Skip to content

Instantly share code, notes, and snippets.

@susam
Last active September 26, 2023 21:28
Show Gist options
  • Select an option

  • Save susam/3cb42e571c4ab12987b286791bdfe9d2 to your computer and use it in GitHub Desktop.

Select an option

Save susam/3cb42e571c4ab12987b286791bdfe9d2 to your computer and use it in GitHub Desktop.

ghost commented Nov 30, 2019

Copy link
Copy Markdown

NIXI sinkholed your domain for malware in partnership with Shadowserver, presumably?

@susam

susam commented Nov 30, 2019

Copy link
Copy Markdown
Author

@gh-bct: NIXI sinkholed your domain for malware in partnership with Shadowserver, presumably?

Thank you for your comment. We can only guess. I was running a really small tech + math blog on my website. Further, it was a static website running on an up-to-date Debian system. I don't see any suspicious logins or processes running on the system. I wonder when and how a malware ended up on this system. And even if it did, why did I not get a notification before sinkholing the domain?

@myk1e

myk1e commented Nov 30, 2019

Copy link
Copy Markdown

Do you still have access to the email address used for this domain? Do you normally receive emails from your registrar? (just one troubleshooting question among others...)

@psuet

psuet commented Nov 30, 2019

Copy link
Copy Markdown

The Public Prosecutor's Office Verden (Staatsanwaltschaft Verden) is responsible for all criminal investigation regarding "IUK-Kirminalität" (crimes using communication technology) in the german state of lower-saxony (Niedersachsen). You might want to contact them:
https://www.staatsanwaltschaft-verden.niedersachsen.de/startseite/kontakt/ihr-weg-zu-uns-156526.html (in German; english is probably not possible; Translation needed?)

@susam

susam commented Nov 30, 2019

Copy link
Copy Markdown
Author

@myk1e Thank you for your comment. Yes, I do have access to the email address used for this domain. Yes, I do normally receive emails from registrar as well as Namecheap on this email. In this case, however, I had not received any notification or authorization request.

@yaleman

yaleman commented Nov 30, 2019

Copy link
Copy Markdown

The Public Prosecutor's Office Verden (Staatsanwaltschaft Verden) is responsible for all criminal investigation regarding "IUK-Kirminalität" (crimes using communication technology) in the german state of lower-saxony (Niedersachsen).

This is the most relevant information - law enforcement organisations typically redirect seized sites to shadowserver because it's a community sinkhole service for collecting malware/bot traffic.

@abbyck

abbyck commented Dec 1, 2019

Copy link
Copy Markdown

Never expect to get a reply from NIXI. You will never get. They are a bunch of lazy government employees.

@dalescraig

Copy link
Copy Markdown

Hello, did you know the domain name susam.cool is available at namecheap?

@susam

susam commented Dec 2, 2019

Copy link
Copy Markdown
Author

The Public Prosecutor's Office Verden (Staatsanwaltschaft Verden) is responsible for all criminal investigation regarding "IUK-Kirminalität" (crimes using communication technology) in the german state of lower-saxony (Niedersachsen).

@yaleman: This is the most relevant information - law enforcement organisations typically redirect seized sites to shadowserver because it's a community sinkhole service for collecting malware/bot traffic.

Thank you for posting this comment. The Shadowserver Foundation contacted me yesterday and informed me that my domain was sinkholed by accident. They contacted NIXI to transfer the domain back to me. I have added a section named Updates to this Gist post with more details about this.

@EpicnessTwo

Copy link
Copy Markdown

Looks like you have a small typo in the first date under Updates. You've put 30-Dec-2019 instead of 30-Nov-2019... Unless you're a time traveler!? :)

@susam

susam commented Dec 3, 2019

Copy link
Copy Markdown
Author

@EpicnessTwo Yes, there was a typo indeed. Thanks for reporting. I have fixed it now. By the way, I have now shared the full story here: https://susam.in/blog/sinkholed.html.

@EpicnessTwo

Copy link
Copy Markdown

I saw, it was a good read :) I'm glad to hear you got your domain back... just a shame how easy it is to loose it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment