Domain seized

Namecheap AuctionsNamecheap Auctions
SpaceshipSpaceship
SpaceshipSpaceship
Watch

boker

Top Member
Impact
4,339
Looks like one of my domains was used in some kind of cyber attacks or something like that. The domain oreux in king, was a hand reg from a year ago and I wanted to transfer it to another registrar. The transfer failed because the domain was locked. I've double checked with my registrar, and everything showed fine in the control panel, domain unlocked and the nameservers where ns1.undeveloped.com, but when I did a whois check, the domain was transfer prohibited and the nameservers were something like:
SC-C.SINKHOLE.SHADOWSERVER.ORG
Looks like the domain was used in some kind of cyber attack and they have seized around 800.000 domains. Nobody has told me anything about it and I still have access to everything in the control panel, the only issue is that control panel doesn't have control over everything. Couple of months ago everything was fine, so looks like they have changed the nameservers in the last months. So be aware, you could own some of the 800.000 domains seized. I have found a link here about it: https://www.europol.europa.eu/newsr...k-dismantled-in-international-cyber-operation
I will wait and see if I can do something about this transfer to epik.
 
15
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
Admittedly this is a complex issue, and one that we don't know everything. For the domain name that started this discussion the only use in years seems (from my examination of Wayback Machine) to have been when it was listed on Undeveloped (and many years previous on a parking site). It seems to me highly problematic that it can be seized without notice or justification.

In their own words the (apparently just a couple of individuals) that operate the sinkhole operation say "we have been registering previously and future malicious domain names and pointing those records to our sinkhole servers". If they indeed were registering available domains and pointing them wherever they want, I have no real problems. But here it seemed they took control without notice or justification or compensation to owner or registrar (well to registrar eventually, 7+ months later).

To do this along with saying that take domains that might be "future malicious domain names" (their words) seems a huge overstep. What is a possible future malicious domain name? Surely that is any domain name? With a few keystrokes malware code can readily be switched from interacting with one domain name to another.

I was for a walk this morning. Cars drove by me - I wondered, surely its possible that car could be used in the future as a getaway vehicle. I hope my local police seize it from the owner. Went by a costume store - could be a disguise in robbery - sure hope they seize everything in the store in advance just to be sure. Then was in kitchen store - it had knives everywhere. Better seize them all in advance, just in case to prevent future misuse!

I know I am being silly but to have about 1 out of every 400 domain names registered seized (800,000) without compensation, notice or justification to owners seems to be ridiculously over stepping authority.

In my mind this is rather different from the FBI seizure of about 800 websites earlier this year. Here there was at lease criminally alleged use and prosecution underway on specific offences (mainly counterfeit goods, illegal sales of prescription drugs, and possible prostitution/trafficking) so public justification was needed and could be cross examined. It was the website, not the domain name per se, that was taken over to prevent ongoing allegedly criminal activity.

To me this case is very different. Here it appears that a few individuals (one of whom is currently charged with malware development himself) recommended on seizure of a huge number of domain names.

I can''t believe that this thread is not totally dominating NPs. As the OP said, it is not the reg fee in this case that is the issue, but if a fear gets out there that you could buy a domain name for 5 figures, use it entirely properly, but one day it is seized without justification or even notice, that will be a chill on the whole domain aftermarket like we have never seen before.

Bob
 
Last edited:
14
•••
To me this case is very different. Here it appears that a few individuals (one of whom is currently charged with malware development himself) recommended on seizure of a huge number of domain names.
Actually it turns that firstly independent IT technician later become accredited authority after founding causes of hi-tech notorious malware spread over millions of Government computers worldwide. Still not sure and convicted into full blow of phenomenon, but these days bot net systems are powerful in wrongdoing(as opposite to regulated business web engines) and possible instrument of much wider public concerns than domain registrars as hybrid data manipulation, representatives meddling and other civil society threats. So I guess when such tunneling got established on a domain(through NS or website files injection/corruption) and malware starts spread, the web sites went usually suspended by hosts(etc) and in the other case when traffic disruption arise through Name Servers - domain has to be isolated (pointed onto mediary servers - directive/warrant of mentioned agency), temporary or so. Still more transparent proceeding would be beneficial widely.
 
