Russian Business Network (RBN) - iFrame Cash and Layered Technologies
According to net-security.org Todd Abrams, the CEO of Layered Technologies had released a statement in which he stated that the company's support database was a target of malicious activity on the evening of September 19th 2007. The incident may have involved the illegal downloading of information such as names, addresses, phone numbers, email addresses and server login details for up to 6,000 clients.
Another blog had reproduced a copy of the email to Layered Technologies abuse team, concerning their dedicated hosting of one of the Russian Business Network’s (RBN) key “commercial” web enterprises ref: iFrame Injection Source? . Although there was never a reply to any email, but possibly with the added assistance of this blog’s bigger friends, they or the RBN obviously took action. This is seen by the change; on September 9th 2007 the change from 72.36.199.58 (USA- Layered Technologies Hosting) to 81.95.153.245 (Russian Federation - Aki Mon Telecom hosting – AKA “RBN”). For those who like the specific details see http://rbnexploit.blogspot.com.
It is reasonable to assume the later attack on Layered Technologies was part of the RBN’s normal procedure to wreak revenge upon those who try to rid themselves of the RBN’s grip. This was just as they did to National Bank of Australia, the Bank of India, and many others.
Hopefully more web hosts will examine who they have as customers in the first place, rather than the value of the credit card?
Details:
Hosting History for Iframedollars.com
IP Address History
|
Name Server History
Event Date | Action | Pre-Action Server | Post-Action Server |
2004-10-04 | New | -none- | Ultralinks.info |
2005-05-22 | Transfer | Ultralinks.info | Iframedollars.biz |
2005-09-22 | Transfer | Iframedollars.biz | Coconia.net |
2007-08-01 | Transfer | Coconia.net | Iframedollars.com |
Information related to 'AS28866'
aut-num: AS28866
as-name: AKIMON-AS
descr: Aki Mon Telecom
org: ORG-AMT5-RIPE
import: from AS40989 accept ANY
export: to AS40989 announce AS-AKI
admin-c: SS7823-RIPE
tech-c: NO322-RIPE
mnt-by: AKIMON-MNT
mnt-routes: RBN-MNT
source: RIPE # Filtered
organisation: ORG-AMT5-RIPE
org-name: Aki Mon Telecom
org-type: OTHER
address: 197022, Russia, Saint-Peterburg
address: pr. Medikov, 5
person: Sergey Startsev
address: Russia, St.Petersburg
phone: +7 903 0983277
nic-hdl: SS7823-RIPE
mnt-by: AKIMON-MNT
source: RIPE # Filtered
person: Nikolay Obraztsov
address: Russia, St.Petersburg
phone: +7 903 0983306
nic-hdl: NO322-RIPE
mnt-by: AKIMON-MNT
source: RIPE # Filtered