As a JSON: github.com/cirosantilli/media/blob/master/cia-2010-covert-communication-websites/hits.json. OurBigBook Markup to JSON conversion helper cia-2010-covert-communication-websites/bigb-to-json:
cia-2010-covert-communication-websites/bigb-to-json cia-2010-covert-communication-websites.bigb
Hit criteria: has Wayback Machine archive, and clear indication of a known communication mechanism. The mechanism itself doesn't need to be archived however, a link to it is enough given other supporting elements: IP range, site style, date, web archive date pattern. JS commons are always quickly visually inspected, other mechanisms we look only at filename patterns. Commented edge cases that didn't make the cut can be found mostly under Section "IP range search" and Section "2013 DNS Census virtual host cleanup heuristic keyword searches".
ip | domain | Wayback Machine | language | country mentions | comms | theme | notes |
---|---|---|---|---|---|---|---|
? | all-sport-headlines.com | 2011 | Arabic | JAR | news | split images[ref][ref]Arabic-looking alphabet, image only so can't Google translate easily. | |
? | firstnewssource.com | 2011 | Farsi | Iran | JAR | news | Copyright 2009. Split images. rss-items . |
? | global-view-news.com | 2011 | English | JAR | news | split images[ref][ref] | |
? | globaltourist.net | 2010 | English | JAR | travel | split images[ref][ref], rss-items . speed.jar "speed test" JAR pattern. Seems to have been legit both before. | |
? | hassannews.net | 2010 | Arabic | SWF | news | CSS or archive quite broken. Split images[ref][ref]. rss-items . | |
? | health-men-today.com | 2011 | Arabic | JAR | news | rss-items . Encoding broken. | |
? | intlnewsdaily.com | 2011 | English | JAR | news | rss-items | |
? | newdaynewsonline.com | 2011 | English | JAR | news | ||
? | newsincirculation.com | 2011 | Arabic | JAR | news | ||
? | newsworldsite.com | 2011 | Pashto | Afghanistan | JAR | news | |
? | pars-technews.com | 2011 | Farsi | Iran | JAR | news | "pars" presumably means "Parsi" or something of the same root |
? | sportsnewsfinder.com | 2011 | Chinese | China | JAR | news | 体育新闻发现者 (sports news finder) |
? | terrain-news.com | 2011 | Pashto | Afghanistan | JAR | news | |
? | theworldnewsfeeds.com | 2011 | English | JAR | news | rss-items . Split images[ref][ref] | |
? | todayoutdoors.com | 2011 | English | JAR | sports, travel | split images[ref][ref] | |
? | todaysnewsreports.net | 2010 | Arabic | JAR | news | ||
? | weblognewsinfo.com | 2011 | English | JAR | news | Split images, rss-items . | |
? | opensourcenewstoday.com | 2010 | Arabic | JAR | news | copyright 2010 | |
? | techwatchtoday.com | 2011 | English | JAR | tech, news | Marked copyright 2008. Split images[ref][ref]. Later legit. | |
? | cyhiraeth-intlnews.com | 2011 | English | JAR | news | en.wikipedia.org/wiki/Cyhyraeth "The cyhyraeth is a ghostly spirit in Welsh mythology, a disembodied moaning voice that sounds before a person's death." WTF! So the serious looking black actress lady is meant to represent the voice of death?. Split images[ref][ref]. rss-items | |
? | 24hoursprimenews.com | 2009 | English | JAR | news | split images[ref][ref] | |
? | dailynewsandsports.com | 2013 | English | JAR | sports | ||
? | europeannewsflash.com | 2011 | English | JAR | news | Split images[ref][ref] | |
? | farsi-newsandweather.com | 2011 | Farsi | Iran | JAR | news | split images[ref][ref] |
? | iranfootballsource.com | 2011 | Farsi | JS | sports, football | ||
? | iraniangoalkicks.com | 2008 | Farsi | Iran | JAR | sports, football | |
? | iraniangoals.com | 2009 | Farsi | Iran | JS | sports, football | |
? | mywebofnews.com | 2011 | Arabic | JAR | news | Split images[ref][ref]. rss-items . | |
? | news-latina.com | 2011 | English | JAR | news | copyright 2007 | |
? | outlooknewscast.com | 2011 | Farsi | Iran | JAR | news | |
? | rastadirect.net | 2010 | English | JAR | fansite | ||
? | todaysengineering.com | 2011 | English | CGI | engineering | ||
? | worldofonlinenews.com | 2011 | English | JAR | news | split images[ref][ref]. Later legit. | |
62.22.60.42 | newsupdatesite.com | 2011 | English | JAR | news | rdns source | |
62.22.60.46 | flyingtimeline.com | 2011 | English | JAR | airplanes | ||
62.22.60.48 | currentcommunique.com | 2011 | English | Egypt | SWF | news | |
62.22.60.49 | telecom-headlines.com | 2011 | English | JS | tech | ||
62.22.60.52 | collectedmedias.com | 2011 | French | JS | news | Marked copyright 2008 | |
62.22.60.55 | thefilmcentre.com | 2011 | English | JS | films | ||
62.22.60.56 | traveltimenews.com | 2011 | English | JS | news | ||
62.22.61.193 | awfaoi.org | 2010 | Arabic | Iraq | JAR | not-for-profit | This was the first clear .org hit with comms we've been able to find. Title translation: "Arab women to help Iraq", so perhaps "awfaoi" stands for "Arab Women For A O? Iraq". This fits well into the .org theme. Marked copyright 2008. |
62.22.61.197 | rc5sports.com | 2011 | English | JAR | sports | ||
62.22.61.198 | inside-vc.com | 2011 | English | CGI | finance | "vc" is a standard abbreviation for venture capital | |
62.22.61.202 | bailsnboots.com | 2011 | English | SWF | sports, cricket | "Bail" is one part of the thing your're supposed to hit with th eball in cricket.[ref] | |
62.22.61.203 | the-cricketer-online.com | 2011 | English | JAR | sports, cricket | marked copyright 2009. | |
62.22.61.204 | hollywoodscreen.net | 2011 | English | JS | films | ||