Last edited:
0
•••
Looks like one of my domains was used in some kind of cyber attacks or something like that. The domain oreux in king, was a hand reg from a year ago and I wanted to transfer it to another registrar. The transfer failed because the domain was locked. I've double checked with my registrar, and everything showed fine in the control panel, domain unlocked and the nameservers where ns1.undeveloped.com, but when I did a whois check, the domain was transfer prohibited and the nameservers were something like:
SC-C.SINKHOLE.SHADOWSERVER.ORG
Looks like the domain was used in some kind of cyber attack and they have seized around 800.000 domains. Nobody has told me anything about it and I still have access to everything in the control panel, the only issue is that control panel doesn't have control over everything. Couple of months ago everything was fine, so looks like they have changed the nameservers in the last months. So be aware, you could own some of the 800.000 domains seized. I have found a link here about it: https://www.europol.europa.eu/newsroom/news/‘avalanche’-network-dismantled-in-international-cyber-operation
I will wait and see if I can do something about this transfer to epik.
My server was hacked a few months back and hundreds of thousands of emails were sent out. The only thing I knew to do was redirect the domains and then I reinstalled Cpanel. I haven't noticed any of the domains be locked to strange name servers, but I set Google alerts for the domain names that I know we're used in the hack. Thanks for the info .
 
1
•••
Hi, you could ask host for mod_secure/ip_tables a php environment module that handles various types of hacking distribution, still many host are not having it as default, so it has to be set as add-on to hosting configuration.
 
1
•••
So was this sinkholing related to the one that is described in the document at the following link? If so, it does seem that a fair amount of oversight was employed. However, the dates don't correspond. This was years ago, so how is it possible to hand register a domain 11 months ago that they then decided to sinkhole, is the key question.

https://www.europol.europa.eu/newsr...k-dismantled-in-international-cyber-operation

The document has the countries who were involved, but I could not find statistics on the domain extensions involved. Does anyone know for example what fraction of the 800,000 were .com?
 
2
•••
So was this sinkholing related to the one that is described in the document at the following link? If so, it does seem that a fair amount of oversight was employed. However, the dates don't correspond. This was years ago, so how is it possible to hand register a domain 11 months ago that they then decided to sinkhole, is the key question.

https://www.europol.europa.eu/newsroom/news/‘avalanche’-network-dismantled-in-international-cyber-operation

The document has the countries who were involved, but I could not find statistics on the domain extensions involved. Does anyone know for example what fraction of the 800,000 were .com?

That is the issue. They reheated the old docket with a fresh domain list and took out some innocent domains in the process. So far nobody at ShadowServer is providing any clarity around who cross-references the takedown list against the old docket. And nobody at DOJ is returning phone calls or emails for the registrant whose domain was wrongfully taken down. The single domain is not a tragedy. The tragedy is that it appears that any .COM can now be taken down without even telling the registrar. And if that is the case, we have a problem.
 
7
•••
The tragedy is that it appears that any .COM can now be taken down without even telling the registrar. And if that is the case, we have a problem.

Indeed! A huge problem. Even if it only rarely happens, if the possibility is there, it will scare some from investing in valuable assets.
 
1
•••
Indeed! A huge problem. Even if it only rarely happens, if the possibility is there, it will scare some from investing in valuable assets.

I would love to know the details of what Verisign gave up in return for their 7% per annum price increase. I am not sure we'll like the answer but better to know than to find out the hard way. Trusted Notifier was part of that deal and my concern is that we might have seen it used in this specific case with ShadowServer as the executing party. Verisign should comment asap.
 
