drmike
100% Tier-1 Gogent
( Hey LowEndTalk @jake, steal this post and repost )
TL;DR 2.0
Thomas LEOnard Dale owns UGVPS and works for ChicagoVPS. His IPs match recent IRC logins and past tense logins as an administrator of Chicago VPS, account tleonard. He goes by the username CVPS_Tleo on LowEndTalk, so say hello to him.
---------------------------------------------------------------------------------------------------------------------
UGVPS = Thomas Dale = Crystal Dale = ChicagoVPS
If you have been around the LowEnd hosting world for the past year, you likely noticed UGVPS (UniqueGeek).
[http://ugvps.com/]
UGVPS appeared on November 1,2012, with a $4.99/mo 1GB OpenVZ offer in Lenoir, NC (Dacentec), Chicago, IL (Colocrossing) and Newcastle, UK.
[http://lowendbox.com/blog/ug-vps-4-99month-1gb-openvz-vps-in-north-carolina-chicago-and-uk/]
By December 15, 2012, UGVPS did its best ChicagoVPS impersonation with a $6.99/mo 2GB of RAM offer and added a second Colocrossing location in Los Angeles to the mix.
[http://lowendbox.com/blog/ugvps-6-99month-2048mb-openvz-vps-in-los-angeles-chicago-lenoir-newcastle-uk/]
April 2, 2013, brought another milestone offer from UGVPS with $19 for 6 months of 2GB RAM OpenVZ ($3.16 a month). Added to the locations, Colo@ in Atlanta. Problem like with most Colocrossing shell companies is that the colocation upstream owner is indeed Colo@, but between UGVPS and Colo@ is Colocrossing.
[http://lowendbox.com/blog/ugvps-19half-year-2gb-openvz-in-atlanta-chicago-los-angeles/]
The Fall of ChicagoVPS – a summary of two major bloopers with customer database
ChicagoVPS is known for insane pricing on large RAM VPS packages (2GB and more recently 3GB) at less than $7 a month. Rumors persist that ChicagoVPS is able to offer these prices due to two factors:
These database disclosures are the source of validation that UGVPS isn't just another ChicagoVPS / Colocrossing customer, but is something far more.
Introducing CVPS_Tleo taking over where CVPS_Adam left off
How to catch a rat in a trap
As witnessed just this week via a popular industry IRC channel:
[email protected]) is authed as cvps-tleo
Who is this masked man called cvps-tleo? CVPS = ChicagoVPS and cvps-tleo thrown into Google yields the account information on LowEndTalk where CVPS-Tleo has replaced CVPS_Kevin, ahh renamed CVPS_Adam after last hack since admin data showed Kevin = Adam Ng. Another long term lie sprung upon the industry by ChicagoVPS, see here for conversation on Kevin/Admin:
http://vpsboard.com/topic/780-kevin-hillstrand-is-a-fraud-adam-ng-is-his-name//
Back to Tom living at 198.23.128.0:
Netrange 198.23.134.0
NetRange: 198.23.134.0 - 198.23.134.31
CIDR: 198.23.134.0/27
OriginAS: AS36352
NetName: CC-198-23-134-0-27
NetHandle: NET-198-23-134-0-1
Parent: NET-198-23-128-0-1
NetType: Reallocated
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/net/NET-198-23-134-0-1
OrgName: Dig The Mine
OrgId: DM-141
Address: 16 Ambrose St
City: Pittston
StateProv: PA
PostalCode: 18640
Country: US
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/org/DM-141
So what? Some fellow in Pittston, Pennsylvania, with a domain called digthemine.com, yawn.
Whois digthemine.com
Domain Name: DIGTHEMINE.COM
Registrar URL: http://www.godaddy.com
Updated Date: 2013-06-30 02:33:18
Creation Date: 2013-06-30 00:48:25
Registrar Expiration Date: 2014-06-30 00:48:25
Registrar: GoDaddy.com, LLC
Registrant Name: Thomas Dale
Registrant Organization:
Registrant Street: 16 Ambrose Street
Registrant City: Pittston
Registrant State/Province: Pennsylvania
Registrant Postal Code: 18640
Registrant Country: United States
Admin Name: Thomas Dale
Admin Organization:
Admin Street: 16 Ambrose Street
Admin City: Pittston
Admin State/Province: Pennsylvania
Admin Postal Code: 18640
Admin Country: United States
Admin Phone: +1.5709918195
Admin Fax:
Admin Email: [email protected]
Tech Name: Thomas Dale
Tech Organization:
Tech Street: 16 Ambrose Street
Tech City: Pittston
Tech State/Province: Pennsylvania
Tech Postal Code: 18640
Tech Country: United States
Tech Phone: +1.5709918195
Tech Fax:
Tech Email: [email protected]
Name Server: NS1.DIGTHEMINE.COM
Name Server: NS2.DIGTHEMINE.COM
Thomas Dale? Hmmmm where have I heard this name before?
http://www.corporationwiki.com/Pennsylvania/Wilkes-Barre/thomas-dale/93227596.aspx
That yields ---> Warfront Cafe LLC
What or who is Warfront Cafe? Don't trust me, trust that pillar of trust LowEndBox:
http://lowendbox.com/blog/ug-vps-4-99month-1gb-openvz-vps-in-north-carolina-chicago-and-uk/
But, maybe it's just some name confusion or something sinister and conspiratorial
whois ugvps.com
Domain Name: UGVPS.COM
Registrar URL: http://www.godaddy.com
Updated Date: 2013-08-01 12:24:55
Creation Date: 2012-10-02 17:00:08
Registrar Expiration Date: 2014-10-02 17:00:08
Registrar: GoDaddy.com, LLC
Registrant Name: Crystal Dale
Registrant Organization: Warfront Cafe LLC
Registrant Street: 23 walnut st
Registrant City: wilkes barre
Registrant State/Province: Pennsylvania
Registrant Postal Code: 18702
Registrant Country: United States
Admin Name: Crystal Dale
Admin Organization: Warfront Cafe LLC
Admin Street: 23 walnut st
Admin City: wilkes barre
Admin State/Province: Pennsylvania
Admin Postal Code: 18702
Admin Country: United States
Admin Phone: +1.5707987184
Admin Fax:
Admin Email: [email protected]
Tech Name: Crystal Dale
Tech Organization: Warfront Cafe LLC
Tech Street: 23 walnut st
Tech City: wilkes barre
Tech State/Province: Pennsylvania
Tech Postal Code: 18702
Tech Country: United States
Tech Phone: +1.5707987184
Tech Fax:
Tech Email: [email protected]
Name Server: DNS1.UGVPS.COM
Name Server: DNS2.UGVPS.COM
Mapping addresses:
Warfront Cafe:
Warfront Cafe LLC
23 walnut st
wilkes-barre, PA 18702
US
UGVPS:
23 walnut st
Wilkes-Barre, PA 18702
How close are these addresses geographically? 7.3 miles with pretty much a straight drive along River Road, only complicated by one way streets exiting Wilkes-Barre. One is urban and the other is the escape to the suburbs.
SO WHAT, THAT DOESN'T PROVE ANYTHING!!! WHERE'S THE SMOKING GUN?
Remember that ChicagoVPS hack? The one back on June 17, 2013, with time stamp of 7:51AM yields your smoking gun.
Remember:
As witnessed just this week via a popular industry IRC channel:
[email protected]) is authed as cvps-tleo
Looking at administrator access log information from the SolusVM exported data from CVPS hack in June 2013, we find a new administrator since the last hack in November 2012.
The new administrator, tleonard. Sounds quite a bit like CVPS_Tleo, doesn't it?
Remember we have Tleo traced back to DIGTHEMINE.COM, UGVPS and Warfront Cafe, but connecting him to ChicagoVPS internally, drumroll please.
