This article is about covert agent communication channel websites used by the CIA in many countries from the late 2000s until the early 2010s, when they were uncovered by counter intelligence of the targeted countries circa 2011-2013. This discovery led to the imprisonment and execution of several assets in Iran and China, and subsequent shutdown of the channel.
The existence of such websites was first reported in November 2018 by Yahoo News: www.yahoo.com/video/cias-communications-suffered-catastrophic-compromise-started-iran-090018710.html.
Previous whispers had been heard in 2017 but without clear mention of websites: www.nytimes.com/2017/05/20/world/asia/china-cia-spies-espionage.html:
Some were convinced that a mole within the C.I.A. had betrayed the United States. Others believed that the Chinese had hacked the covert system the C.I.A. used to communicate with its foreign sources. Years later, that debate remains unresolved.[...]From the final weeks of 2010 through the end of 2012, [...] the Chinese killed at least a dozen of the C.I.A.’s sources. [...] One was shot in front of his colleagues in the courtyard of a government building — a message to others who might have been working for the C.I.A.
Most notably, starting in 2008, CIA contractor John Reidy started raising concerns about the security of the communication systems used, but he was silenced and ignored, leading to catastrophe.[ref][ref]
Then in September 2022 a few specific websites were finally reported by Reuters: www.reuters.com/investigates/special-report/usa-spies-iran/, henceforth known only as "the Reuters article" in this article.
Banner of the Reuters article
. Source. Inspecting the Reuters article HTML source code
. Source. The Reuters article only gave one URL explicitly: iraniangoals.com. But most others could be found by inspecting the HTML of the screenshots provided, except for the Carson website.Ciro Santilli heard about the 2018 article at around 2020 while studying for his China campaign because the websites had been used to take down the Chinese CIA network in China. He even asked on Quora: www.quora.com/What-were-some-examples-of-the-websites-that-the-CIA-used-around-2010-as-a-communication-mechanism-for-its-spies-in-China-and-Iran-but-were-later-found-and-used-to-take-down-their-spy-networks but there were no publicly known domains at the time to serve as a starting point. Chris, Electrical Engineer and former Avionics Tech in the US Navy, even replied suggesting that obviously the CIA is so competent that it would never ever have its sites leaked like that:
Seriously a dumb question.
So when Ciro Santilli heard about the 2022 article almost a year after publication, and being a half-arsed web developer himself, he knew he had to try and find some of the domains himself using the newly available information! It was an irresistible real-life capture the flag. The thing is, everyone who has ever developed a website knows that its attack surface is about the size of Texas, and the potential for fingerprinting is off the charts with so many bits and pieces sticking out. Chris, get fucked.
In particular, it is fun to have such a clear and visible to anyone examples of the USA spying on its own allies in the form of Wayback Machine archives.
Given that it was reported that there were "more than 350" such websites, it would be really cool if we could uncover more of those websites ourselves beyond the 9 domains reported by Reuters!
This article documents the list of extremely likely candidates Ciro has found so far, mostly using:more details on methods also follow. It is still far from the 885 websites reported by citizenlabs, so there must be key techniques missing. But the fact that there are no Google Search hits for the domains or IPs (except in bulk e.g. in expired domain trackers) indicates that these might not have been previously clearly publicly disclosed.
- rudimentary IP range search on viewdns.info starting from the websites reported by Reuters
- heuristic search for keywords in domains of the 2013 DNS Census plus Wayback Machine CDX scanning
If anyone can find others, or has better techniques: Section "How to contact Ciro Santilli". The techniques used so far have been very heuristic, and that added to the limited amount of data makes it almost certain that several IP ranges have been missed. There are two types of contributions that would be possible:Perhaps the current heuristically obtained data can serve as a good starting for a more data-oriented search that will eventually find a valuable fingerprint which brings the entire network out.
- finding new IP ranges: harder more exiting, and potentially requires more intelligence
- better IP to domain name databases to fill in known gaps in existing IP ranges
Disclaimer: the network fell in 2013, followed by fully public disclosures in 2018 and 2022, so we believe it is now more than safe for the public to know what can still be uncovered about the events that took place. The main author's political bias is strongly pro-democracy and anti-dictatorship.
May this list serve as a tribute to those who spent their days making, using, and uncovering these websites under the shadows.
If you want to go into one of the best OSINT CTFs of your life, stop reading now and see how many Web Archives you can find starting only from the Reuters article as Ciro did. Some guidelines:
- there was no ultra-clean fingerprint found yet. Some intuitive and somewhat guessy data analysis was needed. But when you clean the data correctly and make good guesses, many hits follow, it feels so good
- nothing was paid for data. But using cybercafe Wifi's for a few extra IPs may help.
viewdns.info
. Source. activegameinfo.com
domain to IPviewdns.info
. Source. aroundthemiddleeast.com
IP to domainDNS Census 2013 website
. Source. This source provided valuable historical domain to IP data. It was likely extracted with an illegal botnet. Data excerpt from the CSVs:amazon.com,2012-02-01T21:33:36,72.21.194.1
amazon.com,2012-02-01T21:33:36,72.21.211.176
amazon.com,2013-10-02T19:03:39,72.21.194.212
amazon.com,2013-10-02T19:03:39,72.21.215.232
amazon.com.au,2012-02-10T08:03:38,207.171.166.22
amazon.com.au,2012-02-10T08:03:38,72.21.206.80
google.com,2012-01-28T05:33:40,74.125.159.103
google.com,2012-01-28T05:33:40,74.125.159.104
google.com,2013-10-02T19:02:35,74.125.239.41
google.com,2013-10-02T19:02:35,74.125.239.46
The four communication mechanisms used by the CIA websites
. Java Applets, Adobe Flash, JavaScript and HTTPSExpired domain names by day 2011
. Source. The scraping of expired domain trackers to Github was one of the positive outcomes of this project.Compromised Comms by Darknet Diaries (2023)
Source. It was the YouTube suggestion for this video that made Ciro Santilli aware of the Reuters article almost one year after its publication, which kickstarted his research on the topic.
Full podcast transcript: darknetdiaries.com/transcript/75/
From The Reuters websites and others we've found, we can establish see some clear stylistic trends across the websites which would allow us to find other likely candidates upon inspection:The most notable dissonance from the rest of the web is that there are no commercial looking website of companies, presumably because it was felt that it would be possible to verify the existence of such companies.
- natural sounding, sometimes long-ish, domain names generally with 2 or 3 full words. Most in English language, but a few in Spanish, and very few in other languages like French.
- shallow websites with a few tabs, many external links, sometimes many images, and few internal pages
- lots of rectangular images make up the top bar banner image. Stock images are often used to make the full image, and then the full image is split. An example
- common themes include:
- news
- hobbies, notably sports, travel and photography. Golf seems overrepresented. Must be a thing over there in Langley.
