Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

investigate creation date of domain #16

Open
a-douwe opened this issue Feb 25, 2020 · 8 comments
Open

investigate creation date of domain #16

a-douwe opened this issue Feb 25, 2020 · 8 comments

Comments

@a-douwe
Copy link

a-douwe commented Feb 25, 2020

source of new domains

By googling some of the domains currently listed, I stumbled upon this website:
https://domain-status.com/archives/2019-8-30/com/registered/221

It contained westtxnews.com website that was listed on the github, and by simply searching in the page for "news" I found a few more suspicious website, showing the 404 message.

suspicious pages:

westcontracostanews.com
westdfwnews.com (already listed)
westeldoradonews.com
westhoustonnews.com (already listed)
westnovanews.com (already listed)
westrgvnews.com (already listed)
westsgvnews.com
westventuranews.com

All unlisted domains seem to be on the same AWS server. I listed what I found below so it's recorded, but I'm sure there's more on this server, but I don't know how to get all of them.

Namely:
reverse lookup on westcontracostanews.com (3.222.217.66)
alohastatenews.com
antelopevalleytoday.com
beaverstatenews.com
eastkingnews.com
evergreenreporter.com
kitsapreview.com
moseslaketoday.com
newashingtonnews.com
northkingnews.com
northsnohomishnews.com
nwwashingtonnews.com
olympictimes.com
piercetoday.com
seattlesounder.com
sewashingtonnews.com
southkingnews.com
southsnohomishnews.com
southsoundtimes.com
spokanecotimes.com
spokanestandard.com
tricitiesreporter.com
vancouverreporter.com
waislenews.com
wenatcheetimes.com
westcontracostanews.com
westeldoradonews.com
westventuranews.com
yakimatimes.com

all of the above are not listed right now

@zpoch
Copy link

zpoch commented Feb 26, 2020

I came across this issue in my research and decided to do a bit of additional research on that site for the domains registered on 8/30/2019 starting at https://domain-status.com/archives/2019-8-30/com/registered/1 using other keyword patterns I identified in the domain names.

I started with "times" and the first domain I found that matched the pattern for these sites that wasn't listed yet was centraloctimes.com, which had an A Record set for 3.222.217.66. I noticed after I did a reverse IP lookup on that for other domains that this is the same server IP you found. I also noticed that the domain is using Google MX records. See https://who.is/dns/centraloctimes.com

The tool I used for the reverse IP lookup is listing 121 domains on this new IP, and of the 100 I can view on a free account they all match the naming convention for these shady localized news sites. There are quite a few that you don't have listed above. See https://dnslytics.com/reverse-ip/3.222.217.66

Additional IPs not listed above or https://github.com/MassMove/AttackVectors/blob/master/LocalJournals/sites.csv

centralalamedanews.com
centraloctimes.com
centraloregontimes.com
coachellatoday.com
eastalamedanews.com
eastoregonnews.com
eastpdxtoday.com
eastsandiegonews.com
eastsbvtimes.com
eastsfvtoday.com
eastsierranews.com
eastventuranews.com
fresnoleader.com
goldenstatetoday.com
imperialcanews.com
interioralaskanews.com
kauaisun.com
kingscountytimes.com
laharbornews.com
laketahoesun.com
laneconews.com
marinleader.com
mauireporter.com
mercedtimes.com
midcoasttimes.com
midvalleyreporter.com
montereytimes.com
necalinews.com
nesacramentonews.com
northalaskanews.com
northcoastcanews.com
northcoasttoday.com
northinlandnews.com
northoctimes.com
northsactoday.com
northsfvtoday.com
northsgvnews.com
nwlatimes.com
nwriversidenews.com
oaklandrecord.com
portlandcourant.com
redwoodempirenews.com
sacramentostandard.com
sandiegorecord.com
sanfransun.com
sanjoaquintimes.com
sanjosestandard.com
sanmateosun.com
santacruzstandard.com
scalaskanews.com
sealaskanews.com
seattlecitywire.com
selatimes.com
sfvtoday.com
sgvstandard.com
sloreporter.com
solanosun.com
southalamedanews.com
southbayleader.com
southbaysdnews.com
southcoasttimes.com
southoctimes.com
southoregonnews.com
southsactoday.com
southsfbaynews.com
southsfvtoday.com
southsgvnews.com
swalaskanews.com
swriversidenews.com
tularetimes.com
verdugosnews.com
victorvalleytimes.com
westlatimes.com
westoctimes.com
westpdxtoday.com
westsbvtimes.com
westsfvtoday.com
yubasuttertimes.com

@Bermos
Copy link
Contributor

Bermos commented Feb 26, 2020

Shall I scrape and add them to the sites.csv?
I think we should look into a more flexible way to store that information tho. We are getting quite a few people here (which is great :).

Edit: nevermind I just did and they are all not active yet. Do we have confirmation that they belong in the same group or would it be wise to monitor them separately?

@zpoch
Copy link

zpoch commented Feb 26, 2020

I really fell down a rabbit hole tonight with all this. I'd say they definitely fit the pattern of the other sites and are all hosted in the same manner with the DNS already pointing to the same server. They just aren't "active" sites yet. Perhaps we need a status column for now in the CSV to determine sites that have been activated and ones that fit the profile, but are inactive.

@a-douwe
Copy link
Author

a-douwe commented Feb 26, 2020

Edit: nevermind I just did and they are all not active yet. Do we have confirmation that they belong in the same group or would it be wise to monitor them separately?

Given that the creation date of a lot of the domains is the same and also shares the creation date with domains that we know are active, the naming convention is the same and the way it's hosted (aws and many domains on one server), I think it would be safe to assume it's the same organisation.

@Bermos
Copy link
Contributor

Bermos commented Feb 26, 2020

I know that feeling. Damn rabbit holes everywhere as of late! And yes, I think a active column would make sense.

@mariotacke
Copy link
Contributor

@Bermos, just want to point out, I've added other columns in #25. Let's merge that before we add another column (to prevent merge issues).

@mentor20
Copy link
Contributor

@mariotacke #25 is merged, thanks for that. Feel free to merge any pull requests yourself so I'm not a bottleneck.

@mentor20
Copy link
Contributor

@Bermos they are all online now. And confirmed to be inbred: https://centraloregontimes.com/terms - can you scrape and flesh out sites.csv? We have an httpResponseCode column which doubles as an active column now. Send dudes!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants