Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Aurologic accused of being a major actor in enabling cybercrime

11112131517

Comments

  • emghemgh Member, Megathread Squad

    @Levi said:
    Wtf, suddenly it became the world vs AS203446? How? Where is aurologic? That's not even derail, it is completely new topic.

    Not really. They were buddies, now competitors, and they’re in the same type of business.

    Thread isn’t only about Aurologic, it’s also about if upstreams should have any other responsibilities than legal ones.

    Thanked by 1tentor
  • MaxTakebaMaxTakeba Member
    edited November 2025

    @emgh said:

    @Levi said:
    Wtf, suddenly it became the world vs AS203446? How? Where is aurologic? That's not even derail, it is completely new topic.

    Not really. They were buddies, now competitors, and they’re in the same type of business.

    Thread isn’t only about Aurologic, it’s also about if upstreams should have any other responsibilities than legal ones.

    If we take a look at case studies... Upstreamers definitely have other responsibilities such as upholding their reputation.

    How many times have we seen companies and/or services getting nulled and unannounced because they were attracting trouble and it being discussed here? Swear you could write a book on how to successfully fail at being reasonable adults and being good to do business with.

    Thanked by 1emgh
  • @MaxTakeba said: upholding their reputation

    To whom? Upstream is such a niche market that 99.98999% population doesn't even understand that word. Money does not smell. You, emgh and a bunch of other internet personas know, that those upstream providers host a bunch of shady graddy stuff - they thrive on that.

    The main question: what we can do about it? I can't vote with my wallet, I'am not their client. Everything else - is "pouring from empty to empty".

  • @Levi said:

    @MaxTakeba said: upholding their reputation

    To whom? Upstream is such a niche market that 99.98999% population doesn't even understand that word. Money does not smell. You, emgh and a bunch of other internet personas know, that those upstream providers host a bunch of shady graddy stuff - they thrive on that.

    The main question: what we can do about it? I can't vote with my wallet, I'am not their client. Everything else - is "pouring from empty to empty".

    Sure, there's greed, dumb decisions, nothing but wanting to see the numbers and the client list go up.

    That can only go up if we make good business decisions and don't paint ourselves with a giant target on our back, both legally and publicly... (We did... Discuss questionable and disputed services that the two upstreamers upstreamed... We did read the same thread right?)

    Then again. What do you and I know? We're only people on a forum who buys infra, maybe makes an opinion or two and reads shit like this wondering what the fuck happened.

    What the aforementioned upstreamers do behind closed doors we'll never know unless it ends up in discovery. Or maybe life will go on...

    Maybe I am naive... Uneducated on business or whatever...

    Thanked by 1mandala
  • hyperblasthyperblast Member
    edited November 2025

    @Levi said:
    Wtf, suddenly it became the world vs AS203446? How? Where is aurologic? That's not even derail, it is completely new topic.

    whois AS203446, there is no imprint on their website.

    Thanked by 1zed
  • @hyperblast said: whois AS203446, there is no imprint on their website.

    some small business doing business as an individual outside vat.

    Thanked by 1Saragoldfarb
  • @apollo15 said:

    @hyperblast said: whois AS203446, there is no imprint on their website.

    some small business doing business as an individual outside vat.

    Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

  • @Levi said: Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

    most likely not enough for that, the owner probably has a real job elsewhere that makes a living.

  • AS203446AS203446 Member, Patron Provider

    @apollo15 said:

    @Levi said: Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

    most likely not enough for that, the owner probably has a real job elsewhere that makes a living.

    No, that is not the case.

  • @AS203446 said:

    @apollo15 said:

    @Levi said: Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

    most likely not enough for that, the owner probably has a real job elsewhere that makes a living.

    No, that is not the case.

    That’s exactly the case. Precisely.

  • AS203446AS203446 Member, Patron Provider

    @Levi said:

    @AS203446 said:

    @apollo15 said:

    @Levi said: Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

    most likely not enough for that, the owner probably has a real job elsewhere that makes a living.