62.22.61.206 | worldnewsnetworking.com | 2011 | Arabic | JAR | news | ||
62.22.61.212 | nuestrasfinanzas.com | 2011 | Spanish | JAR | finance | ||
62.22.61.217 | court-masters.com | 2011 | English | JAR | sports, tennis | ||
62.22.61.219 | allworldstatistics.com | 2011 | English | JS | statistics | ||
62.22.61.220 | newsjaka.com | 2011 | English | Indonesia | JS | news | "jaka" presumably means Jakarta, the capital of Indonesia. There is a Indonesia section on the left sidebar. But the news are quite global however. |
63.131.229.2 | fightskillsresource.com | 2011 | English | JS | sports, martial arts | ||
63.131.229.4 | unitedterritorynews.com | 2011 | English | JS | news | ||
63.131.229.9 | show-dustry.com | 2011 | English | CGI | entertainment | The website name is a neologism with "show" and "industry". | |
63.131.229.11 | mythriftytrip.com | 2011 | English | CGI | travel | thrifty means: "using money and other resources carefully and not wastefully" | |
63.131.229.12 | cyberreportagenews.com | 2011 | English | JAR | news | rdns source | |
63.131.229.13 | sunrise-news.com | 2011 | English | JAR | news | rdns source | |
63.131.229.15 | cricketnewsforindia.com | 2013 | English | India | JS | sports, cricket | archive quite broken, lots of missing files, including the JS |
63.131.229.16 | nutricion-saludable.net | 2010 | Spanish | CGI | health | ||
63.131.229.20 | fixashion.net | 2011 | English | JS | fashion | ||
63.130.160.50 | theglobalheadlines.com | 2010 | English | JAR | news | this has several archives from 2013, marked as Live Web Proxy Crawls and explained "mostly by the Save Page Now", so presumably by counter intelligence or amateurs | |
63.130.160.51 | hai-pow.com | 2011 | English | JAR | sports, martial arts | ||
63.130.160.53 | echessnews.com | 2011 | Chinese | China | JAR | sports, boxing | Chinese title: 我的象棋世界 (My Chinese Chess world). rdns source. Split images[ref][ref] |
63.130.160.60 | boxingstop.net | 2010 | Polish | Poland | JAR | sports, boxing | |
63.130.160.62 | azerinews.org | 2009 | Azerbaijani | Azerbaijan | JAR | news | rdns source. Split images, rss-items . |
64.16.204.55 | holein1news.com | 2010 | English | JAR | sports, golf | ||
64.16.204.58 | tech-topix.com | 2013 | English | CGI | tech | Archive quite broken, but link to CGI comms. | |
65.61.127.163 | capture-nature.com | 2011 | English | JAR | photography | Reuters example. Since became legitimate, Ciro contacted the owner, and he was unaware of the domain's history. | |
65.61.127.166 | globalnewsbulletin.com | 2013 | English | Tunisia, Afghanistan, Iran, Egypt | CGI | news | PHP pages, images /images/index_01.jpg |
65.61.127.169 | crossovernews.net | 2011 | English | JAR | sports, basketball | ||
65.61.127.174 | dedrickonline.com | 2010 | German | JS | sports | ||
65.61.127.175 | altworldnews.com | 2013 | English | CGI | news | Epoch times link, PHP pages | |
65.61.127.178 | tee-shot.net | 2011 | English | SWF | sports, golf | nice domain name | |
65.61.127.182 | pangawana.com | 2011 | Arabic | Afghanistan | JS | news | |
65.61.127.183 | cutabovenews.com | 2011 | English | Algeria, various others | JS | sports, basketball | |
65.61.127.184 | worldwildlifeadventure.com | 2011 | English | JAR | travel | ||
65.61.127.186 | explorealtmeds.com | 2013 | English | JAR | health | the JAR was not archived, but there's a link to it | |
65.218.91.9 | welcometonyc.net | 2010 | English | CGI | travel | ||
65.218.91.17 | alljohnny.com | 2004 | English | CGI | fansite | mega early hit from 2004 to 2005. Then a gap, then they redid the domain: 2011. Same authors given content similarities e.g. "Submit Your Favorite Carson Moment". Reusing the domain after all these years, the lack of OPSEC is just mind blowing! New website marked Copyright 2003. Part of Oleg Shakirov's findings. One of the Reuters websites. Search documented at: Searching for Carson. | |
66.45.179.192 | thegraceofislam.com | 2011 | English | CGI | religion, Islam | ||
66.45.179.193 | arabicnewsunfiltered.com | 2011 | Arabic | JAR | news | rdns source | |
66.45.179.194 | raulsonsglobalnews.com | 2011 | English | JAR | news | ||
66.45.179.195 | aryannews.net | 2010 | Pashto | Afghanistan | JAR | news | rdns source. Heil. |
66.45.179.199 | attivitaestremi.com | 2011 | Italian | CGI | sports | ||
66.45.179.201 | hitthepavementnow.com | 2011 | English | CGI | sports, running | ||
66.45.179.202 | newimages.org | 2011 | Turkish | Turkey | JAR | photography | JAR unarchived |
66.45.179.203 | noticiascontinental.com | 2011 | Spanish | South America | CGI | news | |
66.45.179.205 | noticiasporjanua.com | 2011 | Spanish | JAR | news | ||
66.45.179.206 | podisticamondiale.com | 2010 | Italian | Italy | JAR | sports, running | marked copyright 2010 |
66.45.179.207 | reflectordenoticias.com | 2011 | Spanish | JAR | news | ||
66.45.179.208 | havenofgamerz.com | 2011 | English | CGI | gaming | marked copyright 2009 | |
66.45.179.210 | sa-michigan.com | 2011 | English | JAR | sports | "sa" is an abbreviation for the site title "Sports Alive" | |
66.45.179.211 | absolutebearing.net | 2010 | English | CGI | travel, sports, boats | ||
66.45.179.213 | myportaltonews.com | 2011 | English | JS | news | ||
66.45.179.214 | investmentintellect.com | 2011 | English | JAR | finance | ||
66.45.179.215 | nigeriastar.net | 2011 | English | Nigeria | JAR | news | Contains link to unarchived JAR |
66.104.169.163 | doctorsoncallsite.com | 2011 | English | JAR | health | ||
66.104.169.164 | lightandshadowonline.com | 2010 | English | JAR | photography | ||
66.104.169.168 | plugged-into-news.net | 2010 | English | JAR | news | JAR uses .zip extension! First instance, wow | |
66.104.169.171 | golf-on-holiday.com | 2011 | English | JAR | sports, golf | ||
66.104.169.172 | perspectiva-noticias.com | 2011 | Spanish | JS | news | ||
66.104.169.175 | aquaswimming.com | 2009 | English | JAR | sports, swimming | ||
66.104.169.177 | dojo-temple.com | 2011 | English | CGI | sports, martial arts | TODO meaning of "kama"? Kama lol? | |
66.104.169.179 | neighbour-news.com | 2010 | English | Germany | JAR | news | Mentions of Goethe-Institut and Germany all over. JAR unarchived |
66.104.169.180 | medicatechinfo.com | 2010 | English | JS | health | ||
66.104.169.181 | brickmanfinancialnews.com | 2011 | English | JS | finance | ||
66.104.169.182 | casanewsnow.com | 2011 | English | JAR | JAR unarchived. TODO why "casa"? Doesn't seem to have any link to Spanish or Portuguese. | ||
66.104.169.184 | bcenews.com | 2011 | Albanian | Albania | JAR | news | |
66.104.173.163 | runakonews.com | 2011 | English | Africa | CGI | news | "Runako" is an African given name. |
66.104.173.164 | shoppingadventure.net | 2010 | English | JAR | travel, shopping | JAR unarchived | |
66.104.173.165 | entertaining-ly.com | 2011 | English | JAR | entertainment | ||
66.104.173.166 | zubeenews.com | 2011 | English | JS | news | "Zubee" is a Muslim name: muslimnames.com/zubee. | |
66.104.173.169 | smart-financeology.com | 2011 | English | JAR | finance | ||
66.104.173.175 | media-coverage-now.com | 2010 | English | SWF | news | ||
66.104.173.176 | jbc-online-news.com | 2011 | English | JS | news | TODO meaning of "JCB". JS unarchived. | |
66.104.173.177 | webscooper.com | 2011 | English | JAR | news | ||
66.104.173.178 | dk-dcinvestment.com | 2010 | English | JAR | finance | TODO meaning of "dk;dc". | |
66.104.173.180 | stara-turistick.com | 2011 | Croatian | JAR | tourism | ||
66.104.173.181 | playbackpolitics.com | 2011 | English | JS | news | ||
66.104.173.182 | snapnewsfront.net | 2011 | English | Japan | JS | news | |
66.104.173.183 | ingenuitytrendz.com | 2011 | English | JAR | tech | ||
66.104.173.184 | armashoy.com | 2011 | Spanish | Spain | SWF | guns | meaning: "Weapons Today". In First World countries the CIA felt it would be safe to touch edgier subjects like guns |
66.104.173.185 | baocontact.com | English | JAR | HTML archive almost empty, but JAR was archived. One wonders what "bao" refers to, could be Chinese, but the small snippet of visible website is in English. | |||
66.104.173.186 | myworldlymusic.com | 2011 | English | Pakistan | JAR | music | JAR unarchived |
66.104.173.189 | hitpoint-gaming.com | 2011 | English | JS | gaming | Marked copyright 2010 | |
66.104.175.34 | itwebtoday.com | 2011 | English | JS | tech | ||
66.104.175.35 | drglobalnews.com | 2011 | English | JAR | news | TODO meaning of "dr"? rdns source. | |
66.104.175.36 | adilnews.net | 2010 | Arabic | SWF | news | Adil is an Arabic masculine name | |
66.104.175.40 | beyondnetworknews.com | 2011 | English | Egypt | CGI | news | |
66.104.175.41 | grubbersworldrugbynews.com | 2011 | English | JS | sports, rugby | ||
66.104.175.44 | yourtripfinder.net | 2010 | English | CGI | travel | comms not found, CGI from unarchived subpage assumed | |
66.104.175.45 | rollinsnetwork.com | 2011 | English | CGI | tech | CGI linked to but not archived | |
66.104.175.46 | infosharenews.com | 2011 | English | JAR | news | ||
66.104.175.47 | southasiaheadlines.com | 2011 | English | Bangladesh, Bhutan, India, Maldives, Nepal, Pakistan, Sri Lanka Tibet | JAR | travel | JAR linked to but missing from archive |
66.104.175.48 | worlddispatch.net | 2010 | Arabic | SWF | news | ||
66.104.175.49 | webworldsports.com | 2011 | Arabic | JAR | sports | ||
66.104.175.50 | fly-bybirdies.com | 2011 | English | JAR | travel | ||
66.104.175.51 | businessexchangetoday.com | 2011 | English | CGI | news, finance | PHP pages | |
66.104.175.52 | mensajeradenoticias.com | 2011 | Spanish | CGI | news | CGI unarchived | |
66.104.175.53 | info-ology.net | 2010 | English | JAR | news | ||
66.104.175.54 | marketflows.net | 2011 | English | JAR | finance | ||
66.104.175.57 | metanewsdaily.com | 2010 | English | CGI | news | ||
66.175.106.134 | paddlescoop.com | 2011 | English | Bangladesh, Pakistan, India, England | JAR | sports, cricket | |
66.175.106.137 | kessingerssportsnews.com | 2010 | English | JS | sports | ||
66.175.106.138 | factorforcenews.com | 2009 | English | JAR | news | ||
66.175.106.142 | kanata-news.com | 2010 | English | Canada | JS | news | "Kanata" is a place in Ottawa, Canada. The name is likely of Indigenous origin. |
66.175.106.143 | thecricketfan.com | 2011 | English | JAR | news | ||
66.175.106.146 | inews-today.com | 2011 | English | Egypt | JAR | news | Marked copyright 2008 |
66.175.106.147 | starwarsweb.net | 2010 | English | SWF | fansite | well, not even the CIA can escape Star Wars. TODO identify boy. | |
66.175.106.148 | activegaminginfo.com | 2011 | Chinese | JAR | gaming | the website is entitled "活跃游戏" which means "Lively games", or "active games" as in the domain name itself | |
66.175.106.149 | feedsdemexicoyelmundo.com | 2011 | Spanish | Mexico | JS | news | |
66.175.106.150 | noticiasmusica.net | 2010 | Brazilian Portuguese | Brazil | JAR | music | |
66.175.106.155 | atomworldnews.com | 2011 | English | Egypt | JAR | news | |
