{"id":1548,"date":"2021-02-09T08:19:26","date_gmt":"2021-02-09T08:19:26","guid":{"rendered":"https:\/\/osintme.com\/?p=1548"},"modified":"2021-02-09T23:56:02","modified_gmt":"2021-02-09T23:56:02","slug":"the-curious-case-of-the-perl-com-domain-hijack","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2021\/02\/09\/the-curious-case-of-the-perl-com-domain-hijack\/","title":{"rendered":"The curious case of the perl.com domain hijack"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"1548\" class=\"elementor elementor-1548\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0030cf2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0030cf2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4e568e7\" data-id=\"4e568e7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-29c5c4c elementor-widget elementor-widget-text-editor\" data-id=\"29c5c4c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Originally published on <a href=\"https:\/\/www.secjuice.com\/the-curious-case-of-perl-com-hijack\/\">Secjuice.com<\/a> on the 7th February 2020.<\/em><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2e7817b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2e7817b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d164d48\" data-id=\"d164d48\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1e9f35c elementor-widget elementor-widget-text-editor\" data-id=\"1e9f35c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In late January 2021 <a href=\"https:\/\/twitter.com\/briandfoy_perl\/status\/1354535622069919748\">disturbing news surfaced on Twitter<\/a> regarding the registration details of perl.com, the website of the once popular PERL programming language.<\/p><p>It seems that suddenly the domain changed ownership and was moved to a different server from where it originally was being hosted.<\/p><p>Usually things like this happen in relatively rare scenarios where a company (or an individual) forget to renew their domain and the ownership of it lapses, resulting in the domain name getting returned to the pool of available domains, from where it can get snapped up by any willing buyer.<\/p><p>Exactly that happened years ago to <a href=\"https:\/\/www.theregister.com\/2003\/11\/06\/microsoft_forgets_to_renew_hotmail\/\">Microsoft&#8217;s hotmail.co.uk<\/a> domain; it also happened to <a href=\"https:\/\/domainnamewire.com\/2010\/03\/26\/foursquare-admits-its-expired-domain-name-mistake\/\">Foursquare<\/a>, and it happened to several other, more or less known online entities over the years.<\/p><p>However, in the case of perl.com, this is NOT what occurred.<\/p><p>The website was previously hosted by Network Solutions LLC using the Bitnames servers.<\/p><p>But suddenly, on the 30th December 2020, the ownership of perl.com was transferred to a Chinese domain registrar Bizcn.com.<\/p><p>On the 27th January 2021 the ownership was moved to Key-Systems GmbH, a German domain hosting provider. Notably, the servers also changed from Bitnames to Afternic (which seems to belong to GoDaddy).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4e70032 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4e70032\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-671070f\" data-id=\"671070f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0ca9c84 elementor-widget elementor-widget-image\" data-id=\"0ca9c84\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"829\" height=\"411\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-1.png?fit=829%2C411&amp;ssl=1\" class=\"attachment-large size-large wp-image-1587\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-1.png?w=829&amp;ssl=1 829w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-1.png?resize=300%2C149&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-1.png?resize=768%2C381&amp;ssl=1 768w\" sizes=\"(max-width: 829px) 100vw, 829px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-31f206b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"31f206b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6759541\" data-id=\"6759541\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5d21901 elementor-widget elementor-widget-image\" data-id=\"5d21901\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"742\" height=\"624\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-2.png?fit=742%2C624&amp;ssl=1\" class=\"attachment-large size-large wp-image-1588\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-2.png?w=742&amp;ssl=1 742w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-2.png?resize=300%2C252&amp;ssl=1 300w\" sizes=\"(max-width: 742px) 100vw, 742px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-104ae21 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"104ae21\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-37e1156\" data-id=\"37e1156\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8706f94 elementor-widget elementor-widget-text-editor\" data-id=\"8706f94\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>So this is a classic case of a domain hijacking.<\/p><p>This happens when an unauthorized change of <abbr title=\"Domain Name System\">DNS<\/abbr> configuration occurs. Essentially, the name resolution for the domain is performed by a rogue name server.<\/p><p>Through unauthorized access, the attacker alters registration contact details and claims ownership of any domains legitimately registered by the victim.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b80e008 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b80e008\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5d04bf0\" data-id=\"5d04bf0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0e278bd elementor-widget elementor-widget-text-editor\" data-id=\"0e278bd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>It&#8217;s crucial to understand that the content of the hijacked website could change completely &#8211; or it does not necessarily change at all.<\/p><p>It&#8217;s not very hard to clone the contents of the previous site and carry on with it as usual, after making malicious uploads that target the users.<\/p><p>The bottom line is: changes to website hosting and DNS are not always reflected on the site itself, therefore using services such as <a href=\"https:\/\/archive.org\/web\/\">The Wayback Machine<\/a> or <a href=\"https:\/\/urlscan.io\/\">Urlscan<\/a> will not always be helpful &#8211; instead, one needs to focus on the historical DNS examination.