AnonymousLK, Case Closed?

If you were reading the series of posts about AnonymousLK, we said that AnonymousLK is comprised of 4 hackers.

However we never posted any info about TX and Zer0 Thunder, therefore I think it’s good to add a short note about why we never posted information about these two.

After making the posts about HackerzMafia and ZonTa, @ipv10 went on to the IRC channel of AnonymousLK few weeks ago (irc.evilzone.org #srilankanz), where she talked with TX who once threatened us commenting on this blog.

By that time we’ve found almost all the information about TX and Zer0 Thunder and it was about whether we should post them or not. @ipv10 told TX what we’ve found about him and he admitted that it is him and he kindly asked not to post about him.

Because he was kind enough to admit his identity and told about his story and given us references to confirm his identity we decided not to post about him.

Same can be said about Zer0 Thunder, although he wasn’t ready to accept his identity. Finding Zer0 Thunder was the best part, it was hard to find loose ends. until we found out that we can get an email from hackimpact.com the website that Sameera (HackerzMafia) and Shalika (ZonTa) and Zer0 Thunder created, the email has the name of Zer0 Thunder in it.

Any one can get this email address by registering at hackimpact.com which is now hidden from the website and from Google by robot.txt.

UPDATE :

I just found this status from AnonymousLK today. The image shows them say that they have set up their IRC channel at irc.evilzone.org at #srilankanz.

If you look at the date you can see that the Tweet was made in August 22, 2011. And if you look at the date that AnonymousLK joined Twitter it’s August 19, 2011. So this further proves us right that the IRC channel was indeed used by AnonymousLK from the beginning.

We expected you, nothing happened.

The End?

Who Is This Anonymous ZonTa? ZonTa Unmasked.

Never stop your enemy while he is making a mistake

I had a different post dedicated for ZonTa which I was thinking publishing first, however I decided to rewrite the post because as the time went on more and more evidence came up about it. When I first published my post Rooting the Anonymous, ZonTa came to my blog commentingabout the post, actually he was the first to comment on the post.

ZonTa accepts Sameera is among AnonymousLK

This comment makes some interesting points, let me give it to you one by one.

  • ZonTa admits Sameera De Alwis tweets from AnonymousLK.
  • ZonTa says Sameera tweeted about the IRC channel that has no connection to them, although the chat records and screen shots clearly shows that the people in the IRC channel #srilankanz talk about AnonymousLK activities.
  • If you look at the comment made by ZonTa even a child can understand that this comment is made by the real ZonTa defending the IRC channel and to show that he has no connection with Sameera, did I anywhere in the post about Sameera have mentioned about the IRC channel? NO, so why is ZonTa panicking so much about the IRC channel?
  • And why no reply from ZonTa after us proving that people #srilankanz channel at irc.evilzone.orgadmitting that they are AnonymousLK?
  • If this is not the real ZonTa how can he say the #srilankanz channel was created 2-3 years ago?
Anyone can access the IRC channel and talk with ZonTa via : irc.lc/irc.evilzone.org/srilankanz (if ZonTa is there)

So ZonTa has no connection with AnonymousLK? I’ll let you decide after this post. But before that let me give you a small story that dates back before AnonymousLK. After the filed browser xAurora, hackerzmafia got together with ZonTa who was arrested same year, and ZeroThunder to from hackimpact.com which was another epic fail as xAurora. Remember this for now, I’ll come to this point tater.

I have to say that it’s not just their Tweet that had the irc link to the #Srilankan channel, even in the Facebook profile picture from their begging they had the irc link to the #srilankanz channel. So if ZonTa say his irc channel #srilankanz has no connection with AnonymousLK why is AnonymousLK show a link to the irc for nearly one year?

Click to see the large photo

AnonymousLK tweet their IRC

So if we go to the AnonymousLK irc channel #srilankanz at irc.evilzone.org, a simple irc command is all you need to see who created the IRC channel, /msg chanserv info #srilankanz. Which gives a result like this,

ZonTa created the #srilankanz channel

This clearly shows that the IRC channel #srilankanz was created by a person named ZonTa back in 2010, which exactly mach the dates of the comment. Coincidence? You decide 😉

As you saw in the post with the chat records, we’ve been to their AnonymousLK IRC channel, and when you see the “whois” information of ZonTa (“/whois zonta” if he is online), the whois information for ZonTa is,

Whois information for ZonTa

As you can see there is a domain name associated with ZonTa, zt-security.com. zt-security.com was hacking forum that was run by ZonTa until 2011, every domain name has a registration information that the person owning the domain name has to give before buying a domain name, you can hide this information if you want, which unfortunately ZonTa didn’t or forgot to hide.

Whois information for zt-security.com : http://whois.gwebtools.com/zt-security.com

So we have a name and an address belonging to ZonTa, which the name is Shalika Ranatunga, and an address leading to Mirigama area. If you are familiar with the hacking incidents in Sri Lanka, the most famous hacking incident was the hacking of the Western Provincial Council Website which was back in 2009, which was done by a hacker naming ZonTa, he didn’t hide his IP and got arrested.

News article about ZonTa’s arrest : http://sundaytimes.lk/cms/article2.php?id=3784,

There is a small typing mistake in the article where the name should be Shalika Gayeshan, not Shantha Gayesha.

A student who is alleged to have hacked into the Western Provincial Council website was produced in courts today and given bail of Rs. one million by Colombo Chief Magistrate, Nishantha Hapuarachchi.

Shantha Gayesha Ranatunga from a leading school in Mirigama is alleged to have distorted facts between the Chief Minister and the Governor of the Western Province and in the process disturbed the functions of the site, the court was informed.

So is this coincident, both the WPC hacking ZonTa and IRC channel creator of ZonTa both having the same name and address, coincidence? 😉 you decide.

More articles showing ZonTa did the hack on WPC website :

Hacker Busted in Sri Lanka ( Real Story ) – ElaKiri

Community Lokuma Boruwa … ( Sri Lankan Hacker ) – ElaKiri Community

So now that we have a name on ZonTa, Shalika Gayeshan Ranatunga, googling the name will give all the information for everyone to see who’s ZonTa. I’m not going to post his social networking profiles, because I don’t think it’s not a good thing for him, he was convicted before and getting caught for hacking for second time means there is no way out for him except jail.

And I won’t put where he’s working, because I don’t like to see him lose his job, I’m not the bad guy like they’re so hard trying to be, ZonTa aka Shalika Ranatunga is responsible the of network security in a leading Sri Lankan mobile company.

However I’m going to give one profile of Shalika Ranatunga, his linked in profile. This nails the coffin on the mysterious ZonTa and shows the connection with ZonTa and Sameera.

ZonTa’s (Shalika Ranatunga’s LinkedIn Profile) : http://lk.linkedin.com/pub/shalika-ranathunga/23/25/72a

Go to the LinkedIn profile and see what’s the “Business Website” of Shalika, guess what it’s hackimpact.com, which is owned by the Sameera De Alwis as we’ve shown the person who create AnonymousLK, ZonTa, Zer0Tunder and Sameera started hackimpact.com, can’t believe it? Check out the video below.

ZonTa also has a Fiverr profile which he uses the username BugFree, where he shows off his black hat capabilities to make money, he used to tweet all these things on Twitter, after we published the first post about Sameera, ZonTa was quick to delete all the tweets, but he didn’t delete his “Fiverr gigs”.

Fiverr.com/bugfree

In an epic fail today, AnonymousLK tweeted this, admitting that ZonTa is their IRC friend, actually he’s not just a friend but the guy who created your IRC channel.

Anonymous admits ZonTa is their friend

That put a wrap to this mystery about who is ZonTa and completes the whole picture about AnonymousLK, anymore things I need to prove?

It’s epic that someone has commented on the Elakiri article about your arrest,

If you’re a good hacker everybody knows about you, if you are a great hacker nobody knows about you.

What now AnonymousLK, more denial? more running from truth? more screwed up theories with no facts? Still say ZonTa is not your friend?

Don’t say ZonTa and everyone are in my team, I don’t work with black hats. Hope this post refresh your memory ZonTa. Tango Down.

When are you going to hack my email Shalika? 😉 

Personal note :

Me and ipv10 were talking about ZonTa last night, most Sri Lankan hackers think that ZonTa is the best hacker in the country, which he is not. He thinks he is a good hacker which he is not, obviously he’s no more than a n00bs. Our guess was that he never expected someone from Sri Lanka will out smart them. Me and ipv10 has been in the infosec field more than you ZonTa, G2kev just stated his infosec work but is younger than you can’t even imagine.

And I’m not a hacker, I’m just a guy who does infosec work as a hobby. I’m Razor or anyone you say I am. So no more hiding ZonTa, no more false tweets. Admit it, we gotcha 😉

I think Shalika has some addiction for hacking, or else who else continue this work even after being arrested?

UPDATES : 

Update 1 :

Due to misunderstanding of some people i need explain that @g2kev is not G2 Gayan and has no connection with G2Labs of G2 Gayan. It just happens to be @g2kev‘s twitter username begins with G2, everything in this op was done by me, ipv10 and g2kev with no support from external sources. I hope this clears things out if people have any doubts. More posts to come, all in good times.

Update 2 : 

We found the deleted tweets of ZonTa asking to check website security on Fiverr, all these tweets were deleted after we posted the first post about Sameera.

Full set of tweets here : http://topsy.com/s?type=tweet&q=from%3Ashalika 

UPDATE 3 :

After a series of posts about AnonymousLK hackers their Twitter account has become private.

I

Rooting The Anonymous : Part 1

If you know about Anonymous hackers, the cyber anarchists, Sri Lanka is no exception with our own Anonymous Sri Lanka (@anonymouslk) hackers, they are famous for their DNS spoofing attacks on Facebook, Apple, Microsoft,  Symantec and many more websites.

Credits :

This is not my own work but a team work that includes @ipv10, and @g2kev which I think are the best in the country in infosec work

The beginning of the investigation.

Today this begins a series of posts where I publish the results of a month long investigation in to finding AnonymousLK, we’re going to publish about the members of the AnonymousLK one by one.

