Many dark web constructs. The most notorious/popular is Tor/Onion. Built for anonymity. The home of criminals, black hat hackers… Trading Post for illicit software— Ransomware, hijacking, DDOS, phishing. Trading in stolen SS#s, credit card numbers, drugs, weapons, and people Visible web Deep web Dark web 9/24/2018
Phishing Expeditions Accumulate email addresses of website managers Send malware with key loggers Gain control of website – Install malware for ransomware ware aaomojomolo1979 aaomojomolo@hotmail.co.uk absolutezero641950 absolutezero64@hotmail.com achardt1966 achardt@outlook.com alexandraboies11976 alexandraboies1@hotmail.com allen.kong1964 allen.kong@hotmail.com altheapaul1981 altheapaul@hotmail.com andersonah5201994 andersonah520@hotmail.com andilila911995 andilila91@yahoo.co.id andreacohen42005 andreacohen4@hotmail.com andreacuyun231986 andreacuyun23@hotmail.com andrew.281957 andrew.28@live.co.uk andy.bt1985 andy.bt@live.com annlouiseberg2000 annlouiseberg@hotmail.com antalon2pbs1962 antalon2pbs@hotmail.com antoniod372000 antoniod37@hotmail.com ashley_m_mason1995 ashley_m_mason@hotmail.com bshepard8271969 bshepard827@msn.com bucketless581962 bucketless58@hotmail.com bzindler_881962 bzindler_88@hotmail.com 9/24/2018
http://lanetharp.com/?716=UAWDHGBuYKV1mQHTRQGZCQi emails 9/24/2018
http://cosmicregistry.org/?5d16r=UAWDHGBuYKV1mQHTRQGZCQi 9/24/2018
http://www. bluedot. co. za/l5afva/getnum. php http://www.bluedot.co.za/l5afva/getnum.php?id=ODA2NGtlbmdhYmVsbWFuQHNvZnRzdGQuY29tNTgyOA== 9/24/2018
http://cadillaclouisville.com/?8Si7jR=UAWDHGBuYKV1mQHTRQGZCQi 9/24/2018
http://jeffbigcountrycaldwell.org/?0KhP=UAWDHGBuYKV1mQHTRQGZCQi 9/24/2018
http://greatharvestbirmingham.com/?28G4gW=UAWDHGBuYKV1mQHTRQGZCQi 9/24/2018
http://www. bluedot. co. za/l5afva/getnum. php http://www.bluedot.co.za/l5afva/getnum.php?id=ODA2NGtlbmdhYmVsbWFuQHNvZnRzdGQuY29tNTgyOA== http://cadillaclouisville.com/?8Si7jR=UAWDHGBuYKV1mQHTRQGZCQi http://jeffbigcountrycaldwell.org/?0KhP=UAWDHGBuYKV1mQHTRQGZCQi http://volvolouisville.com/?04=UAWDHGBuYKV1mQHTRQGZCQi http://sanfordshuttles.com/?048m05=UAWDHGBuYKV1mQHTRQGZCQi http://cryptocurrencypaperwalletcertificate.info/?76=UAWDHGBuYKV1mQHTRQGZCQi http://xyz123web.com/?2A3=UAWDHGBuYKV1mQHTRQGZCQi http://titanapplied.com/?41Awq=UAWDHGBuYKV1mQHTRQGZCQi http://marketexposures.photos/?5aIR=UAWDHGBuYKV1mQHTRQGZCQi http://hostnana.com/?1UA=UAWDHGBuYKV1mQHTRQGZCQi http://www.ceobusiness.com.br/29hevlu/64fngu.php?a2VuZ2FiZWxtYW5Ac29mdHN0ZC5jb20 http://mahboobasif.com/?7u5g6K=UAWDHGBuYKV1mQHTRQGZCQi http://exumaanimalhospital.com/?0SEAU=UAWDHGBuYKV1mQHTRQGZCQi http://civicleagueyouth.com/?207=UAWDHGBuYKV1mQHTRQGZCQi http://wellnesscenterofnashville.com/?3O4382=UAWDHGBuYKV1mQHTRQGZCQi http://keithharenda.com/?68Tdyk=UAWDHGBuYKV1mQHTRQGZCQi http://greatharvestbirmingham.com/?28G4gW=UAWDHGBuYKV1mQHTRQGZCQi http://716chopshop.com/?43=UAWDHGBuYKV1mQHTRQGZCQi http://businessplanbenchmark.com/?0w2HE=UAWDHGBuYKV1mQHTRQGZCQi 9/24/2018
Pay Ransom With Bitcoin Wallet is a randomized ID holding private key. Blockchain is history of every transaction segmented by checksum- difficult to calculate, easy to verify. Two parties construct a transaction. Transaction could take hours to appear in blockchain. Your Bitcoin holdings is the sum of your transactions in the blockchain. 9/24/2018
How you can be Identified and surveilled ISP DHCP server assigns you a unique IP number 72.135.35.66 mfg MAC address is required by ISP 2C7E81CBDA43 MAC used in 802 Wi-Fi protocols ISP assigns users a DNS server Authorities can tap the user connection at the switch 9/24/2018
Overcoming ID and Surveillance HTTPS Origin/destination are exposed vulnerable to man-in-the-middle attacks (third party DNS server) VPN protocol minimum destination header – origin protected transport and application layer protected Proxy server varying levels of protection destination usually informed of proxy in progress Public Internet-Wi-Fi passwords are simple to break ID usually limited to physical signal boosting techniques Ghosting a MAC address MAC address as a fingerprint 9/24/2018
MS .NET RNGenerator Distribution Test Standard deviation 100K 06.248 150K 07.442 200K 08.621 250K 09.704 300K 10.466 350K 11.258 400K 12.021 450K 12.785 500K 13.661 3C703E596F7520636F756C642074656C6C20616C6C206F6620796F757220667269656E647320616E642066616D696C792 9/24/2018
Tor/Onion http://nql7pv7k32nnqor2.onion Most popular of several dark constructs version of Firefox/Chrome roots back to Mosaic Any ability to ID user or activity is stripped out. Multiple levels of encryption Proprietary “DNS” service Google cannot/will not index it. Not quite HTML/HTTP Packets are sent through at least 3 relays before the destination. Surveillance won’t see final destination http://nql7pv7k32nnqor2.onion 9/24/2018
Secure eMail Addresses To register on most onion sites require a secure email address Unlike surface web – these providers promote anonymity ProtonMail Torbox Mail2Tor 9/24/2018