I love a good mystery and a conspiracy. Lets go digging! Here's some additional information on that mysterious site:
Code:
bash-4.2$ nslookup itanimulli.com
Server: 192.168.0.49
Address: 192.168.0.49#53
Non-authoritative answer:
Name: itanimulli.com
Address: 64.202.189.170
bash-4.2$ nslookup nsa.gov
Server: 192.168.0.49
Address: 192.168.0.49#53
Non-authoritative answer:
Name: nsa.gov
Address: 12.120.172.8
Name: nsa.gov
Address: 12.120.184.8
Name: nsa.gov
Address: 12.120.186.8
Name: nsa.gov
Address: 12.120.166.8
bash-4.2$ nslookup www.nsa.gov
Server: 192.168.0.49
Address: 192.168.0.49#53
Non-authoritative answer:
www.nsa.gov canonical name = www.nsa.gov.att-idns.net.
Name: www.nsa.gov.att-idns.net
Address: 12.120.180.8
bash-4.2$ dig -a itanimulli.com
Invalid option: -a
Usage: dig [@global-server] [domain] [q-type] [q-class] {q-opt}
{global-d-opt} host [@local-server] {local-d-opt}
[ host [@local-server] {local-d-opt} [...]]
Use "dig -h" (or "dig -h | more") for complete list of options
bash-4.2$ dig itanimulli.com
; <<>> DiG 9.9.0 <<>> itanimulli.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23298
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 13, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;itanimulli.com. IN A
;; ANSWER SECTION:
itanimulli.com. 3446 IN A 64.202.189.170
;; AUTHORITY SECTION:
. 17509 IN NS e.root-servers.net.
. 17509 IN NS k.root-servers.net.
. 17509 IN NS h.root-servers.net.
. 17509 IN NS j.root-servers.net.
. 17509 IN NS l.root-servers.net.
. 17509 IN NS d.root-servers.net.
. 17509 IN NS a.root-servers.net.
. 17509 IN NS f.root-servers.net.
. 17509 IN NS m.root-servers.net.
. 17509 IN NS i.root-servers.net.
. 17509 IN NS c.root-servers.net.
. 17509 IN NS g.root-servers.net.
. 17509 IN NS b.root-servers.net.
;; Query time: 29 msec
;; SERVER: 192.168.0.49#53(192.168.0.49)
;; WHEN: Sat May 26 07:48:47 2012
;; MSG SIZE rcvd: 270
bash-4.2$ whois itanimulli.com
Whois Server Version 2.0
Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.
Domain Name: ITANIMULLI.COM
Registrar: GODADDY.COM, LLC
Whois Server: whois.godaddy.com
Referral URL: http://registrar.godaddy.com
Name Server: NS45.DOMAINCONTROL.COM
Name Server: NS46.DOMAINCONTROL.COM
Status: clientDeleteProhibited
Status: clientRenewProhibited
Status: clientTransferProhibited
Status: clientUpdateProhibited
Updated Date: 22-nov-2010
Creation Date: 20-nov-2002
Expiration Date: 20-nov-2012
>>> Last update of whois database: Sat, 26 May 2012 11:48:39 UTC <<<
NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.
TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability. VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.
The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
The data contained in GoDaddy.com, LLC's WhoIs database,
while believed by the company to be reliable, is provided "as is"
with no guarantee or warranties regarding its accuracy. This
information is provided for the sole purpose of assisting you
in obtaining information about domain name registration records.
Any use of this data for any other purpose is expressly forbidden without the prior written
permission of GoDaddy.com, LLC. By submitting an inquiry,
you agree to these terms of usage and limitations of warranty. In particular,
you agree not to use this data to allow, enable, or otherwise make possible,
dissemination or collection of this data, in part or in its entirety, for any
purpose, such as the transmission of unsolicited advertising and
and solicitations of any kind, including spam. You further agree
not to use this data to enable high volume, automated or robotic electronic
processes designed to collect or compile this data for any purpose,
including mining this data for your own personal or commercial purposes.
Please note: the registrant of the domain name is specified
in the "registrant" field. In most cases, GoDaddy.com, LLC
is not the registrant of domain names listed in this database.
Registrant:
John Fenley
1985N 360E
Provo, Utah 84604-1803
United States
Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
Domain Name: ITANIMULLI.COM
Created on: 20-Nov-02
Expires on: 20-Nov-12
Last Updated on: 22-Nov-10
Administrative Contact:
Fenley, John Pontifier@hotmail.com
1985N 360E
Provo, Utah 84604-1803
United States
8014273274
Technical Contact:
Fenley, John Pontifier@hotmail.com
1985N 360E
Provo, Utah 84604-1803
United States
8014273274
Domain servers in listed order:
NS45.DOMAINCONTROL.COM
NS46.DOMAINCONTROL.COM
Accessing the site looks like a redirect, so lets see what is going on behind the scenes:
Code:
bash-4.2$ telnet itanimulli.com 80
Trying 64.202.189.170...
Connected to itanimulli.com.
Escape character is '^]'.
GET /index.htm HTTP/1.1
host: itanimulli.com
HTTP/1.1 301 Moved Permanently
Date: Sat, 26 May 2012 11:52:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: http://www.nsa.gov/index.htm
Cache-Control: private
Content-Length: 0
From KB Bot Hunter:
---------------------------------------------------------
IP Address = 64.202.189.170
Threat Level = Moderate
Threat Category = Malicious Scanner
Threat Description = Site is an aggressive Internet scanner
Hostname =
Service Provider = GODADDY.COM INC
Domain Name = SECURESERVER.NET
ASN Number = 26496
ASN Name = AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, Inc.
Network Speed = DSL
Country CC = US
Country = UNITED STATES
Region = ARIZONA
City = SCOTTSDALE
Longitude = -111.872001647949
Latitude = 33.567699432373
Zipcode = 85260
TimeZone = -07:00
BestAnswer = 1
--------------- thank you for asking --------------------
According to DShield:
IP Address (click for more detail): 64.202.189.170
Hostname: pwfwd-v01.prod.mesa1.secureserver.net
Country: US
AS: 26496
AS Name: AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC
Network: 64.202.160.0/19
Reports: 648
Targets: 605
First Reported: 2011-03-27
Most Recent Report: 2012-05-25
Comment: - none -
And Lastly, looking up their Autonomous System Number (what network / ISP were they part of) GoDaddy.
AS | CC | Registry | Allocated | AS Name
26496 | US | arin | 2002-10-01 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC
Interesting, it looks like they were a 'bad boy' and did some scanning, probably in places that they weren't supposed to and Uncle stepped in. But why the CIA?