<\/p><p>Which by the way is a very useful angle whenever conducting OSINT on any websites and IP addresses.<\/p><p>Some of the resources that I found helpful for the historical DNS analysis of perl.com were:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ffaf2b7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ffaf2b7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e2e4e95\" data-id=\"e2e4e95\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a17dcd7 elementor-widget elementor-widget-text-editor\" data-id=\"a17dcd7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul>\n<li><a href=\"https:\/\/securitytrails.com\/\">Security Trails<\/a> &#8211; this is a paid tool, but once you sign up you get access to the free features, which in many cases will be sufficient to provide further leads.<\/li>\n<li><a href=\"https:\/\/whoisrequest.com\/history\/\">WhoIS Request<\/a> &#8211; free web based tool, allows you to track name server changes since 2002 for the most popular top level domains out there.<\/li>\n<li><a href=\"https:\/\/completedns.com\/dns-history\/\">Complete DNS<\/a> &#8211; also free and also web based, paid option is available but not necessary.<\/li>\n<li><a href=\"https:\/\/spyse.com\/\">Spyse<\/a> &#8211; offers a lot of useful information, but DNS history is somewhat vague and incomplete. Use this one in conjunction with other tools, then compare the results to fill the gaps.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8b40ff3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8b40ff3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6585842\" data-id=\"6585842\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-157127f elementor-widget elementor-widget-text-editor\" data-id=\"157127f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>During the period of time between 28th January and 5th February 2021, the perl.com domain was not resolving correctly (blank screen).<\/p><p>The new registrant details were not available publicly, which was a notable change from the previously transparent owner Tom Christiansen to an anonymous person seemingly residing in Chisinau in Moldova (not 100% accurate, I know).<\/p><p>In the meantime, it turned out that the perl.com domain was put up for sale through the available domains listing on Afternic:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8fbd2ee elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8fbd2ee\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-390017f\" data-id=\"390017f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3aa1b31 elementor-widget elementor-widget-image\" data-id=\"3aa1b31\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1024\" height=\"535\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-afternic.png?fit=1024%2C535&amp;ssl=1\" class=\"attachment-large size-large wp-image-1597\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-afternic.png?w=1377&amp;ssl=1 1377w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-afternic.png?resize=300%2C157&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-afternic.png?resize=1024%2C535&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-afternic.png?resize=768%2C401&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0b285ff elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0b285ff\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-283276a\" data-id=\"283276a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-55ca6ce elementor-widget elementor-widget-text-editor\" data-id=\"55ca6ce\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The original URL to the listing (no longer active):<\/p>\n<p><a href=\"https:\/\/www.afternic.com\/listings\/drawmaster\">https:\/\/www.afternic.com\/listings\/drawmaster<\/a><\/p>\n<p><strong>NOTE:<\/strong> This username alone can be a wide angle for further OSINT research, something I did not have the time to delve into. Given the fact that there exists a possible connection to Moldova, which is a bi-lingual, Russian and Romanian speaking country, I would concentrate on sifting through the occurrences of the &#8220;drawmaster&#8221; username in the Russian and Romanian language sources.<\/p>\n<p>Examples:<\/p>\n<p><a href=\"https:\/\/dating.ru\/drawmaster\/\">https:\/\/dating.ru\/drawmaster\/<\/a><\/p>\n<p><a href=\"https:\/\/t.me\/s\/drawmaster\">https:\/\/t.me\/s\/drawmaster<\/a><\/p>\n<p>I am NOT saying these accounts are in any way related to this incident, what I am saying that the handle might or not be related &#8211; this is something that requires a lot more research, and could prove inconclusive at best.<\/p>\n<p>When it comes to the websites linked to the perl.com hijack, other researchers have connected the dots on this faster than I did.<\/p>\n<p>One compelling theory posted on <a href=\"https:\/\/domaingang.com\/domain-crime\/perl-com-a-1994-domain-has-been-stolen-by-busy-chinese-thief\/\">Domain Gang<\/a> blamed Chinese hackers for a coordinated hijack of perl.com and other domains seen advertised for sale above &#8211; all for purely monetary gain.<\/p>\n<p>The whole thing appeared to be an elaborate scam aimed at making a quick buck at the expense of somebody naive enough to risk forking out a six figure sum for a domain name that ultimately could be restored to the rightful owner (I will discuss how such restorations are possible later on).