Part 1 of 7
In continuation of the last submission, regarding the list of 20+ connected domains that spread fake news, I looked further into the characteristics of those domains and those submitters on Voat. I am not sure what to expect with this submission, other than presenting my findings and voice my opinions with the data I have collected at hand. You may notice that the archive dates are spread out across a whole week, that is because it was done in bits and pieces.
Notice that this data may be incomplete, as most of the 20+ domains were already offline or wiped, shortly after the last submission. Because of the number of domains involved, I made minimal effort to archive those sites. Lately, I had to resort to the timestamps from the search engine.
tl;dr: a collection of domains, controlled by a small group of users, could be used to spread fake news, bypass spam rule, or track and dox other users. Use vpn, tor, or anon proxies when possible, especially for high profile users.
Let's start by defining the metrics used to flag a domain, along with the submitters. A domain is flagged as suspicious, along with the users involved, if it exhibits one or a combination of the following characteristics:
- First submission to Voat being too close to domain's registration date: This strongly suggests that the submitter is directly or indirectly affiliated with the domain involved. This submitter either owns the domain or pushes the domain for its owner.
- Low traffic site recently been updated, closely followed by a submission to Voat: This suggests a weak but similar condition as #1.
- Site's wayback activity sparsely archived, with submission too close to the archived date: It suggests that the site showed some recent activity.
- Site's traffic history, followed too closely to the submission date: When a low traffic or barely active site made a submission on Voat, its traffic increases, followed by its decline back to zero or low traffic steady state.
- Multiple domains sharing the same set of IPs: Sharing IPs is common in shared hosting, but having those domains coincidentally showed up by a user or a small group of users, is not so common. This technique was probably used to circumvent Voat's spam rule, or possibly to disguise something else, such as repackaging of MSM news behind no-name domains.
Status of domains been investigated:
- Domain1 akniinfo.com, taken offline, short-lived.
- Domain2 cbinfo24.com, taken offline, short-lived.
- Domain3 coolinfo24.com, taken offline, short-lived.
- Domain4 cukam.com, taken offline, short-lived.
- Domain5 cvikas.com, taken offline, short-lived.
- Domain6 cvikasdrv.com, taken offline, short-lived.
- Domain7 dailyinfo24.info, re-purposed, but traffic continued.
- Domain8 fergieinfo.com, taken offline, short-lived.
- Domain9 lifeinfo24.net, taken offline, short-lived.
- Domain10 ludinfo24.com, taken offline, short-lived. First submission made 3 days after domain registration.
- Domain11: mminfo24.com, taken offline, short-lived.
- Domain12: policeglobal.com, still online on 2019-01-19.
- Domain13: scandallinfo.com, online but data wiped, short-lived. First submission made only 12 hours after domain registration, very interesting!
- Domain14: tapainfo.com, taken offline, short-lived. First submission made 4 days after domain registration.
- Domain15: thenyherald.com, taken offline, short-lived. First submission made only 2.5 days after domain registration.
- Domain16: tvrtinfo.com, taken offline, short-lived.
- Domain17: usapatriotsvoice.com, taken offline on 2019-01-21.
- Domain18: vtamedia.com, taken offline on 2019-01-21.
- Domain19: classic2017.info, taken offline.
- Domain20: ilovemyamerica.net, suspended.
- Domain21 libertyinfonews.com, still online, but short-lived. First submission to Voat, 8 days dated from site's earliest article.
This list came from previous submission, where the domains were flagged for sharing a subset of identical articles that contained fake news. These domains also showed very short user engagement, suggesting clickbait nature.
Suspects found, evaluated by timestamps associated with domain registration, wayback archives, and site's traffic profile: Kilroy_1962, RussianIvantheCrazy, GizaDog, Dailytacs, yurisrevenge, nogarbagetrashonly, theoldones, Russianbots, Mogumbo, Sw0rdofDamocles, mattsixteen24, and Kippering. I tried to minimize the number of suspects and usually only flagged the first submitter to the domain.
- Kilroy_1962
- RussianIvantheCrazy
- GizaDog
- Dailytacs
- yurisrevenge
- nogarbagetrashonly
- theoldones
- Russianbots
- Mogumbo
- Sw0rdofDamocles
- mattsixteen24
- Kippering
Looking further into the suspects, I dumped all of the domains from their submission histories. There were 900+ domains, first sorted by domain names, then by IP addresses. As it was too much work to look at them individually, I only picked those domains that seemed unusual, or domains that shared similar names and/or with the same set of IPs. Many of the domains that were picked showed very similar characteristics as the ones that were previously investigated. They were relatively new domains made it to Voat, with a spike in their traffic histories. Some were strikingly clear to see that they were pushed by specific user. In one specific case, three domains were cascaded together, af-mg.com forwarded to dc-chronicle.com, with dc-chronicle.com's data on thenarrativetimes.org. Very interesting to say the least!!
List of domains picked up from suspects' submissions, that showed very similar behaviour to those of 20+ domains. Initial submissions were usually posted to Voat between days to 3 weeks, after domain registration or before traffic spike.
- Domain22: americanews.network, offline, short-lived. First submission posted 10 days from domain registration.
- Domain23: amirror.link, offline with bad gateway. First submission 6 days from domain registration.
- Domain24: animeright.news, currently online, a shitpost website.
- Domain25.1: americafastnews.net, offline, no ssl. Appeared to be 1 of 4 domains sharing same backend, see data log at the end. First submissions posted to Voat within 2 to 3 weeks of domain registration.
- Domain25.2: conservativegeneration.net, offline, no ssl.
- Domain25.3: conservativemind.net, offline, no ssl.
- Domain25.4: topalertnews.com, offline, no ssl.
- Domain26.1: newsusatoday.co, offline, expired. First submission 5 days from site's traffic spike.
- Domain26.2 viraldailynews.co, offline, expired.
- Domain27.1: politicalbelief.site, offline. First submission 12 days from domain registration.
- Domain27.2: trumptroopers.com, offline. First submission 4 days from domain registration.
- Domain27.3: viralview.site, offline.
- Domain28: viralusfortrump.com, offline. First submission 4 days from domain registration.
- Domain29.1: loveconservative.site, offline. First submission 13 days from domain registration.
- Domain29.2: politicaltribes.site, offline.
- Domain30: freedom-daily.com, re-purposed. First submission 21 days from previous domain registration.
- Domain31.1: democratdossier.org, online. First submission between 1 week to 1 month.
- Domain31.2: truthseries.net, online, no ssl. First submission 13 days before traffic spike.
- Domain31.3: yellowvestmarch.com, online. First submission 15 days after domain registration.
- Domain32: nationonenews.com, offline. First submission 7 days after domain registration.
- Domain33: thenarrativetimes.org, online, connected to dc-chronicle.com, which itself was connected to af-mg.com. First submission 11 days before traffic peaked.
- Domain34: nationonenews.org, offline. First submission 1 fucking day after domain registration.
- Domain35.1: dc-chronicle.com, online, redirected from af-mg.com.
- Domain35.2: af-mg.com, connected to dc-chronicle.com.
- Domain36: dailycallernewsfoundation.org, online.
- Domain37: redstatenation.com, online. First submission 8 days after domain registration.
- Domain38: defiantamerica.com, online.
So it appears to me that there is likely a user or a small group of users, who are here to push contents, by hopping through disposable/burner domain names. Some of those domains pushed fake news, some pushed low quality contents or other bullshits. Some would circumvent spam rule with collection of domains at disposal. This is something that other goats can point out periodically. I am not too worried or concerned about that. But I am in a way concerned with its implications.
Cont to part 2: https://voat.co/v/ProtectVoat/3001782/16431060
view the rest of the comments →
kneo24 ago
I'm not sure if these are set up to track and dox users - I don't know. One thing that I think is clear, these sources exist to push narratives (whether they true or not). I suspect Voat has long had an issue of people using multiple accounts to form consensus on narratives. People would love to pretend that is somehow a Reddit only thing, but there is nothing in place to prevent it on Voat, and to be honest, quite a few NPC's here who will upvote anything that conforms to their narrative.
You might have a few false positives in this list, and you might not. I'm going to ping the faggots in question so they can explain themselves. Let's see how many get their panties twisted.
@Kilroy_1962 @RussianIvantheCrazy @GizaDog @Dailytacs @yurisrevenge
MadWorld ago
Thanks!
Some more users from previous submission who may be interested: @GoylentGreen, @theoldones, @Lazmat, @Peaceseeker, @SchwazaRifleCoffeeCo
MadWorld ago
@ArtistiqueJewelry @Russianbots @Sw0rdofDamocles @MacMike See submission
MadWorld ago
@draaaak, @uvulectomy see submission. Thanks
MadWorld ago
@totes_magotes, @lets_get_hyyerr, see submission.
lets_get_hyyerr ago
Very good post. some of these people I have on a separate investigation Ive been working on. Keep me updated please!
MadWorld ago
Looking forward to see what you have found on those upvotes.club accounts!
kneo24 ago
I'd be surprised if he found something we didn't already know, but I'm sure he's more than willing to take credit for already known information and pat himself on the back for it.
lets_get_hyyerr ago
why don't you @ me next time you talk shit so I can read what you wrote instead of being a (((rat))) and talking in silence
kneo24 ago
You have in the past told me I was a nobody, not important, and when I do typically @ you, you ignore it. It got to the point where it became a fruitless endeavor.
lets_get_hyyerr ago
Please feel free to link me the comments where I said that. I would love to see them.
Because you're very annoying. Case in point: the original reason I commented here
kneo24 ago
Here you go, you dumb cunt.
This is entirely the logic of a woman seeking attention. Why don't you stay in the kitchen there sweety and make everyone a sandwich. Oh, and bring us out a beer too.
lets_get_hyyerr ago
This entire response you've chosen to write out perfectly displays the reasons why I think you're very annoying. thank you for that
kneo24 ago
And yet you still crave my attention. Go ahead, tell me more, lady.