Qurium's Avatar

Qurium

@qurium.org.bsky.social

Prevention, Mitigation, Attribution. Open DM

24 Followers  |  7 Following  |  567 Posts  |  Joined: 17.03.2025  |  1.4273

Latest posts by qurium.org on Bluesky

Video thumbnail

The Big Bash Dubai 2022 #scamempire

20.03.2025 15:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
48 reactions Β· 18 comments | A loyal and highly respected investor sharing her review of the platform. Join this legitimate platform today and you'll be glad you did! Group: Elon... | By Becky | Facebook A loyal and highly respected investor sharing her review of the platform. Join this legitimate platform today and you'll be glad you did! Group: Elon...

Just posted. Quantum AI investments are not a scam. Meta πŸ’ΈπŸ’³ #scamempire
https://www.facebook.com/reel/654852003661912

13.03.2025 06:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Get ready for the "Big bash" #scamempire

10.03.2025 18:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Ten years ago Boaelite (now Affilomania/Trafficon) published this video. What has really change at the #scamempire?

09.03.2025 12:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Coming soon... #scamempire

07.03.2025 08:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Landing pages used by affiliates of the #scamempire

06.03.2025 07:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Tonight watch #scamempire

05.03.2025 09:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

#scamempire

05.03.2025 08:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

β€œBy turning over the material to the media, I/we hope this issue gets enough attention for authorities to take action against these criminals. This problem is not impossible to solve. We all just need to care enough to do something about it.” - Source of the leak of #scamempire

05.03.2025 06:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Scam call centers are destroying lives across the world. Now we’re putting the spotlight on them. Coming soon… #ScamEmpire

04.03.2025 13:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"When Kehr meets Vextrio" shows how dating scams and disinformation use a common infrastructure.
https://www.qurium.org/forensics/when-kehr-meets-vextrio/ (1/4) πŸ‘‡

13.11.2024 11:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Yesterday, Bullet Proof Hosting provider sclad{.}us aka Morningstars (AS215939) connected to UAC-0050 (CERT-UA#8453 and CERT-UA#8494 Alerts) announced "technical works" as their main upstream drop them.

18.08.2024 05:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

One month after the release of our Doppelganger investigation and the shutdown of Aeza at Datacamp, the ASNs that made it to the finish line have migrated to @packetbouncer @aurologiccom and @RoyaleHostingBV @stanvandeklippe
Many prefixes remain behind GRE tunnels.

13.08.2024 15:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

The power of CSI (194.36.177{.}229) server of 1cent{.}host runs in AS210281. Can you figure out where do the GRE tunnels of this BPH terminate? @banthisguy9349

03.08.2024 08:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

MTU1448 update: Doppelganger Prefix sneaking away from Aurologic upstream to AS214891. Prefix now using AS56630 Melbikomas (LT) as upstream in Germany. route: 77.91.66.0/24
origin: AS214891
mnt-by: CENTHOST-MNT
last-modified: 2024-08-02T09:47:27Z

03.08.2024 07:25 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

The answer is 1448. In a standard setup the maximum payload for a ICMP packet will be 1472 bytes (1500-20-8). 28 bytes for the IP (20) and ICMP (8) headers.
If you run GRE tunnels, you need to account for a 24 extra bytes overhead for Outer IP(20) and GRE(4).
1500-20-8-20-4=1448

02.08.2024 10:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Yesterday, AS198981 (netshield/1centhost) continued to serve Doppelganger domains but this time with @packetbouncer (Aurologic) as upstreams. This is not the kind of blocking we were expecting from you.

01.08.2024 06:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

This is why we think that Lethost bullet proof hosting that run DG is NOT just a costumer of Aeza (1/x)

30.07.2024 08:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Suspended Cyberhub ASN that is part of the Doppelganger ecosystem has been just renamed to HellaAS (Hellenic Digital Services Ltd / Luxhost). Seems like "luxhost" is the new Aeza bullet proof hoster. 🀦
@Gi7w0rm @banthisguy9349 @SourcesOuvertes

26.07.2024 06:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

In a new twist in the saga of Doppelganger, Aeza has decided to stop providing connectivity to two bullet proof hosters: Lethost and Sunhost. What a nice way to show the world that they handle "abuse". (1/3)

25.07.2024 09:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Since the release of our forensic investigation about Doppelganger infrastructure there has been a few interesting developments. Once of them is that the F-domains @ TNSECURITY and NETSHIELD remain online thanks to one common upstream provider: Datacamp/CDN77

18.07.2024 06:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

It seems that TNSECURITY/EVILEMPIRE is no longer routing traffic from Germany. Nice to have now a much clear picture of where Lethost is coming from

16.07.2024 17:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Impressed of their setup or our report? Maybe both? @cymnu https://t.co/Ds8gNGobjK

14.07.2024 12:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Hostinger today, DNS parking the F domains of DG. bikerspace[.]shop
btwidea[.]shop
cscerbr[.]shop
envhb[.]shop
summitslope[.]shop
vokei[.]shop

12.07.2024 15:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

TNSecurity (aka Evilempire) is interesting for 4 things:
- Runs from Germany as downstream of @packetbouncer - Runs front proxies for Doppelganger
- It is a hotspot of malware distribution
- It was a "dorector"
@Gi7w0rm @ffforward @banthisguy9349

12.07.2024 09:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Let us check of few domains of DG campaign today that were registered with Namecheap and then moved to Hostinger DNS parking service. The service has been provided for months and tje domains have been pointed to:
AS215428 Mykyta Skorobohatko RU
AS216309 Tnsecurity Ltd RU

11.07.2024 20:04 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Just a couple of hours ago, all these domains has been used by Doppelganger. All controlled from:
- Hostinger DNS Parking service and - Served from "Evilempire" downstream of Aurologic in Germany.

11.07.2024 16:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Today, we make public our latest research on Doppelganger. https://www.qurium.org/alerts/russia/exposing-the-evil-empire-of-doppelganger-disinformation/

11.07.2024 06:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Meet Ben Rose from Supreme Media (Amashen) that runs "regulated financial traffic". 🀣

15.05.2024 15:26 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Do you wonder who is promoting those scams impersonating personalities and media?
Read about how we found three affiliate networks behind those ads.
https://www.qurium.org/alerts/tell-of-spring-exposing-crypto-scam-affiliate-networks/ πŸ‘‡(1/8)

15.05.2024 08:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@qurium.org is following 7 prominent accounts