66.175.106.158 | nouvellesetdesrapports.com | 2011 | French | Egypt, Tunisia | JAR | news | |
66.237.236.227 | newsandmusicminute.com | 2011 | Pashto | JS | music | ||
66.237.236.229 | pearls-playlist.com | 2011 | English | SWF | music | ||
66.237.236.230 | beyondthefringe.info | 2012 | English | JAR | rugs | JAR unarchived | |
66.237.236.231 | primetimemovies.net | 2009 | English | JS | films | JS unarchived | |
66.237.236.235 | persephneintl.com | 2013 | JAR | archive very broken, JAR unarchived. Full title: "Persephne International", reference to Greek Goddess of "spring, the dead, the underworld, grain, and nature" | |||
66.237.236.236 | directoalgrano.net | 2010 | Spanish | JAR | news | ||
66.237.236.240 | actualizaciondebeisbol.com | 2011 | Spanish | JS | sports, baseball | ||
66.237.236.243 | mygadgettech.com | 2009 | Chinese | CGI | tech | Archive very broken | |
66.237.236.247 | comunidaddenoticias.com | 2011 | Spanish | Ecuador | JAR | news | |
66.237.236.249 | sumerjaseahora.com | 2011 | Spanish | CGI | sports, SCUBA diving | submerge yourself now | |
69.84.156.69 | al-ashak-news-me.com | 2011 | Arabic | JS | news | ||
69.84.156.71 | worldfinancetoday.net | 2011 | English | JAR | finance | ||
69.84.156.72 | autonewsarabia.com | 2011 | Arabic | JAR | cars | ||
69.84.156.74 | blue-moon-news.com | 2011 | Arabic | JS | news | ||
69.84.156.76 | tnc-urdu.com | 2011 | Urdu | JAR | tech | TODO meaning of "tnc"? | |
69.84.156.82 | arabicnewsonline.com | 2011 | Arabic | JAR | news | rdns source. Some very similar domains: modernarabicnews.com, arabicnewsource.com. Needed more creativity here! Later legit. | |
69.84.156.83 | unganadormundial.com | 2010 | Spanish | CGI | sports, fitness | ||
69.84.156.88 | diariodeelmundo.com | 2011 | Spanish | JAR | news | ||
69.84.156.89 | todaysarabnews.com | 2011 | Arabic | JAR | news | JAR unarchived. | |
69.84.156.90 | stickshiftnews.com | 2011 | English | JAR | cars | ||
69.84.156.91 | theinternationalgoal.com | 2011 | Spanish | CGI | news | ||
72.34.53.174 | electronictechreviews.com | 2011 | English | JAR | tech | JAR unarchived. Split images, rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | just-the-news.com | 2011 | Arabic | JAR | news | copyright 2009. Present at "Mass Deface III" pastebin. JAR unarchived. | |
72.34.53.174 | kickitnews.com | 2010 | Arabic | JAR | sports, football | copyright 2009. Present at "Mass Deface III" pastebin. | |
72.34.53.174 | moyistochnikonlaynovykhigr.com | 2011 | Russian | Russia | fansite | copy of myonlinegamesource.com, but on a Russian transliterated domain rather than the English one, very interesting | |
72.34.53.174 | myhealthlibrary.net | 2011 | English | JAR | health | present at: "Mass Deface III" pastebin. | |
72.34.53.174 | myonlinegamesource.com | 2011 | Russian | Russia | gaming | Can't find comms, but stylistically perfect. rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | mytravelopian.com | 2011 | English | JAR | travel | ||
72.34.53.174 | recursosdenoticias.com | 2011 | Spanish | JAR | news | Split images, rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | sayaara-auto.com | 2010 | Arabic | JAR | cars | ||
72.34.53.174 | technologytodayandtomorrow.com | 2011 | English | JAR | tech | rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | todaysnewsandweather-ru.com | 2011 | Russian | Russia | JS | news | JavaScript with SHAs |
74.116.72.227 | dayenews.com | 2011 | English | JAR | news | rdns source. Previously 69.74.45.67. | |
74.116.72.229 | guide-daventure.com | 2011 | French | France | JAR | travel | |
74.116.72.231 | bleachersfootballnews.com | 2011 | English | JAR | sports, football | TODO meaning of "Bleacher"? Possible reference to Bleacher Report. | |
74.116.72.232 | indirectfreekick.com | 2011 | English | JAR | sports, football | ||
74.116.72.233 | wwiichronicles.net | 2011 | English | CGI | history | ||
74.116.72.234 | petroleumagenews.com | 2011 | English | JAR | oil | ||
74.116.72.235 | the-open-book-online.com | 2011 | English | JS | literature | ||
74.116.72.236 | techtopnews.com | 2011 | English | JAR | tech | ||
74.116.72.239 | crickettoday.info | 2013 | Pashto | JS | sports, cricket | JS unarchived. The requested URL /cricket.js was not found on this server | |
74.116.72.240 | zafernews.com | 2011 | Arabic | JAR | news | ||
74.116.72.242 | gdgtsource.com | 2011 | English | CGI | tech | Presumably "gdgt" stands for "GaDGeT", which is mentioned on subtitle | |
74.116.72.246 | vuvuzelanews.com | 2011 | English | JAR | sports, football | Vuvuzela is this plastic horn, popular in football stadiums. The term is of African origin. Later legit. rdns source. Previously at 69.74.45.86. | |
74.116.72.247 | ballbatstumpsandbails.com | 2011 | English | JAR | sports, cricket | ||
74.116.72.249 | round-trip-travel.com | 2010 | English | CGI | travel | this got archived a lot of times, though all seem to be Alexa crawls. | |
74.116.72.250 | arabicnewsource.com | 2011 | Arabic | CGI | news | ||
74.254.12.163 | half-court.net | 2010 | English | Philippines | JAR | sports, basketball | |
74.254.12.164 | dailywellnessnews.com | 2011 | English | JAR | health | rdns source. split images[ref][ref]. | |
74.254.12.165 | dylandon.net | 2011 | Chinese | SWF | music | "Dylan" presumably a reference to Bob Dylan? "Don" unclear. Maybe Don McLean? | |
74.254.12.166 | afghanpoetry.net | 2010 | English | Afghanistan | SWF | poetry | Also at 63.131.229.10[ref] in a range. |
74.254.12.168 | non-stop-news.net | 2010 | Farsi | JAR | news | ||
