Nik Cubrilovic

  • About

Large Number of Tor Hidden Sites Seized by the FBI in Operation Onymous were Clone or Scam Sites

Published:

Modified:

This post is the first in a series dealing with the takedown of Silk Road 2.0 and Operation Onymous. The data in this post was put together with @secruedmh and @imposter. A big thanks to Juha Nurmia and his Tor Hidden Service Index, and researchers who share their work or report on stories such as lamoustache, gwern, deepdotweb along with others who don’t wish to be named for helping us fill in our index and cache. For updates follow on twitter.

In the two weeks since Silk Road 2.0 and a large number of other Tor hosted hidden services were taken down as part of Operation Onymous, we have crawled and indexed onion sites to find out just how many sites were seized and what sites were seized. Initial reports said 410 sites were seized, then 400 and this number has continued to be revised down until Europol said only some two-dozen sites were seized. Our crawl of just over 9,000 onion sites has found 276 seized onion sites.

The full table of seized onion sites discovered is below, an overview of the data and some findings:

  1. Out of a total of 276 seized onion addresses found, we identified 153 of the addresses as belonging to either clone, scam or phishing sites.
  2. Of the 153 clone or scam sites, 133 were clones and 20 were scam or phishing sites.
  3. In a number of cases the FBI has seized the clone or scam version of a site while leaving up the real site.
  4. In May of 2014 a bot known as the “Onion Cloner” was discovered and became known to Tor hidden service operators. This bot would find Tor hidden sites and clone them on its own address in an effort to steal passwords or intercept Bitcoin transactions. Of the 133 clone sites that the FBI seized, a large number of them were clone sites produced by the Onion Cloner that were mistaken for the real copy.
  5. Of the 8 websites mentioned in the FBI press release, 2 are clones and 1 is a scam site.
  6. Of the 32 onion addresses mentioned in the DOJ seizure notice filed in US court, 3 are scam sites and 9 are clone websites.
  7. As far as our survey has revealed and based on prior data about the Onion Cloner, every single Onion Cloner clone site has been seized or is no longer available.
  8. For the following sites, the clone or fake version was seized while the real site remains live: Cannabis UK, CStore, Dedope, Executive Outcomes, FakeID, Fake Real Plastic, Hackintosh, Pablo Escobar Drug Store, Real Cards Team, Smokeables, Zero Squad. Some of these sites were mentioned in the FBI press release or court seizure notice as having been taken down when in fact the clones were seized.
  9. There are almost 200 sites that have been seized that are not mentioned in any seizure notice or press release. These include the (real) sites for Fish Squad, Exposed, Hack the Planet, Cash Machine, DOXBIN, Pink Meth, OnionSphere, Mr Ouid’s Forum. That list includes personal websites, forums or other sites that had no outward appearance of illegal activity, and they are also not mentioned in any court or press documents. These sites were seized with what appears to be no, or little legal justification.
  10. Scam or phishing versions of Silk Road 2.0, Agora, Real Cards Team, Evolution and many other sites were seized.
  11. For some of the onion addresses, being mentioned in the FBI press release or the seizure notice is the first and only ever public web mention of the address.
  12. The website “Executive Outcomes”, which the FBI claims in seizure notices and press releases was a retailer of firearms was a well known scam site – it never shipped any weapons but took users funds.
  13. A clone of a Jihad funding website called “Fund the Islamic Struggle without leaving a trace” was seized, while the real website remains live (and has accepted over 5 BTC in donations)

Indications of Method

That the FBI seized so many clone and fake websites suggests a broad, untargeted sweep of hidden services rather than a targeted campaign. The slapshot nature of how sites were seized suggests that rather than starting with an onion address and then discovering the host server to seize, this campaign simply vacuumed up a large number of onion websites by targeting specific hosting companies. We have tracked down the hosting companies affected and the details will be published in a follow-up.

On that note, if you were the administrator of a hidden site that was seized, be it a clone or a real site, please get in touch. I’ve spoken to a number of admins and hosting companies and have put together what the seized sites had in common in order to deduce the method used to locate them. Information from admins and hosts is invaluable in working out what the weaknesses of the seized sites was, and what can be learned from the seizures. There is a high likelihood that none of the seizures will be tested or revealed in court, at least not in the short term, so getting this information is important.

Tor Onion Data

The database of hidden sites, which I believe is the largest that has been collated, will be posted to this GitHub repository sometime in the next couple of days. An earlier version of the crawler used is also available on GitHub. We are currently putting together an index of data from the seized sites, including the forums, and other Tor hidden services along with a search engine. If you’re interested in contributing or adding data to it send a pull request.

