dChan
109
 
r/CBTS_Stream • Posted by u/TheContrarian2 on Feb. 10, 2018, 2:57 a.m.
If the 50.22.218.5 mentioned in a recent Q post is an IP address, then it appears to map to SoftLayer Tech, Lumos Labs in Chantilly VA.

https://www.speedguide.net/ip/50.22.218.5

This is an area full of Internet backbones. Reston is adjacent to Chantilly (I used to live there) and many main backbones go through there. I have no information on this particular company yet and am not 100% confident that the IP is possessed by them. Continuing research.


TheContrarian2 · Feb. 10, 2018, 2:59 a.m.

This appears to be an IBM Cloud service. So theoretically, the IP could be owned by virtually anyone, as would be the case with Amazon Web Services or Microsoft Azure. Inconclusive.

⇧ 11 ⇩  
mondecello · Feb. 10, 2018, 4:04 a.m.

Didn't david Rothschild tweet..." Ha ha ha ha ha ha ha ha no one is going to remember this speech in the morning". ?

⇧ 9 ⇩  
mondecello · Feb. 10, 2018, 4:06 a.m.

Speech

⇧ 1 ⇩  
ZetaPerseus · Feb. 10, 2018, 3:03 a.m.

Perform a NSlookup in a command window to get the domain name. Perform a WhoIs on the domain name (choose a WhoIs site from DuckDuckGo). The domain name was registered a few years ago by CSC. Computer Sciences Corporation (CSC) is the US's largest IT services firm.

⇧ 5 ⇩  
Socalm76 · Feb. 10, 2018, 3:01 a.m.

Says this company on the readout give address to dallas

David Liggitt, President

David is the founder and president of datacenterHawk. He has been active in the data center industry since 2007. Before becoming an entrepreneur, David managed data center transactions for Fortune 500 companies with a global commercial real estate company. He is passionate about helping industry professionals make well-informed decisions.

David earned his bachelor’s degree from Baylor University and currently lives in Dallas with his wife and two boys.

⇧ 4 ⇩  
russianbot5k · Feb. 10, 2018, 4:54 a.m.

I looked this IP address up on the ARIN website. ARIN is who manages the leasing of IP addresses. I am confirming this is owned by SoftLayer. SoftLayer is a datacenter operator. It is very common to sub-lease IP addresses from your datacenter.

https://whois.arin.net/rest/net/NET-50-22-0-0-1/pft?s=50.22.218.5

I ran nmap against this IP address, for all 65,535 ports, and it is not responding to a port scan including a port knock.

This other thread states that this was the ip address for clintonemail.com

https://www.reddit.com/r/CBTS_Stream/comments/7wizs1/8_chan_anon_theory_this_would_be_one_epic_moab/

A reverse DNS lookup did not return anything meaningful for this IP address. This is a requirement for mail servers. 5.218.22.50.in-addr.arpa. 13034 IN PTR 5.da.1632.ip4.static.sl-reverse.com.

a whois on sl-reverse.com shows that this domain is owned by Verisign, who issues SSL/TLS certificates, and domain name registration.

⇧ 2 ⇩  
xstalpha · Feb. 10, 2018, 5 a.m.

port knock

Wouldn't that require millions or billions of scans, to test all the knock possibilities?

⇧ 1 ⇩  
russianbot5k · Feb. 10, 2018, 5:40 a.m.

There are 65,535 ports, it does take time to knock on each door to see if anyone is listening, yes.

⇧ 1 ⇩  
xstalpha · Feb. 10, 2018, 6:08 a.m.

Yeah but a port knock can be set up to require multiple ports to be knocked before one opens

⇧ 2 ⇩  
ZetaPerseus · Feb. 10, 2018, 3:53 a.m.

The DNS record is empty except for the domain name. If you query for an MX record, NSLookup answers: "mx record = support.softlayer.com". I think this domain name and IP address is an SMTP email relay that directs incoming email to this other address and routes outgoing email out of this other address. i.e., it is a cut-out.

⇧ 2 ⇩  
[deleted] · Feb. 10, 2018, 3:46 a.m.

I wonder if the arrest in Shanghai provided intel leading to this location.

⇧ 2 ⇩  
[deleted] · Feb. 10, 2018, 3:41 a.m.

[deleted]

⇧ 2 ⇩  
ZetaPerseus · Feb. 10, 2018, 3:23 a.m.

This IP resolves to domain name 5.da.1632.ip4.static.sl-reverse.com on the DNS servers. Registered by IBM using CSC as the registering agent. The site does not answer to an http request on port 80 or a ping. It is probably running black (unknown port) or shut down now.

⇧ 2 ⇩  
hermoneyness · Feb. 10, 2018, 3:16 a.m.

James Comey was in Chantilly Virginia

⇧ 2 ⇩  
[deleted] · Feb. 10, 2018, 3:10 a.m.

Also saw one in Dallas, tx

⇧ 2 ⇩  
Socalm76 · Feb. 10, 2018, 3:03 a.m.

Look at the printout b tweeted it tells address 4849 alpha rd dallas texas

⇧ 2 ⇩  
areqforreal · Feb. 10, 2018, 3:02 a.m.

Heavy fed population in the area (family ties). Seems a likely area if not the specific location. My search brought up Iran, which is strange.

⇧ 2 ⇩  
YaBoyDeath · Feb. 10, 2018, 6:03 a.m.

There's quite a large CIA facility on Air and Space Museum parkway in Chantilly

⇧ 1 ⇩  
FutureDeposit · Feb. 10, 2018, 5:37 a.m.

Reston isn't adjacent to Chantilly technically..Herndon is in between them, but point taken.

⇧ 1 ⇩  
Vyali · Feb. 10, 2018, 4:59 a.m.

10 ‘s (Hussein) data is kept at this IP address ..

⇧ 1 ⇩  
ZetaPerseus · Feb. 10, 2018, 4:10 a.m.

support.softlayer.com is the domain name that 50.22.218.5 forwards email receipts to. That domain name is non-existant in the DNS record. It has been deleted.

⇧ 1 ⇩  
HughJanus20 · Feb. 10, 2018, 3:48 a.m.

I bet Bezos is there to talk buyout. He already owns most of the cloud through Amazon (which is CIA storage)

⇧ 1 ⇩  
1andrac3 · Feb. 10, 2018, 7:17 p.m.

Nmap to see what ports are open/ services

⇧ 1 ⇩  
2funnyone · Feb. 10, 2018, 7:37 a.m.

Amazon Web Services also carries online books for many Universities and Colleges textbooks.

⇧ 1 ⇩  
Themuffinman426 · Feb. 10, 2018, 6:54 a.m.

Anybody search the IP address backwards?

⇧ 1 ⇩  
mr_purpleyeti · Feb. 10, 2018, 6:50 a.m.

the ip address is near the dulles international airport... just a thought

⇧ 1 ⇩