    No, that is not the case.

    That’s exactly the case. Precisely.

    What makes you believe that?

  • @AS203446 said:

    @Levi said:

    @AS203446 said:

    @apollo15 said:

    @Levi said: Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

    most likely not enough for that, the owner probably has a real job elsewhere that makes a living.

    No, that is not the case.

    That’s exactly the case. Precisely.

    What makes you believe that?

    All evidence and calculations points to it.

  • SeederKunSeederKun Member
    edited November 2025

    AS401115 (EKABI), AS401116 (Nybula LLC), AS401109 (Zhongguancun LLC) and AS401120 (cheapy.host LLC). 🕵️ Of course, all of them are listed in #DROP and ASN-DROP.) 🛡️

    All this time the physical infrastructure appears to have been hosted by 🇳🇱 Serverion BV, though iterations of this BPH saw attempts to obfuscate its physical location and hamper investigation attempts. 🧐

    Congratulations to all parties involved in this takedown! Looking forward to seeing more of them soon! 👏 2/2

    Source: https://infosec.exchange/@spamhaus/115565462913160872

    TLDR: All the 4 mentioned ASNs were behind Aurologic via SovyCloud

  • emghemgh Member, Megathread Squad
    edited November 2025

    @SeederKun said:

    AS401115 (EKABI), AS401116 (Nybula LLC), AS401109 (Zhongguancun LLC) and AS401120 (cheapy.host LLC). 🕵️ Of course, all of them are listed in #DROP and ASN-DROP.) 🛡️

    All this time the physical infrastructure appears to have been hosted by 🇳🇱 Serverion BV, though iterations of this BPH saw attempts to obfuscate its physical location and hamper investigation attempts. 🧐

    Congratulations to all parties involved in this takedown! Looking forward to seeing more of them soon! 👏 2/2

    Source: https://infosec.exchange/@spamhaus/115565462913160872

    TLDR: All the 4 mentioned ASNs were behind Aurologic via SovyCloud

    .

    Like all other internet abuse, bulletproof hosting does not just happen - it is enabled by facilitators such as network carriers, datacenter operators, IP brokers and domain registrars. Sometimes, malicious infrastructure agglomerates in the internet vicinity of such facilitators - why not join the show if your criminal competitors thrive there already?🧐

    A particularly prolific example is 🇩🇪aurologic GmbH (regular readers might recognize the name), as highlighted by Recorded Future in a report published on November 6 ⤵️
    https://www.recordedfuture.com/research/malicious-infrastructure-finds-stability-with-aurologic-gmbh

    https://infosec.exchange/@spamhaus/115526471152777254

    Thanked by 1Peppery9
  • @emgh said:

    @Levi said:
    Wtf, suddenly it became the world vs AS203446? How? Where is aurologic? That's not even derail, it is completely new topic.

    Not really. They were buddies, now competitors, and they’re in the same type of business.

    Thread isn’t only about Aurologic, it’s also about if upstreams should have any other responsibilities than legal ones.

    That is literally what the law is there for. It defines your responsibilities.

  • emghemgh Member, Megathread Squad
    edited November 2025

    @OpaqueRegistrant said:

    @emgh said:

    @Levi said:
    Wtf, suddenly it became the world vs AS203446? How? Where is aurologic? That's not even derail, it is completely new topic.

    Not really. They were buddies, now competitors, and they’re in the same type of business.

    Thread isn’t only about Aurologic, it’s also about if upstreams should have any other responsibilities than legal ones.

    That is literally what the law is there for. It defines your responsibilities.

    No, it defines what is lawful. Responsabilities is determines by everyone induvidually, this is called culture.

    The proof: tons of people in this thread don’t agree with you. This is because of personal preference about right and wrong. I get that you think that something being legal is enough, but lots of people won’t agree.

    Thanked by 2MaxTakeba tentor
  • SaragoldfarbSaragoldfarb Member, Megathread Squad

    What a shit show. It's basically like real life. Legally, it's all fine. But you and everyone else knows your neighbour is a proper wanker.

