German police raid DDoS-friendly host FlyHosting
krebsonsecurity.com
krebsonsecurity.com
The gang producing them got so overwhelmed with burning CDs in their basement, that they went to a factory in Germany.
Police looked at the serial number on the CD, went to the factory and asked who the customer was and that's how they got busted.
Organized crime also does a lot of "dumb" stuff but they do it at scale and make it harder to trace back the individual incident to the organization's core. They also heavily rely on disposable accomplices, which is why you still see these "make money doing nothing from home, just let us use your bank account" scams.
You would be mistaken btw to think this only applies to non-western parts of the world. The spectrum is a wide one, from completely covert operations, over organized crime, to companies and even the government itself. The ones who are caught are usually not the smart ones. Of course, the Dunning Kruger effect is also strong here, so most of them think they're too smart to be caught.
Bitcoin (and most other cryptocoins) needs a bit of effort to grovel the public transaction history, and XMR does things that supposedly make that not really work at all, but other than that...
Any source? Can't find anything.
I'm not qualified to say whether that actually achieves that goal though
Which would limit what you could do with the money, but isn't that true of any crime related money?
Outside of cash transfer services which often also require an ID on both ends albeit that is often easier to fake there aren’t ways to transfer money anonymously.
So companies use either alternative settlement methods such as crypto or gift cards or what is also quite common twin settlement.
You want a VPC? We’ll give you one for free just buy a 3 months VPN service from our sister company.
Basically the idea here is to split the records across as many platforms as possible and have as much separation as possible from payments and actual usage.
whats funnier is those who run these booter sites then ACCEPTS payment with paypal. dios mio
And then:
> An ad for FlyHosting posted by the the user “bnt” on the now-defunct cybercrime forum BreachForums
So we have a dark web 'offering' advertising on a clearnet forum. This is a conflict of interests IMHO. You're either fully operating on the darkweb or you're not. Clearnet e-crime sites are famously de-anonymized. It just takes a payment from PayPal registered in your legal name to buy hosting services, and boom: you've been decloaked by the authorities.
$ whois -h whois.ripe.net AS202437
[...]
aut-num: AS202437
as-name: FLYHOSTING
remarks: -------------------------------------------------------------
remarks: This internet resource will be deregistered by 9 June 2023.
remarks: -------------------------------------------------------------
[...]
last-modified: 2023-03-31T13:34:39Z
There's no equivalent remark on their IP space (185.132.53.0/24 and 2a0f:9400:6119::/48) yet.The notion of ignoring networks (ASNs) which have predominantly hostile traffic at the BGP level has been bandied about for a long time, but so far as I know, most network operators are exceedingly reluctant to do this, absent a few, mostly political, instances. Israel and its Arab neighbours come to mind, my understanding is that direct network connections are limited, or at least were historically. There are a few other cases largely between hostile nations.
Would RIPE be acting on the request of German legal authorities and/or courts, or on some other basis? And how would this be determined?
This is getting uptake because instead of the pitch to operators being "help validate internet advertisements" it's "now you don't have to manually configure accept policies or worry about misconfigured advertisements from clients".
https://www.arin.net/resources/manage/rpki/troubleshooting/#...
This is a guess but either a) giving out incorrect information (which is a clear basis, all AS operators must be either a person or a legal company, yes you could practically bypass this by registering a shell company but considering that they've used PayPal I'm pretty sure that they have not planned this well) or b) a German or Hessian (it seems that it's registered in Hesse) court might have forcibly transferred the legal entity to the state, in which case since the state now owns the entity they could simply file paperwork to voluntarily relinquish the AS.
Depeering is much more easier: all major transit networks have a provision in their contract to terminate the transit if it's unnecessarily burdening their systems or if it is used for malicious purposes.
they also usually have a small number of actual manually-configured peers and if they're a member of an IX, they use the routeservers instead. Very easy for an IX to disconnect a criminal entity.
disconnecting a HUGE network that has a large portion of abusive traffic is much harder, like trying to bgp blackhole some major ISPs in China.
This... might actually be effective.
One major reason I stopped using Kazaa/LimeWire back in the day was growing fear (and experience) with files being laced with malware.
Throw out enough landmines to make someone think every service could be a trap... seems smart.