captainGeech42 / ransomwatch

Ransomware leak site monitoring
MIT License
305 stars 64 forks source link

Cuba/Suncrypt/Everest always think its the first scrape #55

Open x-originating-ip opened 3 years ago

x-originating-ip commented 3 years ago

Describe the bug Darknet sites for Cuba, Suncrypt and Everest always return as "This is the first scrape for x, no victim notifications will be sent." I feel like scraping for these specific sites might currently be faulty as they definitely currently have victims on the site which should be being captured and archives as part of the scrapes.

To Reproduce Run the tool with Cuba/Suncrypt/Everest TOR addresses inputted in config.

Expected behavior For the Cub/Suncrypt/Everest site scrapes to return victims that are successfully populated into the SQL database.

Screenshots N/A

Logs N/A

Environment

Additional context I should probably raise as a separate bug report but unsure if this is actually a bug or just the nature of TOR - does anyone else have exceptionally shaky up time with the darknet sites? I can run multiple concurrent scans and find that on one scan certain sites will be scraped fine while an immediate subsequent scan will find that the same site is down? Has anyone else experienced this flakiness of the scrapes? I know TOR sites are up and down like yoyos at the best of times, but this feels like it might be mroe bug based...

captainGeech42 commented 3 years ago

The scrape may not be working properly for those, I'll take a look when I can and get those updated. Thanks for flagging the issue!

Some sites are definitely up more than others, a few of them have terrible uptime (Avaddon was one that was up maybe half the time). It could be that the timeout value is too aggressive for your network connection, adjusting that may be beneficial. You can change the timeout value in the config.