- .com and .net top-level domains, plus a few other very rare non .com .net TLDs, notably .info and .org
- each one has one "communication mechanism file": communication mechanisms
- narrow page width like in the days of old, lots of images
- each hit domain is the only domain for its IP, i.e. the websites are all private hosted, no shared web hosting service examples have been found so far
- split images images: many of the website banners are composed of several images cut up. Stock images were first assembled into the banner, and then the resulting image was cut. Possibly this was done to make reverse image search to their stock image provider harder. But it somewhat backfired and serves as a good marker that confirms authorship. Maybe it is some kind of outdated web design thing, which they took much further in time than the average website, like the JAR. Their websites do appear to follow common style guidelines form earlier eras, around the early 2000s notably, some legit sites that look a lot like hits:
- some common pattern they follow in their news lists:
ul.rss-items > li.rss-item
, e.g.: web.archive.org/web/20110202092126/http://beamingnews.com/- links with class
a.newslink
anda.newslinkalt
e.g. web.archive.org/web/20110128181622/http://profile-news.com/
It would be fun to actually reverse search into one of their stock image provider's original images. Ones we've found:
As a JSON: github.com/cirosantilli/media/blob/master/cia-2010-covert-communication-websites/hits.json. OurBigBook Markup to JSON conversion helper cia-2010-covert-communication-websites/bigb-to-json:and new results that have been added to the list below can automatically be merged with cia-2010-covert-communication-websites/bigb-to-json-merge:
cia-2010-covert-communication-websites/bigb-to-json cia-2010-covert-communication-websites.bigb
cia-2010-covert-communication-websites/bigb-to-json-merge > tmp.json
mv tmp.json ../media/cia-2010-covert-communication-websites/hits.json
Hit criteria: has Wayback Machine archive, and clear indication of a known communication mechanism. The mechanism itself doesn't need to be archived however, a link to it is enough given other supporting elements: IP range, site style, date, web archive date pattern. JS commons are always quickly visually inspected, other mechanisms we look only at filename patterns. Commented edge cases that didn't make the cut can be found mostly under Section "IP range search" and Section "2013 DNS Census virtual host cleanup heuristic keyword searches".
ip | domain | Wayback Machine | language | country mentions | comms | theme | notes |
---|---|---|---|---|---|---|---|
? | 24hoursprimenews.com | 2009 | English | JAR | news | split images[ref][ref] | |
? | all-sport-headlines.com | 2011 | Arabic | JAR | news | split images[ref][ref]Arabic-looking alphabet, image only so can't Google translate easily. | |
? | cyhiraeth-intlnews.com | 2011 | English | JAR | news | en.wikipedia.org/wiki/Cyhyraeth "The cyhyraeth is a ghostly spirit in Welsh mythology, a disembodied moaning voice that sounds before a person's death." WTF! So the serious looking black actress lady is meant to represent the voice of death?. Split images[ref][ref]. rss-items . Here she is on Getty Images: www.istockphoto.com/photo/natural-style-for-the-individual-gm171403107-26684547 by Urilux | |
? | dailynewsandsports.com | 2013 | English | JAR | sports | ||
? | differentviewtoday.com | 2011 | English | JAR | news | split images, JAR unarchived | |
? | euronewsonline.net | 2010 | English | JAR | news | a.newslink. The image of the woman reading newspapers reverse searches to www.istockphoto.com/photo/news-gm101581053-7410445, iStock from Getty images | |
? | europeannewsflash.com | 2011 | English | JAR | news | Split images[ref][ref] | |
? | farsi-newsandweather.com | 2011 | Farsi | Iran | JAR | news | split images[ref][ref] |
? | financecentraltoday.com | 2011 | English | JAR | news, finance | unusual td > p > strong article list. Copyright 2008. | |
? | firstnewssource.com | 2011 | Farsi | Iran | JAR | news | Copyright 2009. Split images. rss-items . |
? | global-view-news.com | 2011 | English | JAR | news | split images[ref][ref] | |
? | globaltourist.net | 2010 | English | JAR | travel | split images[ref][ref], rss-items . speed.jar "speed test" JAR pattern. Seems to have been legit both before. | |
? | hassannews.net | 2010 | Arabic | SWF | news | CSS or archive quite broken. Split images[ref][ref]. rss-items . | |
? | health-men-today.com | 2011 | Arabic | JAR | news | rss-items . Encoding broken. | |
? | inkfreenews.com | 2011 | English | JAR | news | split images, JAR unarchived | |
? | internationalnewsworthiness.com | 2011 | English | JAR | news | RSS, split images, JAR unarchived | |
? | intlnewsdaily.com | 2011 | English | JAR | news | rss-items | |
? | intoworldnews.com | 2011 | English | JAR | news | split images. Links to news websites from frontpage, not news themselves. | |
? | iranfootballsource.com | 2011 | Farsi | JS | sports, football | ||
? | iraniangoalkicks.com | 2008 | Farsi | Iran | JAR | sports, football | |
? | iraniangoals.com | 2009 | Farsi | Iran | JS | sports, football | |
? | latinamericanewsbeat.com | 2010 | English | JAR | news | split images | |
? | magneticfieldnews.com | 2010 | English | JAR | news | rss, split images | |
? | middle-east-newstoday.com | 2010 | Farsi | JS | news | rss, split images | |
? | mideasttoday.net | 2010 | Farsi | JAR | news | a.rss-item, split images, copyright 2008 | |
? | mydailynewsreport.com | 2011 | Pashto | Afghanistan | JAR | news | rss, split images |
? | mynepalnews.com | 2011 | English | JAR | news | split images, JAR unarchived. Nice swimsuit ad. | |
? | newdaynewsonline.com | 2011 | English | JAR | news | ||
? | mywebofnews.com | 2011 | Arabic | JAR | news | Split images[ref][ref]. rss-items . | |
? | networkconnectionsite.com | 2011 | English | JS | news | rss, split images | |
? | news-latina.com | 2011 | English | JAR | news | copyright 2007 | |
? | newsdelivered.net | 2010 | English | JAR | news | rss, split images, JAR unarchived | |
? | newsincirculation.com | 2011 | Arabic | JAR | news | ||
? | newsworldsite.com | 2011 | Pashto | Afghanistan | JAR | news | |
? | opensourcenewstoday.com | 2010 | Arabic | JAR | news | copyright 2010 | |
? | outlooknewscast.com | 2011 | Farsi | Iran | JAR | news | |
? | pars-technews.com | 2011 | Farsi | Iran | JAR | news | "pars" presumably means "Parsi" or something of the same root |
? | pondernews.net | 2011 | Arabic | JAR | news | rss | |
? | profile-news.com | 2011 | English | JAR | news | a.newslink | |
? | purlicue-news.com | 2011 | English | JAR | news | split images, rss | |
? | rastadirect.net | 2010 | English | JAR | fansite | ||
? | segomonews.com | 2011 | English | JAR | news | rss, split images. TODO meaning of "segomo"? The main Wikipedia hit is a Gallo-Roman God, but the website is focused on Asia? | |
? | shadesofnews.com | 2011 | Arabic | JAR | news | a.rss-item, split images. Also has a second JAR at: web.archive.org/web/20131229092754/http://shadesofnews.com/sptgms213.jar | |
? | sportsnewsfinder.com | 2011 | Chinese | China | JAR | news | 体育新闻发现者 (sports news finder) |
? | technologypresstoday.com/ | 2011 | Farsi | JAR | news | split images, RSS | |