*Table key: Column S = Site mentioned in DOJ seizure notice. Column P = Site mentioned in FBI press release*

SiteHostSP
Tor Bazaar Forum22iwhc2luicynjqy.onion
Fake ID23swqgocas65z7xz.onionClone**
NLGrowers25ffhn7bm5fget24.onionScam
Tor web developer:2hcruaawg3e55vfa.onionClone
The Dealer:2sr3d7kvco5iy6ws.onionClone
Doublespend2xfmz7uf6ip6kpg3.onionScam
The Hidden Wiki (mirror):33lwkzt672innsj6.onionClone
KavkazCenter:33vqatzbvipi5ghe.onionClone
Trava Pricelist34j2fiy32xwuxsku.onion
Sea Kitten Palace:3cvsdlyltwapggbf.onionClone
EU DRUGSTORE:3d635wnxku6h43eg.onionClone
FAQ :3e5rqv7542gxvwpk.onionClone
Bitiply3ioo62dyl5xawlmw.onionClone
3nslokdcllxywuxp.onion
TORFORUM:3osf4ttzukk5aouy.onionClone
Tor Bazaar3p42y56a76g6okuv.onion*
Fund The Islamic Struggle Anonymouslybc3nbr42tdnqamvs.onion
Exposed – The Secret Web4dpc64mjcbu5kkyn.onionClone
AYPSELA news:4jdirmqv2o65dlum.onionClone
Cloud Nine4jt6iq3r3agaldg7.onion
EasyCoin Bitcoin Wallet & Mixer”4p7orzshxhif6cfz.onionClone
TorShops4ywfa43x2dutp5ta.onionScam
Jotunbane’s Reading Club:52frxf3nn43n6rt5.onionClone
BrainMagic5j7o54ivsh3qqgu3.onionClone
1 Hour Laundry:5mkcloe3kuefrqvr.onionClone
Fast Cash!5oulvdsnka55buw6.onion**
TorBox:5wxxvwnsvwsv2ens.onionClone
Farmer15x5hcw4ym6nno42p.onion*
GreenPaper Counterfeiters (Super Notes)67yjqewxrd2ewbtp.onionScam*
Onion Mail:6e44iwci5e6iodyw.onionClone
Green Machine6hstmidevw5dhkct.onion
The Green Machine6ijclyvilv53ll76.onion*
SteamLoader:6nkwg6ngv5txpfqc.onionClone
Doxbin / DeDope6odhiu7bke342ip5.onion*
Green Dragon Supplier6wlmeo5zdm5jzex5.onion
Evolution (Phishing)7bt3s7ikypzurhue.onionScam
Wall Street Tor:7ttedph3rjhoh24y.onionClone
7xghcctm7r5ef6ce.onion
Cash Flow7y6e3uutyvoi2myq.onion
Babylona7jtfnjllglyjq4q.onion
Onion Identity Servicesabbujjh5vqtq77wg.onionScam
USFakeIDsabo7iovzgznlqbno.onionClone
Lossless Audio Files:afismo35weljjdcv.onionClone
KognitionsKyrkan:afkpdjdkvkir4mp4.onionClone
Agora (Phishing)agorazbdc4zq5oww.onionScam
Alpacaalpaca727o3c75xx.onion
Alpaca Marketplacealpaca7bcqv2rnu3.onion*
SOL’s Unified USD Counterfeit’saodaost3cbxnzgno.onionClone*
Cloud Nineaoyukbwlwxzcllet.onion
NLGrowers:aukpec3jyuuoe5cm.onionClone
img.bi:b35trto3blj4bpq4.onionClone
Onionweb filehosting:b3xbwcuuflw73r5u.onionClone
TORCHb7i32g7huhreg2dd.onionClone
Tor Bazaarbazaar755zbjb121.onion*
Tor Bazaarbazaarlv2a7i3uyn.onion*
Onion Channelbcyh7mzfrekxobud.onionClone
Cloud Ninebg62ti72ckuo6rm2.onion
Blue Skyblueskyplzv4fsti.onion**
Mysteriousbt7wb565zgx3xuug.onionClone
Bungee54bungee54uqchxfny.onion*
Lion Pharmabvhbasj4jxhwc7d7.onionClone
Cloud Nine (Main)bviaqyj6obc54vhn.onion
Cloud Ninec6x3fexjje4uaczd.onion
c76dtzddabepos74.onion
Buy Twitter Followers:c7kbn6qnsw6glp5c.onionClone
