No the website is called any.run
This is actually really cool! This sounds like a great service. Seems like they run dynamic analysis for malware.
For other people that want to have a Dynamic Analysis Malware Lab at home just like this, here are some resources.
hxxps://cuckoosandbox.org/
hxxps://www.youtube.com/watch?v=p7VMV8R7pyo
To catch malware to test with:
hxxps://www.honeynet.org/projects/active/dionaea/
You can search github for some malware databases.
People collect samples and upload them.
I'm not gonna share because I'm not sure if it's against the rules so I don't want to break them.
But you can find some online, setup your lab, put them in, and see what they do.
Most are pretty dumb.
If you're using Tor for illegal activities, how safe are you and how to improve that ?
If you're buying drugs or something on it, you should be fine. If you're hosting a website on tor from home, that can be way more difficult.
Your ISP knows every time you connect to Tor, which means the feds also know. One way they know who's who online, is to see who signs on and off on Forums on Tor. They match the time with the logs they get from ISPs and they can deanonymize people this way. Having a VPN provider helps this, especially if they're outside your country, and the fourteen eyes. Takes a lot longer to work with other governments and companies outside a country.
Definitions:
clearnet = hxxp://website[.]com
on the Tor Network would be like aklshenruiofgnjknaoisdf[.]onion
Also, depending if you stay on the Tor Network vs. go to clearnet, is another way to be deanonymized.
Example) I visit EvilClearnetFourm[.]com, but I"m Tor. Now let's say the feds are monitoring all traffic being sent to EvilClearnetFourm because the internet provider of this website is giving them all the logs. When I travel to the website, MY ISP knows how much traffic in bytes are being sent out. EvilClearnetFourm's ISP RECEIVES the EXACT same number of bytes, close to the same time. Feds use this to deanonymize people that use Tor on the clearnet. It's called a correlation attack.
hxxps://www.eff.org/deeplinks/2014/06/why-you-should-use-tor
hxxps://blog.torproject.org/traffic-correlation-using-netflows?page=1
Is possible to get information, because they have EXIT Relays and that is where you can be caugh. Is not impossible, FBI and Europol or Interpol does that to catch high profile criminals.
Isn't impossible, if is little harder? Yes, but from them they are high skilled. They will try to track, and you will left traces like Login in personal Social Media with TOR, same passwords you use, they will try to match to any Social media.
And they got it, easily. With a simple password they can discover who you are. Let's talk you use "mypassowordishard2" you are the one in the world who uses that or in your country, they know your password by takedown any website in TOR, they use that password and they ask for information in Social Media, Websites they will discover you easily.
By using a password, don't you believe? Better start thinking that's possible and they do it. Most of people doesn't know that, or doesn't care about that, but that is a TRACE.
This is correct. The Exit Relay attack is what I listed above. As for the social media, this is why Qubes is pretty nifty. You can create a VM, put all your personal stuff in one, and have it go out through your ISP, while having all your sketchy stuff in another VM, that sends traffic to your VPN, and then TOR. You'd segment your personal life with your other life, and you setup the traffic so they also look like they're coming from different locations.
And yes, never use the same password across the internet. Some websites don't encrypt people's password, and when they get hacked, hackers and anyone with the database can see your password and email. If you didn't change it, they'll login to your email or any other website they can find you at.
Why aren't hackers targeting internet marketers? It would certainly be the most profitable ones to target?
Also to address this further. Some hackers do malvertising. I'm not quite familiar with the process entirely, but what I believe happens, is someone will signup with advertisers that allow it (or do it sneakily), create an Ad and put malicious code in it. Could be a script that executes code from another website or location), and then put their Ad on as many websites as possible. In this way, as soon as someone visits the site, they're hacked. It's usually a network of people that do this. One guy will own a shitload of compromised websites, and another person handles the ads/pulling out the money, and another person will create the exploit kit. They all get paid well.