? | techwatchtoday.com | 2011 | English | JAR | tech, news | Marked copyright 2008. Split images[ref][ref]. Later legit. | |
? | terrain-news.com | 2011 | Pashto | Afghanistan | JAR | news | |
? | theworldnewsfeeds.com | 2011 | English | JAR | news | rss-items . Split images[ref][ref] | |
? | todayoutdoors.com | 2011 | English | JAR | sports, travel | split images[ref][ref] | |
? | todaysnewsreports.net | 2010 | Arabic | JAR | news | ||
? | weblognewsinfo.com | 2011 | English | JAR | news | Split images, rss-items . | |
? | wiredworldnews.com | 2011 | English | JAR | tech | split images, copyright 2008 | |
? | worldofonlinenews.com | 2011 | English | JAR | news | split images[ref][ref]. Later legit. | |
62.22.60.46 | flyingtimeline.com | 2011 | English | JAR | airplanes | ||
62.22.60.48 | currentcommunique.com | 2011 | English | Egypt | SWF | news | |
62.22.60.49 | telecom-headlines.com | 2011 | English | JS | tech | ||
62.22.60.52 | collectedmedias.com | 2011 | French | JS | news | Marked copyright 2008 | |
62.22.60.55 | thefilmcentre.com | 2011 | English | JS | films | ||
62.22.60.56 | traveltimenews.com | 2011 | English | JS | news | ||
62.22.61.193 | awfaoi.org | 2010 | Arabic | Iraq | JAR | not-for-profit | This was the first clear .org hit with comms we've been able to find. Title translation: "Arab women to help Iraq", so perhaps "awfaoi" stands for "Arab Women For A O? Iraq". This fits well into the .org theme. Marked copyright 2008. |
62.22.61.197 | rc5sports.com | 2011 | English | JAR | sports | ||
62.22.61.198 | inside-vc.com | 2011 | English | CGI | finance | "vc" is a standard abbreviation for venture capital | |
62.22.61.200 | zerosandonesnews.com | 2011 | English | SWF | news | rss, split images | |
62.22.61.202 | bailsnboots.com | 2011 | English | SWF | sports, cricket | "Bail" is one part of the thing your're supposed to hit with th eball in cricket.[ref] | |
62.22.61.203 | the-cricketer-online.com | 2011 | English | JAR | sports, cricket | marked copyright 2009. | |
62.22.61.204 | hollywoodscreen.net | 2011 | English | JS | films | ||
62.22.61.206 | worldnewsnetworking.com | 2011 | Arabic | JAR | news | ||
62.22.61.212 | nuestrasfinanzas.com | 2011 | Spanish | JAR | finance | ||
62.22.61.213 | sandstormnews.com | 2011 | Arabic | SWF | news | rss, split images | |
62.22.61.217 | court-masters.com | 2011 | English | JAR | sports, tennis | ||
62.22.61.219 | allworldstatistics.com | 2011 | English | JS | statistics | ||
62.22.61.220 | newsjaka.com | 2011 | English | Indonesia | JS | news | "jaka" presumably means Jakarta, the capital of Indonesia. There is a Indonesia section on the left sidebar. But the news are quite global however. Photo source: www.shutterstock.com/image-photo/little-boat-on-bratan-lake-front-5860873 depicts "Bratan lake in front of the Pura Ulu Danau temple" by Ine Beerten. Pinged her at: portfolio.inebeerten.be/#Contact |
63.131.229.2 | fightskillsresource.com | 2011 | English | JS | sports, martial arts | Getty Images for the karate dude: www.istockphoto.com/photo/take-off-gm98702037-1196239 | |
63.131.229.4 | unitedterritorynews.com | 2011 | English | JS | news | ||
63.131.229.9 | show-dustry.com | 2011 | English | CGI | entertainment | The website name is a neologism with "show" and "industry". | |
63.131.229.11 | mythriftytrip.com | 2011 | English | CGI | travel | thrifty means: "using money and other resources carefully and not wastefully" | |
63.131.229.12 | cyberreportagenews.com | 2011 | English | JAR | news | rdns source | |
63.131.229.13 | sunrise-news.com | 2011 | English | JAR | news | rdns source | |
63.131.229.15 | cricketnewsforindia.com | 2013 | English | India | JS | sports, cricket | archive quite broken, lots of missing files, including the JS |
63.131.229.16 | nutricion-saludable.net | 2010 | Spanish | CGI | health | ||
63.131.229.20 | fixashion.net | 2011 | English | JS | fashion | ||
63.130.160.50 | theglobalheadlines.com | 2010 | English | JAR | news | this has several archives from 2013, marked as Live Web Proxy Crawls and explained "mostly by the Save Page Now", so presumably by counter intelligence or amateurs | |
63.130.160.51 | hai-pow.com | 2011 | English | JAR | sports, martial arts | ||
63.130.160.53 | echessnews.com | 2011 | Chinese | China | JAR | sports, boxing | Chinese title: 我的象棋世界 (My Chinese Chess world). rdns source. Split images[ref][ref] |
63.130.160.60 | boxingstop.net | 2010 | Polish | Poland | JAR | sports, boxing | |
63.130.160.62 | azerinews.org | 2009 | Azerbaijani | Azerbaijan | JAR | news | rdns source. Split images, rss-items . |
64.16.204.55 | holein1news.com | 2010 | English | JAR | sports, golf | ||
64.16.204.58 | tech-topix.com | 2013 | English | CGI | tech | Archive quite broken, but link to CGI comms. | |
65.61.127.163 | capture-nature.com | 2011 | English | JAR | photography | Reuters example. Since became legitimate, Ciro contacted the owner, and he was unaware of the domain's history. | |
65.61.127.166 | globalnewsbulletin.com | 2013 | English | Tunisia, Afghanistan, Iran, Egypt | CGI | news | PHP pages, images /images/index_01.jpg |
65.61.127.169 | crossovernews.net | 2011 | English | JAR | sports, basketball | ||
65.61.127.174 | dedrickonline.com | 2010 | German | JS | sports | ||
65.61.127.175 | altworldnews.com | 2013 | English | CGI | news | Epoch times link, PHP pages | |
65.61.127.178 | tee-shot.net | 2011 | English | SWF | sports, golf | nice domain name | |
65.61.127.182 | pangawana.com | 2011 | Arabic | Afghanistan | JS | news | |
65.61.127.183 | cutabovenews.com | 2011 | English | Algeria, various others | JS | sports, basketball | The globe on Shutterstock: www.shutterstock.com/image-illustration/creative-drawing-charts-graphs-business-success-211092952 by rzoze19. Pinged him at: x.com/cirosantilli/status/1899748328549609700 |
65.61.127.184 | worldwildlifeadventure.com | 2011 | English | JAR | travel | ||
65.61.127.186 | explorealtmeds.com | 2013 | English | JAR | health | the JAR was not archived, but there's a link to it | |
65.218.91.9 | welcometonyc.net | 2010 | English | CGI | travel | ||
65.218.91.17 | alljohnny.com | 2004 | English | CGI | fansite | mega early hit from 2004 to 2005. Then a gap, then they redid the domain: 2011. Same authors given content similarities e.g. "Submit Your Favorite Carson Moment". Reusing the domain after all these years, the lack of OPSEC is just mind blowing! New website marked Copyright 2003. Part of Oleg Shakirov's findings. One of the Reuters websites. Search documented at: Searching for Carson. Carson is also featured, although less proeminently, at webofcheer.com . There must have been some massive Johnny Carson fan among the contractors a that time! | |
66.45.179.192 | thegraceofislam.com | 2011 | English | CGI | religion, Islam | ||
66.45.179.193 | arabicnewsunfiltered.com | 2011 | Arabic | JAR | news | rdns source | |
66.45.179.194 | raulsonsglobalnews.com | 2011 | English | JAR | news | ||
66.45.179.195 | aryannews.net | 2010 | Pashto | Afghanistan | JAR | news | rdns source. Heil. |
66.45.179.199 | attivitaestremi.com | 2011 | Italian | CGI | sports | ||
66.45.179.201 | hitthepavementnow.com | 2011 | English | CGI | sports, running | ||
66.45.179.202 | newimages.org | 2011 | Turkish | Turkey | JAR | photography | JAR unarchived |
66.45.179.203 | noticiascontinental.com | 2011 | Spanish | South America | CGI | news | |
66.45.179.205 | noticiasporjanua.com | 2011 | Spanish | JAR | news | ||
66.45.179.206 | podisticamondiale.com | 2010 | Italian | Italy | JAR | sports, running | marked copyright 2010 |
66.45.179.207 | reflectordenoticias.com | 2011 | Spanish | JAR | news | ||
66.45.179.208 | havenofgamerz.com | 2011 | English | CGI | gaming | marked copyright 2009 | |
66.45.179.210 | sa-michigan.com | 2011 | English | JAR | sports | "sa" is an abbreviation for the site title "Sports Alive" | |
66.45.179.211 | absolutebearing.net | 2010 | English | CGI | travel, sports, boats | ||
66.45.179.213 | myportaltonews.com | 2011 | English | JS | news | ||
66.45.179.214 | investmentintellect.com | 2011 | English | JAR | finance | ||
66.45.179.215 | nigeriastar.net | 2011 | English | Nigeria | JAR | news | Contains link to unarchived JAR |
66.104.169.163 | doctorsoncallsite.com | 2011 | English | JAR | health | ||
66.104.169.164 | lightandshadowonline.com | 2010 | English | JAR | photography | ||
66.104.169.168 | plugged-into-news.net | 2010 | English | JAR | news | JAR uses .zip extension! First instance, wow | |
66.104.169.171 | golf-on-holiday.com | 2011 | English | JAR | sports, golf | ||
66.104.169.172 | perspectiva-noticias.com | 2011 | Spanish | JS | news | ||
66.104.169.175 | aquaswimming.com | 2009 | English | JAR | sports, swimming | ||
66.104.169.177 | dojo-temple.com | 2011 | English | CGI | sports, martial arts | TODO meaning of "kama"? Kama lol? | |
66.104.169.179 | neighbour-news.com | 2010 | English | Germany | JAR | news | Mentions of Goethe-Institut and Germany all over. JAR unarchived |
66.104.169.180 | medicatechinfo.com | 2010 | English | JS | health | ||
66.104.169.181 | brickmanfinancialnews.com | 2011 | English | JS | finance | ||
66.104.169.182 | casanewsnow.com | 2011 | English | JAR | JAR unarchived. TODO why "casa"? Doesn't seem to have any link to Spanish or Portuguese. | ||
66.104.169.184 | bcenews.com | 2011 | Albanian | Albania | JAR | news | |
66.104.173.163 | runakonews.com | 2011 | English | Africa | CGI | news | "Runako" is an African given name. |
66.104.173.164 | shoppingadventure.net | 2010 | English | JAR | travel, shopping | JAR unarchived | |
66.104.173.165 | entertaining-ly.com | 2011 | English | JAR | entertainment | ||
66.104.173.166 | zubeenews.com | 2011 | English | JS | news | "Zubee" is a Muslim name: muslimnames.com/zubee. | |
66.104.173.169 | smart-financeology.com | 2011 | English | JAR | finance | ||
66.104.173.175 | media-coverage-now.com | 2010 | English | SWF | news | ||
66.104.173.176 | jbc-online-news.com | 2011 | English | JS | news | TODO meaning of "JCB". JS unarchived. | |
66.104.173.177 | webscooper.com | 2011 | English | JAR | news | ||
66.104.173.178 | dk-dcinvestment.com | 2010 | English | JAR | finance | TODO meaning of "dk;dc". | |
66.104.173.180 | stara-turistick.com | 2011 | Croatian | JAR | tourism | ||
66.104.173.181 | playbackpolitics.com | 2011 | English | JS | news | ||
66.104.173.182 | snapnewsfront.net | 2011 | English | Japan | JS | news | |
66.104.173.183 | ingenuitytrendz.com | 2011 | English | JAR | tech | ||
66.104.173.184 | armashoy.com | 2011 | Spanish | Spain | SWF | guns | meaning: "Weapons Today". In First World countries the CIA felt it would be safe to touch edgier subjects like guns |
66.104.173.185 | baocontact.com | English | JAR | HTML archive almost empty, but JAR was archived. One wonders what "bao" refers to, could be Chinese, but the small snippet of visible website is in English. | |||
66.104.173.186 | myworldlymusic.com | 2011 | English | Pakistan | JAR | music | JAR unarchived |
66.104.173.189 | hitpoint-gaming.com | 2011 | English | JS | gaming | Marked copyright 2010 | |
66.104.175.34 | itwebtoday.com | 2011 | English | JS | tech | ||
66.104.175.35 | drglobalnews.com | 2011 | English | JAR | news | TODO meaning of "dr"? rdns source. | |
66.104.175.36 | adilnews.net | 2010 | Arabic | SWF | news | Adil is an Arabic masculine name | |
66.104.175.40 | beyondnetworknews.com | 2011 | English | Egypt | CGI | news | |
66.104.175.41 | grubbersworldrugbynews.com | 2011 | English | JS | sports, rugby | ||
66.104.175.42 | news-and-sports.com | 2011 | English | JAR | news | rss, split images | |
66.104.175.44 | yourtripfinder.net | 2010 | English | travel | comms not found, CGI from unarchived subpage assumed | ||
66.104.175.45 | rollinsnetwork.com | 2011 | English | CGI | tech | CGI linked to but not archived | |
66.104.175.46 | infosharenews.com | 2011 | English | JAR | news | ||
66.104.175.47 | southasiaheadlines.com | 2011 | English | Bangladesh, Bhutan, India, Maldives, Nepal, Pakistan, Sri Lanka Tibet | JAR | travel | JAR linked to but missing from archive |
66.104.175.48 | worlddispatch.net | 2010 | Arabic | SWF | news | ||
66.104.175.49 | webworldsports.com | 2011 | Arabic | JAR | sports | ||
66.104.175.50 | fly-bybirdies.com | 2011 | English | JAR | travel | ||
66.104.175.51 | businessexchangetoday.com | 2011 | English | CGI | news, finance | PHP pages | |
66.104.175.52 | mensajeradenoticias.com | 2011 | Spanish | CGI | news | CGI unarchived | |
66.104.175.53 | info-ology.net | 2010 | English | JAR | news | ||
66.104.175.54 | marketflows.net | 2011 | English | JAR | finance | ||
66.104.175.57 | metanewsdaily.com | 2010 | English | CGI | news | ||
66.175.106.134 | paddlescoop.com | 2011 | English | Bangladesh, Pakistan, India, England | JAR | sports, cricket | |
66.175.106.137 | kessingerssportsnews.com | 2010 | English | JS | sports | ||
66.175.106.138 | factorforcenews.com | 2009 | English | JAR | news | ||
66.175.106.142 | kanata-news.com | 2010 | English | Canada | JS | news | "Kanata" is a place in Ottawa, Canada. The name is likely of Indigenous origin. |
66.175.106.143 | thecricketfan.com | 2011 | English | JAR | news | ||
66.175.106.146 | inews-today.com | 2011 | English | Egypt | JAR | news | Marked copyright 2008 |
66.175.106.147 | starwarsweb.net | 2010 | English | SWF | fansite | well, not even the CIA can escape Star Wars. TODO identify boy. | |
66.175.106.148 | activegaminginfo.com | 2011 | Chinese | JAR | gaming | the website is entitled "活跃游戏" which means "Lively games", or "active games" as in the domain name itself. The center character seems to be from one of the infinitely many Romance of the Three Kingdoms games that must exist: www.gamersky.com/news/200711/82611.shtml | |
66.175.106.149 | feedsdemexicoyelmundo.com | 2011 | Spanish | Mexico | JS | news | |
66.175.106.150 | noticiasmusica.net | 2010 | Brazilian Portuguese | Brazil | JAR | music | |
66.175.106.155 | atomworldnews.com | 2011 | English | Egypt | JAR | news | |
66.175.106.158 | nouvellesetdesrapports.com | 2011 | French | Egypt, Tunisia | JAR | news | |
66.237.236.227 | newsandmusicminute.com | 2011 | Pashto | JS | music | ||
66.237.236.229 | pearls-playlist.com | 2011 | English | SWF | music | ||
66.237.236.230 | beyondthefringe.info | 2012 | English | JAR | rugs | JAR unarchived | |
66.237.236.231 | primetimemovies.net | 2009 | English | JS | films | JS unarchived | |
66.237.236.235 | persephneintl.com | 2013 | JAR | archive very broken, JAR unarchived. Full title: "Persephne International", reference to Greek Goddess of "spring, the dead, the underworld, grain, and nature" | |||