    Not much can be done. But we all know.

    Thanked by 2emgh xaoc
  • @Levi said:
    Wtf, suddenly it became the world vs AS203446? How? Where is aurologic? That's not even derail, it is completely new topic.

    They realized they can't bully Aurologic into cutting off downstreams, so now they’ve got to find someone else to pester. How else are they going to justify waking up at 5am just to post about some ancient 2011 malware?

    Thanked by 1OpaqueRegistrant
  • @AS203446 said:

    @Felcloud said: I’m curious what exactly did you and Joseph do to make all these jealous people so upset? Are you really that much better than them?

    I think there is a big difference between SMARTNET and aurologic - the mentioned customer that advertises "bulletproof services" is one of 20 downstreams.

    People think that SMARTNET facilitates crime but we are just offering our services. And in all honesty, one customer that advertises "bulletproof" is not enough to compare us to a network that apparently has more than 17% bulletproof ISPs or hosting services as downstream.

    But I don't care which kind of customers aurologic serves. They can do whatever they want. Just because Joseph and I had a dispute a few months ago does not mean that I am going to support these drama queens here.

    Oh and I forgot to mention: We also terminated Railnet in July 2025. Same reason. So to everybody that claims we love crime, we don't. We've taken action in the past and will take action again.

    these jealous people

    I don't think they are jealous, they seem to love drama. But I also love drama.

    No, it's clear they're just jealous. Most of them run around with IPv6 "networks" because they’re too broke to god forbid even rent IPv4. They could never compare to SMARTNET / Aurologic. I hope Joseph keeps all these downstreams active let them keep chasing their tails. And you keep whatever that Optibounce stuff is active.

    Thanked by 1384_cz
  • @Levi said:

    @AS203446 said:

    @Levi said:

    @AS203446 said:

    @apollo15 said:

    @Levi said: Small shady business, lil here and there. Earning living. Putting butter on the bread so to say.

    most likely not enough for that, the owner probably has a real job elsewhere that makes a living.

    No, that is not the case.

    That’s exactly the case. Precisely.

    What makes you believe that?

    All evidence and calculations points to it.

    Oh, I'm sure you’ve got plenty of room to talk about someone else’s finances. If you want a slice of the pie, just say so. Is all the commentary really necessary?

  • @jh_aurologic said:

    @emgh said:
    Also, saying you don’t have time to research who the fuck your clients are when they might be in the business of keeping child porn online looks extremely bad for you.

    Tell the same to the other upstreams who wont scan / look into customer networks. Obviously you are unable to differentiate, thats not very intelligent.

    Haha, you should add this to your LowEndTalk activity feed:

  • emghemgh Member, Megathread Squad

    Not sure he’s into you mate

    Thanked by 1beanman109
  • vailiernitsvailiernits Member
    edited November 2025

    @Felcloud said: No, it's clear they're just jealous. Most of them run around with IPv6 "networks" because they’re too broke to god forbid even rent IPv4. They could never compare to SMARTNET / Aurologic. I hope Joseph keeps all these downstreams active let them keep chasing their tails. And you keep whatever that Optibounce stuff is active.

    What is your domain? Is it Felcloud.NET or .IO?
    I want to give you benefit of the doubt

  • new contestant!

    Thanked by 3tentor emgh vailiernits
  • darkmasterdarkmaster Member
    edited November 2025

    So, i changed a lot of code.
    I added:

    • Feed Caching -> Reduced API calls
    • Parallel Processing -> Faster
    • CIDR overlap check -> Faster
    • Added Spamhaus DROP (optional)
    • Added custom AS blocklist

    I hope that i can push as of later today

    AS30823 (Aurologic GmbH)
    https://files.catbox.moe/b3sap6.png

    AS203446 (SMARTNET LIMITED)
    https://files.catbox.moe/04m4kx.png

    AS34549 (meerfarbig GmbH & Co. KG) as requested by @Alyx
    https://files.catbox.moe/kn8nib.png

    Thanked by 2tentor Alyx
  • vailiernitsvailiernits Member
    edited November 2025

    @Felcloud said: Most of them run around with IPv6 "networks" because they’re too broke to god forbid even rent IPv4.