4
•••
So was this sinkholing related to the one that is described in the document at the following link? If so, it does seem that a fair amount of oversight was employed. However, the dates don't correspond. This was years ago, so how is it possible to hand register a domain 11 months ago that they then decided to sinkhole, is the key question.

https://www.europol.europa.eu/newsroom/news/‘avalanche’-network-dismantled-in-international-cyber-operation

The document has the countries who were involved, but I could not find statistics on the domain extensions involved. Does anyone know for example what fraction of the 800,000 were .com?
Yes, it appears the (800,000) domains were part of the 'Avalanche Network of Malware' which is a big issue due to many variations. A large concern is that another attack is imminent, according to some hacker forums. That would explain why the dates are not corresponding.

There may be a lot of secrecy here as the U.S. Homeland Security Dept. is involved with investigating and containing this malware network.

ICANN had information about this malware network, but has since been removed:

https://ccnso.icann.org/en/meetings/copenhagen58/presentation-fbi-operation-avalanche-13mar17-en.pdf

This has the potential to be a disaster for domain owners if scenarios are not mitigated prior to a large attack.

Thank you @Rob Monster for leading this issue!
 
Last edited:
3
•••
So was this sinkholing related to the one that is described in the document at the following link? If so, it does seem that a fair amount of oversight was employed. However, the dates don't correspond. This was years ago, so how is it possible to hand register a domain 11 months ago that they then decided to sinkhole, is the key question.

https://www.europol.europa.eu/newsroom/news/‘avalanche’-network-dismantled-in-international-cyber-operation

The document has the countries who were involved, but I could not find statistics on the domain extensions involved. Does anyone know for example what fraction of the 800,000 were .com?
Will take a look at the transfers later this morning, Bob.
It won't be precise but it should be enough to give an idea.

Regards...jmcc
 
3
•••
This is the hosting history for OREUX.COM:

Old hoster - New hoster - Month - Zone Date - Transaction

UNDEVELOPED.COM SHADOWSERVER.ORG November 2018 2018-12-01 Transfer
REGISTER.IT UNDEVELOPED.COM July 2018 2018-08-01 Transfer
N/A REGISTER.IT January 2018 2018-02-01 New
DOMAINCONTROL.COM N/A November 2014 2014-12-01 Deleted
N/A DOMAINCONTROL.COM October 2012 2012-11-01 New
PARKINGWAY.NET N/A March 2007 2007-04-01 Deleted
N/A PARKINGWAY.NET February 2007 2007-03-01 New
INTERIMNAMESERVER.COM N/A October 2005 2005-11-01 Deleted
ACZL.COM INTERIMNAMESERVER.COM September 2005 2005-10-01 Transfer
N/A ACZL.COM September 2004 2004-10-01 New
EASYPOST.COM N/A June 2004 2004-07-01 Deleted
N/A EASYPOST.COM May 2003 2003-06-01 New

The odd thing is that the domain name was out of the zonefile since the December 2014 zonefile. If the Add Grace Period/AGP was being used to register and then drop these domain names within the five day AGP, it might not have been seen in the monthly checks.

The number of inbound transfers as of the 01 December 2018 zonefile with respect to the 01 November 2018 zonefiles were:
COM: 358
NET: 34
ORG: 0
BIZ: 2
INFO: 0
MOBI:
NGT: 1

In .COM and .NET, most of the transfers were 5Ls. With .COM, Chinese hosters/registrars dominated the transfers.

Just looking at the counts and it seems that some auction sites and PPC parkers are caught up in this. UNDEVELOPED.COM lost 6. ZTOMY.COM lost 6. BUYDOMAINS.COM lost 3. BRANDBUCKET.COM lost 3. THIS-DOMAIN-FOR-SALE.COM lost 3. PARKLOGIC.COM lost 3. INTERNETTRAFFIC.COM lost 3. AFTERNIC.COM lost 2. ABOVE.COM lost 1.