66.237.236.236 | directoalgrano.net | 2010 | Spanish | JAR | news | ||
66.237.236.240 | actualizaciondebeisbol.com | 2011 | Spanish | JS | sports, baseball | ||
66.237.236.243 | mygadgettech.com | 2009 | Chinese | CGI | tech | Archive very broken | |
66.237.236.247 | comunidaddenoticias.com | 2011 | Spanish | Ecuador | JAR | news | |
66.237.236.249 | sumerjaseahora.com | 2011 | Spanish | CGI | sports, SCUBA diving | submerge yourself now | |
69.84.156.69 | al-ashak-news-me.com | 2011 | Arabic | JS | news | ||
69.84.156.71 | worldfinancetoday.net | 2011 | English | JAR | finance | ||
69.84.156.72 | autonewsarabia.com | 2011 | Arabic | JAR | cars | ||
69.84.156.74 | blue-moon-news.com | 2011 | Arabic | JS | news | ||
69.84.156.76 | tnc-urdu.com | 2011 | Urdu | JAR | tech | TODO meaning of "tnc"? | |
69.84.156.82 | arabicnewsonline.com | 2011 | Arabic | JAR | news | rdns source. Some very similar domains: modernarabicnews.com, arabicnewsource.com. Needed more creativity here! Later legit. | |
69.84.156.83 | unganadormundial.com | 2010 | Spanish | CGI | sports, fitness | ||
69.84.156.88 | diariodeelmundo.com | 2011 | Spanish | JAR | news | ||
69.84.156.89 | todaysarabnews.com | 2011 | Arabic | JAR | news | JAR unarchived. | |
69.84.156.90 | stickshiftnews.com | 2011 | English | JAR | cars | ||
69.84.156.91 | theinternationalgoal.com | 2011 | Spanish | CGI | news | ||
72.34.53.174 | electronictechreviews.com | 2011 | English | JAR | tech | JAR unarchived. Split images, rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | just-the-news.com | 2011 | Arabic | JAR | news | copyright 2009. Present at "Mass Deface III" pastebin. JAR unarchived. | |
72.34.53.174 | kickitnews.com | 2010 | Arabic | JAR | sports, football | copyright 2009. Present at "Mass Deface III" pastebin. | |
72.34.53.174 | moyistochnikonlaynovykhigr.com | 2011 | Russian | Russia | fansite | copy of myonlinegamesource.com, but on a Russian transliterated domain rather than the English one, very interesting | |
72.34.53.174 | myhealthlibrary.net | 2011 | English | JAR | health | present at: "Mass Deface III" pastebin. | |
72.34.53.174 | myonlinegamesource.com | 2011 | Russian | Russia | gaming | Can't find comms, but stylistically perfect. rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | mytravelopian.com | 2011 | English | JAR | travel | ||
72.34.53.174 | recursosdenoticias.com | 2011 | Spanish | JAR | news | Split images, rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | sayaara-auto.com | 2010 | Arabic | JAR | cars | ||
72.34.53.174 | technologytodayandtomorrow.com | 2011 | English | JAR | tech | rss-items . Present at "Mass Deface III" pastebin. | |
72.34.53.174 | todaysnewsandweather-ru.com | 2011 | Russian | Russia | JS | news | JavaScript with SHAs |
74.116.72.227 | dayenews.com | 2011 | English | JAR | news | rdns source. Previously 69.74.45.67. | |
74.116.72.229 | guide-daventure.com | 2011 | French | France | JAR | travel | |
74.116.72.231 | bleachersfootballnews.com | 2011 | English | JAR | sports, football | TODO meaning of "Bleacher"? Possible reference to Bleacher Report. | |
74.116.72.232 | indirectfreekick.com | 2011 | English | JAR | sports, football | ||
74.116.72.233 | wwiichronicles.net | 2011 | English | CGI | history | ||
74.116.72.234 | petroleumagenews.com | 2011 | English | JAR | oil | ||
74.116.72.235 | the-open-book-online.com | 2011 | English | JS | literature | ||
74.116.72.236 | techtopnews.com | 2011 | English | JAR | tech | ||
74.116.72.239 | crickettoday.info | 2013 | Pashto | JS | sports, cricket | JS unarchived. The requested URL /cricket.js was not found on this server | |
74.116.72.240 | zafernews.com | 2011 | Arabic | JAR | news | ||
74.116.72.242 | gdgtsource.com | 2011 | English | CGI | tech | Presumably "gdgt" stands for "GaDGeT", which is mentioned on subtitle | |
74.116.72.246 | vuvuzelanews.com | 2011 | English | JAR | sports, football | Vuvuzela is this plastic horn, popular in football stadiums. The term is of African origin. Later legit. rdns source. Previously at 69.74.45.86. | |
74.116.72.247 | ballbatstumpsandbails.com | 2011 | English | JAR | sports, cricket | ||
74.116.72.249 | round-trip-travel.com | 2010 | English | CGI | travel | this got archived a lot of times, though all seem to be Alexa crawls. | |
74.116.72.250 | arabicnewsource.com | 2011 | Arabic | CGI | news | ||
74.254.12.163 | half-court.net | 2010 | English | Philippines | JAR | sports, basketball | |
74.254.12.164 | dailywellnessnews.com | 2011 | English | JAR | health | rdns source. split images[ref][ref]. | |
74.254.12.165 | dylandon.net | 2011 | Chinese | SWF | music | "Dylan" presumably a reference to Bob Dylan? "Don" unclear. Maybe Don McLean? | |
74.254.12.166 | afghanpoetry.net | 2010 | English | Afghanistan | SWF | poetry | Also at 63.131.229.10[ref] in a range. |
74.254.12.168 | non-stop-news.net | 2010 | Farsi | JAR | news | ||
74.254.12.169 | soldiersofsouthasia.com | 2011 | English | JAR | history | ||
74.254.12.171 | autism-news.org | 2011 | English | SWF | health | copyright 2007. Split images. rss-items . Previously at 69.74.45.67. | |
74.254.12.173 | thefreshnews.com | 2009 | English | SWF | news | rss, split images | |
74.254.12.176 | pakcricketgrd.com | 2011 | Urdu | JAR | sports, cricket | TODO meaning of "grd" | |
74.254.12.177 | networkofnews.com | 2011 | English | JAR | news | rdns source. Later legit. | |
74.254.12.179 | wineconnaisseur.net | 2010 | English | JS | wine | ||
74.254.12.180 | helpinghandssite.com | 2011 | English | JAR | news | ||
74.254.12.188 | first-tee-golf.com | 2011 | English | JAR | sports, golf | ||
74.254.12.189 | fabu-foto.com | 2011 | English | CGI | photography | ||
74.254.12.190 | viptravelabroad.com | 2011 | English | JS | travel | ||
174.133.70.18 | dryterrainnews.com | 2011 | English | Africa | JAR | news | rss |
174.133.70.18 | thefootball-life.com | 2011 | English | JS | sports, football | rss, split images | |
174.133.70.18 | thenewsofpakistan.com | 2009 | English | Pakistan | JAR | news | a.rss-item, split images |
174.133.70.18 | totallynewsnow.com | 2011 | English | JS | news | rss | |
199.85.212.105 | mide-news.com | 2010 | English | CGI | news | "MIDE" stands for "Middle East". Comms not archived, presumably CGI comms variant. | |
199.85.212.111 | newsandsportscentral.com | 2009 | English | JAR | news | rdns source | |
199.85.212.118 | just-kidding-news.com | 2011 | English | JAR | news | epic name | |
199.187.208.12 | webofcheer.com | 2011 | English | JAR | fansite, comedy | has a an unarchived "members only!" section pointing to webofcheer.com/member.html, CGI comms variant. Copyright 2005! Features Johnny Carson, Charles Chaplin, Rowan Atkins, The Three Stooges and some other Americans no one knows about anymore. There must have been a massive Johnny Carson amongst the CIA contractors at that time given alljohnny.com ! The HTML page is weirdly titled pg1c . Interesting, feels like a leak of the site generation system. | |
199.187.208.12 | world-news-online.net | 2010 | English | JAR | news | a.rss-item, split images | |
204.176.38.130 | i-pressnews.com | 2011 | English | JAR | news | ||
204.176.38.132 | turkishnewslinks.com | 2011 | English | Turkey | JAR | news | |
204.176.38.133 | globalcitizennews.net | 2010 | English | JAR | news | rss, split images | |
