← back to threat intelligence
⚖️Disclaimer & Methodology
How these investigations are produced · what they are and are not · effective 2026-06-20
1. Nature of publications
The threat intelligence dossiers published on this site are analytical assessments and opinions — not legal findings, not judicial determinations, and not accusations of criminal conduct.
Conclusions presented herein may be wrong. They represent the best interpretation of available evidence at the time of publication and may be revised, retracted, or superseded as new information becomes available.
Confidence levels (HIGH, MEDIUM, LOW) are explicitly stated for each major claim. Where sources disagree, the disagreement is documented rather than hidden.
2. Personal-capacity disclaimer
The research, views, and opinions expressed on shuffle-on.com are entirely my own. They do not reflect the official policies, positions, or opinions of my employer, Digital Science, or any of its affiliates.
Everything on this site is published in my personal capacity, on my own time, on my own infrastructure. No employer resources, data, or systems are used or referenced.
3. Data collection pipeline
All investigations follow a consistent 6-step pipeline:
- Step 1 — Passive capture: SSH honeypot (Cowrie) records all inbound connection attempts, credentials, commands, and payloads. No scanning, no active engagement of victims.
- Step 2 — Automated enrichment: IPs are enriched from 12+ OSINT sources (RDAP, AbuseIPDB, Shodan, GreyNoise, OTX, VirusTotal, Censys, PeeringDB, etc.).
- Step 3 — Correlation: Entity-linking algorithms detect shared SSH keys, shared malware, temporal coordination, and credential clustering.
- Step 4 — Investigation: Patterns that cross a significance threshold are promoted to formal investigations with structured evidence collection.
- Step 5 — Research: Institutional anchors are identified — RIR records, corporate registrations, government contracts, sanctions filings, court documents.
- Step 6 — Publication: Findings are written up with full source citations, confidence calibration, and alternative hypotheses addressed.
4. AI-assisted research
This research uses large language models (LLMs) as research assistants. Specifically:
- What AI does: Summarizes large document sets, identifies patterns in structured data, drafts prose from structured findings, suggests alternative hypotheses, performs bulk data lookups.
- What AI does NOT do: Make attribution decisions, assign confidence levels, determine what to investigate, choose what to publish, or override human judgment on any factual claim.
Every factual claim in a published dossier traces back to a verifiable source (captured traffic, public record, OSINT platform). The AI assists in finding and organizing evidence — it does not fabricate it.
All editorial decisions, conclusions, and responsibility for accuracy rest solely with the human author.
5. Source hierarchy
Evidence is weighted by reliability tier:
- TIER 1 Direct observation — captured traffic, recorded sessions, file hashes from honeypot
- TIER 2 Authoritative records — RIR databases (RIPE, APNIC, ARIN), court filings, regulatory disclosures, corporate registries
- TIER 3 Community intelligence — AbuseIPDB reports, OTX pulses, GreyNoise tags, PeeringDB profiles, Shodan banners
- TIER 4 Contextual — news reports, blog posts, Wikipedia, industry commentary (used for context only, never as sole basis for claims)
6. Limitations acknowledged
- Observational bias: The honeypot only sees what attacks it. Absence of evidence is not evidence of absence.
- IP attribution imperfection: IPs can be spoofed, VPNed, or proxied. ASN-level attribution is more reliable than individual IP attribution.
- Single researcher: This work does not benefit from institutional peer review. Errors may persist longer than they would in a team environment.
- No legal review: Publications are not reviewed by legal counsel prior to publication.
- Temporal decay: Infrastructure changes. Findings reflect the state at the time of investigation and may not reflect current conditions.
7. Factual corrections
If you identify a factual error in any published material — a misattributed IP, an incorrect organization name, a wrong date — please contact me at lisneanucristian@gmail.com for correction.
Documented corrections will be applied promptly and will leave a visible audit trail in the affected post or dossier. Corrections strengthen the work; they are welcome.
8. Named-entity policy
Where commercial entities or threat actors are named, the naming is supported by publicly verifiable evidence (registration records, captured traffic, signed documents, court filings, regulatory disclosures).
Such material is published under the standard journalistic principle of accurate reporting in the public interest. The purpose is to document observable patterns in internet infrastructure — not to defame individuals or organizations.
Subjects of any publication who believe the material is materially incorrect are encouraged to contact the corrections email above. Good-faith factual corrections will be applied regardless of the source.
9. Data protection & GDPR legal basis
This research processes IP addresses (personal data under GDPR) and, in some cases, names of individuals associated with corporate registrations or public records. The legal bases for this processing are:
- Article 6(1)(f) — Legitimate interest: The security of information systems constitutes a recognized legitimate interest (Recital 49 GDPR). Processing attacker IPs that target personal infrastructure is necessary for network security.
- Article 85 — Journalistic and academic exemption: This research is conducted for journalistic purposes (documenting threats to internet infrastructure in the public interest) and benefits from the derogations provided by EU member states under Art. 85(2).
- Romanian Law 190/2018, Art. 7: Romania's GDPR implementation provides specific exemptions for journalistic, academic, artistic, and literary expression, including exemption from the right to erasure where processing serves the public interest.
References: GDPR Recital 49, Art. 6(1)(f), Art. 85(2), Art. 17(3)(a); Romanian Law 190/2018 Art. 7
10. Data subject rights
If you believe your personal data (e.g., an IP address registered to you) appears in a published investigation, you may contact lisneanucristian@gmail.com to:
- Request information about what data is held (Art. 15 GDPR)
- Request rectification of inaccurate data (Art. 16 GDPR)
- Object to processing (Art. 21 GDPR)
However, please note that the right to erasure (Art. 17) is limited where processing is necessary for exercising the right of freedom of expression and information (Art. 17(3)(a)), for reasons of public interest in the area of public health and security, or for archiving purposes in the public interest / scientific research (Art. 17(3)(d)).
Each request will be assessed individually. Legitimate corrections are always applied; requests to suppress accurate, publicly-sourced information about malicious infrastructure will generally be declined.
11. Active reconnaissance disclosure
In some cases, IP addresses that have attacked this infrastructure are subsequently scanned to determine what services they expose. This counter-reconnaissance is:
- Conducted only against IPs that first initiated unauthorized access attempts against the honeypot
- Limited to port scanning and service fingerprinting (non-destructive, read-only operations)
- Routed through anonymization infrastructure to prevent attribution back to personal systems
- Used solely to enrich threat intelligence (e.g., identifying shared infrastructure patterns)
No exploitation, data extraction, denial of service, or modification of remote systems is performed. This is analogous to checking if a burglar's vehicle has visible license plates — observational, not interventional.
12. Non-commercial purpose
This research is published without any commercial purpose. Specifically:
- No advertising, sponsorship, or affiliate revenue is generated
- No data is sold to third parties
- No paid subscriptions or paywalls exist
- No consulting services are offered based on this research
- The infrastructure is self-funded and self-hosted
The sole purpose is contribution to public knowledge about internet security threats. This non-commercial nature is relevant to both GDPR legitimate interest balancing and to defamation law assessments of intent.
13. Jurisdiction & governing law
This website is operated from Iași, Romania, within the European Union. Any dispute arising from or relating to the content published on this site shall be governed by Romanian law and subject to the exclusive jurisdiction of the courts of Iași, Romania.
The author is a natural person domiciled in Romania and benefits from the protections afforded by:
- The Romanian Constitution, Art. 30 — Freedom of expression
- The European Convention on Human Rights, Art. 10 — Freedom of expression
- EU Charter of Fundamental Rights, Art. 11 — Freedom of expression and information
- Romanian Civil Code, Art. 70-77 — Right to free expression, defense of legitimate public interest
Applicable law: Romanian Civil Code; ECHR Art. 10; EU Charter Art. 11; Romanian Constitution Art. 30
14. Quotation & fair use
Published investigations may quote or reference material from third-party sources (news articles, court filings, corporate disclosures, academic papers). Such use is made under:
- Romanian Copyright Law (Law 8/1996), Art. 33: Right of quotation for purposes of criticism, commentary, and review
- EU Directive 2019/790, Art. 15: Press publishers' rights do not apply to individual words, short extracts, or hyperlinking
- Berne Convention, Art. 10: Quotation compatible with fair practice for criticism and review
All quoted material is attributed to its source. No full reproduction of copyrighted works is made. Quotation is limited to what is necessary to support the analytical point being made.
15. External links & third-party content
This site contains links to external websites and resources (OSINT platforms, news outlets, public registries, academic papers). These links are provided for source verification purposes.
The author:
- Does not control or endorse the content of linked external sites
- Is not responsible for the availability or accuracy of external content
- Cannot guarantee that linked content will remain accessible (archival references are used where possible)
- Provides links in good faith as citations supporting published claims
Effective 2026-06-20 · Last updated 2026-06-21 · Lișneanu Dumitru-Cristian · Iași, Romania
shuffle-on.com · Threat Intelligence