tleonard (ChicagoVPS admin from CVPS data dump) --- these are the IP's used as per the dump log information:
108.50.20.76 – Verizon Scranton, PA
172.245.32.7 - ChicagoVPS
198.23.164.125 - ChicagoVPS
71.181.141.194 - Verizon Scranton, PA
71.181.141.198 - Verizon - Hazelton
72.79.130.76 - Verizon - Scranton - Hazelton
72.79.132.113 - Verizon
Darn it! Nothing. Oh wait, here we go:
198.23.134.9 - Dig the Mine
whois 198.23.134.9
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=198.23.134.9?showDetails=true&showARIN=false&ext=netref2
#
# start
NetRange: 198.23.128.0 - 198.23.255.255
CIDR: 198.23.128.0/17
OriginAS: AS36352
NetName: CC-10
NetHandle: NET-198-23-128-0-1
Parent: NET-198-0-0-0-0
NetType: Direct Allocation
RegDate: 2012-10-05
Updated: 2012-10-05
Ref: http://whois.arin.net/rest/net/NET-198-23-128-0-1
OrgName: ColoCrossing
OrgId: VGS-9
Address: 8469 Sheridan Drive
Address: ATTN: ARIN
City: Williamsville
StateProv: NY
PostalCode: 14221
Country: US
RegDate: 2005-06-20
Updated: 2012-01-10
Ref: http://whois.arin.net/rest/org/VGS-9
OrgNOCHandle: VIALA-ARIN
OrgNOCName: Vial, Alex
OrgNOCPhone: +1-800-518-9716
OrgNOCEmail: [email protected]
OrgNOCRef: http://whois.arin.net/rest/poc/VIALA-ARIN
OrgTechHandle: NETWO882-ARIN
OrgTechName: Network Operations
OrgTechPhone: +1-800-518-9716
OrgTechEmail: [email protected]
OrgTechRef: http://whois.arin.net/rest/poc/NETWO882-ARIN
OrgAbuseHandle: ABUSE3246-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-800-518-9716
OrgAbuseEmail: [email protected]
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE3246-ARIN
# end
# start
NetRange: 198.23.134.0 - 198.23.134.31
CIDR: 198.23.134.0/27
OriginAS: AS36352
NetName: CC-198-23-134-0-27
NetHandle: NET-198-23-134-0-1
Parent: NET-198-23-128-0-1
NetType: Reallocated
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/net/NET-198-23-134-0-1
OrgName: Dig The Mine
OrgId: DM-141
Address: 16 Ambrose St
City: Pittston
StateProv: PA
PostalCode: 18640
Country: US
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/org/DM-141
OrgAbuseHandle: DALET3-ARIN
OrgAbuseName: Dale, Thomas
OrgAbusePhone: +1-716-435-7305
OrgAbuseEmail: [email protected]
OrgAbuseRef: http://whois.arin.net/rest/poc/DALET3-ARIN
OrgTechHandle: DALET3-ARIN
OrgTechName: Dale, Thomas
OrgTechPhone: +1-716-435-7305
OrgTechEmail: [email protected]
OrgTechRef: http://whois.arin.net/rest/poc/DALET3-ARIN
# end
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
TL;DR 2.0
Thomas LEOnard Dale owns UGVPS and works for ChicagoVPS. His IPs match recent IRC logins and past tense logins as an administrator of Chicago VPS, account tleonard. He goes by the username CVPS_Tleo on LowEndTalk, so say hello to him.
---------------------------------------------------------------------------------------------------------------------
UGVPS = Thomas Dale = Crystal Dale = ChicagoVPS
If you have been around the LowEnd hosting world for the past year, you likely noticed UGVPS (UniqueGeek).
[http://ugvps.com/]
UGVPS appeared on November 1,2012, with a $4.99/mo 1GB OpenVZ offer in Lenoir, NC (Dacentec), Chicago, IL (Colocrossing) and Newcastle, UK.
[http://lowendbox.com/blog/ug-vps-4-99month-1gb-openvz-vps-in-north-carolina-chicago-and-uk/]
By December 15, 2012, UGVPS did its best ChicagoVPS impersonation with a $6.99/mo 2GB of RAM offer and added a second Colocrossing location in Los Angeles to the mix.
[http://lowendbox.com/blog/ugvps-6-99month-2048mb-openvz-vps-in-los-angeles-chicago-lenoir-newcastle-uk/]
April 2, 2013, brought another milestone offer from UGVPS with $19 for 6 months of 2GB RAM OpenVZ ($3.16 a month). Added to the locations, Colo@ in Atlanta. Problem like with most Colocrossing shell companies is that the colocation upstream owner is indeed Colo@, but between UGVPS and Colo@ is Colocrossing.
[http://lowendbox.com/blog/ugvps-19half-year-2gb-openvz-in-atlanta-chicago-los-angeles/]
The Fall of ChicagoVPS – a summary of two major bloopers with customer database
ChicagoVPS is known for insane pricing on large RAM VPS packages (2GB and more recently 3GB) at less than $7 a month. Rumors persist that ChicagoVPS is able to offer these prices due to two factors:
- Mass overselling of resources (substantiated by the database ratio of accounts to servers)
- Relationship / ownership by popular low end dedicated server and colo facility Colocrossing.
These database disclosures are the source of validation that UGVPS isn't just another ChicagoVPS / Colocrossing customer, but is something far more.