204.176.38.134 | photographyarecord.com | 2011 | English | CGI | photography | Cute | |
204.176.38.135 | breakingthewicket.com | 2011 | English | CGI | sports, cricket | ||
204.176.38.136 | politicalworldtoday.com | 2011 | English | Egypt | JAR | news | |
204.176.38.137 | hi-tech-today.com | 2011 | English | JAR | tech | ||
204.176.38.139 | bigscreenbattles.com | 2011 | English | JAR | films | ||
204.176.38.141 | rakotafootball.com | 2011 | English | JAR | sports, football | "Rakota" is an Indian family name | |
204.176.38.143 | noticiassofisticadas.com | 2011 | Spanish | CGI | news | ||
204.176.38.142 | senderosdemontana.com | 2011 | Spanish | JS | sports, cycling | Talks about mountain biking and Eurobike 2010, so likely Spain focused, but it is not direct enough to be certain. JS unarchived. | |
204.176.38.144 | techno-today.com | 2011 | English | JAR | tech | was legit previously. | |
204.176.38.145 | tickettonews.com | 2011 | English | JAR | news | rdns source. Epoch times link. | |
204.176.38.146 | dps-digitalphotosharing.com | 2011 | English | JAR | photography | ||
204.176.38.147 | theputtingreen.com | 2011 | English | JAR | sports, golf | ||
204.176.38.149 | sportsnewstodayar.com | 2011 | Arabic | Lebanon, others | JAR | sports | "ar" on domain name presumably means "Arabic" |
204.176.38.159 | kairuafricanews.com | 2011 | English | Africa | JAR | news | what is "Kairu"? en.wikipedia.org/wiki/Kairu a place in India? en.wiktionary.org/wiki/kairu "frog" in Japanese? rdns source |
204.176.39.97 | beamingnews.com | 2011 | Arabic | JAR | news | Nice design. rdns source | |
204.176.39.98 | cubriendonoticias.com | 2011 | Spanish | JAR | news | archive quite broken. JAR unarchived. | |
204.176.39.100 | rowleyworldpost.com | 2011 | English | Egypt, others | JAR | news | |
204.176.39.103 | economicnewsbuzz.com | 2011 | Korean | CGI | finance | Love the kawaii style | |
204.176.39.104 | spectranewsonline.com | 2011 | English | CGI | news | marked copyright 2010. | |
204.176.39.105 | entertainmentnewscompany.com | 2011 | Chinese | SWF | films, music | Title: "娱乐新闻公司", lit. Entertainment News Company | |
204.176.39.110 | arabnewsatdawn.com | 2011 | Arabic | CGI | news | cute, the Arab chick's ice cream actually has a cocktail umbrella on it. Marked copyright 2010. Here she is: www.shutterstock.com/image-photo/young-veiled-woman-reading-newspaper-eating-4836766 by Anneka. Pinged her privately on www.facebook.com/Anyka.Fotografie. | |
204.176.39.115 | globalprovincesnews.com | 2010 | Arabic | JS | news | ||
204.176.39.116 | mahparah-news.com | 2011 | Farsi | JS | news | ||
204.176.39.119 | commercialspacedesign.com | 2013 | Farsi | CGI | architecture | C O N C E P T U A L design. A rare example of a fake company website. | |
207.210.250.131 | starrynightnews.com | 2011 | Arabic | JS | news | interesting design | |
207.210.250.132 | aeronet-news.com | 2011 | English | JAR | airplanes | ||
207.210.250.133 | bakaribulletin.com | 2011 | English | Africa | JS | news | Bakari could either be a given name, or a village in Togo |
207.210.250.134 | deprensaenlarevisiondehoy.com | 2011 | Spanish | JAR | news | ||
207.210.250.135 | icwb-news.com | 2011 | English | JAR | news | ICWB stands for "Inner Circle Worldwide Business (News)", the title of the website | |
207.210.250.136 | sportsreelhighlights.com | 2011 | English | JAR | sports | ||
207.210.250.138 | inquiry-human-past.com | 2011 | English | JAR | history | ||
207.210.250.139 | thefairwaysaregreen.com | 2011 | Thai | JAR | sports, golf | ||
207.210.250.143 | archaeologyreview.net | 2010 | English | JAR | history, archeology | ||
207.210.250.146 | noticias-caracas.com | 2011 | Spanish | Venezuela | CGI | news | Caracas is the capital of Venezuela. But you knew that, right? |
207.210.250.147 | bailandstump.com | 2011 | English | JS | sports, cricket | "Bail" and "Stump" are the two parts of the thing your're supposed to hit with the ball in cricket.[ref] | |
207.210.250.149 | globalventurestat.com | 2008 | English | SWF | news | ||
207.210.250.152 | al-rashidrealestate.com | 2010 | Arabic | Egypt | CGI | finance, real-estate | |
207.210.250.153 | newsintheworld-ru.com | 2011 | Russian | JAR | news | ||
208.93.112.105 | fastnews-online.com | 2009 | English | JAR | news | a.newslink | |
208.93.112.106 | travelxtreme.net | 2008 | English | JAR | travel | split images | |
208.93.112.108 | nbanewsroundup.com | 2013 | English | CGI | sports, basketball | quite broken with only HTML archived in 2013, but we're counting it due to coms link and IP range. | |
208.254.38.39 | todaysengineering.com | 2011 | English | CGI | engineering | ||
208.254.38.56 | nejadnews.com | 2011 | Arabic | JAR | news | rss, JAR unarchived | |
208.254.40.96 | sixty2media.com | 2011 | English | Various | JAR | news | Epoch times link |
208.254.40.99 | newspoliticssource.com | 2013 | Arabic | JAR | news | One of the news mentions Snowden | |
208.254.40.110 | musical-fortune.net | 2010 | English | CGI | music | images /images/banner-02.jpg | |
208.254.40.113 | ashoka-gemstones.com | 2010 | English | JAR | jewelry | ||
208.254.40.117 | worldnewsandent.com | 2010 | Arabic | Egypt | CGI | mews | |
208.254.40.124 | riskandrewardnews.com | 2013 | English | CGI | finance | ||
208.254.42.194 | it-proonline.com | 2011 | English | CGI | tech | images /images/header_01.jpg | |
208.254.42.205 | driversinternationalgolf.com | 2011 | English | CGI | sports, golf | ||
208.254.42.209 | mardelsurnoticias.com | 2011 | Spanish | JAR | news | weird mixture of Portuguese and Spanish language external links | |
208.254.42.215 | nowfreshfinances.com | 2011 | English | CGI | finance | CGI unarchived | |
208.254.42.216 | circulatingnews.net | 2010 | English | JAR | travel | ||
208.254.42.219 | westingtonpassnews.com | 2011 | English | JAR | news | ||
209.51.136.178 | cellar-notes.com | 2011 | English | JAR | wine | rss, split images, JAR unarchived | |
209.51.136.178 | the-news-scene.com | 2011 | English | JAR | news | split images, RSS | |
210.80.75.36 | e-commodities.net | 2011 | English | JAR | finance | ||
210.80.75.37 | trekkingtoday.com | 2011 | English | JAR | sports, running | split images[ref][ref]. rdns source. | |
210.80.75.41 | multinews-33.com | JAR | news | No archives of the HTML, but the JAR was archived | |||
210.80.75.43 | gulfandmiddleeastnews.com | 2011 | Arabic | JS | news | ||
210.80.75.44 | whirlybirdinflight.com | 2011 | English | JAR | helicopters | ||
210.80.75.45 | kings-game.net | 2011 | English | JAR | gaming, chess | JAR unarchived | |
210.80.75.46 | topglobalnewsdaily.com | 2011 | English | JS | news | ||
210.80.75.49 | recipe-dujour.com | 2011 | English | JAR | cooking | nice design | |
210.80.75.55 | philippinenewsonline.net | 2010 | Philippines | JAR | news | ||
210.80.75.56 | technewsforme.com | 2011 | Farsi | JAR | tech | ||
212.4.16.224 | lanoticiasdehoyelinforme.com | 2010 | Spanish | JAR | news | ||
212.4.16.232 | mynewscheck.com | 2011 | English | Canada | JAR | news | rdns source |
212.4.16.245 | financial-crisis-news.com | 2011 | Russian | Russia | JAR | news | rdns source |
212.4.16.252 | minutosdenoticias.com | 2010 | Spanish | CGI | news | CSS | |
212.4.17.38 | fightwithoutrules.com | 2011 | Russian | JAR | sports, combat sports | The photo on top middle can be seen e.g. at spfightingtalk.wordpress.com/2013/01/18/breaking-down-mixed-martial-arts-what-is-mma/. The fither on top is Mac Danzig, TODO find bottom one lazy now. | |
212.4.17.41 | newtechfrontier.com | 2010 | English | CGI | tech | since became legit: newtechfrontier.com/ | |
212.4.17.43 | smart-travel-consultant.com | 2011 | Chinese | CGI | travel | ajaxtax.js may be of interest for fingerprinting. Title: "智能旅行顾问", lit. Smart Travel Consultant | |
212.4.17.46 | atentlaloc.com | 2009 | English | Quatar, Lebanon, Israel, Iran | JS | jewelry | Tlaloc is an Aztec deity, and Aten is an Egyptian deity. Both appear to be somewhat linked to gold, thus their usage in a jewelry website. Creative domain name. |
212.4.17.53 | newsresolution.net | 2010 | English | Côte d'Ivoire, Lebanon, Sudan | JAR | news, UN Peacekeeping | |
212.4.17.56 | lesummumdelafinance.com | 2010 | French | France | JAR | finance | |
212.4.17.98 | topbillingsite.com | 2011 | English | CGI | films | ||
212.4.17.122 | b2bworldglobal.com | 2011 | English | CGI | news | ||
212.4.17.125 | worldaroundyunnan.com | 2011 | Chinese | JAR | news | rss, split images, JAR | |
212.4.17.160 | localtoglobalnews.com | 2010 | English | JAR | news | rss, split images | |
212.4.18.14 | football-enthusiast.com | 2011 | English | Europe | JS | sports, football | |
212.4.18.129 | sightseeingnews.com | 2010 | English | JAR | travel | ||
212.209.74.105 | globalbaseballnews.com | 2011 | English | JS | sports, baseball | ||
212.209.74.106 | football-de-luxe.com | 2010 | French | France | JAR | sports, football | |
212.209.74.112 | developmental-league.com | 2010 | English | CGI | sports, American football | CGI comms variant? | |
212.209.74.115 | mediocampodefutbol.com | 2010 | Spanish | JAR | sports, football | ||
212.209.74.117 | myengineeringaffinity.com | 2011 | English | JAR | tech | ||
212.209.74.123 | worldfinancialexchangenews.com | 2010 | English | SWF | finance | SWF unarchived. | |
212.209.74.125 | avoilurefixe.com | 2011 | French | Tunisia | JAR | airplanes | "à voilure fixe" is French for "with fixed wing", i.e. fixed wing aircraft |
212.209.74.126 | headlines2day.com | 2011 | Farsi | JAR | news | marked copyright 2009 | |
212.209.79.34 | fgnl.net | 2011 | English | Iran | CGI | news | four letter domain! FGNL stands for "Farsi Global News Links" Marked copyright 2009. |
212.209.79.37 | fitness-sources.com | 2010 | English | JS | sports, fitness | ||
212.209.79.40 | hydradraco.com | 2011 | English | JAR | sports, American football | TODO meaning of the name? | |
212.209.79.41 | noticiasdelmundolatino.com | 2011 | Spanish | JAR | news | ||
212.209.79.42 | suparakuvi.com | 2011 | French | France | JAR | news | a Tour Eiffel image, and young people stuff, i.e. first world stuff. It's for France alright. But TODO meaning of domain name? Ciro's second language French didn't cut it this time. |
212.209.79.46 | cetusdelph.com | 2011 | English | JS | sports, scuba | ||
212.209.79.47 | willtoworship.com | 2011 | English | JAR | religion, Christianity | marked copyright 2007 (!) | |
212.209.79.48 | themvconnection.com | 2011 | English | JAR | music | ||
212.209.79.51 | pi-resources.net | 2010 | English | JS | private investigators | "pi" stands for Private Investigators. The CIA must have had some fun making this one. | |
212.209.79.53 | ourscubaworld.com | 2011 | English | JS | sports, scuba | ||
212.209.79.58 | tech-love-home.com | 2011 | Chinese | JS | tech | Title: "消费类电子产品", lit. Consummer Electronics | |
212.209.79.60 | first-solo-aviation.com | 2010 | English | JAR | airplanes | ||
212.209.79.61 | china-destinations.org | 2011 | Chinese | JS | travel | title: "中国目的地指南", lit. "China Destination Guide" | |
212.209.90.69 | worldedgenews.com | 2011 | English | JAR | news | ||
212.209.90.74 | globalinvestmentnews.net | 2010 | English | JAR | news | rss, split images | |
212.209.90.80 | nsmovies.net | 2010 | English | JAR | films | "ns" stands for "Nirguna Saguna", two separate Hindu names/deities. But there are no other Indian references beyond those. | |
212.209.90.82 | middleeastjournal.net | 2010 | Arabic | JS | news | ||
212.209.90.84 | thenewseditor.com | 2011 | English | JAR | news | ||
212.209.90.87 | newsandweathersource.com | 2009 | English | JAR | news | marked copyright 2009. | |
212.209.90.89 | pakisports.com | 2010 | English | Pakistan | SWF | sports | |
212.209.90.90 | vriha-aesthetics.com | 2011 | Arabic | JS | news | ||
212.209.90.92 | amishkanews.com | 2011 | English | India | JS | news | Amishka is an Indian name, plus some prominent mentions of Bollywood both point to India specifically |
212.209.90.93 | theentertainbiz.com | 2011 | English | JAR | entertainment | ||
212.209.90.94 | eurosportssummary.com | 2011 | English | JAR | sports | ||
216.93.248.194 | esmundonoticias.com | 2011 | Spanish | JAR | news | rss-items . Shares IP with kukrinews.com. | |
216.93.248.194 | kukrinews.com | 2010 | English | JS | News | JavaScript with SHAs. Talks to /cgi-bin/news.cgi . A Kukri is the national weapon of Nepal. Slogan: "Nepal's Sharp Edge", thus matching the website name. Split image header. Copyright 2009. Shares IP with esmundonoticias.com. | |
216.93.248.194 | lasthournews.com | 2010 | Urdu | jAR | news | split images | |
216.105.98.139 | cultura-digital.net | 2008 | Spanish | CGI | news | Marked copyright 2008. Previously legit. | |
216.105.98.140 | uaeshoppingspree.com | 2013 | English | UAE | JAR | shopping | Archive quite broken, but has link to unarchived JAR. Has an unusually personal touch "As you can probably tell from the title of my website, shopping is my very favorite pastime." |
216.105.98.145 | montanismoaventura.com | 2012 | Spanish | Spain | JS | sports, mountaineering | JS unarchived. Marked copyright 2010. |
216.105.98.147 | nepalnewsbrief.com | 2008 | English | Nepal | JAR | news | Marked copyright 2006 (!) If true this would be the earliest known reference to a date in the websites. |
216.105.98.152 | modernarabicnews.com | 2013 | Arabic | JAR | news | HTML archive quite broken, but JAR was archived thankfully. | |
216.105.98.154 | everythingcricket.org | 2011 | English | JAR | sports, cricket | Also has archives from 2009, but they were a bit broken. The 2011 one is marked copyright 2011, so they actually bothered to updated that. | |
216.105.98.156 | familyhealthonline.net | 2011 | English | CGI | health | ||
219.90.61.110 | surya-brahma.com | 2011 | Spanish | JAR | news | Surya and Brahman are Hindu concepts, but the website appears to have nothing to do with India or Hinduism. Interesting. | |
219.90.61.111 | classicalmusicboxonline.com | 2010 | English | CGI | music | ||
219.90.61.116 | athletepro.net | 2010 | English | JAR | sports | ||
219.90.61.117 | lajornadanow.com | 2010 | Spanish | JAR | news | ||
219.90.61.120 | theinternationalworld.com | 2011 | English | JAR | news | rdns source. rss-items . | |
219.90.61.121 | thepyramidnews.com | 2011 | Farsi | Iran | JAR | news | |
219.90.61.122 | iran-newslink-today.com | 2011 | Farsi | Iran | JAR | news | |
219.90.61.123 | journeystravelled.com | 2011 | English | JAR | travel | ||
219.90.62.229 | information-junky.com | 2011 | English | Ghana | JAR | news | |
219.90.62.231 | todosperuahora.com | 2011 | Spanish | Peru | CGI | news | |
219.90.62.233 | theworld-news.net | 2010 | Urdu | CGI | news | ||
