DarkMarket_ Cyberthieves, Cybercops and You - Misha Glenny [55]
He started examining all the administrators’ traffic and then spotted some IP addresses that looked odd. Anyone can look up IP addresses and see where they are located – which company or individual is associated with them, and the name of their parent Internet Service Provider. One was registered to a company called Pembrooke Associates. Iceman looked high and low on the Web for information about the company, but there was nothing except on a website listing businesses. Here was the company name and a phone number. He then performed a reverse search on the phone number and found its associated address: 2000 Technology Drive, Pittsburgh, PA.
When he read the address, it was enough to make even Iceman shiver. He had come across it only a couple of weeks earlier, after one of his colleagues on CardersMarket had found a template document on a website, which included the acronym NCFTA and that same address in Pittsburgh. When Iceman looked up this organisation, he discovered it was the National Cyber Forensic Training Alliance, a quasi-governmental body that assists a variety of US law-enforcement agencies in their work on a broad range of cyber-security issues.
Deep in his virtual existence, Iceman suddenly felt the chill touch of the real world. He had always suspected that law enforcement was lurking around every corner, but this was unambiguous – he was convinced that it could not be a mistake. Having believed for many months that he was untouchable and the man controlling the carding community, Max Vision was suddenly worried.
After lengthy consultations, three of Iceman’s colleagues at CardersMarket – silo, c0rrupted0ne and dystopia – decided to contact Matrix001 from DarkMarket to share their suspicions about the IP address and the FBI, and to plan a way forward. Matrix001 was the one administrator whom nobody believed was attached to law enforcement in any way, so they sent him the evidence about the NCFTA and Technology Drive in Pittsburgh, with a stark message sent over icq:
dystopia: we’ve known it for a long time, but we finally have proof
dystopia: matrix, DM is a sting site
dystopia: 100%
c0rrupted0: we worked hard to try and make peace and if we go public Law Enforcement is going to come after us HARD but if we dont say anything we are responsible for all those who get fucked over
siloadmin: happy days to you, you’re an admin of a sting site!
siloadmin: Pembrooke Associates 2000 Technology Dr Pittsburgh PA 15219. something fa jmiliar 2000 Technology Dr?
Matrix smelt a rat. He trusted no one as a rule, but he was especially suspicious of c0rrupted0ne and silo. CardersMarket had for a long time acted with unbridled aggression towards DarkMarket, hoping to destroy it by any means available. He examined the document and, despite not having English as a mother tongue, immediately spotted that it was riddled with errors:
matrix001: the word document is a fake
matrix001: didnt anyone of you guys notice the typos in it?
matrix001: oh and there is no company or any other name on the top line
matrix001: saying ncfta
matrix001: just the address
matrix001: oh and just to mention one typo: it’s spelled available not avaliable
matrix001: you guys want me to continue?
Siloadmin’s response was defensive, as if he was annoyed with himself for not noticing the typos:
siloadmin: listen matrix
siloadmin: I know the shit looks fake, typos etc
siloadmin: but thats what was pulled
siloadmin: I didnt make this shit up
matrix001: no company in the whole world would ever have such a document
matrix001: its totally ridiculous
This could quite easily have been a set-up and the exchange convinced Matrix of exactly that. Accusing rival boards of being a sting operation organised by law enforcement was a common practice designed to scare off members so that they would join the competition. If members were to desert DarkMarket, Matrix was convinced Iceman and CardersMarket would recruit them immediately and that might threaten DarkMarket