Bitcoin Forum
April 19, 2024, 06:26:46 AM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 »  All
  Print  
Author Topic: Bitcoin Bouny Hunter: Bitalo DDOS attacker discussion  (Read 11561 times)
MemoryDealers (OP)
VIP
Legendary
*
Offline Offline

Activity: 1052
Merit: 1105



View Profile WWW
November 04, 2014, 02:53:00 AM
 #1

Please use this thread for discussion of the Bitalo DDOS attacker case specifically: http://bitcoinbountyhunter.com/bitalo.html

For general discussion about BitcoinBountyHunter.com,  please use: https://bitcointalk.org/index.php?topic=784520

1713508006
Hero Member
*
Offline Offline

Posts: 1713508006

View Profile Personal Message (Offline)

Ignore
1713508006
Reply with quote  #2

1713508006
Report to moderator
1713508006
Hero Member
*
Offline Offline

Posts: 1713508006

View Profile Personal Message (Offline)

Ignore
1713508006
Reply with quote  #2

1713508006
Report to moderator
BitcoinCleanup.com: Learn why Bitcoin isn't bad for the environment
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713508006
Hero Member
*
Offline Offline

Posts: 1713508006

View Profile Personal Message (Offline)

Ignore
1713508006
Reply with quote  #2

1713508006
Report to moderator
1713508006
Hero Member
*
Offline Offline

Posts: 1713508006

View Profile Personal Message (Offline)

Ignore
1713508006
Reply with quote  #2

1713508006
Report to moderator
1713508006
Hero Member
*
Offline Offline

Posts: 1713508006

View Profile Personal Message (Offline)

Ignore
1713508006
Reply with quote  #2

1713508006
Report to moderator
Bitalo_Martin
Member
**
Offline Offline

Activity: 81
Merit: 10



View Profile WWW
November 05, 2014, 03:04:51 PM
 #2

Here is the full initial email communication. I will add more attack logfiles asap.                         
                                                                                                                                                                                                                                     
Delivered-To: martin@bitalo.com
Received: by 10.140.16.43 with SMTP id 40csp270558qga;
        Mon, 3 Nov 2014 06:33:55 -0800 (PST)
X-Received: by 10.60.68.108 with SMTP id v12mr602259oet.69.1415025235205;
        Mon, 03 Nov 2014 06:33:55 -0800 (PST)
Return-Path: <dd4bc@outlook.com>
Received: from SNT004-OMC1S8.hotmail.com (snt004-omc1s8.hotmail.com. [65.55.90.19])
        by mx.google.com with ESMTPS id 21si18495325oin.129.2014.11.03.06.33.53
        for <multiple recipients>
        (version=TLSv1.2 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
        Mon, 03 Nov 2014 06:33:55 -0800 (PST)
Received-SPF: pass (google.com: domain of dd4bc@outlook.com designates 65.55.90.19 as permitted sender) client-ip=65.55.90.19;
Authentication-Results: mx.google.com;
       spf=pass (google.com: domain of dd4bc@outlook.com designates 65.55.90.19 as permitted sender) smtp.mail=dd4bc@outlook.com;
       dmarc=pass (p=NONE dis=NONE) header.from=outlook.com
Received: from SNT146-W55 ([65.55.90.9]) by SNT004-OMC1S8.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
    Mon, 3 Nov 2014 06:33:53 -0800
X-TMN: [IyzY3qwIBGGm2XlnVY5tp8RicYKI1Pj8]
X-Originating-Email: [dd4bc@outlook.com]
Message-ID: <SNT146-W55B111E126F9274BA539C3E9990@phx.gbl>
Return-Path: dd4bc@outlook.com
Content-Type: multipart/alternative;
   boundary="_991179ca-6b3d-4765-8753-5bcd7337b00c_"
From: DD4BC TEAM <dd4bc@outlook.com>
To: Martin Albert <martin@bitalo.com>
CC: "fabio@bitalo.com" <fabio@bitalo.com>, "antti@bitalo.com"
   <antti@bitalo.com>, "pawel@bitalo.com" <pawel@bitalo.com>, "mauro@bitalo.com"
   <mauro@bitalo.com>, "michael@bitalo.com" <michael@bitalo.com>,
   "isaac@bitalo.com" <isaac@bitalo.com>, "maciej@bitalo.com"
   <maciej@bitalo.com>, "lilia@bitalo.com" <lilia@bitalo.com>,
   "felix@bitalo.com" <felix@bitalo.com>, "peter@bitalo.com" <peter@bitalo.com>,
   "sebastian@bitalo.com" <sebastian@bitalo.com>, "trevin@bitalo.com"
   <trevin@bitalo.com>, "christian@bitalo.com" <christian@bitalo.com>,
   "michaelg@bitalo.com" <michaelg@bitalo.com>, "fabiob@bitalo.com"
   <fabiob@bitalo.com>, "support@bitalo.com" <support@bitalo.com>,
   "martin.albert@gmx.net" <martin.albert@gmx.net>
Subject: RE: DDOS ATTACK!
Date: Mon, 3 Nov 2014 15:33:53 +0100
Importance: Normal
In-Reply-To: <SNT146-W27EAE07C4902DE6896E211E99B0@phx.gbl>
References:
 <SNT146-W199CA9C530BBEE76D4BB1E99F0@phx.gbl>,<SNT146-W698F7ECDB0BFB431B9CFF0E99F0@phx.gbl>,<SNT146-W86C2E73DC98A683683AFC7E99F0@phx.gbl>,<SNT146-W83C2ACB65C5F2E0722AFDEE99F0@phx.gbl>,<SNT146-W947131BCC73C0BD6528E1E99C0@phx.gbl>,<SNT146-W37B7611425909EBDAE1E87E99D0@phx.gbl>,<SNT146-W722383831A32387AF3DEE9E99B0@phx.gbl>,<CAJobRfdW+46S2E5A9SJhXiy_wbJ+TSgK_H7HLPurdXyc4=o-FA@mail.gmail.com>,<SNT146-W95268ECC0E0271350B6C3AE99B0@phx.gbl>,<SNT146-W14B29293D971DA042CFA42E99B0@phx.gbl>,<SNT146-W27EAE07C4902DE6896E211E99B0@phx.gbl>
MIME-Version: 1.0
X-OriginalArrivalTime: 03 Nov 2014 14:33:53.0817 (UTC) FILETIME=[3157C890:01CFF773]

--_991179ca-6b3d-4765-8753-5bcd7337b00c_
Content-Type: text/plain; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

Let me know if you are interested.=20

From: dd4bc@outlook.com
To: martin@bitalo.com
CC: fabio@bitalo.com=3B antti@bitalo.com=3B pawel@bitalo.com=3B mauro@bital=
o.com=3B michael@bitalo.com=3B isaac@bitalo.com=3B maciej@bitalo.com=3B lil=
ia@bitalo.com=3B felix@bitalo.com=3B peter@bitalo.com=3B sebastian@bitalo.c=
om=3B trevin@bitalo.com=3B christian@bitalo.com=3B michaelg@bitalo.com=3B f=
abiob@bitalo.com=3B support@bitalo.com=3B martin.albert@gmx.net
Subject: RE: DDOS ATTACK!
Date: Sat=2C 1 Nov 2014 13:47:16 +0100

=0A=
=0A=
=0A=
To end this and because I'm in a good mood today=2C I will offer you a disc=
ounted price of 0.5 BTC=2C so we end this and I move further.

If yes: 17aLGgw8AwJdqiBtMMG1QtQJgNQQkiyEsp

If not=2C this is my last email to you and we will both be doing what we mu=
st...


From: dd4bc@outlook.com
To: martin@bitalo.com
Subject: RE: DDOS ATTACK!
Date: Sat=2C 1 Nov 2014 12:59:43 +0100

=0A=
=0A=
=0A=
Let me go back to important part:

In a first mail I have told you that I'm offering info how to properly prot=
ect your site. And that's true.

I'm not script kiddie and I know how this works=2C I can bypass =0A=
almost any protection (except Prolexic)=2C because I know every protection=
=0A=
 and their weaknesses - I'm regulary DDoS-ing sites behind CloudFlare and I=
ncapsula=2C Blacklotus=2C Staminus and OVH.

I know what I can't bypass and if I can't - nobody can.=20

When I say info how to properly setup=2C I mean how to do it for a good pri=
ce. Yes=2C you can always go for Prolexic and pay 10K per month.

From: dd4bc@outlook.com
To: martin@bitalo.com
Subject: RE: DDOS ATTACK!
Date: Sat=2C 1 Nov 2014 12:39:33 +0100

=0A=
=0A=
=0A=
OMG=2C no! That hurts!

What am I going to do if I lose my Outlook account... LOL.=20


You know what's funny?

This morning I dreamed that somebody=2C somehow=2C found  my real name and =
published it in a press release... And there was my name all over the Inter=
net... When I woke up=2C I laughed.

Because it's possible only in a dream. Smiley

DDoS attacks are impossible to trace back to origin. You can try over email=
 logins like you are doing=2C but there are two things:

- Microsoft will not give you my IPs just like that. You need to report me =
to your local police in Finland=2C then THEY must ask for my login directly=
 from Microsoft or through FBI.

- Once they (and IF=2C because they probably won't care) get my login IPs=
=2C they will point to TOR...


And third=2C probably most important=2C you are not helping yourself doing =
this. Smiley


Date: Sat=2C 1 Nov 2014 12:58:11 +0200
Subject: Fwd: DDOS ATTACK!
From: martin@bitalo.com
To: dd4bc@outlook.com=3B abuse@Outlook.com

Dear outlook team=2C
we want to report a criminal abuse of your mail system (see mail below) and=
 would like to request all login data from the user so that we can forward =
these to the local police authorities
---------- Forwarded message ----------
From: DD4BC TEAM <dd4bc@outlook.com>
Date: Sat=2C Nov 1=2C 2014 at 4:57 AM
Subject: DDOS ATTACK!
To: "martin@bitalo.com" <martin@bitalo.com>=2C "fabio@bitalo.com" <fabio@bi=
talo.com>=2C "antti@bitalo.com" <antti@bitalo.com>=2C "pawel@bitalo.com" <p=
awel@bitalo.com>=2C "mauro@bitalo.com" <mauro@bitalo.com>=2C "michael@bital=
o.com" <michael@bitalo.com>=2C "isaac@bitalo.com" <isaac@bitalo.com>=2C "ma=
ciej@bitalo.com" <maciej@bitalo.com>=2C "lilia@bitalo.com" <lilia@bitalo.co=
m>=2C "felix@bitalo.com" <felix@bitalo.com>=2C "peter@bitalo.com" <peter@bi=
talo.com>=2C "sebastian@bitalo.com" <sebastian@bitalo.com>=2C "trevin@bital=
o.com" <trevin@bitalo.com>=2C "christian@bitalo.com" <christian@bitalo.com>=
=2C "michaelg@bitalo.com" <michaelg@bitalo.com>=2C "fabiob@bitalo.com" <fab=
iob@bitalo.com>=2C "support@bitalo.com" <support@bitalo.com>=2C "martin.alb=
ert@gmx.net" <martin.albert@gmx.net>


=0A=
=0A=
=0A=

=0A=
=0A=
=0A=
=0A=
=0A=

HelloYour site is extremely vulnerable to ddos attacks.I want to offer you =
info how to properly setup your protection=2C so that you can't be ddosed!M=
y price is 1 Bitcoin only.Right now I will star small (very small) attack w=
hich will not crash your server=2C but you should notice it in logs. Just c=
heck it.I want to offer you  info on how I did it and what you have to do t=
o prevent it. If interested pay me 1 BTC to 17aLGgw8AwJdqiBtMMG1QtQJgNQQkiy=
EspThank you.    =20
=0A=
                                            =0A=