Cannabis Roadcannabiskofvl7pa.onion*
Hack The Planetchippyits5cqbd7p.onion
Cstore – Carded Storecstoreav7i44h2lr.onion
MAGIC MUSHROOMS STORE:cvy25jynw7g6tamj.onionClone
Cloud Ninecxhlovvocanzs7ka.onion
TorSafe:cxyamaiowtvnj22a.onionClone
Cloud Ninecyeji6dcpvad5zsq.onion
Cloud Nineczl2oqmd3ovghwk5.onion
The Pot Shopd5jkxy5i6r3sddfw.onion
Data Bindatabinhwin4xuxx.onion
DeDopededope6uu7errzu3.onionScam
Steal This Wiki mirror:dejxz2tiz6f5nbrp.onionClone
Black Marketdgoega4kbhnp53o7.onionClone*
Black Market:dgoegaf7vnu3uowm.onionClone
Clean My Coins Fakedjyy6p2ohwkkmn2l.onionClone
Andromedadlifghyxshlgjlzw.onionClone
Help Guydm4gtebssktdskxn.onionClone
Blackbank Market (Scam)do37y4wk2detgi6x.onionScam
Cannabis UKdokpyl6egokvejos.onionClone*
Doxbindoxbinbhx7nvfq62.onion
Doxbindoxbindtelxceher.onion
Doxbindoxbinicsjqqmohl.onion
Doxbindoxbinphonls5hsk.onion
Doxbindoxbinumfxfyytnh.onion
Doxbindoxbinyvbolyfhss.onion
Doxbindoxbinzqkeoso6sl.onion
Pablo Escobar Drugstoredrugs6ayt3njhzha.onionScam*
Doxbindxwmc6b3mtklq44j.onion
The Armory clonedzc6ptsiaajb3mjj.onion
Amberoade2lp3d74xdfqmguk.onionClone
Silkroad 2.0:e5wvymnx6bx5euvy.onionClone
Outlaw Marketeaq2e77pmdvrepbq.onion
EasyCoineasycoinsayj7p5l.onion
Cloud Nineeb3bbtsqywrdo5ae.onion
Real Cards Teamen74n7uqro3flkmz.onionClone*
Cloud Nineepj7nsddjr3jaorc.onion
Cloud Nineepvjwvjhqs74iq7l.onion
EuroGunseurogunjz5w4qb46.onionScam
Exposedexposed36mq3ns23.onion
Sell your pictures for Bitcoinsf2x5eapxymahuf2t.onionClone
EuCannaf4ggfopjge6utz3n.onionClone
fbnu5jkwi2daxcze.onion
Cstore – Carded Storefd4qqglswwsv6fph.onionClone*
Deutschland im Deep Webfjgf5eo4zyntgbus.onionClone
Flugsvampflugsvampfgdzp76.onion
Bitcoin For Proxyfogcoreohrvfeur5.onionScam
Cannabis Roadforumzxmoorof4ja.onion*
Welcome, We’ve been expecting you!:”foubiqu6uin2dv2n.onionClone
USA/EU Fake Documents store:ftkfjfsbsc3yebzw.onionClone
Laundry King:fvb7crr4hu7u57m6.onionClone
Apples 4 Bitcoinfvpibvo6tphexfvl.onionScam
Double Your Bitcoinsfwpplqylgbpjymrr.onionClone
MALINAfzmmntb5ufod2zyt.onionClone
TorFind:g3tqsiw5rc6d6vmc.onionClone
konkret – das linke magazinegcymml5rdr6lhpto.onion
ghwntyvlyt5t65l4.onion
Словесный Богатырьgr4dszr5zd2k44qa.onionClone
Deep Web Radio:gzkqe6rodeexilic.onionClone
DuckDuckGo:h2dbmwstr6klbsi6.onionClone
The Pirate Market:h5nfci2xgob2nheu.onionClone
Cloud Nineh5ry3wfk7md3vkfc.onion
Cash Machinehcutffvavocsh6nd.onion
The PaypalCenterhd74evbdzn6cl264.onionScam
heqiepy33ssju7bn.onion
Black&Yellowhwvx64v3zu43ih75.onion
Hydra Forumhydrafmchvpq5yc6.onion*
Hydrahydrampvvnunildl.onion**
Hydra Russianhydraruehsdjjfud.onion
TorSearch:i7fahngv323nndta.onionClone
Executive Outcomesiczyaan7hzkyjown.onionClone**
Fake Real Plasticigvmwp3544wpnd6u.onion**
TorGameDepot:ilf5incisxerov56.onionClone
Cloud Nineitjsuhezvyyi7pjg.onion
ixfdahfew32luevo.onion
Super Notes Counterj62alxawj7624ejg.onionClone
Hydraj6372sksh6uolrzz.onion
Site do Renan Jackson:jcfcrq76kdc4ghmo.onionClone
Cocaine Marketjd3gdrtmhm7vwudx.onion
CYRUSERV:jf5p4debofmd2kdq.onionClone
Mr Quid’s Forumjfekrr6wghtmalpd.onion
Apple’s Torjff4wifbjuqmhubb.onionClone*
OnionNews:jgfoj3jyfinnrbs5.onionClone
Cloud Ninejgpvu5d5fufwpqa7.onion
Cloud Nineji45q56enmtidgl5.onion
Cheap Eurosjmntdqtytkuhqlzu.onionClone
The House of Cards:jmobhake4txapqd7.onionClone
paraZitejuctmzs5jwu3cd6l.onionClone
Cloud Ninejz3rmfugjt5eiyr5.onion
WeBuyBitcoinsjzn5w5pmhmbqxmzi.onion
Onion Identity Servicesk5dvoeyiwakymez5.onionClone
DeDopekbvbh4kdddiha2ht.onion
Apple Palacekcan7d4ahhryu6gg.onionClone
The Hidden Wikikpvz7ki2v5agwt35.onion
The Tor Library:lgic2yjpimouvjnw.onionClone
Cloud Ninelhckzzv3qlvcwfg2.onion
Doxbinlhvxqyd7ux2oinn7.onion
Kamagra for Bitcoin:lnien5hngzlojppv.onionClone
The PayPal Centerlygnimwoedhioopl.onion
Silkkitiem2lbhzmzmfv5a763.onion
Vault43m7653h3gcw7d2ytf.onion
MALINAmalina2ihfyawiau.onion
CebollaChan:mdlhkgnddfijuh4z.onionClone
Runionmescqp3y3sfo27rm.onionClone
Hidden Betcoinmqaa6l5vb7rbpksf.onion
The PayPal Centermv5cb4hz3ecscshx.onion*
Cloud Ninemx7rzz5my2fq46wz.onion
Prepaid Bliss:n5qsqwl2y3qrr2jq.onionClone
Cloud Ninen7hwwwncx3bcx5vc.onion
Cloud Ninened32wtuel43cxbf.onion
Torchan:noqfeqisdgchn7zb.onionClone
Doxbinnpieqpvpjhrmdchg.onion
MORAL.NUnskxjg4c3nvwzxuw.onionClone
Paypal-Coinso3ecpxemcg4itdoy.onionClone
Onionshoponionsvpscug6wpk.onion
The Secret Story Archive:oqgylsk6seo42gpk.onionClone
Tor Bazaar Betaorjidjtyniyzn5il.onion
Drug Marketoxr3dae6epxdc4pg.onionClone
The Secret Story Archive #1st:oxrxwesdxlnwsj3x.onionClone
USJUD Counterfeitsp4ecvpaclc44j3jz.onionClone
Cloud Ninep6qx55i5r64mxq7n.onion
Pandorapandora3uym4z42b.onion**
Clone Sitepbq2zmsrh4cdxdxl.onionScam
UK Passports:pclb34gpalrdxj4u.onionClone
nachashpenisycpu3fixdcr.onion
Green Dragon Supplierpg5epl6suareiqq6.onion
Old Man Fixer’s Fixing Servicesph22uxxxttai7v2n.onionClone
BitPharmapharmagbsxol4n4k.onion
BitPharmapharmajiyhpjflqi.onionClone
Pink Methpinkmethuylnenlz.onion
Mobile Storepptzzk2wye6rfeki.onionClone
MailTor:pyvdmllsh6mczfgb.onionClone
PayPal4Uqbikfpcr4mhqoumm.onion
R2D2qrfnwgdjdsgtx5u4.onionClone
Tor Carding Forumsqtr46f7bgf4kzt7q.onion
Cloud Ninergam2tqpqhelm4ow.onion
Cloud Ninerhmhjalcohuys4a5.onion
UK Guns and Ammorhqetwhda65zcakj.onionClone
RUForum:rk5pbdbyrqksxui4.onionClone
Hidden Wiki:rmhpp6w3ncrvxiub.onionClone
Tor:rmnd3b5dvuqtshlh.onionClone
Cloud Ninerndm56yv54aqe7pn.onion
Example rendezvous points page:rqjfolmb2h7iqdvq.onionClone
Thunder’s Place:s5yvlnz7qljsdmtc.onionClone
ccPalsafj5y2f45whsvvs.onionClone
Cloud Ninesdjv72hp5x6pt5en.onion
Doxbinsenmtjpxn2m72nlu.onionClone
Silkkitiesilkkitiehdg5mug.onion
Silk Road 2.0silkroad3og4b6bq.onionScam
Silk Road Forumssilkroad5v7dywlc.onion
Silk Roadsilkroad6midjsbr.onion*
Silk Roadsilkroad6ownowfk.onion
Smokablessmoker3gvmgfbi4e.onionClone*
Brave Bunnysqxamnigeby5u37b.onionClone
Wikileaks New link:srozpqsnh2lgyewu.onionClone
Cloud Ninesrz5wvnyd7skt5uh.onion
samsungstorestoregsq3o5mfxiz.onion
Флибуста | Книжное братство”su74joxcacuafyq6.onionClone
[Forum PHISHING LINK]t6la6i24jkow5roh.onionScam
Cloud Ninetaifcjgrifyjiwey.onion
Apples 4 Bitcointfwdi3izigxllure.onionScam
USA Citizenshiptgielwnuv3xzfg7r.onion
Topixtopixslhezyytrvm.onion
â… TOR-SERV â…:torservsbt7rsbfg.onionClone
Cash Machinetpe3rm2w4fkbtciu.onionClone
Galaxy Social Networktvbkrvflzx2pmvpw.onionClone
The Hidden Marketuaq62zdqnjr4xo4q.onion
Rent-A-Hackerubquja4ech6symkv.onionClone
Assassination Market:ugq2p64trcyg3xgt.onionClone
Code:Greenuhfftlqlyjnelhcf.onionClone
Real Cards Teamujompjlrdgbhkmuj.onion
Dark Hosting:ul4kmrygtkhbb5vz.onionClone
samsungstoreunsbwt2utosasdxq.onionClone
keys open doors:uqbmgvisfz2wpj4v.onionClone
Creative Hack:urjlsqe373ismjwg.onionClone
Fake Real Plasticvc5apwufjoil3svw.onionClone
Torbook:vg4gxg3mjymuh54x.onionClone
Green Star Station:vgfzmngu7dh5ye76.onionClone
Hack The Planet:vpkyqijluxa33ywp.onionClone
Rich Richard:vz3ofn5f2lous44c.onionClone
Doxbinwn323ufq7s23u35f.onion
woacuqcx45nfnfxy.onion
HQERwtpum5yzyihiewlq.onion
Golden Nuggetwyj4d4u237p3coca.onionScam
lol 20th Century Western Musicx4am6cpmndsqzbu2.onionClone
x4bfgkcuwiousozy.onion
Cloud Ninex7ikq6a3qx5qjikf.onion
CC-Planet Fullzxadxysdnd3ug2dea.onion
Hydra Forumsxdbn2gsuk74nwd7f.onion
Clean My Coinsxgrsaj3wykpofseb.onion
RepAAA’s Hidden Empirexskus6q7olpdlrkb.onion*
Cloud Ninexvqrvtnn4pbcnxwt.onion**
Beneath VT:y4hzxepemtqcf4qh.onionClone
paraZitey66x4b3jrt3mnglw.onionClone
Onion Wallety6dyzauztb5u2ufa.onionClone
Flugsvampyakwbcn5ou2wkzfx.onion
Cipollaybphbuwerurne43o.onion
ycjvz5cu3mjc4wyd.onion
Suojeluskunta:ycngkogtvlaphgx2.onionClone
Cloud Nineye5n3ecw64utvmmh.onion
Onix Electronics:yhu73qfnjti3cmvf.onionClone
Zyprexa Kills:yifsrwkdvjiojr7w.onionClone
Peoples Drug Store:yrenuxvrrhmuvces.onionClone
USD Counterfeitsyrpavngfbhbc3tcc.onionClone
BuggedPlanet.Info:yy5pepg54c5jry36.onionClone
Zero Squadz5fvd3hwmtzkgaqy.onionScam*
The Intel Exchange:z7d7gx53ne7fouyf.onionClone
Cloud Ninez7rpuixjsncgomw7.onion
OnionSphere:zbojy7pmy5vrrcqe.onionClone
nekrotown:zect4qky5qdam2xd.onionClone
Bitcoin-escrow:zkwwpiiksjafjo35.onionClone
Mail2Tor:zv7lufndr4khlicg.onionClone
© 2023 - Nik Cubrilovic - follow @dir for blog updates