Used Maltego CE to run an investigation on findingassange.com domain. Here's the topology it spit back out to me:
Part 1 -
https://sli.mg/Z1bHvz.png
Part 2 -
https://sli.mg/Ujaxwy.png
This is where I need some help and opinions : wildcard-in-use.findingassange.com
Weird looking website really, and the IP block is originating from somewhere else than the original URL findingassange.com.
Also weird privacy statement with no contact info and product reference : http://wildcard-in-use.findingassange.com/privacy
The IP for wildcard-in-use.findingassange.com linked to these two entities:
Bodis : https://bodis.com/ --> domain parking
Prolexic Technologies : https://en.wikipedia.org/wiki/Prolexic_Technologies --> DDoS mitigation and IT security services
The IP for findingassange.com linked to these two different entities:
WILDCARD-AS --> cant find shit on this
I Fast Net LTD : https://ifastnet.com/ --> hosting
Also, ftp.findingassange.com prompts for username password, if anyone wants to try to work their way in.
I'll keep digging, but to me, it looks weird, and I need opinions about this! Upvoat for visibility!!!
view the rest of the comments →
pizzagateishell ago
Like do we really want to trust this shit ? It almost looks like a scam to attract high volume to their website for ad revenue or even maybe upselling the domain. I dont know man. All im saying is that it doesnt really look "official" , specifically this : http://wildcard-in-use.findingassange.com/privacy
pizzagateishell ago
http://findingassange.com/privacy
redirects here
http://parked-domain.org/
Explanations anybody?
j_m_d ago
Whoever set up the site probably just redirected the link for /privacy to go to that URL. Similar to http://itanimulli.com redirecting to the NSA dot gov site. And that prilosec company or whatever is just ddos protection like cloudflare is. I wouldn't waste my time with it.
pizzagateishell ago
Tell me, why waste money employing Prolexic (which doesnt look to come cheap $$$) to prevent DDoS attacks when you can just straight up release the data without a countdown. I'll tell you why, because that dump is litterally a dump of shit, and they are protecting their MSM pile of shit from being taken down. I bet you they will talk about this website tomorrow in the MSM attracting even more attention to it!