                                                                                        =

--_991179ca-6b3d-4765-8753-5bcd7337b00c_
Content-Type: text/html; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<style><!--
.hmmessage P
{
margin:0px=3B
padding:0px
}
body.hmmessage
{
font-size: 12pt=3B
font-family:Calibri
}
--></style></head>
<body class=3D'hmmessage'><div dir=3D'ltr'>Let me know if you are intereste=
d. <br><br><div><hr id=3D"stopSpelling">From: dd4bc@outlook.com<br>To: mart=
in@bitalo.com<br>CC: fabio@bitalo.com=3B antti@bitalo.com=3B pawel@bitalo.c=
om=3B mauro@bitalo.com=3B michael@bitalo.com=3B isaac@bitalo.com=3B maciej@=
bitalo.com=3B lilia@bitalo.com=3B felix@bitalo.com=3B peter@bitalo.com=3B s=
ebastian@bitalo.com=3B trevin@bitalo.com=3B christian@bitalo.com=3B michael=
g@bitalo.com=3B fabiob@bitalo.com=3B support@bitalo.com=3B martin.albert@gm=
x.net<br>Subject: RE: DDOS ATTACK!<br>Date: Sat=2C 1 Nov 2014 13:47:16 +010=
0<br><br>=0A=
=0A=
<style><!--=0A=
.ExternalClass .ecxhmmessage P {=0A=
padding:0px=3B=0A=
}=0A=
=0A=
.ExternalClass body.ecxhmmessage {=0A=
font-size:12pt=3B=0A=
font-family:Calibri=3B=0A=
}=0A=
=0A=
--></style>=0A=
<div dir=3D"ltr">To end this and because I'm in a good mood today=2C I will=
 offer you a discounted price of 0.5 BTC=2C so we end this and I move furth=
er.<br><br>If yes: 17aLGgw8AwJdqiBtMMG1QtQJgNQQkiyEsp<br><br>If not=2C this=
 is my last email to you and we will both be doing what we must...<br><span=
 style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetic=
a=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:=
normal=3Bfont-weight:normal=3Bletter-spacing:normal=3Bline-height:21.875px=
=3Btext-align:start=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:n=
ormal=3Bword-spacing:0px=3Bdisplay:inline !important=3Bbackground-color:rgb=
(250=2C250=2C250)=3B"><br></span><br><div><hr id=3D"ecxstopSpelling">From: =
dd4bc@outlook.com<br>To: martin@bitalo.com<br>Subject: RE: DDOS ATTACK!<br>=
Date: Sat=2C 1 Nov 2014 12:59:43 +0100<br><br>=0A=
=0A=
<style><!--=0A=
.ExternalClass .ecxhmmessage P {=0A=
padding:0px=3B=0A=
}=0A=
=0A=
.ExternalClass body.ecxhmmessage {=0A=
font-size:12pt=3B=0A=
font-family:Calibri=3B=0A=
}=0A=
=0A=
=0A=
--></style>=0A=
<div dir=3D"ltr">Let me go back to important part:<br><br>In a first mail I=
 have told you that I'm offering info how to properly protect your site. An=
d that's true.<br><br>I'm not script kiddie and I know how this works=2C I =
can bypass =0A=
almost any protection (except Prolexic)=2C because I know every protection=
=0A=
 and their weaknesses - I'm regulary DDoS-ing sites behind CloudFlare and I=
ncapsula=2C Blacklotus=2C Staminus and OVH.<br><br>I know what I can't bypa=
ss and if I can't - nobody can. <br><br>When I say info how to properly set=
up=2C I mean how to do it for a good price. Yes=2C you can always go for Pr=
olexic and pay 10K per month.<br><br><div><hr id=3D"ecxstopSpelling">From: =
dd4bc@outlook.com<br>To: martin@bitalo.com<br>Subject: RE: DDOS ATTACK!<br>=
Date: Sat=2C 1 Nov 2014 12:39:33 +0100<br><br>=0A=
=0A=
<style><!--=0A=
.ExternalClass .ecxhmmessage P {=0A=
padding:0px=3B=0A=
}=0A=
=0A=
.ExternalClass body.ecxhmmessage {=0A=
font-size:12pt=3B=0A=
font-family:Calibri=3B=0A=
}=0A=
=0A=
=0A=
--></style>=0A=
<div dir=3D"ltr">OMG=2C no! That hurts!<br><br>What am I going to do if I l=
ose my Outlook account... LOL. <br><br><br>You know what's funny?<br><br>Th=
is morning I dreamed that somebody=2C somehow=2C found&nbsp=3B my real name=
 and published it in a press release... And there was my name all over the =
Internet... When I woke up=2C I laughed.<br><br>Because it's possible only =
in a dream. Smiley<br><br>DDoS attacks are impossible to trace back to origin. =
You can try over email logins like you are doing=2C but there are two thing=
s:<br><br>- Microsoft will not give you my IPs just like that. You need to =
report me to your local police in Finland=2C then THEY must ask for my logi=
n directly from Microsoft or through FBI.<br><br>- Once they (and IF=2C bec=
ause they probably won't care) get my login IPs=2C they will point to TOR..=
.<br><br><br>And third=2C probably most important=2C you are not helping yo=
urself doing this. Smiley<br><br><br><div><hr id=3D"ecxstopSpelling">Date: Sat=
=2C 1 Nov 2014 12:58:11 +0200<br>Subject: Fwd: DDOS ATTACK!<br>From: martin=
@bitalo.com<br>To: dd4bc@outlook.com=3B abuse@Outlook.com<br><br><div dir=
=3D"ltr"><div>Dear outlook team=2C</div><div><br></div><div>we want to repo=
rt a criminal abuse of your mail system (see mail below) and would like to =
request all login data from the user so that we can forward these to the lo=
cal police authorities</div><br><div class=3D"ecxgmail_quote">---------- Fo=
rwarded message ----------<br>From: <b class=3D"ecxgmail_sendername">DD4BC =
TEAM</b> <span dir=3D"ltr">&lt=3B<a href=3D"mailto:dd4bc@outlook.com">dd4bc=
@outlook.com</a>&gt=3B</span><br>Date: Sat=2C Nov 1=2C 2014 at 4:57 AM<br>S=
ubject: DDOS ATTACK!<br>To: "<a href=3D"mailto:martin@bitalo.com">martin@bi=
talo.com</a>" &lt=3B<a href=3D"mailto:martin@bitalo.com">martin@bitalo.com<=
/a>&gt=3B=2C "<a href=3D"mailto:fabio@bitalo.com">fabio@bitalo.com</a>" &lt=
=3B<a href=3D"mailto:fabio@bitalo.com">fabio@bitalo.com</a>&gt=3B=2C "<a hr=
ef=3D"mailto:antti@bitalo.com">antti@bitalo.com</a>" &lt=3B<a href=3D"mailt=
o:antti@bitalo.com">antti@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:pawel@=
bitalo.com">pawel@bitalo.com</a>" &lt=3B<a href=3D"mailto:pawel@bitalo.com"=
>pawel@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:mauro@bitalo.com">mauro@b=
italo.com</a>" &lt=3B<a href=3D"mailto:mauro@bitalo.com">mauro@bitalo.com</=
a>&gt=3B=2C "<a href=3D"mailto:michael@bitalo.com">michael@bitalo.com</a>" =
&lt=3B<a href=3D"mailto:michael@bitalo.com">michael@bitalo.com</a>&gt=3B=2C=
 "<a href=3D"mailto:isaac@bitalo.com">isaac@bitalo.com</a>" &lt=3B<a href=
=3D"mailto:isaac@bitalo.com">isaac@bitalo.com</a>&gt=3B=2C "<a href=3D"mail=
to:maciej@bitalo.com">maciej@bitalo.com</a>" &lt=3B<a href=3D"mailto:maciej=
@bitalo.com">maciej@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:lilia@bitalo=
.com">lilia@bitalo.com</a>" &lt=3B<a href=3D"mailto:lilia@bitalo.com">lilia=
@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:felix@bitalo.com">felix@bitalo.=
com</a>" &lt=3B<a href=3D"mailto:felix@bitalo.com">felix@bitalo.com</a>&gt=
=3B=2C "<a href=3D"mailto:peter@bitalo.com">peter@bitalo.com</a>" &lt=3B<a =
href=3D"mailto:peter@bitalo.com">peter@bitalo.com</a>&gt=3B=2C "<a href=3D"=
mailto:sebastian@bitalo.com">sebastian@bitalo.com</a>" &lt=3B<a href=3D"mai=
lto:sebastian@bitalo.com">sebastian@bitalo.com</a>&gt=3B=2C "<a href=3D"mai=
lto:trevin@bitalo.com">trevin@bitalo.com</a>" &lt=3B<a href=3D"mailto:trevi=
n@bitalo.com">trevin@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:christian@b=
italo.com">christian@bitalo.com</a>" &lt=3B<a href=3D"mailto:christian@bita=
lo.com">christian@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:michaelg@bital=
o.com">michaelg@bitalo.com</a>" &lt=3B<a href=3D"mailto:michaelg@bitalo.com=
">michaelg@bitalo.com</a>&gt=3B=2C "<a href=3D"mailto:fabiob@bitalo.com">fa=
biob@bitalo.com</a>" &lt=3B<a href=3D"mailto:fabiob@bitalo.com">fabiob@bita=
lo.com</a>&gt=3B=2C "<a href=3D"mailto:support@bitalo.com">support@bitalo.c=
om</a>" &lt=3B<a href=3D"mailto:support@bitalo.com">support@bitalo.com</a>&=
gt=3B=2C "<a href=3D"mailto:martin.albert@gmx.net">martin.albert@gmx.net</a=
>" &lt=3B<a href=3D"mailto:martin.albert@gmx.net">martin.albert@gmx.net</a>=
&gt=3B<br><br><br>=0A=
=0A=
=0A=
<div><div dir=3D"ltr"><br>=0A=
=0A=
=0A=
<div><div dir=3D"ltr">=0A=
=0A=
<div dir=3D"ltr"><br><span style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'=
Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-st=
yle:normal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:norm=
al=3Bline-height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-trans=
form:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bdisplay:inline !importa=
nt=3Bbackground-color:rgb(250=2C250=2C250)=3B">Hello</span><br style=3D"col=
or:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Cs=
ans-serif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont=
-weight:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:=
start=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-s=
pacing:0px=3Bbackground-color:rgb(250=2C250=2C250)=3B"><br style=3D"color:r=
gb(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-=
serif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-wei=
ght:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:star=
t=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spaci=
ng:0px=3Bbackground-color:rgb(250=2C250=2C250)=3B"><span style=3D"color:rgb=
(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-se=
rif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weigh=
t:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:start=
=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spacin=
g:0px=3Bdisplay:inline !important=3Bbackground-color:rgb(250=2C250=2C250)=
=3B">Your site is extremely vulnerable to ddos attacks.</span><br style=3D"=
color:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=
=2Csans-serif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3B=
font-weight:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-al=
ign:start=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bwo=
rd-spacing:0px=3Bbackground-color:rgb(250=2C250=2C250)=3B"><br style=3D"col=
or:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Cs=
ans-serif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont=
-weight:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:=
start=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-s=
pacing:0px=3Bbackground-color:rgb(250=2C250=2C250)=3B"><span style=3D"color=
:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csan=
s-serif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-w=
eight:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:st=
art=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spa=
cing:0px=3Bdisplay:inline !important=3Bbackground-color:rgb(250=2C250=2C250=
)=3B">I want to offer you info how to properly setup your protection=2C so =
that you can't be ddosed!</span><br style=3D"color:rgb(51=2C51=2C51)=3Bfont=
-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=
=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-sp=
acing:normal=3Bline-height:21.875px=3Btext-align:start=3Btext-indent:0px=3B=
text-transform:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bbackground-co=
lor:rgb(250=2C250=2C250)=3B"><span style=3D"color:rgb(51=2C51=2C51)=3Bfont-=
family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=
=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-sp=
acing:normal=3Bline-height:21.875px=3Btext-align:start=3Btext-indent:0px=3B=
text-transform:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bdisplay:inlin=
e !important=3Bbackground-color:rgb(250=2C250=2C250)=3B">My price is 1 Bitc=
oin only.</span><br style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'Helveti=
ca Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-style:nor=
mal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:normal=3Bli=
ne-height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-transform:no=
ne=3Bwhite-space:normal=3Bword-spacing:0px=3Bbackground-color:rgb(250=2C250=
=2C250)=3B"><br style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica N=
eue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-style:normal=
=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:normal=3Bline-=
height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-transform:none=
=3Bwhite-space:normal=3Bword-spacing:0px=3Bbackground-color:rgb(250=2C250=
=2C250)=3B"><span style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'Helvetica=
 Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-style:norma=
l=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:normal=3Bline=
-height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-transform:none=
=3Bwhite-space:normal=3Bword-spacing:0px=3Bdisplay:inline !important=3Bback=
ground-color:rgb(250=2C250=2C250)=3B">Right now I will star small (very sma=
ll) attack which will not crash your server=2C but you should notice it in =
logs. Just check it.</span><br style=3D"color:rgb(51=2C51=2C51)=3Bfont-fami=
ly:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfon=
t-style:normal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:=
normal=3Bline-height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-t=
ransform:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bbackground-color:rg=
b(250=2C250=2C250)=3B"><br style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'=
Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-st=
yle:normal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:norm=
al=3Bline-height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-trans=
form:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bbackground-color:rgb(25=
0=2C250=2C250)=3B"><span style=3D"color:rgb(51=2C51=2C51)=3Bfont-family:'He=
lvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfont-size:14px=3Bfont-styl=
e:normal=3Bfont-variant:normal=3Bfont-weight:normal=3Bletter-spacing:normal=
=3Bline-height:21.875px=3Btext-align:start=3Btext-indent:0px=3Btext-transfo=
rm:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bdisplay:inline !important=
=3Bbackground-color:rgb(250=2C250=2C250)=3B">I want to offer you&nbsp=3B in=
fo on how I did it and what you have to do to prevent it. If interested pay=
 me 1 BTC to 17aLGgw8AwJdqiBtMMG1QtQJgNQQkiyEsp</span><br style=3D"color:rg=
b(51=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-s=
erif=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weig=
ht:normal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:start=
=3Btext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spacin=
g:0px=3Bbackground-color:rgb(250=2C250=2C250)=3B"><br style=3D"color:rgb(51=
=2C51=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=
=3Bfont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weight:n=
ormal=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:start=3Bt=
ext-indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spacing:0p=
x=3Bbackground-color:rgb(250=2C250=2C250)=3B"><br style=3D"color:rgb(51=2C5=
1=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bf=
ont-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weight:norma=
l=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:start=3Btext-=
indent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spacing:0px=3B=
background-color:rgb(250=2C250=2C250)=3B"><span style=3D"color:rgb(51=2C51=
=2C51)=3Bfont-family:'Helvetica Neue'=2CHelvetica=2CArial=2Csans-serif=3Bfo=
nt-size:14px=3Bfont-style:normal=3Bfont-variant:normal=3Bfont-weight:normal=
=3Bletter-spacing:normal=3Bline-height:21.875px=3Btext-align:start=3Btext-i=
ndent:0px=3Btext-transform:none=3Bwhite-space:normal=3Bword-spacing:0px=3Bd=
isplay:inline !important=3Bbackground-color:rgb(250=2C250=2C250)=3B">Thank =
you. &nbsp=3B &nbsp=3B<span> <br></span></span></div>=0A=
                      </div></div>                      </div></div>=0A=
</div><br></div></div>                      </div></div>                      </div></div>           =
           </div></div>                      </div></body>
</html>=

--_991179ca-6b3d-4765-8753-5bcd7337b00c_--
bitcomsec
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile WWW
November 05, 2014, 03:07:54 PM
 #3

Hi Roger,

My name is Mike and I'm with the BITCOMSEC (Bitcoin Community Secuity) Project. Our aim is to provide the community security services free of charge, and we're donation based. In the last year we've extensively audited exchanges, pools and merchants for security issues and provided the research to each of them respectively. Recently we've focused more on investigative research into these thieves:

Tracking down the CryptoRush.in hacker:
https://bitcomsec.true.io/bitcomsec/tracking-a-bitcoin-thief-cryptorush-hack/

Exposing and shutting down an elaborate Coinbase.com/Blockchain.info phishing network:
https://bitcomsec.true.io/bitcomsec/coinbase_com-and-blockchain_info-bitcoin-wallet-phishing-scam-exposed/

With that being said we are in the business of tracking down and exposing Bitcoin thieves to the community.

- Is there an archived copy of the extortion email + headers?

Thanks. Looking into this immediately.

Mike
Bitalo_Martin
Member
**
Offline Offline

Activity: 81
Merit: 10



View Profile WWW
November 05, 2014, 03:17:53 PM
 #4

Initial "small" ddos

i will have more logfiles from the follow ups

Direction IN
Internal 176.9.38.40
Threshold FlowsDiff 40 flows/s, Diff: 239 flows/s
Sum 71.841 flows/300s (239 flows/s), 71.881.000 packets/300s (239.603 packets/s), 2,738 GByte/300s (74 MBit/s)
External 211.153.8.169, 4 flows/300s (0 flows/s), 24.000 packets/300s (80 packets/s), 0,011 GByte/300s (0 MBit/s)
External 94.231.81.38, 3 flows/300s (0 flows/s), 3.000 packets/300s (10 packets/s), 0,001 GByte/300s (0 MBit/s)
External 173.74.75.83, 3 flows/300s (0 flows/s), 3.000 packets/300s (10 packets/s), 0,001 GByte/300s (0 MBit/s)
External 58.142.206.194, 2 flows/300s (0 flows/s), 3.000 packets/300s (10 packets/s), 0,000 GByte/300s (0 MBit/s)
External 67.55.209.73, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 177.47.16.130, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 78.97.94.244, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 219.124.114.1, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 199.58.240.1, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 196.23.6.234, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 58.210.9.222, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 219.159.39.58, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 61.97.9.100, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 194.185.38.14, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 205.171.93.37, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 120.83.5.152, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 72.13.143.84, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 186.219.240.68, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 58.240.213.254, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 207.240.120.138, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 111.195.28.4, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 183.232.148.17, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 112.214.75.254, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 89.137.112.222, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 46.36.35.180, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 111.12.150.169, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 4.26.50.58, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 37.252.196.14, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 78.84.22.172, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 183.232.112.18, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 12.89.10.34, 2 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 211.140.203.109, 1 flows/300s (0 flows/s), 3.000 packets/300s (10 packets/s), 0,001 GByte/300s (0 MBit/s)
External 213.192.9.248, 1 flows/300s (0 flows/s), 3.000 packets/300s (10 packets/s), 0,000 GByte/300s (0 MBit/s)
External 120.202.108.54, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 212.104.156.25, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 206.248.145.38, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 189.125.26.74, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 207.238.95.11, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 78.111.125.156, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 92.223.139.56, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 202.56.129.90, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 67.107.71.162, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,001 GByte/300s (0 MBit/s)
External 98.243.106.47, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 71.244.53.219, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 41.223.26.2, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 218.62.10.197, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 219.92.58.165, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 96.10.249.186, 1 flows/300s (0 flows/s), 2.000 packets/300s (6 packets/s), 0,000 GByte/300s (0 MBit/s)
External 98.214.231.148, 1 flows/300s (0 flows/s), 1.000 packets/300s (3 packets/s), 0,000 GByte/300s (0 MBit/s)
External 8.198.132.105, 1 flows/300s (0 flows/s), 1.000 packets/300s (3 packets/s), 0,000 GByte/300s (0 MBit/s)



bitcomsec
Newbie
*
Offline Offline

Activity: 24
Merit: 0


View Profile WWW
November 05, 2014, 03:29:50 PM
 #5

Martin,

Great information. Thanks!

Mike @ BITCOMSEC
Marc_addict
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
November 06, 2014, 11:43:07 PM
 #6

I have all the information on DD4BC, someone responsible for the bounty pm me so we can discuss further on skype!
DD4BC
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
November 07, 2014, 01:16:03 PM
 #7

I have all the information on DD4BC, someone responsible for the bounty pm me so we can discuss further on skype!

No, please, no! Sad
DD4BC
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
November 07, 2014, 08:37:02 PM
 #8


Yes, that's me.

GBBG|Ware
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile WWW
November 08, 2014, 10:43:11 AM
 #9

Is it possible to get someone to look into this person:

Bernd Willmann; Rattinghauser Weg 6; 49324 Melle
Germany
Marc_addict
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
November 08, 2014, 11:50:19 AM
 #10

I have all the information on DD4BC, someone responsible for the bounty pm me so we can discuss further on skype!

No, please, no! Sad

You can run, but you can't hide

jk lol, you can hide in mexico , you will blend in just right...
Marc_addict
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
November 08, 2014, 11:59:20 AM
 #11

Is it possible to get someone to look into this person:

Bernd Willmann; Rattinghauser Weg 6; 49324 Melle
Germany

where did you get the address from? its not correct.
DD4BC
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
November 08, 2014, 12:34:19 PM
 #12

I have all the information on DD4BC, someone responsible for the bounty pm me so we can discuss further on skype!

No, please, no! Sad

You can run, but you can't hide

jk lol, you can hide in mexico , you will blend in just right...

Mexico?!

No, you are wrong... We, Germans, hide in Argentina.
Marc_addict
Newbie
*
Offline Offline

Activity: 5
Merit: 0


View Profile
November 08, 2014, 12:36:39 PM
 #13

idk man seems like a long shot,

btw contacting the authorities is a big hassle,

so im going to offer you a deal ill give you 20BTC from the bounty that i collect  after you serve time in jail if you turn yourself in.

deal?
Kimax
Newbie
*
Offline Offline

Activity: 33
Merit: 0


View Profile
November 08, 2014, 12:46:53 PM
 #14

Thats a cute Little DDOS. Can't do any harm.
Bitalo_Martin
Member
**
Offline Offline

Activity: 81
Merit: 10



View Profile WWW
November 08, 2014, 02:35:16 PM
 #15

savagedegod@gmail.com just sent the following email:

Hi martin,


you made me and my home boy DD4BC very mad when you set a 100BTC bounty on him

so this is how it's going to go now we will hit the website off for 1 week straight
unless we are paid 20BTC to this wallet 1xEagymjSEnxgSwzd2Y7ZagMQ2AGhJx4C

we will start the attack at 4PM PST

you know the drill, we dont get paid we ddos for 1 week and next week same thing happens but double the price Cheesy
DD4BC
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
November 08, 2014, 02:45:56 PM
 #16

savagedegod@gmail.com just sent the following email:

Ignore that fool.

We are not related in any way (except that he is bothering me with stupid emails too Cheesy).
semidead
Member
**
Offline Offline

Activity: 94
Merit: 10

★Bitin.io★ - Instant Exchange


View Profile
November 09, 2014, 03:25:23 AM
 #17

savagedegod@gmail.com just sent the following email:

Ignore that fool.

We are not related in any way (except that he is bothering me with stupid emails too Cheesy).
i need your help, sent you a pm

DD4BC
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
November 11, 2014, 02:31:00 PM
 #18

bump
snitch
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile
November 12, 2014, 03:58:50 AM
Last edit: November 14, 2014, 10:20:12 AM by snitch
 #19

refer to next post.
Bitalo_Martin
Member
**
Offline Offline

Activity: 81
Merit: 10



View Profile WWW
November 12, 2014, 11:32:37 AM
 #20

proof of existence shows that you are the first one with a time stamp that submitted the identity with the chain of proof.


The attack was recently, we do not have a full file prepared to start conviction. Also, public police are bureaucrats that did not even start doing something. But since we have the bounty in third party escrow with the highly reputable and well known Roger Ver you should not experience any problems with the payout of the bounty


Pages: [1] 2 3 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!