or they want to stop you from getting those things to others. So the motivation is always there in some way on a nation state level and all of the techniques used in information war or hacking can be used to great effect on these problems.

Once I had some time to think about all that I had heard I started to contemplate everything that had taken place over the last election and what is still happening today. It became clear to me today that my convictions on “cyber” war were the same as they always had been but with some caveats. Primarily for me is the notion that “cyber” war is really just information warfare. It is even still information warfare when something physically is caused to blow up or eat itself like the centrifuges in Natanz back in 2011. Information warfare since then though has been escalated with the active measures by the GRU and SVR (KGB) that took place in our last election cycle. Clearly it was information being used to manipulate the populace and their opinions. The hacking or “cyber” as many like to call it was just a component, an element of this and it was the information that was a key to this. The net effect here is that once again I put it to you all, the “cyber” war doesn’t exist, it is all just information war using hacking and code as a force multiplier.

What you all need to worry about now is the use of technology to manipulate just like the active measures campaign did in 2016. The revelations on Facebook’s being used by Russia to manipulate public opinion is just one instance and a more nuanced approach needs to be applied to information warfare henceforth. I see articles every day now asking how do we fight this kind of warfare and honestly I see no easy way to do so. People are easily led and much more so now that the electronic media is so prevalent and easily manipulated by ad buy’s, hacks, and open source troll accounts. That people now have their digital bubbles cum echo chambers makes it even worse with their cognitive dissonance at eleven. Honestly, much of the time lately I feel like Joshua and have decided not to play the game at all and go dark.

Maybe you should too.

K.

Written by Krypt3ia

2017/09/14 at 13:02

Posted in CyberWar

EQUIHAX

with 3 comments

Trawling the darknet as one does, I came across this little simple page this morning. It claims to be the real EQUIFAX hackers, unlike the last darknet site that was soon taken down by morons. I have looked at all the data on the pages (see screen shots below) and have come to the conclusion that whoever this is they too had access to Equifax. As this is an evolving nightmare I thought it prudent to do a quick write up on this site and let you all know. These actors are offering a crowd source solution to the whole database for the same amount as the fake site the other day (600btc) but also are offering single records as well as 1,000,000 entries for 4 bitcoins or 56 ETC for the same amount of records.

This time the actors actually give you samples, a taste, as they say on the street as bona fides…

 

These samples are what makes me think that this actor had access. I know for a fact that as the ongoing arguments take place online over what the compromise consisted of (what attack worked) that I personally saw a tweet from an alleged Russian actor claiming to have shell access on one of their servers online. This later was proven out to have ADMIN/ADMIN as the log and pass which is just horrid security, or should I say lack thereof? Anyway, you can see above that those records seem legit as do the screen shots of the access to the systems using real internal server names etc.

An onion scan of the site turns up no real vulnerabilities…

The bitcoin wallet shows no activity as yet.

EDIT/UPDATE:

In the process of watching this a change has been made to a small point of data that leads me to believe that this is a fake. Someone pointed out that the data for Bill Gates address was incorrect. Since then it has changed…

Oopsies… State : WA

BEFORE

Screenshot from 2017-09-14 14-16-55

AFTER

Screenshot from 2017-09-14 14-07-43

UPDATE TWO:

A new story has surfaced online that makes the claim that the site creators have access to Equifax and there are other screen shots. I am still concerned with the changes to the data seen here but for what it’s worth here’s the link to the story.

https://t.co/IGoKPCXcDD

Written by Krypt3ia

2017/09/14 at 11:38

Posted in Uncategorized

Extortion Phishing: So, closer to the point. You surfed the internet with роrn, which I’ve placed with the virus…

leave a comment »

A series of extortion emails have gone out this last month that caught my eye. The phish are simple straight forward attempts at extorting users by claiming they had been hacked and watched surfing porn. The phishers then demand that the user pay a certain amount of bitcoins to them and all their trouble will go away. Basically it is the equivalent of the old “Say, that’s a nice family you have there, it’d be a shame if something happened to it” routine familiar to anyone who has seen a mafia movie. I had a user get one and so I began the usual looking around to see if more came in and what the deal was with it. Once I began Googling key words and phrases I saw that this had been making the rounds since at least August 14th and that this last round had actually made some money for the extortionists.

