To view the list of links, please access this site using Tor Browser.
If you’re seeing this message, access is restricted for regular browsers.
Already using Tor? If you are sure you’re currently in Tor Browser, proceed to our .onion version:
13. Similar to the above, the funds from Wallet 4 were also “mixed” by a commercial service, and through thorough analysis, the United States Postal Inspection Service was able to “de-mix” the flow of transactions, to eventually ascertain that funds from Wallet 4 paid FROST’s accounts at the Gaming Company.
14. Similar to the above, the funds from Wallet 5 were also “mixed” by a commercial service, and through thorough analysis, the United States Postal Inspection Service was able to “de-mix” the flow of transactions, to eventually ascertain that funds from Wallet 5 paid FROST’s account at the Gaming Company.
3. During the BKA’s investigation, the BKA determined the
WSM administrators accessed the WSM infrastructure primarily
through the use of two VPN
service providers. The BKA
determined that one of the administrators (based on the fact
that this individual was accessing control elements of WSM to
which only an administrator had access) used VPN Provider #1.
Based on the BKA’s analysis of the WSM server infrastructure,
the BKA noticed that on occasion, VPN Provider #1 connection
would cease, but because that specific administrator continued
to access the WSM infrastructure, that administrator’s access
exposed the true IP address of the administrator.
According to the Dutch National Police, which
issued legal process from Github, a platform for software and
coding development sharing, LOUSEE holds an account with the
user name “codexx420” similar to the administrator account
“coder420” found on the Gitlab server.
The third administrator for WSM was known as “TheOne,”
and as described below, the investigation has further revealed
probable cause to believe that FROST is “TheOne” for two primary
reasons. First, as described below (at paragraph 30), the PGP
public key for “TheOne” is the same as the PGP public key for
another moniker on Hansa Market, “dudebuy.” As described below,
a financial transaction connected to a virtual currency wallet
used by FROST was linked to “dudebuy.” As explained above in
paragraph 4.l, a PGP public key, in the context of darknet
investigations, is likely a unique identifier to an individual.
Second, as described below (at paragraph 31), investigators have
identified a wallet used by FROST that subsequently received
Bitcoin from a wallet used by WSM for paying commissions to
administrators.
20. In the course of BKA’s investigation, and pursuant to valid legal process in Germany, the BKA identified the servers operating WSM. Through valid legal process, the BKA imaged a copy of the database of WSM. The BKA has reviewed that database and confirmed that the database held information for WSM. I have also reviewed that database and confirmed that it is part of the infrastructure enabling WSM to operate. For example, in my review of the database imaged by the BKA, I observed that the SQL database was named “tulpenland.”
21. In reviewing the WSM database, I reviewed the settings table. Based on my review of the settings table, I learned that it included conversations between The Administrators using the monikers “coder,” “TheOne,” and “Kronos.” Those conversations are in German and discuss, among other things, WSM server maintenance, concerns regarding vendors, and payments between The Administrators. Further, the settings table reveals that payments from WSM are split into three equal parts, one for each of The Administrators and paid once a month.
22. Additionally, the BKA advised me that in its analysis of the WSM infrastructure that was located in Germany, it found another server, located in the Netherlands, responsible for the development, testing, and updating of the WSM infrastructure (the “Gitlab server”). The Dutch National Police, in the course of its own investigation, and pursuant to valid legal process in the Netherlands, obtained an image of the Gitlab server. I also reviewed a copy of the image of the Gitlab server, and confirmed that it was part of the WSM infrastructure because of, among other things, the server contained programming code language for
design, functionality, and maintenance of WSM.
8d. Usually after the vendor confirmed on WSM that the contraband had been shipped, WSM released the funds to the vendor for payment from the customer, less commission fees retained by WSM.
Further investigation revealed that these packages came from a vendor, "U4IA," who advertised on WSM... ...I learned that this darknet vendor had been convicted for distributing fentanyl resulting in the overdose death of the Florida resident and was sentenced to 12 years in prison.
He'll look around the danknet, he won't tell you his plan
He's got a rolled cigarette, hanging out his mouth he's a doxxboi kid
Yeah found a way to exit scam
In his admin's panel, hidden oh in a box of fun things,
i don't even know what
But he's coming for you, yeah he's coming for you
All the other kids, with no PGP skills
You'd better run, better run, outrun LE
All the other kids with no PGP skills
You'd better run, better run, faster than Speedstepper
All the other kids, with no PGP skills
You'd better run, better run, outrun LE
All the other kids with no PGP skills
You'd better run, better run, faster than Speedstepper
Vendor works a long day
He be coming home late, he's coming home late
And he's bringing me a surprise
'Cause my speed's in the kitchen and it's packed in ice
I've waited for a long time
Yeah the ESCROW of my order is now a quick press FE
I reason with my lawyer
And say your address's in plaintext, you must have lost your wits, yeah
All the other kids, with no PGP skills
You'd better run, better run, outrun LE
All the other kids with no PGP skills
You'd better run, better run, faster than Speedstepper
All the other kids, with no PGP skills
You'd better run, better run, outrun LE
All the other kids with no PGP skills
You'd better run, better run, faster than Speedstepper