I tried posting to /r/darknetmarkets but the mods said I didn't provide enough proof so they removed this post. Truth be told, this was a pretty easy (and lucky) find that LE could have done the same. I say it's lucky because when I did some investigation into the IP, it appears that this is a new server.. the admin is likely moving around to avoid detection.
I found this on Censys.io when I queried for the address of Wall Street's forum... and this IP popped up.
> SSL certificates specifically should only be bought from a small group of authorities trusted worldwide or they’re essentially pointless
https://www.censys.io/certificates/2028b5221de277ef1e961f4e3182a3c500ee5aa67bf5b544d3a6d58a5ea6777d
> C=RU, ST=Moscow, L=Moscow, O=RU-Center (ЗАО Региональный Сетевой Информационный Центр), CN=RU-CENTER High Assurance Services CA 2
> Browser Trust
Apple Trusted Intermediate
Microsoft Trusted Intermediate
Mozilla NSS Trusted Intermediate
The IPs now show 404 errors, which makes us think they were using Nginx as a reverse proxy for the real site. A few people found the other IP, which was also taken down.
I am not sure how they found their IP but I found the one I posted by searching the site censys.io for various keywords. You can start with "onion market" but you'll see 100K's of results. Best to start narrowing it down with keywords that are unique to the site.
For Wall Street, I found it by searching for the onion address of their forum: https://www.censys.io/ipv4?q=x7bwsmcore5fmx56
You'll see two results. The 5.x.x.x one is a phishing site. The second one was not.