Introducing CVPS_Tleo taking over where CVPS_Adam left off
How to catch a rat in a trap
As witnessed just this week via a popular industry IRC channel:
[email protected]) is authed as cvps-tleo
Who is this masked man called cvps-tleo? CVPS = ChicagoVPS and cvps-tleo thrown into Google yields the account information on LowEndTalk where CVPS-Tleo has replaced CVPS_Kevin, ahh renamed CVPS_Adam after last hack since admin data showed Kevin = Adam Ng. Another long term lie sprung upon the industry by ChicagoVPS, see here for conversation on Kevin/Admin:
http://vpsboard.com/topic/780-kevin-hillstrand-is-a-fraud-adam-ng-is-his-name//
Back to Tom living at 198.23.128.0:
Netrange 198.23.134.0
NetRange: 198.23.134.0 - 198.23.134.31
CIDR: 198.23.134.0/27
OriginAS: AS36352
NetName: CC-198-23-134-0-27
NetHandle: NET-198-23-134-0-1
Parent: NET-198-23-128-0-1
NetType: Reallocated
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/net/NET-198-23-134-0-1
OrgName: Dig The Mine
OrgId: DM-141
Address: 16 Ambrose St
City: Pittston
StateProv: PA
PostalCode: 18640
Country: US
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/org/DM-141
So what? Some fellow in Pittston, Pennsylvania, with a domain called digthemine.com, yawn.
Whois digthemine.com
Domain Name: DIGTHEMINE.COM
Registrar URL: http://www.godaddy.com
Updated Date: 2013-06-30 02:33:18
Creation Date: 2013-06-30 00:48:25
Registrar Expiration Date: 2014-06-30 00:48:25
Registrar: GoDaddy.com, LLC
Registrant Name: Thomas Dale
Registrant Organization:
Registrant Street: 16 Ambrose Street
Registrant City: Pittston
Registrant State/Province: Pennsylvania
Registrant Postal Code: 18640
Registrant Country: United States
Admin Name: Thomas Dale
Admin Organization:
Admin Street: 16 Ambrose Street
Admin City: Pittston
Admin State/Province: Pennsylvania
Admin Postal Code: 18640
Admin Country: United States
Admin Phone: +1.5709918195
Admin Fax:
Admin Email: [email protected]
Tech Name: Thomas Dale
Tech Organization:
Tech Street: 16 Ambrose Street
Tech City: Pittston
Tech State/Province: Pennsylvania
Tech Postal Code: 18640
Tech Country: United States
Tech Phone: +1.5709918195
Tech Fax:
Tech Email: [email protected]
Name Server: NS1.DIGTHEMINE.COM
Name Server: NS2.DIGTHEMINE.COM
Thomas Dale? Hmmmm where have I heard this name before?
http://www.corporationwiki.com/Pennsylvania/Wilkes-Barre/thomas-dale/93227596.aspx
That yields ---> Warfront Cafe LLC
What or who is Warfront Cafe? Don't trust me, trust that pillar of trust LowEndBox:
http://lowendbox.com/blog/ug-vps-4-99month-1gb-openvz-vps-in-north-carolina-chicago-and-uk/
Well hello Crystal, how are you doing, hun? All we hear in the industry is this UGVPS and that hottie Crystal, a geek chic. Think again dweebs.“UG VPS were launched earlier this month. I’ve been informed that they are not yet a registered company but will be in the near future. Their domain is, however, registered to a “Warfront Café LLC” which it appears was a previous project of theirs; interestingly enough, a gaming cafe”
But, maybe it's just some name confusion or something sinister and conspiratorial
whois ugvps.com
Domain Name: UGVPS.COM
Registrar URL: http://www.godaddy.com
Updated Date: 2013-08-01 12:24:55
Creation Date: 2012-10-02 17:00:08
Registrar Expiration Date: 2014-10-02 17:00:08
Registrar: GoDaddy.com, LLC
Registrant Name: Crystal Dale
Registrant Organization: Warfront Cafe LLC
Registrant Street: 23 walnut st
Registrant City: wilkes barre
Registrant State/Province: Pennsylvania
Registrant Postal Code: 18702
Registrant Country: United States
Admin Name: Crystal Dale
Admin Organization: Warfront Cafe LLC
Admin Street: 23 walnut st
Admin City: wilkes barre
Admin State/Province: Pennsylvania
Admin Postal Code: 18702
Admin Country: United States
Admin Phone: +1.5707987184
Admin Fax:
Admin Email: [email protected]
Tech Name: Crystal Dale
Tech Organization: Warfront Cafe LLC
Tech Street: 23 walnut st
Tech City: wilkes barre
Tech State/Province: Pennsylvania
Tech Postal Code: 18702
Tech Country: United States
Tech Phone: +1.5707987184
Tech Fax:
Tech Email: [email protected]
Name Server: DNS1.UGVPS.COM
Name Server: DNS2.UGVPS.COM
Mapping addresses:
Warfront Cafe:
Warfront Cafe LLC
23 walnut st
wilkes-barre, PA 18702
US
UGVPS:
23 walnut st
Wilkes-Barre, PA 18702
How close are these addresses geographically? 7.3 miles with pretty much a straight drive along River Road, only complicated by one way streets exiting Wilkes-Barre. One is urban and the other is the escape to the suburbs.