<\/p>\n<p>But there was still one more angle to explore &#8211; the IP address associated with perl.com during the hijack:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-abe6745 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"abe6745\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-acb5426\" data-id=\"acb5426\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4a3c0a9 elementor-widget elementor-widget-image\" data-id=\"4a3c0a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"488\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-IP-address.png?fit=1024%2C488&amp;ssl=1\" class=\"attachment-large size-large wp-image-1599\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-IP-address.png?w=1187&amp;ssl=1 1187w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-IP-address.png?resize=300%2C143&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-IP-address.png?resize=1024%2C488&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-hijack-osint-IP-address.png?resize=768%2C366&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f191752 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f191752\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-59cc1e6\" data-id=\"59cc1e6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b279c23 elementor-widget elementor-widget-text-editor\" data-id=\"b279c23\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The IP address 35.186.238.101 indeed has a bad reputation according to multiple sources:<\/p><ul><li><a href=\"https:\/\/talosintelligence.com\/reputation_center\/lookup?search=35.186.238.101\">https:\/\/talosintelligence.com\/reputation_center\/lookup?search=35.186.238.101<\/a><\/li><li><a href=\"https:\/\/www.virustotal.com\/gui\/ip-address\/35.186.238.101\/detection\">https:\/\/www.virustotal.com\/gui\/ip-address\/35.186.238.101\/detection<\/a><\/li><li><a href=\"https:\/\/mxtoolbox.com\/SuperTool.aspx?action=blacklist%3a35.186.238.101&amp;run=toolpage\">https:\/\/mxtoolbox.com\/SuperTool.aspx?action=blacklist%3a35.186.238.101&amp;run=toolpage<\/a><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-13ae82d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"13ae82d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a5df742\" data-id=\"a5df742\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ed3174b elementor-widget elementor-widget-text-editor\" data-id=\"ed3174b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This could be coincidental and it is possible that the attacker&#8217;s motive was monetary gain &#8211; but it also appears possible that something more sinister could have been planned or at least attempted &#8211; especially since other websites associated with that IP have in the past been identified as involved in distribution of spam, malware and ransomware.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c938d21 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c938d21\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-91cdc74\" data-id=\"91cdc74\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7b1c604 elementor-widget elementor-widget-heading\" data-id=\"7b1c604\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Conclusion<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-40d5a15 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"40d5a15\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-8b347b6\" data-id=\"8b347b6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-24879dd elementor-widget elementor-widget-text-editor\" data-id=\"24879dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Thankfully for the owners of perl.com and the whole PERL community, the DNS host record was returned into the legitimate hands several days ago.<\/p><p>Due to everything that happened, some problems with resolving the DNS might still persist.<\/p><p>Brian Foy, who originally reported the problem on Twitter, created <a href=\"https:\/\/github.com\/tpf\/perldotcom\/issues\/313\">an issue on Github<\/a> where he provided the recent update and is asking users to report any difficulties when visiting the website:<\/p><p><em>&#8220;Verisign restored the DNS on Feb 2, but various servers may have cached values or may have sinkholed it. I want to know if there are parts of the world that are still seeing different answers. Thumbs up if you see the right results. Comment if you can see something different.&#8221;<\/em><\/p><p>This is what the correct DNS information for perl.com should look like:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2011246 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2011246\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-01ceb73\" data-id=\"01ceb73\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e89c8b9 elementor-widget elementor-widget-image\" data-id=\"e89c8b9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"593\" height=\"364\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-DNS-host-record.png?fit=593%2C364&amp;ssl=1\" class=\"attachment-large size-large wp-image-1616\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-DNS-host-record.png?w=593&amp;ssl=1 593w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/02\/perl-DNS-host-record.png?resize=300%2C184&amp;ssl=1 300w\" sizes=\"(max-width: 593px) 100vw, 593px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-563b79d elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"563b79d\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3452bbc\" data-id=\"3452bbc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2724508 elementor-widget elementor-widget-text-editor\" data-id=\"2724508\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>PS. Useful information from ICANN on what to do in the case of domain hijacking and why documentation is crucial in the whole restitution process can be found <span style=\"text-decoration: underline;\"><a href=\"https:\/\/www.icann.org\/news\/blog\/documentation-is-key-to-recovering-hijacked-domain-names\">here<\/a>.<\/span><\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>An OSINT driven research into how the perl.com domain ended up in the hands of cyber criminals who then attempted to auction it off&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[93],"tags":[80,60,34,123,81,15],"class_list":["post-1548","post","type-post","status-publish","format-standard","hentry","category-my-investigations","tag-domain","tag-hacking","tag-investigation","tag-perl","tag-scam","tag-security"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/1548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=1548"}],"version-history":[{"count":77,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/1548\/revisions"}],"predecessor-version":[{"id":1662,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/1548\/revisions\/1662"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=1548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=1548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=1548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}