#EpikFail leak #3 researchers, I present your network layout. Note that "NATCOWEB" is a fake company hosting nearly all Epik infrastructure using IP addresses procured in Ukraine. Also home of oathkeepers, prolifewhistleblower, americafirstfoundation, etc sites.
Want to know more about #EpikFail and NATCOWEB? It starts with the incorporation docs... sos.arkansas.gov/corps/search_c…
SERGEY SABETIEV owns NatCoWeb and it's associated companies (iPipe / Allus Online) under the names:
Sergei Sabetev
Sergiy Sabyetyev
But look at who the incorporator of NATCOWEB is - Alexandra Kouras. Check out all the other shady companies spun off of this person, including a wild game safari tour company. opencorporates.com/officers?q=ale…
NATCOWEB is a shell company hosting Epik and it's customers, such as GOP.
Besides Sergey Sabyetyev spelling his name differently on every legal doc, this same method is used to procure IP addresses for Epik. They buy them as "IPEK" then rename to "Epik" after purchase to avoid law enforcement and intelligence services review of sales documents.
These are the networks being hosted out of NatCoWeb (AS46636). Overoptics Systems is a UK shell company reg'd to a Ukrainian from Crimea. level0, Life on Mars, iPipe, HQhost: fake. See that "russian department" network? Same datacenter with texasgop and others? #EpikFail
iPipe's remaining network blocks can be found in Moscow, using Russian DINET-AS (AS12695). Why do the #GOP, alt-right and other extremists host their websites in a datacenter with network peering directly to Russia? #EpikFail
Epik has no idea what the software does that runs their company. Epik CEO Rob Monster admitted publicly that WECANDEVELOPIT, a dev team made up of Russians and Ukrainians, have been running the show for 10+ years. #EpikFail
Official hosting company of Mike Flynn’s “America’s Future” and other J6 celebrities’ sites say they’re now an official Portuguese company! Congrats, but you’ve been hosting those customers since 2021 as IPVolume & K4X (Estonia).
In this move, there was a minor mistake. 🇷🇺🧵
Let’s take a look at americasfuture[.]net’s real web server IP that‘s hidden behind Cloudflare: 91.149.224.78. Currently registered to Gigahost, rebranded from Terrahost, IPVolume, and Anonymize, which were all Epik projects. I’ve referenced this before
On July 6, while transitioning IP blocks for this “new” K4X, the America’s Future server IP was registered to a Russian IP network “BRM” (Berdiev Ruslan Mukhabatovich, ORG-BRM5-RIPE) with sponsoring org Alex Group LLC🇷🇺 (ORG-AGL35-RIPE). Only lasted a day ripewhowas.prefixbroker.com/?search=91.149…