Saturday, December 2, 2023

Dark Website Leaked its hidden server IP Address that Sells Illegal Cannabis Drug

An Illegal Dark website called ElHerbolario that sells Cannabis drug Leaked its secret server IP address online due to poor server configuration made by their server admins.

The Darkweb, invisible web, or hidden web are parts of the World Wide Web whose contents are not indexed by standard search engines for any reason.

Also Read: Mysterious Deep Web : Secrets from the Dark Side of the Internet

In this case, Leaked original IP Address leads to track the original site owner and seize the server and later Law enforcement will be playing against the owner.

This Drug selling Dark Website is an intermediate seller so that possible rate of doing illegally selling things like this type of Cannabis drug is obvious one.

This Dark Website is highly rated one Even though this belongs is Darkweb site that makes researcher go into a deep investigation.

How Does the Investigation go on – Dark Website

Initially, Researcher starting the investigation by checking the String of  ElHerbolario which is the name of this illegal website.

Later To find the content management system (CMS) for this site, he was checked by applying the “wp-admin” at the end of the URL which is unique to a WordPress site. but the attempt was failed due to the admin of the site ower disabled the wp-admin login form link.

Later Right click on it and click on “Investigate Element” to open the Network tab and reload it.The status is 200. 200 because Riku was sent to when you reload es means that capital was normal. So, it means that a folder called / wp-content / existed.

According to Researcher, So it was confirmed that owner of this site was using WordPress.The reason why we wrote about this folder is that in the same way, the database leaked out due to mistakes in folder permission setting on another drug seller’s site in the past.

In this case, he felt that E and L Seem unnatural, later he found that it means a herbalist in Spanish.so he confirmed that the person who built this server is a person who is related to Spain.

Later investigation revealed that website Server is NGINX and OS use Debian. But IP Address didn’t find in this area.

Last but not least, we do have a deep search Engines to find some mysterious things that we cant get it on google.

So he used one of the deep web Search engine called  Censys and search by using the characteristic word ElHerbolario.

There is “El Herbolario Personal Shop” on the top of the results in Dark Website list. and its shows the IP Address of the website.

Later by checking the  IP address to confirm the original site of the IP, it has been checked with Tor Brower.

Finally,  DDoS attack was found that it is a mirror server to be used when subjected to. In addition, the server uses Blazing fast.

This is famous as a bulletproof server. As you can see there are other uses of Debian and nginx. It is the same as the original server.

Website

Latest articles

Active Attacks Targeting Google Chrome & ownCloud Flaws: CISA Warns

The CISA announced two known exploited vulnerabilities active attacks targeting Google Chrome & own...

Cactus Ransomware Exploiting Qlik Sense code execution Vulnerability

A new Cactus Ransomware was exploited in the code execution vulnerability to Qlik Sense...

Hackers Bypass Antivirus with ScrubCrypt Tool to Install RedLine Malware

The ScrubCrypt obfuscation tool has been discovered to be utilized in attacks to disseminate the RedLine Stealer...

Hotel’s Booking.com Hacked Logins Let Attacker Steal Guest Credit Cards

According to a recent report by Secureworks, a well-planned and advanced phishing attack was...

Critical Zoom Vulnerability Let Attackers Take Over Meetings

Zoom, the most widely used video conferencing platform has been discovered with a critical...

Hackers Using Weaponized Invoice to Deliver LUMMA Malware

Hackers use weaponized invoices to exploit trust in financial transactions, embedding malware or malicious...

US-Seized Crypto Currency Mixer Used by North Korean Lazarus Hackers

The U.S. Treasury Department sanctioned the famous cryptocurrency mixer Sinbad after it was claimed...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

API Attack Simulation Webinar

Live API Attack Simulation

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked.The session will cover:an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

Related Articles