    Where did your IPv4 go buddy?
    https://bgp.tools/prefix/195.96.129.0/24#validation
    RPKI Chain (Current origin: Invalid)

    Hilarious that you posted this shortly after getting kicked out
    last-modified: 2025-11-16T13:28:33Z

    Maybe the LIR got upset over you not hosting anything other than phishing and c2's?
    https://urlscan.io/ip/195.96.129.0/24

    https://check.spamhaus.org/results?query=SBL688229
    Oy

    His second /24 (also gone) was previously used by "FEMBOY PROXY SOLUTIONS HOLDINGS LLC"

    Always funny to see fellow criminals running defense for people who allow them to commit crimes
    Of course he is affiliated with Pfcloud/Netiface skids

    "Superior hosting", includes the fan favorite term "RDP" in their AD as well

    64% uptime, that's bad even by Calin's standards.

    Find a new LIR before shitting at IPv6-only hobbynets, loser.

    Thanked by 1sillycat
  • @vailiernits said:

    @Felcloud said: Most of them run around with IPv6 "networks" because they’re too broke to god forbid even rent IPv4.

    Where did your IPv4 go buddy?
    https://bgp.tools/prefix/195.96.129.0/24#validation
    RPKI Chain (Current origin: Invalid)

    Hilarious that you posted this shortly after getting kicked out
    last-modified: 2025-11-16T13:28:33Z

    Maybe the LIR got upset over you not hosting anything other than phishing and c2's?
    https://urlscan.io/ip/195.96.129.0/24

    https://check.spamhaus.org/results?query=SBL688229
    Oy

    Always funny to see fellow criminals running defense for people who allow them to commit crimes
    Of course he is affiliated with Pfcloud/Netiface skids

    "Superior hosting", includes the fan favorite term "RDP" in their AD as well

    Find a new LIR before shitting at IPv6-only hobbynets, loser.

    “Fellow criminals” oh please, shut up. I wake up happy every day no matter what’s going on, and I know you roll out of bed miserable and mad at the world. You’re the loser here, not me. And that prefix issue you keep crying about? It was fixed days ago, and it wasn’t even related.

    Also, “IPv6 only hobbynets” Are you one of them or something? Purely asking for a friend, of course. I mean, you actually went out of your way to “track” me down? What kind of pent up anger are you carrying around? Because it’s obvious this hit a nerve. Let me know I’m curious

  • vailiernitsvailiernits Member
    edited November 2025

    @Felcloud said: And that prefix issue you keep crying about? It was fixed days ago

    Thanks for admitting that you are indeed Felcloud.net, a yet another skid bulletproof host.

    Move on.

  • @vailiernits said:

    @Felcloud said: And that prefix issue you keep crying about? It was fixed days ago

    Thanks for admitting that you are indeed Felcloud.net, a yet another skid bulletproof host.

    Move on.


    Ew. You sat in that same chair for nine hours "looking" around about me? Don’t talk to me I don’t want to hear a thing out of you. Your a FREAK.

    Step away from the keyboard, little dude. And seriously, you went all the way to even discover who i am and my profile literally has the domain in it you genius? “Skid bulletproof host”? Let me ask: since you’re so eager to act like you’ve got something impressive going on, why not actually show it?

    Because when I pull up your profile on this lovely site, all I see is:
    “Do you own, operate, or work for a hosting provider? No.”

    So again: what exactly do you run that gives you time to obsess over me for nine hours? Or even to hover around here like this? It’s pretty clear you’re not exactly living large I see you in those bargain VPS threads begging for upgrades.
    “Invoice #2606 double bandwidth please, if possible. Thank you in advance.”
    Yeah, real powerhouse stuff.

    So go on. Explain it. I’m waiting.

This discussion has been closed.