219.90.62.234 | recuerdosdeviajeonline.com | 2011 | Spanish | SWF | travel | marked "Copyright 2009" | |
219.90.62.237 | elcorreodenoticias.com | 2011 | Spanish | Venezuela | JAR | news | |
219.90.62.237 | ride-captain.com | 2011 | English | JAR | sports, motorcyles | ||
219.90.62.238 | freshtechonline.com | 2011 | English | CGI | tech | ||
219.90.62.241 | newscentertoday.com | 2011 | English | JAR | news | Copyright 2008. rdns source. rss-items . Later legit, with a pause The domain name you have entered is not available. It has been taken down because the email address of the domain holder (Registrant) has not been verified.. | |
219.90.62.243 | fitness-dawg.com | 2021 | English | JAR | sports, fitness | Original Reuters article sample. Pushup dude stock: www.istockphoto.com/photo/sweating-young-man-doing-push-ups-gm115455429-645125 by Mike R. Manzano, pinged at: x.com/cirosantilli/status/1899750172260806711. Dude was an ex-Sr. Software engineer at Coinbase from 2019-2022, he likely retired with the Bitcoin boom already legend. Still making apps as of 2024 though: www.facebook.com/leftspin. Dog at: www.istockphoto.com/photo/english-bulldog-gm92095947-2629950 by GlobalP. | |
219.90.62.244 | easytraveleurope.com | 2012 | English | JAR | travel | nice design | |
219.90.62.245 | world-news-now.net | 2011 | English | JAR | news | ||
219.90.62.246 | negativeaperture.com | 2011 | English | CGI | photography | nice domain name | |
219.90.62.247 | conquermstoday.com | 2011 | English | CGI | health | MS means multiple sclerosis. Comms not found, CGI from unarchived subpage assumed. Has a subdomain "heal.conquermstoday.com" according to 2013 DNS Census, but no links to it in the archive. |
This is an update to the article: Section "CIA 2010 covert communication websites"
I found 44 new covert websites made by the CIA around 2010 bringing the total to 397!
Most websites were boring as usual, but one was slightly cooler: webofcheer.com is a comedy fansite featuring Johnny Carson, Charles Chaplin, Rowan Atkins (of Mr. Bean fame), The Three Stooges and some other Americans no one knows about anymore. There must have been a massive Johnny Carson amongst the contractors at that time, given that we previously also knew about
alljohnny.com
, a site dedicated fully to him! Both of these sites also serve as some of the earliest examples we've got so far, dating back to 2004 and 2005.2011 Wayback Machine archive of webofcheer.com
. Source. 2011 Wayback Machine archive of webofcheer.com scrolled to show Johnny Carson
. Source. 2004 Wayback Machine archive of alljohnny.com
. Source. This one was a previously known website featuring Johnny Carson.Another cool discovery is that I found the Getty Images source of the Jedi boy on their Star Wars themed site starwarsweb.net: web.archive.org/web/20101230033220/http://starwarsweb.net/ The photo can still be licensed today as of 2025: www.gettyimages.co.uk/detail/photo/little-jedi-royalty-free-image/172984439. I found it by searching for "jedi boy" on gettyimages.co.uk. The photo is credited to username
madisonwi
, presumably an alias of a photographer from Madison, Wisconsin. Inspired by this I reverse image searched and found the source of many other stock images from other websites, and I pinged their authors whenever I could locate them e.g. x.com/cirosantilli/status/1899750172260806711.Stock photo of a Jedi boy from Getty Images used on starwarsweb.net
. Source. 2010 Wayback Machine archive of starwarsweb.net
. There were two small advances that led to the discovery of new domains:
- while looking for a way to procrastinate I decided to scrape justdropped.com/drops/ for fun. That website lists expired domain names and see if it would yield any new results.I had already scrapped other expired domain websites before and used that data, and I hoped that this one would provide some new domain hits, even though it had very large overlap with the other websites I had scraped domains from previously.Such domain name lists tend to contain all SCAM domains in existence, since those inevitably expire once the scammers are caught.
- even more importantly, I noticed by chance that I was being too strict on a small part of my fingerprinting which was excluding a few good domains, by removing any hits that had multiple archives of the Communication mechanism
With those two new developments, I then kicked off my pre-existing search pipelines searching for domain names with the word
news
on them, an amazingly efficient heuristic because many of the websites were disguised as news aggregators, and after a few hours theses new hits emerged. A few of those also led to the discovery of new IPs which then led to new domains.One entirely new IP range was found around fastnews-online.com from 208.93.112.105 to 208.93.112.125. There were many domain names with very promising names in the range, but unfortunately for some reason most didn't have Wayback Machine Archives so I didn't count them as hits as per my guidelines.
2009 Wayback Machine archive of fastnews-online.com
. Also the newly found todaysengineering.com at 208.254.38.39 appears to form an IP range with the previously known nejadnews.com at 208.254.38.56, but I couldn't find any other domains in the region with our current data sources.
2011 Wayback Machine archive of todaysengineering.com
. All other domains either slot into previously known IP ranges, or more commonly don't currently have a known IP, though they would likely just slot in existing ranges if we had better data.
Thanks to Jack Rhysider from the Darknet Diaries podcast for pointing me to the existing of the 2022 Reuters article that kickstarted my research on the subject!
One outcome of this update is that I've increased my jq level to better automate the maintenance of the hits.json file were I store all the known websites in JSON format. I love that tool so much, I managed to merge two JSONs with it removing duplicates and then sort the JSON as desired. Beauty.
The full list of newly found websites is:
- cellar-notes.com
- dailywellnessnews.com
- differentviewtoday.com
- dryterrainnews.com
- euronewsonline.net
- fastnews-online.com
- financecentraltoday.com
- globalcitizennews.net
- globalinvestmentnews.net
- inkfreenews.com
- internationalnewsworthiness.com
- intoworldnews.com
- lasthournews.com
- latinamericanewsbeat.com
- localtoglobalnews.com
- magneticfieldnews.com
- middle-east-newstoday.com
- mideasttoday.net
- mydailynewsreport.com
- mynepalnews.com
- nbanewsroundup.com
- nejadnews.com
- networkconnectionsite.com
- news-and-sports.com
- newsdelivered.net
- pondernews.net
- profile-news.com
- purlicue-news.com
- sandstormnews.com
- segomonews.com
- shadesofnews.com
- technologypresstoday.com/
- the-news-scene.com
- thefootball-life.com
- thefreshnews.com
- thenewsofpakistan.com
- totallynewsnow.com
- travelxtreme.net
- webofcheer.com
- wiredworldnews.com
- world-news-online.net
- worldaroundyunnan.com
- worldofonlinenews.com
Announced at:
- mastodon.social/@cirosantilli/114156495883418926
- x.com/cirosantilli/status/1900249928653271334
- www.facebook.com/cirosantilli/posts/pfbid02LbrfezGmFik582d6H7ZEoCf9bwpU73vyivdGLVbbzWjejWLS5Rv9EjGNXBPQppUBl
- www.linkedin.com/posts/cirosantilli_httpslnkdineyu8qwc-i-found-44-new-covert-activity-7306015949374058496-X5zl/