The .NET transfers also show a significant Chinese hoster/registrar share.

There are some odd inclusions in that domain names appear to have been deleted and then reregistered. The new buyer may have been unaware of the history of the domain names.

This is the .COM domain length (excluding '.COM') for the domain names on SHADOWSERVER.ORG:
Length - Count
| 5 | 1288 |
| 6 | 762 |
| 7 | 733 |
| 8 | 796 |
| 9 | 902 |
| 10 | 906 |
| 11 | 837 |
| 12 | 2225 |
| 13 | 1271 |
| 14 | 2009 |
| 15 | 1276 |
| 16 | 1140 |
| 17 | 4547 |
| 18 | 695 |
| 19 | 404 |
| 20 | 251 |
| 21 | 168 |
| 22 | 106 |
| 23 | 58 |
| 24 | 27 |
| 25 | 4 |
| 26 | 5 |
| 27 | 3 |
| 28 | 2 |
| 30 | 1 |

There's a combination of natural language domain names and also algorithmically generated domain names. The 5, 6, 12, 14, 17, 18 length domain names seem to be botnet associated ones. The 5 length domain names are all alphabetical. Suppose that ICANN had a lucky escape. ;)

Regards...jmcc
 
5
•••
Wow what a wealth of information @jmcc! Thank you!

So it appears the domain in the thread was indeed not in use from Nov 2014 until hand registered in January.

So the ones sinkholed were from various places with 6 at Undeveloped and 3 at Brandbucket. These and some others (like the 2 Afternic) were obviously for sale, it would seem without owner or potental buyers suspecting. Interesting none parked at Sedo.

I had not thought about length. I suspect your noticing the alphabetical is the key to their statement about sinkholing names that might in future be used in malware.

If the purpose of a domain is a kill switch as in the WannaCry case it seems risky that they use as short as 5 length com as any combination that short in com is likely to get registered anyway.

Thanks again for your superb contribution to what we know.

Bob
 
Last edited:
2
•••
Wow what a wealth of information @jmcc! Thank you!

So it appears the domain in the thread was indeed not in use from Nov 2014 until hand registered in January.

So the ones sinkholed were from various places with 6 at Undeveloped and 3 at Brandbucket. These and some others (like the 2 Afternic) were obviously for sale, it would seem without owner or potental buyers suspecting. Interesting none parked at Sedo.
I think that there was at least one on Sedo. It looks like a bit of a mess in that domain names were allowed to delete and then were reregistered.

I had not thought about length. I suspect your noticing the alphabetical is the key to their statement about sinkholing names that might in future be used in malware.
The problem with some in the legal profession is that they don't seem to realise that the people writing malware may realise that a particular type of domain name had been used in the past as a killswitch and they may not use that kind of domain name again. The length of the domain name could be a function of domain name generation algorithms.

A lot depends on the kind of domain name generation algorithm in use. If the algorithm was just going to use short alphabetical domain names, then it is a limited number of possibilities. If numbers and hyphens are added then the number of possible domain names increases. Some of the alpha-numerical domain names seem to be algorithmically generated domain names for botnets and other malware.

The big danger with an open ended "future use" sinkholing is that it has no precision. Valid domain names/words could easily be caught up in this kind of action. If that reasoning was applied to some of the NGTs then some of the market leaders would easily lose domain names because some of the registrars facilitated randomly generated domain name registration in the heavily discounted NGTs. Another important issue is that the world does not speak English. A domain name that does not make sense in an English speaking market might make perfect sense, for example, in the Chinese market.

If the purpose of a domain is a kill switch as in the WannaCry case it seems risky that they use as short as 5 length com as any combination that short in com is likely to get registered anyway.
It depends on whether they decide to incorporate a killswitch. I suppose that the battle between malware writers and AV people is not unlike codebreaking. In codebreaking, if something allows a code to be broken, it has to be treated carefully so as not to alter the opponent. The publicity surrounding the WannaCry killswitch neutralised that approach being used to stop a future malware attack because any malware writer will probably take care not to repeat that kind of error.

Regards...jmcc
 
4
•••
3
•••
Honest question, what if this happened to a large entity like Google just for example. Someone just gonna take that?
 
3
•••
Just left another voicemail with the DOJ contact for this case, Colin Callahan. I am documenting here the ongoing good faith effort to whitelist a domain that was wrongly sinkholed, and the non-responsive handling by the DOJ to address request for timely cure for this particular domain. There is a larger issue of Due Process for takedowns generally but for this immediate case of collateral damage of an innocent domain, it would appear that the agency responsible for compiling the sinkhole list is unresponsive.
 
6
•••
Just left another voicemail with the DOJ contact for this case, Colin Callahan. I am documenting here the ongoing good faith effort to whitelist a domain that was wrongly sinkholed, and the non-responsive handling by the DOJ to address request for timely cure for this particular domain. There is a larger issue of Due Process for takedowns generally but for this immediate case of collateral damage of an innocent domain, it would appear that the agency responsible for compiling the sinkhole list is unresponsive.
Thanks Rob!

Also important would be the protocol for the blacklisting. To be able to whitelist, we should be able to understand the blacklist process, start to finish.
 
2
•••
Does anyone here have a list of all the domains that were seized by ICE? i.e. presumably this seizure was just part of the operation discussed at:

https://www.ice.gov/news/releases/over-million-websites-seized-global-operation

https://www.techdirt.com/articles/2...-that-copyright-trademark-are-different.shtml

It might be useful for the ICANN RPM PDP working group (if it was really "TM infringing" domains, as opposed to simply copyright violations in the content of non-TM infringing domains), where we're studying things like the UDRP, URS, etc

If it's in a court file, etc., please tell me the case number, etc.
 
1
•••
Does anyone here have a list of all the domains that were seized by ICE? i.e. presumably this seizure was just part of the operation discussed at:

https://www.ice.gov/news/releases/over-million-websites-seized-global-operation

https://www.techdirt.com/articles/2...-that-copyright-trademark-are-different.shtml

It might be useful for the ICANN RPM PDP working group (if it was really "TM infringing" domains, as opposed to simply copyright violations in the content of non-TM infringing domains), where we're studying things like the UDRP, URS, etc

If it's in a court file, etc., please tell me the case number, etc.
I'm not sure, but my guess is that the 1 million websites are different from the 800k domains seized. The latest one's were seized first in 2016 and released when they have expired and the court order was renewed in november 2018 sio that they are seized again. I could be wrong, but that's what I see, so the total will be close to 2 million domains names if you count both operations.
 
3
•••
Does anyone here have a list of all the domains that were seized by ICE?
I see some of them regularly in the web usage surveys. I think that some of them used to be moved to a particular set of nameservers. The TLDs aren't mentioned but it would not be surprising if some of them were new gTLDs and particular ccTLDs. The domain name used in the press release was shifted to SEIZEDSERVERS.COM but that only hosts 1370 C/N/O/B/I domains as of 01/Jan/2019. Some of the domain names seized through civil actions are generally pointed to the brand owner's sites or a kind of trophy page.

It might be useful for the ICANN RPM PDP working group (if it was really "TM infringing" domains, as opposed to simply copyright violations in the content of non-TM infringing domains), where we're studying things like the UDRP, URS, etc
There's a combination of things that make these targeted domain names stand out. Some of them use TMs in the domain names but many would have websites selling counterfeit goods. The heavily discounted NGTs really do facilitate this type of abuse. Some of them are promoted in search engine results using link injections on compromised Wordpress sites.

Regards...jmcc
 
2
•••
Olitt — high-converting AI websites, only from $1/moOlitt — high-converting AI websites, only from $1/mo

We're social

Escrow.com
Spaceship
Domain Recover
CryptoExchange.com
Catchy
DomDB
NameFit
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back