You say honeypot, I say free government-provided cloud storage, w00t!
I dealt with one case that was completely horrific, and two minor. The horrific case involves the PRODUCTION of CP using other service members children via the spouses daycare, then distribution from our network. The other two were relatively simple storage/redistribution via workstations.
It happens, but from my viewpoint if it’s that rare it must be extremely rare elsewhere if your statement is true.
I dont know where the servers were, but i feel like it was used for less lovely purposes by the owners and a lack of identifiers & internet curated mess would obfuscate law enforcement's efforts
Edit: my theory however falls flat if there were multiple websites, since having a one large database would be in their best interest. You could argue that there were multiple entities self-hosting the same thing, but why would they link to eachother? Coupled with the VPN ad, sounds like data harvesting all around (honeypot or not)
If they're all hosted on the same server -- which, to all appearances, they were -- there's little practical distinction.
- https://web.archive.org/web/20230801/https://anonfiles.com/
- https://web.archive.org/web/20230801/https://bayfiles.com/
- https://web.archive.org/web/20230801/https://file.bz/
- https://web.archive.org/web/20230801/https://filechan.org/
- https://web.archive.org/web/20230801/https://forumfiles.com/
- https://web.archive.org/web/20230801/https://hotfile.io/
- https://web.archive.org/web/20230801/https://letsupload.cc/
- https://web.archive.org/web/20230801/https://lolabits.se/
- https://web.archive.org/web/20230801/https://megaupload.nz/
- https://web.archive.org/web/20230801/https://myfile.is/
- https://web.archive.org/web/20230801/https://openload.cc/
- https://web.archive.org/web/20230801/https://rapidshare.nu/
- https://web.archive.org/web/20230801/https://share-online.is...
- https://web.archive.org/web/20230801/https://upload.st/
- https://web.archive.org/web/20230801/https://uplovd.com/
- https://web.archive.org/web/20230801/https://upvid.cc/
- https://web.archive.org/web/20230801/https://vshare.is/
- https://web.archive.org/web/20230801/https://zippysha.re/
All of them were hosted by a single IP in svea.net, with a couple of associated IPs at the same host for "cdn##" subdomains.
There never appeared to be more than a few at a time and I did not find too many in total.
https://web.archive.org/web/20220620143327/https://bayfiles....
https://web.archive.org/web/20220623051910/https://openload....
https://web.archive.org/web/20220620170814/https://myfile.is...
https://web.archive.org/web/20230401012418/https://filechan....
https://web.archive.org/web/20230401012318/https://letsuploa...
They also started advertising ovpn.com as a "court-proven VPN" on June 23rd 2022: https://web.archive.org/web/20220623173752/https://anonfiles...
It looks like from June 24th 2022 through August 10th 2023 (or 16th, likely whenever they changed their index to announce the shutdown) they only listed filechan.org and letsupload.cc.
On July 4th 2022 they dropped ovpn.com: https://web.archive.org/web/20220704154732/https://anonfiles...
All of the file sharing sites listed do appear to be parodies of other popular websites, some of them file sharing. They also appear to all be identical except for the site name and styling. All of the file sharing sites except for anonfiles.com now return NXDOMAIN. (ovpn.com appears to still exist.)
The obvious parodies of file sharing websites does call into question their assertion that they didn't want abuse.