74.254.12.169 | soldiersofsouthasia.com | 2011 | English | JAR | history | ||
74.254.12.171 | autism-news.org | 2011 | English | SWF | health | copyright 2007. Split images. rss-items . Previously at 69.74.45.67. | |
74.254.12.176 | pakcricketgrd.com | 2011 | Urdu | JAR | sports, cricket | TODO meaning of "grd" | |
74.254.12.177 | networkofnews.com | 2011 | English | JAR | news | rdns source. Later legit. | |
74.254.12.179 | wineconnaisseur.net | 2010 | English | JS | wine | ||
74.254.12.180 | helpinghandssite.com | 2011 | English | JAR | news | ||
74.254.12.188 | first-tee-golf.com | 2011 | English | JAR | sports, golf | ||
74.254.12.189 | fabu-foto.com | 2011 | English | CGI | photography | ||
74.254.12.190 | viptravelabroad.com | 2011 | English | JS | travel | ||
199.85.212.105 | mide-news.com | 2010 | English | CGI | news | "MIDE" stands for "Middle East". Comms not archived, presumably CGI comms variant. | |
199.85.212.111 | newsandsportscentral.com | 2009 | English | JAR | news | rdns source | |
199.85.212.118 | just-kidding-news.com | 2011 | English | JAR | news | epic name | |
204.176.38.130 | i-pressnews.com | 2011 | English | JAR | news | ||
204.176.38.132 | turkishnewslinks.com | 2011 | English | Turkey | JAR | news | |
204.176.38.134 | photographyarecord.com | 2011 | English | CGI | photography | Cute | |
204.176.38.135 | breakingthewicket.com | 2011 | English | CGI | sports, cricket | ||
204.176.38.136 | politicalworldtoday.com | 2011 | English | Egypt | JAR | news | |
204.176.38.137 | hi-tech-today.com | 2011 | English | JAR | tech | ||
204.176.38.139 | bigscreenbattles.com | 2011 | English | JAR | films | ||
204.176.38.141 | rakotafootball.com | 2011 | English | JAR | sports, football | "Rakota" is an Indian family name | |
204.176.38.143 | noticiassofisticadas.com | 2011 | Spanish | CGI | news | ||
204.176.38.142 | senderosdemontana.com | 2011 | Spanish | JS | sports, cycling | Talks about mountain biking and Eurobike 2010, so likely Spain focused, but it is not direct enough to be certain. JS unarchived. | |
204.176.38.144 | techno-today.com | 2011 | English | JAR | tech | was legit previously. | |
204.176.38.145 | tickettonews.com | 2011 | English | JAR | news | rdns source. Epoch times link. | |
204.176.38.146 | dps-digitalphotosharing.com | 2011 | English | JAR | photography | ||
204.176.38.147 | theputtingreen.com | 2011 | English | JAR | sports, golf | ||
204.176.38.149 | sportsnewstodayar.com | 2011 | Arabic | Lebanon, others | JAR | sports | "ar" on domain name presumably means "Arabic" |
204.176.38.159 | kairuafricanews.com | 2011 | English | Africa | JAR | news | what is "Kairu"? en.wikipedia.org/wiki/Kairu a place in India? en.wiktionary.org/wiki/kairu "frog" in Japanese? rdns source |
204.176.39.97 | beamingnews.com | 2011 | Arabic | JAR | news | Nice design. rdns source | |
204.176.39.98 | cubriendonoticias.com | 2011 | Spanish | JAR | news | archive quite broken. JAR unarchived. | |
204.176.39.100 | rowleyworldpost.com | 2011 | English | Egypt, others | JAR | news | |
204.176.39.103 | economicnewsbuzz.com | 2011 | Korean | CGI | finance | Love the kawaii style | |
204.176.39.104 | spectranewsonline.com | 2011 | English | CGI | news | marked copyright 2010. | |
204.176.39.105 | entertainmentnewscompany.com | 2011 | Chinese | SWF | films, music | Title: "娱乐新闻公司", lit. Entertainment News Company | |
204.176.39.110 | arabnewsatdawn.com | 2011 | Arabic | CGI | news | cute, the Arab chick's drink actually has a cocktail umbrella on it. Marked copyright 2010. | |
204.176.39.115 | globalprovincesnews.com | 2010 | Arabic | JS | news | ||
204.176.39.116 | mahparah-news.com | 2011 | Farsi | JS | news | ||
204.176.39.119 | commercialspacedesign.com | 2013 | Farsi | CGI | architecture | C O N C E P T U A L design. A rare example of a fake company website. | |
207.210.250.131 | starrynightnews.com | 2011 | Arabic | JS | news | interesting design | |
207.210.250.132 | aeronet-news.com | 2011 | English | JAR | airplanes | ||
207.210.250.133 | bakaribulletin.com | 2011 | English | Africa | JS | news | Bakari could either be a given name, or a village in Togo |
207.210.250.134 | deprensaenlarevisiondehoy.com | 2011 | Spanish | JAR | news | ||
207.210.250.135 | icwb-news.com | 2011 | English | JAR | news | ICWB stands for "Inner Circle Worldwide Business (News)", the title of the website | |
207.210.250.136 | sportsreelhighlights.com | 2011 | English | JAR | sports | ||
207.210.250.138 | inquiry-human-past.com | 2011 | English | JAR | history | ||
207.210.250.139 | thefairwaysaregreen.com | 2011 | Thai | JAR | sports, golf | ||
207.210.250.143 | archaeologyreview.net | 2010 | English | JAR | history, archeology | ||
207.210.250.146 | noticias-caracas.com | 2011 | Spanish | Venezuela | CGI | news | Caracas is the capital of Venezuela. But you knew that, right? |
207.210.250.147 | bailandstump.com | 2011 | English | JS | sports, cricket | "Bail" and "Stump" are the two parts of the thing your're supposed to hit with the ball in cricket.[ref] | |
207.210.250.149 | globalventurestat.com | 2008 | English | SWF | news | ||
207.210.250.152 | al-rashidrealestate.com | 2010 | Arabic | Egypt | CGI | finance, real-estate | |
207.210.250.153 | newsintheworld-ru.com | 2011 | Russian | JAR | news | ||
208.254.40.96 | sixty2media.com | 2011 | English | Various | JAR | news | Epoch times link |
208.254.40.99 | newspoliticssource.com | 2013 | Arabic | JAR | news | One of the news mentions Snowden | |
208.254.40.110 | musical-fortune.net | 2010 | English | CGI | music | images /images/banner-02.jpg | |
208.254.40.113 | ashoka-gemstones.com | 2010 | English | JAR | jewelry | ||
208.254.40.117 | worldnewsandent.com | 2010 | Arabic | Egypt | CGI | mews | |
208.254.40.124 | riskandrewardnews.com | 2013 | English | CGI | finance | ||
208.254.42.194 | it-proonline.com | 2011 | English | CGI | tech | images /images/header_01.jpg | |
208.254.42.205 | driversinternationalgolf.com | 2011 | English | CGI | sports, golf | ||
208.254.42.209 | mardelsurnoticias.com | 2011 | Spanish | JAR | news | weird mixture of Portuguese and Spanish language external links | |
208.254.42.215 | nowfreshfinances.com | 2011 | English | CGI | finance | CGI unarchived | |
208.254.42.216 | circulatingnews.net | 2010 | English | JAR | travel | ||
208.254.42.219 | westingtonpassnews.com | 2011 | English | JAR | news | ||
210.80.75.36 | e-commodities.net | 2011 | English | JAR | finance | ||
210.80.75.37 | trekkingtoday.com | 2011 | English | JAR | sports, running | split images[ref][ref]. rdns source. | |
210.80.75.41 | multinews-33.com | JAR | news | No archives of the HTML, but the JAR was archived | |||
210.80.75.43 | gulfandmiddleeastnews.com | 2011 | Arabic | JS | news | ||
210.80.75.44 | whirlybirdinflight.com | 2011 | English | JAR | helicopters | ||
210.80.75.45 | kings-game.net | 2011 | English | JAR | gaming, chess | JAR unarchived | |
210.80.75.46 | topglobalnewsdaily.com | 2011 | English | JS | news | ||
210.80.75.49 | recipe-dujour.com | 2011 | English | JAR | cooking | nice design | |
210.80.75.55 | philippinenewsonline.net | 2010 | Philippines | JAR | news | ||
210.80.75.56 | technewsforme.com | 2011 | Farsi | JAR | tech | ||
212.4.16.224 | lanoticiasdehoyelinforme.com | 2010 | Spanish | JAR | news | ||
212.4.16.232 | mynewscheck.com | 2011 | English | Canada | JAR | news | rdns source |
212.4.16.245 | financial-crisis-news.com | 2011 | Russian | Russia | JAR | news | rdns source |
212.4.16.252 | minutosdenoticias.com | 2010 | Spanish | CGI | news | CSS | |
212.4.17.38 | fightwithoutrules.com | 2011 | Russian | JAR | sports, combat sports | ||
212.4.17.41 | newtechfrontier.com | 2010 | English | CGI | tech | since became legit: newtechfrontier.com/ | |
212.4.17.43 | smart-travel-consultant.com | 2011 | Chinese | CGI | travel | ajaxtax.js may be of interest for fingerprinting. Title: "智能旅行顾问", lit. Smart Travel Consultant | |
212.4.17.46 | atentlaloc.com | 2009 | English | Quatar, Lebanon, Israel, Iran | JS | jewelry | Tlaloc is an Aztec deity, and Aten is an Egyptian deity. Both appear to be somewhat linked to gold, thus their usage in a jewelry website. Creative domain name. |
212.4.17.53 | newsresolution.net | 2010 | English | Côte d'Ivoire, Lebanon, Sudan | JAR | news, UN Peacekeeping | |
212.4.17.56 | lesummumdelafinance.com | 2010 | French | France | JAR | finance | |
212.4.17.98 | topbillingsite.com | 2011 | English | CGI | films | ||
212.4.17.122 | b2bworldglobal.com | 2011 | English | CGI | news | ||
212.4.18.14 | football-enthusiast.com | 2011 | English | Europe | JS | sports, football | |
212.4.18.129 | sightseeingnews.com | 2010 | English | JAR | travel | ||
212.209.74.105 | globalbaseballnews.com | 2011 | English | JS | sports, baseball | ||
212.209.74.106 | football-de-luxe.com | 2010 | French | France | JAR | sports, football | |
212.209.74.112 | developmental-league.com | 2010 | English | CGI | sports, American football | CGI comms variant? | |
212.209.74.115 | mediocampodefutbol.com | 2010 | Spanish | JAR | sports, football | ||
212.209.74.117 | myengineeringaffinity.com | 2011 | English | JAR | tech | ||
212.209.74.123 | worldfinancialexchangenews.com | 2010 | English | SWF | finance | SWF unarchived. | |
212.209.74.125 | avoilurefixe.com | 2011 | French | Tunisia | JAR | airplanes | "à voilure fixe" is French for "with fixed wing", i.e. fixed wing aircraft |
212.209.74.126 | headlines2day.com | 2011 | Farsi | JAR | news | marked copyright 2009 | |
212.209.79.34 | fgnl.net | 2011 | English | Iran | CGI | news | four letter domain! FGNL stands for "Farsi Global News Links" Marked copyright 2009. |
212.209.79.37 | fitness-sources.com | 2010 | English | JS | sports, fitness | ||
212.209.79.40 | hydradraco.com | 2011 | English | JAR | sports, American football | TODO meaning of the name? | |
212.209.79.41 | noticiasdelmundolatino.com | 2011 | Spanish | JAR | news | ||
212.209.79.42 | suparakuvi.com | 2011 | French | France | JAR | news | a Tour Eiffel image, and young people stuff, i.e. first world stuff. It's for France alright. But TODO meaning of domain name? Ciro's second language French didn't cut it this time. |
212.209.79.46 | cetusdelph.com | 2011 | English | JS | sports, scuba | ||
212.209.79.47 | willtoworship.com | 2011 | English | JAR | religion, Christianity | marked copyright 2007 (!) | |
212.209.79.48 | themvconnection.com | 2011 | English | JAR | music | ||
212.209.79.51 | pi-resources.net | 2010 | English | JS | private investigators | "pi" stands for Private Investigators. The CIA must have had some fun making this one. | |
212.209.79.53 | ourscubaworld.com | 2011 | English | JS | sports, scuba | ||
212.209.79.58 | tech-love-home.com | 2011 | Chinese | JS | tech | Title: "消费类电子产品", lit. Consummer Electronics | |
212.209.79.60 | first-solo-aviation.com | 2010 | English | JAR | airplanes | ||
212.209.79.61 | china-destinations.org | 2011 | Chinese | JS | travel | title: "中国目的地指南", lit. "China Destination Guide" | |
212.209.90.69 | worldedgenews.com | 2011 | English | JAR | news | ||
212.209.90.80 | nsmovies.net | 2010 | English | JAR | films | "ns" stands for "Nirguna Saguna", two separate Hindu names/deities. But there are no other Indian references beyond those. | |
212.209.90.82 | middleeastjournal.net | 2010 | Arabic | JS | news | ||
212.209.90.84 | thenewseditor.com | 2011 | English | JAR | news | ||
212.209.90.87 | newsandweathersource.com | 2009 | English | JAR | news | marked copyright 2009. | |
212.209.90.89 | pakisports.com | 2010 | English | Pakistan | SWF | sports | |
212.209.90.90 | vriha-aesthetics.com | 2011 | Arabic | JS | news | ||
212.209.90.92 | amishkanews.com | 2011 | English | India | JS | news | Amishka is an Indian name, plus some prominent mentions of Bollywood both point to India specifically |
212.209.90.93 | theentertainbiz.com | 2011 | English | JAR | entertainment | ||
212.209.90.94 | eurosportssummary.com | 2011 | English | JAR | sports | ||
216.93.248.194 | esmundonoticias.com | 2011 | Spanish | JAR | news | rss-items . Shares IP with kukrinews.com. | |
216.93.248.194 | kukrinews.com | 2010 | English | JS | News | JavaScript with SHAs. Talks to /cgi-bin/news.cgi . A Kukri is the national weapon of Nepal. Slogan: "Nepal's Sharp Edge", thus matching the website name. Split image header. Copyright 2009. Shares IP with esmundonoticias.com. | |
216.105.98.139 | cultura-digital.net | 2008 | Spanish | CGI | news | Marked copyright 2008. Previously legit. | |
216.105.98.140 | uaeshoppingspree.com | 2013 | English | UAE | JAR | shopping | Archive quite broken, but has link to unarchived JAR. Has an unusually personal touch "As you can probably tell from the title of my website, shopping is my very favorite pastime." |
216.105.98.145 | montanismoaventura.com | 2012 | Spanish | Spain | JS | sports, mountaineering | JS unarchived. Marked copyright 2010. |
216.105.98.147 | nepalnewsbrief.com | 2008 | English | Nepal | JAR | news | Marked copyright 2006 (!) If true this would be the earliest known reference to a date in the websites. |
216.105.98.152 | modernarabicnews.com | 2013 | Arabic | JAR | news | HTML archive quite broken, but JAR was archived thankfully. | |
216.105.98.154 | everythingcricket.org | 2011 | English | JAR | sports, cricket | Also has archives from 2009, but they were a bit broken. The 2011 one is marked copyright 2011, so they actually bothered to updated that. | |
216.105.98.156 | familyhealthonline.net | 2011 | English | CGI | health | ||
219.90.61.110 | surya-brahma.com | 2011 | Spanish | JAR | news | Surya and Brahman are Hindu concepts, but the website appears to have nothing to do with India or Hinduism. Interesting. | |
219.90.61.111 | classicalmusicboxonline.com | 2010 | English | CGI | music | ||
219.90.61.116 | athletepro.net | 2010 | English | JAR | sports | ||
219.90.61.117 | lajornadanow.com | 2010 | Spanish | JAR | news | ||
219.90.61.120 | theinternationalworld.com | 2011 | English | JAR | news | rdns source. rss-items . | |
219.90.61.121 | thepyramidnews.com | 2011 | Farsi | Iran | JAR | news | |
219.90.61.122 | iran-newslink-today.com | 2011 | Farsi | Iran | JAR | news | |
219.90.61.123 | journeystravelled.com | 2011 | English | JAR | travel | ||
219.90.62.229 | information-junky.com | 2011 | English | Ghana | JAR | news | |
219.90.62.231 | todosperuahora.com | 2011 | Spanish | Peru | CGI | news | |
219.90.62.233 | theworld-news.net | 2010 | Urdu | CGI | news | ||
219.90.62.234 | recuerdosdeviajeonline.com | 2011 | Spanish | SWF | travel | marked "Copyright 2009" | |
219.90.62.237 | elcorreodenoticias.com | 2011 | Spanish | Venezuela | JAR | news | |
219.90.62.237 | ride-captain.com | 2011 | English | JAR | sports, motorcyles | ||
219.90.62.238 | freshtechonline.com | 2011 | English | CGI | tech | ||
219.90.62.241 | newscentertoday.com | 2011 | English | JAR | news | Copyright 2008. rdns source. rss-items . Later legit, with a pause The domain name you have entered is not available. It has been taken down because the email address of the domain holder (Registrant) has not been verified.. | |
219.90.62.243 | fitness-dawg.com | 2021 | English | JAR | sports, fitness | ||
219.90.62.244 | easytraveleurope.com | 2012 | English | JAR | travel | nice design | |
219.90.62.245 | world-news-now.net | 2011 | English | JAR | news | ||
219.90.62.246 | negativeaperture.com | 2011 | English | CGI | photography | nice domain name | |
219.90.62.247 | conquermstoday.com | 2011 | English | CGI | health | MS means multiple sclerosis. Comms not found, CGI from unarchived subpage assumed. Has a subdomain "heal.conquermstoday.com" according to 2013 DNS Census, but no links to it in the archive. |
Some less-trivial breakthroughs:
- finding 2013 DNS Census
- CGI comms characterization
- secure subdomain search on 2013 DNS Census let to a few hits
- 2013 DNS Census virtual host cleanup heuristic keyword searches was massive and led to many new ranges
Initial announcements by self on 2023-06-10:
- twitter.com/cirosantilli/status/1667532991315230720. Follow up when more domains were found: twitter.com/cirosantilli/status/1717445686214504830
- www.reddit.com/r/OSINT/comments/146185r/i_found_16_new_cia_covert_communication_websites/. Marked as SPAM 5 by mods days later. After reaching 92 votes, a very positive reply for that niche sub, and being obviously on topic. Weird. Anyways, did its job and likely kicked off hackernews.