I then began the usual OSINT on the domain that the emails came from after collecting as much info as I could from Reddit and other places where people had mentioned the extortion attempts. What I came up with is an arcology of malware and phishing that seem to tie back to one individual in Ukraine who may be the nexus of it all. Before I go down the OSINT rabbit hole though, I just want to take a moment to consider this threat and the psychology of it. One might think that if you got this email you would just laugh it off and then trash it. Some people though had guilty minds or had in fact been surfing “the porn”, as we all do mind you, (come on you all do and you know it!) so they got worried and they actually paid this guy off to make it all go away and this is interesting to me. Do those who paid really think that an extortionist, once successful at getting them to pay them will just walk away after such an easy exploit?

*shakes head*

You fools…

Anywho, it seems that even a non exploit exploit of just threatening a user’s browsing habits with “I am gonna email all your contacts with your pron habits” is can work and potentially give the attacker some pin money at least. So I tracked the emails and the IP’s that these came from to Ukraine. Specifically to a subnet of systems owned by one guy: Roman Shurbarev.

From: return@aukcion.org

Received: from nat5.aukcion.org (nat5.aukcion.org [188.225.27.25])

As you can see there are porn like sites in there…

The domain owner of not only the domain in question that was set up as a mailer for these phish but also a string of other domains that he owns connected to other malware and phish sites and activities that include, wait for it… Wait… Ransomware! Yup, this guy has it all goin on! Now, when I started poking at the system that this all came from I ran an Nmap and the shit is tight, there were no open ports and the firewall as filtering everything so I kinda doubt that this guy has been popped and being used as a relay for these. So I went on to profile all his domains and got the following malware connections:

 

PICK A MALWARE! ANY MALWARE!

So yeah, this guy has many bad connections but not anything directly connected to his domains themselves that I could see, at least in the sense that they were hosting the malware or being used as a C2. Now though I would like to talk about the money. These poor fools who actually paid this scammer have netted him about .28794615 Bitcoins which is about 80516.75 Rubles or $1,375.29 dollars as of yesterday when I looked. The money has been moved around a lot from the series of wallets used in this extortion scheme:

156eSKJU22jHHUEr6zznqMiDyR1L7DFFPY
1FJND3abrT4TjwijUbfYPD8jogCFeSbL
1Pku8VSnjgZePRt8yLF3QWfUYMTAjhA3io
1DGgLh6xeDmasCBHaLEQXwJ7C9gEvpYvWr
12pRJwZfZKi3RZa2eFijVCjmjCbB1YcXXXrA
15YhkTnuTprtPDRsdxiE2y8sMqiSmLPx2g
17qDi9fFG8C7a4mmTBBjsV7QmUN9QUBScZ
1H6DRf3XvHYudc7g6RvCiMbunHHKpbjhD2
1Nu2hju7Bs4vkUw2xyqi4E3ktSgx2VJEJq
13HSMufjTvzGJKoHdSQsLiJbsPcQcVMf4K <— 7 transactions


 

 

 

It ain’t Wannacry money but it would buy some shit in Ukraine I guess. There has been some movement of money around so I am wondering if they are trying to mixmaster or what. I did not go down that rabbit hole so if you all want to go right ahead. As for me I thought that this post should be put out there for others to see the actor, the act, and maybe as a PSA to put a stop to it. So, here are the other variations on the theme. The emails all pretty much say the same thing with some variations on “I see you have been surfing porn because I infected your machine with porn!” and ask for the money;

So there you have it. You don’t have to be anyone special, you don’t have to be 1337 to scam people with an email…

Yay internet!

K.

Written by Krypt3ia

2017/09/01 at 11:51

Posted in Extortion, Phishing