Friday, June 29, 2007

Lower than scum...**(UPDATED & BUMPED)**

Jim Lynch from bRight & Early alerted me to this.

A site that purports itself as a military recruiting web site is anything but. The url, officialarmy.com, looks official enough.

But it asks for personal information, including social security number, and it's not even on a secure server.

I put down an assumed name, address, etc., to see what would happen. The site stated that a "army recruiter" would be calling me within the next 24 hours. When I tried emailing the contact addy provided, the email came back as undeliverable.

I've contacted various branches of the FBI...


One of my friends provided a WHOIS on the site as follows:

Here is the "whois" 411.

network: Class-Name: network
network: ID: NET-207360016
network: Auth-Area: 207.36.0.0/16
network: Network-Name: AFFI-207.36.0.0/16
network: IP-Network: 207.36.238.208/29
network: IP-Network-Block: 207.36.238.209 - 207.36.238.214
network: Org-Name: Ryan Russell Investments
network: Street-Address: 6500 Champion Grandview Way
network: City: Austin
network: State: TX
network: Postal-Code: 78750
network: Country-Code: US
network: Phone:
network: Tech-Contact;I: ZA94-ARIN
network: Admin-Contact;I: ip-admin@affinity.com

network: Created:
network: Updated:
network: Updated-By: ip-admin@affinity.com

network: Class-Name: network
network: ID: NETBLK.207.36.0.0/16
network: Auth-Area: 207.36.0.0/16
network: Network-Name: AFFI-207.36.0.0
network: IP-Network: 207.36.0.0/16
network: IP-Network-Block: 207.36.0.1 - 207.36.255.255
network: Org-Name: Affinity Internet Inc
network: Street-Address: 3250 W Commercial Blvd. Suite 200
network: City: Ft Lauderdale
network: State: FL
network: Postal-Code: 33309
network: Country-Code: US
network: Phone:
network: Tech-Contact;I: ip-admin@affinity.com

network: Admin-Contact;I: ip-admin@affinity.com

network: Created:
network: Updated:
network: Updated-By: ip-admin@affinity.com

I've reported this to several branches of the FBI, but if someone who is good at cyber-detectiving (is that a word?) can shed some quick light on these cockroaches, all the better.

I'll keep you posted as details develop.

***UPDATE 1:54pm CDT****

BTW--the whois lists an address of 6500 Champion Grandview Way, in Austin, TX...

Here is the website for the apartment complex. (LINK)

How much you wanna bet that his pad is paid for with stolen credit and identities?

...developing

***UPDATE 6:35pm CDT***

A friend of mine (a civilian contractor with military connections) relays the following:

The DoD Webmaster forum has given me all kinds of information as to the ownership of this website. It is registered to GoDaddy.com and covered by a company known for hosting phishers and spammers. I have been advised to report this to Army Legal counsel as everyone on the forum has come to the conclusion it is a phishing site- one that needs to be shut down.

Thanks again!

....developing

***UPDATE 4:13 am*****

Another friend of mine, who is retired NCIS, will also take this up with his buddies today.

This slimebucket does not know what he's gotten himself into.

...developing

****UPDATE 2:11 pm CDT****

From my contractor friend....

It seems that it was shut down.

I will now tell you a bit more of things that happened here. We received an email from one DOD site that stated that this site was indeed on their scope, had been shut down before and that it did appear to be a pfishing site. They would look into it again.

We then got another response from an Army organization that stated it was an official pilot program for the Army Recruiting command. Since our office does digits for the Army, all have served and more than half are retired, we quickly listed many of our concerns. Security, type of info requested, site management, ISP hosting and no links to verify validity of the site were key but not not even half of our issues. The issue was then readdressed to the DOD and DOA certification areas as well as TRADOC.

If it was a pilot program and they intend to continue or readdress the issue of this site, we have asked them to provide better compliance with DOD and DOA security requirements and oversight to ensure the person(s) developing and managing have better oversight as well as the ability to validate such sites and links to their COR email.
The site is still up.

There is no way that this is an official site, especially given what we have found regarding it.

....Developing

****UPDATE 2:35pm******

Again, from my contractor friend:

The IA Division of Army Recruiting Command has confirmed that www.officialarmy.com is not an official Army website and is operated by a non-government source. It is not an Army sanctioned website.
....Developing

*****UPDATE 10:00pm******

Reader BlkOps states:

Rgr, we have big Army looking into it. They are moving fast!Included in this action is, and not limited to : the FBI, Homeland Security, and Organizations within the US Army. Officialarmy.com is NOT an Army Sanctioned website!


Looks like the cavalry is here!

BTW--I will be on vacation through the middle of next week, and will be out of range of internet for the most part.

Thanks to everyone for all the work that is being done to get this scumbag out of cyberspace and behind bars!

-Leo-