- www.facebook.com/cirosantilli/posts/pfbid04KvRbEXghJakcD4AQz4379L5oVjPZ6vrBF1Eak3p81VnqRSXuXdvvYonCWPhGfQXl
Shared by others soo after:
- 2023-06-11:
- news.ycombinator.com/item?id=36279375#36280220 (212 points). Shame that this was published when we only had about 20 websites. As of writing we had 240. Might have been a greater hit then.
- Google Analytics backlink from lms.fh-wedel.de/ path unknown. Some shitty German university: en.wikipedia.org/wiki/Fachhochschule_Wedel_University_of_Applied_Sciences LMS stands for Learning management system, apparently a Moodle instance. Maybe they have some Open educational resources, but all in German so pointless
- www.reddit.com/r/conspiracy/comments/14705gp/cia_2010_covert_communication_websites/ failed attempt with bad link unfortunately
- a few days later:
- 2023-06-19 www.reddit.com/r/numberstations/comments/14dexiu/after_numbers_stations_vanished/ (30 points) off topic on that sub, but thankfully was not deleted, interesting sub topic
2023-10-26 twitter.com/cirosantilli/status/1717445686214504830: announcement by self after finding 75 more sites
Second wave:
- 2023-12-01: news.ycombinator.com/item?id=38492304 (65 points). Second submission but pointing to OurBigBook.com rather than cirosantilli.com: ourbigbook.com/cirosantilli/cia-2010-covert-communication-websites We take those. Reached only 65 points as of January 2024.
- 2023-12-02: buttondown.email/grugq/archive/december-2-2023/. "grugq" is the handle of a zero day dealer whose received some scrutiny in 2012 after a Forbes protile was written about him: archive.ph/7mUG5. He comments:presumably referring to DNS Census 2013.
I don’t think anyone anticipated that databases leaked by hackers would enable OSINT researchers to conduct counterintelligence investigations that rival the state security services.
Some more:/ny
- 2024-01-12: twitter.com/jeremy_wokka/status/1745657801584656564 (40k followers, mid of thread)
- 2024-01-15: Oleg Shakirov's findings, publication announced by Ciro Santilli at: twitter.com/cirosantilli/status/1747742453778559165 two days later
- 2024-01-23: ipinf.ru gives 4 hits and 4 new suspects, announced at: mastodon.social/@cirosantilli/111807480628392615
The third one from Cambridge after:
Some good mentions at: Video "Where is Anatomy Encoded in Living Systems? by Michael Levin (2022)".
As of 2023, working with DNS data is just going through a mish-mash of closed datasets/expensive APIs.
We really need some open data in that area.
- opendata.stackexchange.com/questions/1951/dataset-of-domain-names
- opendata.stackexchange.com/questions/2110/domain-name-system-record-a-database
- webmasters.stackexchange.com/questions/33395/find-the-ip-address-of-expired-domains/142751#142751
- superuser.com/questions/686195/how-to-find-the-last-ip-used-for-an-expired-domain-name/1793224#1793224
École Polytechnique student culture by Ciro Santilli 35 Updated 2025-01-10 +Created 1970-01-01
This is going to be the most important application of generative AI. Especially if we ever achieve good text-to-video.
Image generators plus human ranking:
- pornpen.ai/ a bit too restrictive. Girl laying down. Girl sitting. Penis or no penis. But realtively good at it
- civitai.tv/. How to reach it: civitai.tv/tag/nun/2/
www.pornhub.com/view_video.php?viewkey=ph63c71351edece: Heavenly Bodies Part 1: Sister's Mary First Act. Pornhub title: "AI generated Hentai Story: Sexy Nun alternative World(Isekai) Stable Diffusion" Interesting concept, slide-narrated over visual novel. The question is how they managed to keep face consistency across images.
The fundamental insight of Git design is: a SHA represents not only current state, but also the full history due to the Merkle tree implementation, see notably:
This makes it so that you will always notice if you are overwriting history on the remote, even if you are developing from two separate local computers (or more commonly, two people in two different local computers) and therefore will never lose any work accidentally.
It is very hard to achieve that without the Merkle tree.
Consider for example the most naive approach possible of marking versions with consecutive numbers:
- Local 1:
- 0: root commit
- 1: commit 1
- 2: commit 2 by local 1
- Local 2:
- 0: root commit
- 1: commit 1
- 2: commit 2 by local 2
- 3: commit 3 by local 2
- Remote
- 0: root commit
- 1: commit 1
If Local 1 were to push to Remote first, how could Local 2 notice that when it tries to push itself? The navie method of just checking: "does Remote have commit "2"" does not work, because Local 2 has a different version of commit 2 than local 1.
Unlisted articles are being shown, click here to show only listed articles.