Booter Takedown - Affidavit For Seizure Warrant
Booter Takedown - Affidavit For Seizure Warrant
Booter Takedown - Affidavit For Seizure Warrant
Page ID #:1
I am a Supervisory Special Agent with the Federal Bureau of Investigation (“FBI”) and have reason to believe that in the
EASTERN District of PENNSYLVANIA
there is now concealed a certain person or property, namely (describe the person or property to be seized)
which is (state one or more bases for seizure under United States Code)
The facts to support a finding of Probable Cause for issuance of a Seizure Warrant are as follows:
_____________________________________________
Signature of Affiant
state as follows:
formal and informal training from the FBI and other institutions
technology.
approximate.
and experience:
1
IP version 4, or “IPv4”, is the version of IP most commonly used today, and
is the version described above. A newer version of the protocol, “IPv6”,
wholly different in appearance to IPv4, is sometimes used, but does not
pertain to this request, and will not be referred to further.
- 2 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 4 of 22
Page ID #:4
associated with the domain, much as the name John Doe might be
telephone number.
- 3 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 5 of 22
Page ID #:5
level domain. For example, the registry for the “.com” and
- 4 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 6 of 22
Page ID #:6
A. SUBJECT DOMAINS
a. anonsecurityteam.com
b. critical-boot.com
c. defianceprotocol.com
d. ragebooter.com
e. str3ssed.me
f. bullstresser.net
g. quantumstress.net
h. booter.ninja
i. downthem.org
j. netstress.org
k. torsecurityteam.org
l. vbooter.org
m. defcon.pro
n. request.rip
o. layer7-stresser.xyz
- 5 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 7 of 22
Page ID #:7
a. Str3ssed.me:
Namecheap, Inc., 11400 W Olympic Blvd Ste 200, Los
Angeles, CA 90064
8. As detailed in Attachments A-1 through A-6, each of
2 Thus the FBI will be providing the “phone book” that others will use when
connecting to the SUBJECT DOMAIN NAMES, ensuring that most visitors will be
routed to the FBI-controlled splash page.
- 6 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 8 of 22
Page ID #:8
transactions are made without governance by any central bank, and encryption
techniques are used to regulate the generation of units of currency and to
verify the transfer of funds. Based on my training and experience, I know
that this type of currency is often used to conceal the identities of the
parties involved in a financial transaction.
- 7 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 9 of 22
Page ID #:9
might cost $100 a month and allow access to ten or more attack
might cost $25 to $35 a month and provide a more limited number
- 8 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 10 of 22
Page ID #:10
attack.
- 9 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 11 of 22
Page ID #:11
are merely different front ends for the same underlying attack
architecture.
follows:
- 10 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 12 of 22
Page ID #:12
than the attacker, receives the resulting flood of data from the
protocol request.
returns its much larger response not to the attacker, but to the
victim.
Attack.”
- 11 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 13 of 22
Page ID #:13
factors of 10, 20, 100, and even more. By doing so, RAAs
resources that the attacker does not pay for, and which far
providers.
- 12 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 14 of 22
Page ID #:14
- 13 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 15 of 22
Page ID #:15
all over the United States and in other countries. I have also
- 14 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 16 of 22
Page ID #:16
booter sites would offer test DDoS attacks for free; some
- 15 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 17 of 22
Page ID #:17
- 16 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 18 of 22
Page ID #:18
private sector experts and other FBI colleagues, the testing FBI
residential connection.
(“Start operation”).
- 17 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 19 of 22
Page ID #:19
IPs, that is, discover the true IP associated with a web server
services.
- 18 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 20 of 22
Page ID #:20
Internet.
VI. CONCLUSION
//
- 20 -
Case 2:18-mj-03329-DUTY *SEALED* Document 1 *SEALED* Filed 12/17/18 Page 22 of 22
Page ID #:22
enforcement.
______________________________
GABRIEL F. ANDREWS
Supervisory Special Agent,
Federal Bureau of Investigation
______________________________
United States Magistrate Judge
- 21 -