Click to see the enlarged images, so they’ll be more clear.

There is nothing illegal regarding the information we’re publishing, all the data, pictures and everything are publicly accessible on the internet which can be found by a simple googling.

AnonymousLK is a team of 4 people :

  • HackerzMafia, the leader and the person most of the time behind Twitter which we’re going to root now.
  • Zonta
  • ZeroThunder
  • TX

On their Facebook  profile picture they show an email address to contact them, the email address is anonymoussrilanka@gmail.com. Which is also the email address of their Facebook account.

The link between the emails.

The first thing we did was to reset the password of the email account, not to hack the account, but to get an idea of the associated contact info that is used to send the password reset code/link. When resetting anonymoussrilanka@gmail.com account you get something like this,

Password reset form for anonymoussrilanka@gmail.com

You can see the anonymoussrilanka@gmail.com account is linked with an email with 12 digits that begins with h and ends in an a. and a mobile phone number ending with 84.

Most people have written time and time again that Anonymouslk is a guy called Dr Sameera De Alwis, a failed wanna be tech guy who got screwed really bad. So we did a small googling about Dr Sameera De Alwis and we found an old post he made on a forum talking about his failed xaurora browser. Link  to the post : http://www.skyscrapercity.com/showthread.php?p=21993769

There Sameera De Alwis is giving his contact information, note the email address : hackerzmafia@gmail.com. A 12 digit email address, that begins with a and ends with a. 

So we decided to check the associated contact information for the hackerzmafia@gmail.com email account, and it comes up like this,

reset password form for hackerzmafia@gmail.com

There you can also see that the email account is associated with a number ending with 84 same as the anonymoussrilanka@gmail.com email account. And in the picture showing Sameera De Alwis’s contact information there is another gmail account belonging to him, dr.sameera.de.alwis@gmail.com, so we decided to reset the password for that email account and this comes up,

Password reset form for dr.sameera.de.alwis@gmail.com

And the email account dr.sameera.de.alwis@gmail.com email account is also connected to a mobile number ending in 84. We can see that anonymoussrilanka@gmail.com, hackerzmafia@gmail.com, dr.sameera.de.alwis@gmail.com all these emails are connected to a mobile number ending in 84. So we can assume that all three email accounts are connected to the same mobile number. Which means the email anonymoussrilanka@gmail.com is created by non other than Sameera De Alwis himself also known as HackerzMafia.

Sameera De Alwis also owns a website called hackimpact.com,

If you go to the contact page of hackimpact.com you’ll get something like this.

http://hackimpact.com/contact-us | Click to see clearly

We’ve censored the name because it belongs to a lawyer, probably Sameera’s lawyer, however if you see the contact number of the website owned by Sameera De Alwis (hackimpact.com) the number is : 077-2516084, well well well what have we here, a number ending with 84 that is on Sameera De Alwis’s website hackimpact.com, so we can assume that all the anonymoussrilanka@gmail.com, dr.sameera.de.alwis@gmail.com and hackerzmafia@gmail.com are linked with the number, 077-2516084.

The Typing style of AnonymousLK and Sameera De Alwis.

Both Anonymouslk and Sameera has a common typing style that you can see from time to time. For example,

See the underlines phrase..

See the phrase underlined red, “Freedom for all man kind on earth”, now where have we seen that before?

Sameera has used the very same phrase, “Freedom for all man kind on earth” on his online forum post, and  “May peace prevail…” is another phrase that is being commonly used by Sameera, or should I say Anonymouslk 😉

This was taken from an old blog post made by Sameera De Alwis,

Sameera has used the exact phrase again.

Who is Sameera De Alwis?

The guy who created AnonymousLK, Sameera De Alwis

Sameera De Alwis was a wanna be tech guy, who reversed engineered a popular browser and released it as his own, collecting money asking for further development of the browser, however people took notice of this and Sameera had to stop his browsing adventure, lost his job as the head of IT security at Maharaja INC and lost his job as a Lecturer of SLIIT.

This article gives all the infomation about the life of Saeera De Alwis : http://sameeradealwis.wordpress.com/2009/06/16/dr-sameera-de-alwis-can-be-trusted/

Sameera’s Hi5 profile where he posted photos of his dead mother and her ashes : http://www.hi5.com/hackerzmafia 

A letter written by Dr Sameera De Alwis after the truth about xAurora browser was exposed : english.kalingasblog.com/2008/10/xaurora-the-fake-web-browser

xAurora getting caught of being a fake browser : http://forum.maxthon.com/viewthread.php?tid=74416&extra=&page=1

XAurora Browser Blog : xaurora.wordpress.com

Final conclusion

So the final conclusion is that Sameera De Alwis started the AnonymousLK accounts and he also recruited the other hackers named Zonta, ZeroThunder and TX.

This is the reason for the change of language when tweeting, Sameera is the one tweeting with bad words while Zonta is the one who tweets normally.

Hiding your ip is not enough  AnonymousLK, In prison the inmates will root you 😉 Tango Down.

External links :

Sameera De Alwis’s dotnet forum profile – HackerzMafia : dotnetforum.lk/forums/p/10216/35030.aspx