Page 1 of 1

On the offensive

Posted: December 4, 2003, 5:02 pm
by Pahreyia
I got hit by a virus on my workstation today. The trojan is a keystroke recorder. Fortunately, I was able to track the website it was sending information to. I want to know if anyone can show me the link to find out the information regarding who owns/runs certain websites/IP addresses.

Posted: December 4, 2003, 5:17 pm
by archeiron
http://www.whois.net gives some information.

Incidentally, I ran it for VV and got this result, which was amusing.

I am sure that there are others, in fact, I thought I had a better one in my favorites here at work, but I guess I don't...

Hope that is a little bit helpful.

p.s. enter info into the second edit box ;)

Posted: December 4, 2003, 5:19 pm
by Sylvus
You just need to do a whois query. That can usually be done from about any linux shell, or you can go to sam spade or better whois or a multitude of other sites.

Posted: December 4, 2003, 5:23 pm
by archeiron
Domain Name:VEESHANVAULT.ORG
Created On:02-Jul-2002 21:35:25 UTC
Last Updated On:25-Jun-2003 19:06:54 UTC
Expiration Date:02-Jul-2004 21:40:52 UTC
Sponsoring Registrar:R91-LROR
Status:OK
Registrant ID:GODA-01216834
Registrant Name:V. V.
Registrant Street1:Freeport
Registrant City:Norrath
Registrant State/Province:California
Registrant Postal Code:90210
Registrant Country:US
Registrant Phone:+1.8885551212
Registrant Email:support@veeshanvault.org
Admin ID:GODA-21216834
Admin Name:V. V.
Admin Street1:Cshome
Admin City:Norrath
Admin State/Province:California
Admin Postal Code:90210
Admin Country:US
Admin Phone:+1.8885551212
Admin Email:support@veeshanvault.org
Tech ID:GODA-11216834
Tech Name:V. V.
Tech Street1:Temple of Veeshan
Tech Street2:North Wing

Tech City:Norrath
Tech State/Province:California
Tech Postal Code:90210
Tech Country:US
Tech Phone:+1.8885551212
Tech Email:support@veeshanvault.org
Name Server:NS2.VEESHANVAULT.ORG
Name Server:NS1.VEESHANVAULT.ORG
:lol:

Posted: December 4, 2003, 6:07 pm
by Pahreyia
Danke schön.

Posted: December 30, 2003, 1:27 pm
by Bubba Grizz
Holy shit that is kind of scarey. I just did my site and it came up with my home address and shit. Is there any way to block that or to change the info?

Posted: December 30, 2003, 2:19 pm
by Vetiria
Try the website you registered your DNS, Bubba.