SO WHAT, THAT DOESN'T PROVE ANYTHING!!! WHERE'S THE SMOKING GUN?
Remember that ChicagoVPS hack? The one back on June 17, 2013, with time stamp of 7:51AM yields your smoking gun.
Remember:
As witnessed just this week via a popular industry IRC channel:
[email protected]) is authed as cvps-tleo
Looking at administrator access log information from the SolusVM exported data from CVPS hack in June 2013, we find a new administrator since the last hack in November 2012.
The new administrator, tleonard. Sounds quite a bit like CVPS_Tleo, doesn't it?
Remember we have Tleo traced back to DIGTHEMINE.COM, UGVPS and Warfront Cafe, but connecting him to ChicagoVPS internally, drumroll please.
tleonard (ChicagoVPS admin from CVPS data dump) --- these are the IP's used as per the dump log information:
108.50.20.76 – Verizon Scranton, PA
172.245.32.7 - ChicagoVPS
198.23.164.125 - ChicagoVPS
71.181.141.194 - Verizon Scranton, PA
71.181.141.198 - Verizon - Hazelton
72.79.130.76 - Verizon - Scranton - Hazelton
72.79.132.113 - Verizon
Darn it! Nothing. Oh wait, here we go:
198.23.134.9 - Dig the Mine
whois 198.23.134.9
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=198.23.134.9?showDetails=true&showARIN=false&ext=netref2
#
# start
NetRange: 198.23.128.0 - 198.23.255.255
CIDR: 198.23.128.0/17
OriginAS: AS36352
NetName: CC-10
NetHandle: NET-198-23-128-0-1
Parent: NET-198-0-0-0-0
NetType: Direct Allocation
RegDate: 2012-10-05
Updated: 2012-10-05
Ref: http://whois.arin.net/rest/net/NET-198-23-128-0-1
OrgName: ColoCrossing
OrgId: VGS-9
Address: 8469 Sheridan Drive
Address: ATTN: ARIN
City: Williamsville
StateProv: NY
PostalCode: 14221
Country: US
RegDate: 2005-06-20
Updated: 2012-01-10
Ref: http://whois.arin.net/rest/org/VGS-9
OrgNOCHandle: VIALA-ARIN
OrgNOCName: Vial, Alex
OrgNOCPhone: +1-800-518-9716
OrgNOCEmail: [email protected]
OrgNOCRef: http://whois.arin.net/rest/poc/VIALA-ARIN
OrgTechHandle: NETWO882-ARIN
OrgTechName: Network Operations
OrgTechPhone: +1-800-518-9716
OrgTechEmail: [email protected]
OrgTechRef: http://whois.arin.net/rest/poc/NETWO882-ARIN
OrgAbuseHandle: ABUSE3246-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-800-518-9716
OrgAbuseEmail: [email protected]
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE3246-ARIN
# end
# start
NetRange: 198.23.134.0 - 198.23.134.31
CIDR: 198.23.134.0/27
OriginAS: AS36352
NetName: CC-198-23-134-0-27
NetHandle: NET-198-23-134-0-1
Parent: NET-198-23-128-0-1
NetType: Reallocated
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/net/NET-198-23-134-0-1
OrgName: Dig The Mine
OrgId: DM-141
Address: 16 Ambrose St
City: Pittston
StateProv: PA
PostalCode: 18640
Country: US
RegDate: 2013-07-18
Updated: 2013-07-18
Ref: http://whois.arin.net/rest/org/DM-141
OrgAbuseHandle: DALET3-ARIN
OrgAbuseName: Dale, Thomas
OrgAbusePhone: +1-716-435-7305
OrgAbuseEmail: [email protected]
OrgAbuseRef: http://whois.arin.net/rest/poc/DALET3-ARIN
OrgTechHandle: DALET3-ARIN
OrgTechName: Dale, Thomas
OrgTechPhone: +1-716-435-7305
OrgTechEmail: [email protected]
OrgTechRef: http://whois.arin.net/rest/poc/DALET3-ARIN
# end
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
Last edited by a moderator: