Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

RBN - Partners Official Sponsors of ICANN?


Russian Business Network (RBN); what if they were out to own the Internet by owning the DNS? The Internet totally relies on DNS (Domain Name System) so obviously this must be the stuff that Hollywood movies are made of, but this nightmare scenario is more real than any of us would like to believe.


This article draws a few of the ingredients together, it is important to stress this is not to discredit ICANN, but to show just how RBN and their associates are applying themselves to the weakness of DNS allocation and exploiting ICANN’s vulnerability via influence, commercial sponsorship and registrar development.


  • Firstly, RBN’s normal chaos creation, shown within the important and recent security research paper “Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority” by David Dagon, Niels Provos, et. al.; “291,528 hosts on the Internet performing either incorrect or malicious DNS service. With DNS resolution behavior so trivially changed, numerous malware instances in the wild, we urge the security community to consider the corruption of the (DNS) resolution path as an important problem.” [ref 1]
  • Connect this to the newer RBN technique to now ‘auto-generate’ 1,000’s of new malware and rogue domain registrations via duped or controlled registrars, e.g. Tucows (Ca), EstDomains, and shielded by PrivacyProtect - which now can outrun most security bloggers, security companies, black listing or rogue domain listings. [ref 2]

So, who runs or has the responsibility for DNS and keeping it safe? - ICANN (Internet Corporation for Assigned Names and Numbers) mostly self elected and privately operated as ICANNwatch.org describes “avoiding governmental accountability mechanisms, but ICANN also lacks much of the accountability normally found in corporations and in nonprofits.” [ref 3]



The facts – who?

LogicBoxes and Skenzo host a "Taj Mahal Sojourn" for guests at the 31st ICANN Meet in Delhi, India - “The elite list of attendees included the likes of Enom and Tucows head honchos, Paul Stahura and Eliott Noss respectively. Trey Harvin - CEO dotMobi, Jonathan Nevett - Network Solutions, Alexa Raad CEO PIR, Tim Cole - Chief Registrar Liaison at ICANN, Craig Schwartz - Chief gTLD Registry Liaison at ICANN, Tina Dam - Director, IDN Program ICANN, Dave Wodelet, Wendy Seltzer, Thomas Narten – ICANN Board members” [ref 4]



Directi, LogicBoxes and Skenzo - controls / manages / owns ‘PrivacyProtect’ – a domain privacy service which shields cybercrime, and does so by design. It currently shields 759,172 domains. [fig 2]



“LogicBoxes currently powers the infrastructure and software of over 50 ICANN Accredited Domain Registrars including EST Domains” [ref 5] LogicBoxes online corporate profile – EstDomains, which is associated with Atrivo aka Intercage. It is estimated Estdomains provide Atrivo with 40% to 60% of its revenue.



Directi, LogicBoxes and Skenzo associated with – Everyones Internet (US) and The Planet (US), rack space etc., for opticaljungle / orderbox-dns. Coincidentally both are within the top 10 of hosts in the world with infected web sites = 6,000 . [ref 6]



Bhavin Turakhia - CEO and Chairman of The Directi Group “Directi to continue growing at triple digit growth rates year after year, technical advisor to the local CyberCrime Investigation Cell, Bhavin was also former chairman for the Global ICANN Accredited Registrars Constituency for two consecutive terms. He has been the youngest elected chair for this post in the history of ICANN” - [ref 7] [ref 8]



The facts (just a few notable examples) – what?


Historical Aug 07 - Bank of India iFrame hack - X-TRAFFIC.BIZ – RBN, ICANN Registrar: ESTDOMAINS [ref 9]


Ongoing – RBN retail - Loads.cc - ICANN Registrar = DIRECTI – Registrant = PrivacyProtect.org [ref 10] [ref 11] [ref 12]


Ongoing - RBN retail payment systems isoftpay – Current; ICANN Registrar: ESTDOMAINS Registrant: PrivacyProtect.org [ref 13]


Current - Robotraff: A Hacker's Go-To For Clicks – Brian Krebs Washington Post - robotraff.com; ICANN Registrar = DIRECTI – Registrant = PrivacyProtect.org [ref14]


Newer rogue / fake sample – malwarebell; The filename MALWAREBELL.EXE was first seen on Apr 14 2008 in CANADA, BELGIUM on Apr 15 2008, SPAIN on Apr 23 2008, GERMANY on Apr 23 2008; ICANN Registrar = Estdomains; Registrant = PrivacyProtect.org [ref 15]


Brand New - Mass File Injection Attack from Russia with Zlob - “If you do a Google search for these URLs, you get about 400,000 sites" - The key domain = xprmn4u.info ("HaCKeD By BeLa & BodyguarD" = 90,000 hits on Google); ICANN registrar for = Estdomains; Registrant = PrivacyProtect.org [ref 16]



Fig 2 - PrivacyProtect - map

Conclusions

“But if someone broke — or worse, subverted — the fundamental way in which we find web sites, we wouldn’t trust URLs any more. Own the DNS and you own the Internet.” [ref 17]



The background research and this summary article has been around four months in the making within the community. It should be emphasized there is considerably more ‘who’ and ‘what’ which will be presented in full later.



We feel even the most casual reader will be concerned, as this affects every user of the internet. We as a group want to further stress we are believers of an open and unrestricted internet however, if this trend of a parallel DNS system being developed with an unofficial DNS architecture that will fake all records, this will be a real mess, resulting in a groundswell of Internet users who rightly request governmental action in some form to assume some form of control.



We hope many readers as a minimum many will contact ICANN [ref 18] to at least determine what they are going to do about Estdomains, PrivacyProtect and anonymous domain registrants – right now! This also begs the question of the commercial approach of ICANN apparently supporting unfettered registrar development and who it allows in sponsorship or election. If ICANN does not rapidly clean up its own act to encourage the view that the DNS is safe in their hands, realistically several Internets will evolve, “Good, Bad, and the Ugly”



As for Directi and co., there will undoubtedly be arguments of; we are unaware, not responsible, we only manage, or a very small minority……. From their logged and monitored action we do not believe them. Even so, with their claimed expertise and if they were unaware of the role of EstDomains or PrivacyProtect, thus RBN, then should they be trusted within or in any form of association with ICANN?




Special thanks, to name but a few:
Jim McQuaid, Debbie Rosman, David Bizeul, EmergingThreats.net malwaredomains.com, open source security community, Robtex, CyberDefCon, et.al.



References:

[ref 1] Corrupted DNS Resolution Paths: The Rise of a Malicious Resolution Authority

[ref 2] Top 25 Exploit Hosts

[ref 3] ICANN for Beginners

[ref 4] LogicBoxes and Skenzo host a "Taj Mahal Sojourn" for ICANN

[ref 5] LogicBoxes online corporate profile

[ref 6] The Planet and Everyones Internet

[ref 7] Directi CEO

[ref 8] CyberCell Mumbai India

[ref 9] Bank of India Hack Aug 07

[ref 10] RBN Retail

[ref 11] Loads cc

[ref 12] One-Stop Shopping for Hackers

[ref 13] RBN payment systems

[ref 14] Robotraff – Brian Krebs

[ref 15] Rogue - Malwarebell

[ref 16] Mass File Injection Attack from Russia with Zlob – ISC.sans

[ref 17] Alistair Croll '10 Ways the Internet (As We Know It) Will Die'

[ref 18] Contact ICANN



Coming soon - RBN - Automated Mass Malware Domain Registration

RBN - PDF email Exploit

Thanks to the input from Honeyblog.Org providing detailed confirmation related to the earlier ZDNet article, concerning the latest Gozi Trojan exploit involving PDF files attached to email courtesy of the RBN.



The PDF file attached to an email contains an exploit for the recently disclosed vulnerability involving Adobe PDF and the Microsoft reported security advisory (
here). As stated within this blog earlier the exploit is being distributed as a PDF file in spam and downloads a variant of the Gozi Trojan
The exploit which contains shellcode to download a binary from the RBN, the downloaded binary injects itself into several MS Windows processes and collects personal information from the infected PC and sends it to the RBN.


To confirm:






Download binary from IP address 81.95.146.130






Then send your personal data for ID theft to 81.95.147.107



Both 81.95.146.130 and 81.95.147.107 is served by Autonomous System AS 40989 = RBN AS RBusiness Network,


Perhaps more ISPs and users should simply blocklist the whole IP range, in and out?


RBN – The Top 20, fake anti-spyware and anti-malware Tools

In a continuation of the discovery of the RBN’s “Retail Division” one of the most important exploit delivery methods is the fake; anti-spyware and anti-malware for PC hijacking and personal ID theft, this is a source of revenue for the RBN also from a direct sale.

For example, MalwareAlarm is a dangerous fake anti-spyware software and it is an update version of Malware Wiper. MalwareAlarm is stealth based malware, according to McAfee’s Site Advisor they tested 279 “bad” downloads. The methodology is to get the user to use a “free download”, MalwareAlarm then displays a warning message to purchase the paid version of MalwareAlarm, and of course the damage is done with the initial action.


The purpose of this article is to demonstrate the multiplicity of nodes, connections and delivery routes. However, it is a prompt for the community of the need for real-time CYBERINT (see blog here) based blocking and shield services. As is shown below, many are either or both SBL and XBL blacklisted, but this is only the core IP address and not the multiplicity of other mirrored hosts and servers.


There are several well known “RBN retail brands” shown below (Table 1) we show the “Top 20”;






All of these are blacklisted elsewhere in some form, but still highly active at this time, as in any product marketing model some are entering into a mature phase and others are newer variants.. As seen within Table 1, this can produce some confusion, due to the apparent array of domains and IP addresses. Table 2 provides a simplification to the ten actual hosts and servers involved. As is a common theme of this blog again it has to be noted the several major US based servers involved, we hope unwittingly? Also note the potential for MITM “inside the server” website exploits of a further 1 million + web sites. For RBN blocking purposes 4/5 of the below would prevent access by the majority. The RBNetwork - AS 40989, encompasses AS28866 (AKIMON AS Aki Mon Telecom) and AS41173 (SBT AS SBT Telecom) as previously mentioned within this blog.







In answer to a few readers’ queries and one of the major problems with an analysis of the RBN’s activities is “What is the scale of this, how do we quantify?” In Table 3 below shows a limited sample and is provided in this brief form to deliberately demonstrate the numbers. It should be understood that luckily not every site visitor will download the exploits. A simple “Google” of some these examples will show the numerous forum and queries of how to remove the resultant infections. Included is the “Alexa” rank; to demonstrate jellyfish.com an auction site recently acquired by Microsoft, has about the same rank as MalwareAlarm.


As requested there will be a more detailed follow up on this topic, plus the requested RBN IP block information. Also a forthcoming article will shed light on the RBN’s payment and secure data transmissions.

RBN - iFrame Cash Update - The Enemy Within the Gates

A great article and associated blog articles on the Russian Business Network (RBN) from Brian Krebs in the Washington Post. However, the puzzle and a theory for a few of us has always has been, where are the RBN's; external communications, web site exploit, and ID theft divisions, let us call it the RBN retail division. These have to be outside their conventional Nevacon / RBNnetwork / Aki Mon, those are becoming well blocked on SBL XBL etc., thanks to Spamhaus et. al.

Despite what some researchers may think about domestic PCs, the logic for the RBN has to base these operations within accessible hosts. Also from inside any server it is much easier to use "Man-in-the-Middle" (MITM) techniques to exploit neighboring web sites and for personal ID theft. Where better than within a low cost US host that only cares about the credit card used for not what the web site does, and you have over 1 million web sites and their users to prey on?

So here is the "good news" - the RBN have moved some key domains as of today, and luckily every time they do this it reveals more of their bases. Below is just a sample of many, if you put them on the outside of the major hosting hubs, you will starve the main body.


"The Enemy Within the Gates" - all "within" major US hosts, also note every one has fictitious domain registrants and is breaking the TOS (terms of service) for hosting:


iframecash com = 38.97.225.135 = Hiding within Cogent Communications (DC, US) moved back onshore to the US from Aki Mon Telecom

iframecash net = 66.29.87.11 = Hiding within Net Access Corporation (NJ, US) - along with many (what look like) bank phishing domains

anonymous-service (dot) com = 67.19.24.170 = within ThePlanet com (US) & proxy registered via Global Net Access (US) - also key domains
adulthosting (dot) ru, aspmedia (dot) net, sexbomba (dot) ru. webmoney-hosting (dot) net

76service com = 66.232.122.239 = still within Noc4hosts Inc (FL, US) and proxy registered via Global Net Access - also key domains:
firstoceanicbank (dot) net, gamesboard (dot) ru, hydrometeocenter (dot) net, newpulses (dot) com, odeku (dot) net, putany (dot) net, sosnovsky (dot) net

If we can persuade these major US hosts / servers to act voluntarily and quickly, as we did with Layered Technologies (iframe cash com) then at least we could prevent a great deal of web site exploits from "within" the major US hosting servers.

Just to re-emphasize listed above provides RBN direct access to over 1 million web sites and their users.

Russian Business Network (RBN) - iFrame Cash and Layered Technologies

Russian Business Network (RBN) - iFrame Cash and Layered Technologies

According to net-security.org Todd Abrams, the CEO of Layered Technologies had released a statement in which he stated that the company's support database was a target of malicious activity on the evening of September 19th 2007. The incident may have involved the illegal downloading of information such as names, addresses, phone numbers, email addresses and server login details for up to 6,000 clients.

Another blog had reproduced a copy of the email to Layered Technologies abuse team, concerning their dedicated hosting of one of the Russian Business Network’s (RBN) key “commercial” web enterprises ref: iFrame Injection Source? . Although there was never a reply to any email, but possibly with the added assistance of this blog’s bigger friends, they or the RBN obviously took action. This is seen by the change; on September 9th 2007 the change from 72.36.199.58 (USA- Layered Technologies Hosting) to 81.95.153.245 (Russian Federation - Aki Mon Telecom hosting – AKA “RBN”). For those who like the specific details see http://rbnexploit.blogspot.com.

It is reasonable to assume the later attack on Layered Technologies was part of the RBN’s normal procedure to wreak revenge upon those who try to rid themselves of the RBN’s grip. This was just as they did to National Bank of Australia, the Bank of India, and many others.

Hopefully more web hosts will examine who they have as customers in the first place, rather than the value of the credit card?

Details:

Hosting History for Iframedollars.com


IP Address History

Event Date

Action

Pre-Action IP

Post-Action IP

2005-01-01

New

-none-

67.15.35.16

2005-01-22

Change

67.15.35.16

67.15.35.19

2005-03-05

Not Resolvable

67.15.35.19

-none-

2005-03-20

New

-none-

67.15.35.19

2005-05-22

Change

67.15.35.19

81.222.131.59

2005-06-04

Change

81.222.131.59

195.95.218.170

2005-06-26

Change

195.95.218.170

195.95.218.174

2005-07-02

Change

195.95.218.174

85.255.113.2

2005-09-22

Change

85.255.113.2

70.85.116.53

2006-06-03

Change

70.85.116.53

64.72.112.136

2007-08-01

Change

64.72.112.136

72.36.199.58

2007-09-09

Change

72.36.199.58

81.95.153.245






Name Server History

Event Date

Action

Pre-Action Server

Post-Action Server

2004-10-04

New

-none-

Ultralinks.info

2005-05-22

Transfer

Ultralinks.info

Iframedollars.biz

2005-09-22

Transfer

Iframedollars.biz

Coconia.net

2007-08-01

Transfer

Coconia.net

Iframedollars.com


Information related to 'AS28866'

aut-num: AS28866
as-name:
AKIMON-AS
descr:
Aki Mon Telecom
org:
ORG-AMT5-RIPE
import:
from AS40989 accept ANY
export:
to AS40989 announce AS-AKI
admin-c:
SS7823-RIPE
tech-c:
NO322-RIPE
mnt-by:
AKIMON-MNT
mnt-routes:
RBN-MNT
source:
RIPE # Filtered


organisation: ORG-AMT5-RIPE
org-name:
Aki Mon Telecom
org-type:
OTHER
address:
197022, Russia, Saint-Peterburg
address:
pr. Medikov, 5

person: Sergey Startsev
address:
Russia, St.Petersburg
phone:
+7 903 0983277
nic-hdl:
SS7823-RIPE
mnt-by:
AKIMON-MNT
source:
RIPE # Filtered


person: Nikolay Obraztsov
address:
Russia, St.Petersburg
phone:
+7 903 0983306
nic-hdl:
NO322-RIPE
mnt-by:
AKIMON-MNT
source:
RIPE # Filtered

RBN - Too coin Software & SBT Telecom

RBN traceroute - Nevecon Ltd. - 194.146.204.3 - Too coin Software Limited (UK) - SBT Telecom Network (Seychelles); Traceroute

Panama > Ukraine > UK > Seychelles



Too coin Software Limited

SHEARWAY BUSINESS PARK 16, FOLKESTONE, KENT,
CT19 4RH, UK

phone: +1 401 369 8152
e-mail: noc@rbnnetwork.com

Its RIPE NCC Association Membership status is: Full

announced by AS41173(SBT AS SBT Telecom) AS24867(Adapt AS Adapt Services Ltd)
* as-sbtel(member of as-arbinet-lon-buyers, as-bandxuk, as-c4l, as-cais, as-interoute, as-mnet-t, as-tiscalicust, as-tsn)
* AS20807 Credolink ASN Credolink ISP Autonomous System St Petersburg
* AS39848 DELTASYS Delta Systems network
* AS40989 RBN AS RBusiness Network
* AS41108 OINVEST AS Online Invest group LLC
* AS41173 SBT AS SBT Telecom
* AS41181 RUSTELECOM AS Rustelecom AS
* AS41731 NEVSKCC AS NEVACON LTD

RBN - Nevecon Ltd. Panama

RBN's IP & Domain Deployment - Nevecon Ltd. Panama - 194.146.204.0/22

AS41731 NEVSKCC as Nevacon Ltd.


Number of unique AS-peers:

1

Number of found peering routers:

0

Number of prefixes:

1

Number of ip numbers:

1024


RBN - MPack

MPack is the latest and greatest tool for sale on the Russian Underground. $ash sells MPack for around $500-1,000. In a recent posting $ash attempted to sell a "loader" for $300 and a kit for $1,000. The author claims that attacks are 45-50 percent successful, including the animated cursor exploit and many others, including ANI overflow, MS06-014, MS06-006, MS06-044, XML Overflow, WebViewFolderIcon Overflow, WinZip ActiveX Overflow, QuickTime Overflow (all these are $ash names for exploits). Attacks from MPack , aka WebAttacker II, date back to October 2006 and account for roughly 10 percent of web based exploitation today according to one public source.


More than 10,000 referral domains exist in a recent MPack attack, largely successful MPack attack in Italy, compromising at least 80,000 unique IP addresses. It is likely that cPanel exploitation took place on host provider leading to injected iFrames on domains hosted on the server. When a legitimate page with a hostile iFrame is loaded the tool silently redirects the victim in an iFrame to an exploit page crafted by MPack. This exploit page, in a very controlled manner, executes exploits until exploitation is successful, and then installs malicious code of the attacker's choice.


Torpig is one of the known payloads for MPack attacks to date. This code relates back to the Russian Business Network (RBN), through which many Internet-based attacks take place today. The RBN is a virtual safe house for attacks out of Saint Petersburg, Russia, responsible for Torpig and other malicious code attacks, phishing attacks, child pornography and other illicit operations. The Italian hosts responsible for most of the domains seen in a recent MPack attack are using cPanel, a Web administration tool for clients. A zero-day cPanel attack took place in the fall of 2006 leading up to the large scale vector mark-up language (VML) attacks at that time. It appears likely that the Russian authors of the cPanel exploit, Step57.info, who are also related to the RBN used the exploit to compromise the Italian ISP and referral domains used in the latest mPack attack.


MPack uses a command and control website interface for reporting of MPack success. A JPEG screenshot of a recent attack is attached to this message.


QUOTES


1. MPack is a powerful Web exploitation tool that claims about 50 percent success in attacks silently launched against Web browsers.


2. $ash is the primary Russian actor attempting to sell mPack on the underground, for about $1,000 for the complete MPack kit.


3. MPack leverages multiple exploits, in a very controlled manner, to compromise vulnerable computers. Exploits range from the recent animated cursor (ANI) to QuickTime exploitation. The latest version of mPack, .90, includes the following exploits:

MS06-014
MS06-006
MS06-044
MS06-071
MS06-057
WinZip ActiveX overflow
QuickTime overflow
MS07-017


4. The Russian Business Network (RBN) is one of the most notorious criminal groups on the Internet today. A recent MPack attack installed Torpig malicious code hosted on an RBN server. RBN is closely tied to multiple attacks including Step57.info cPanel exploitation, VML, phishing, child pornography, Torpig, Rustock, and many other criminal attacks to date. Nothing good ever comes out of the Russian Business Network net block.


5. MPack attacks experience high success, according to attack log files analyzed by VeriSign-iDefense. In just a few hours more than 2,000 new victims reported to an MPack command and control website. A recent attack, largely focused in the area of Italy, involved more than 80,000 unique IPs.

RBN - The Bank of India

Bank of India IT staff are mopping up the mess left by attackers who rigged the firm's website to feed malware to customers trying to access online services.


The bank managed to pry loose the rogue iframe responsible for the malware sometime early Friday morning California time. At time of writing, though, Bank of India's website was effectively cordoned off, bearing a terse notification saying: "This site is under temporary maintenance and will be available after 09:00 IST on 1.09.07."

The shuttering came a day after employees for security provider Sunbelt Software discovered someone had planted an iframe in the site that caused unpatched Windows machines to be infected with some of the most destructive pieces of malware currently in circulation. Sunbelt counted 31 separate pieces in all, including Pinch, a powerful and easy-to-use Trojan that siphons personal information from a user's PC. Other malware included Trojan.Netview, Trojan-Spy.Win32.Agent.ql, various rootkits and several spam bots.


Executives and IT administrators at US offices of Bank of India who were contacted Friday morning by IDG were initially unaware of the attack. A spokesman later told the news service that officials were aware of the problem and were working to correct it, but had no information concerning its severity or duration.

Some of the servers used to install the malware belonged to the notorious Russian Business Network, a group Spamhaus says is involved in child porn, phishing and other misdeeds. According to Verisign's iDefense unit, the RBN also played a hand in bringing us MPack, a powerful Trojan downloader that infected more than 10,000 websites in just three days.


In this case, the attackers appeared to use an exploit kit dubbed n404, according to this post by Dancho Danchev. It relies on a technique known as Fast Flux domain name service, which is proving to be resilient against bot hunters because there is no single point of weakness to take down.


Roger Thompson, a researcher with Exploit Prevention Labs, said he spotted one piece of code that exploited a vulnerability patched by last year's Microsoft Security Bulletin MS06-042."It's pretty much a cut-and-paste of the original proof-of-concept that was put out on Metasploit last July," Thompson said of the code.

RBN Info - Spamhaus.org Rosko Listing

Spamhaus.Org - RBN Info

Russian Business Network - Among the world's worst spammer, child-pornography, malware, phishing and cybercrime hosting networks. Provides "bulletproof hosting", but is probably involved in the crime too.

Dear stupid trackback spammer at 81.95.144.66,

in case you haven't noticed yet: None of the trackback spams you have attempted to send to this and a couple of other sites over the last 24 hours has made it through. They are deleted automatically, and I didn't even have to block your IP address ...

Sincerely,
The Management

There's a reason why we haven't seen a lot of trackback spam recently, but it seems someone in Russia (81.95.144.66 belongs to Russian Business Network in St. Petersburg) hasn't gotten the memo yet.

Oh, and while you're at it, block 81.95.144.67 through to .70, too. I see Bad Behavior takes care of those already (claiming to be GoogleBot isn't really helping in getting trackback spam through), but just in case.


iFrameDollars.com or .biz


MICRONNET-NET: 195.114.16.0 - 195.114.17.255

etname: MICRONNET-NET; descr: Micronnet LTD network; country: RU

Address: Reshetnikova str. HSE 9, 197119 St. Petersburg , Russia

E-mail: info@micronnet.net


RBN Exploit - IP Addresses (1)

Just so you know your enemy, our good friends the RBN (Russian Business Network) - now widening their buisiness to "bullet proof" hosting of MPack (diy exploiters) - if you try and complain to Nevacon, do not expect a reply ;-) - I keep wondering why the international community cannot do something about this? - WE seem more inclined to blame China or Russia as countries. Just so we now 4/5 times more spam & exploits are from USA hostings then China:

Add all below to your IP banned list on your hosts / servers, another 300+ RBN IPs to go with these :-(

YEKTCNT.INFO

IP Address: 194.146.207.222
IP Location Panama (just domains) - Panama - Nevacon Ltd, new hosting out of The Seychelles.

Blacklist Status:
Yet another part of Russian Business Network / iframe cash gang. (see; Spamhaus Org - Rosko) Endless malware and PC hijacking.

gretabc.com [194.146.207.21]
tesla4.net [194.146.207.11]
intostec.com [194.146.207.11]
dedust2.net [194.146.207.11]
mayconcern.com [194.146.207.11]
mayconcern.net [194.146.207.11]

inetnum: 194.146.204.0 - 194.146.207.255
netname: NEVSKCC-NET
descr: NEVACON LTD
country: RU

194.146.207.222 [reverse DNS - ip-207-222.nevacon.net]
1. Adencnt.info
2. Dinacnt.info
3. Empacnt.info
4. Gifecnt.com
5. Grigcnt.info
6. Hasicnt.info
7. Hoicnt.info
8. Juidacnt.info
9. Lipocnt.com
10. Mircnt.net
11. Nisocnt.net
12. Rikocnt.info
13. Sogcnt.info
14. Tipocnt.com
15. Wetricnt.info
16. Xifcnt.com
17. Yektcnt.info

Domain ID:D18788623-LRMS
Domain Name:YEKTCNT.INFO
Created On:30-Jun-2007 17:17:14 UTC
Last Updated On:04-Sep-2007 18:01:41 UTC
Expiration Date:30-Jun-2008 17:17:14 UTC

Registrant ID:DI_6786675
Registrant Name:Wedrov Kirill
Registrant Organization:N/A
Registrant Street1:Lesi Ukraynki 15/7
Registrant Street2:
Registrant Street3:
Registrant City:Lviv
Registrant State/Province:Lviv Oblast
Registrant Postal Code:48751
Registrant Country:UA
Registrant Phone:+093.4584442

Name Server:NS1.YEKTCNT.INFO
Name Server:NS2.YEKTCNT.INFO

81.95.144.182/32 rbnnetwork.com SBL58402 2007-09-04 02:44:54
81.95.149.171/32 rbnnetwork.com SBL58369 2007-09-03 02:09:43
81.95.144.3/32 rbnnetwork.com SBL58287 2007-08-31 03:12:22
81.95.149.27/32 rbnnetwork.com SBL58284 2007-08-31 03:01:04
81.95.149.181/32 rbnnetwork.com SBL58009 2007-08-21 00:35:36
81.95.149.178/32 rbnnetwork.com SBL58008 2007-08-21 00:35:08
193.93.235.5/32 rbnnetwork.com SBL57580 2007-08-10 03:38:22
81.95.149.110/31 rbnnetwork.com SBL57575 2007-08-10 02:19:56
81.95.148.18/32 rbnnetwork.com SBL57411 2007-08-05 12:08:37
81.95.148.130/31 rbnnetwork.com SBL57122 2007-07-30 02:17:40
81.95.148.132/31 rbnnetwork.com SBL57123 2007-07-30 02:17:54
81.95.153.243/32 rbnnetwork.com SBL57112 2007-07-30 00:48:36
81.95.147.202/31 rbnnetwork.com SBL57085 2007-07-29 09:56:50
81.95.147.182/32 rbnnetwork.com SBL55191 2007-06-02 06:48:43

RBN (Russian Business Network) - A User's Guide

ACCORDING to VeriSign, one of the world's largest internet security companies, RBN, an internet company based in Russia's second city, St Petersburg, is "the baddest of the bad". In a report seen by The Economist, VeriSign's investigators unpick an extraordinary story of blatant cybercrime that implies high-level political backing.


In one sense, RBN (Russian Business Network) does not exist. It has no legal identity; it is not registered as a company; its senior figures are anonymous, known only by their nicknames. Its web sites are registered at anonymous addresses with dummy e-mails. It does not advertise for customers. Those who want to use its services contact it via internet messaging services and pay with anonymous electronic cash.


But the menace it poses certainly exists. "RBN is a for-hire service catering to large-scale criminal operations," says the report. It hosts cybercriminals, ranging from spammers to phishers, bot-herders and all manner of other fraudsters and wrongdoers from the venal to the vicious. Just one big scam, called Rock Phish (where gullible internet users were tricked into entering personal financial information such as bank account details) made $150m last year, VeriSign estimates.

Despite the attention it is receiving from Western law enforcement agencies, RBN is not on the run. Its users are becoming more sophisticated, moving for example from simple phishing (using fake e-mails) to malware known as "Trojans" that sit inside a victim's computer collecting passwords and other sensitive information and sending them to their criminal masters.


A favorite trick is to by-pass the security settings of a victim's browser by means of an extra piece of content injected into a legitimate website. An unwary user enters his password or account number into what looks like the usual box on his log-in page, and within minutes a program such as Corpse's Nuclear Grabber, OrderGun and Haxdoor has passed it to a criminal who can empty his bank account. When VeriSign managed to hack into the RBN computer running the scam, it found accumulated data representing 30,000 such infections. "Every major Trojan in the last year links to RBN" says a VeriSign sleuth.


RBN even fights back. In October 2006, the National Bank of Australia took active measures against Rock Phish, both directly and via a national anti-phishing group to which the bank's security director belonged. RBN-based cybercriminals replied by crashing the bank's home-page for three days.


What can be done? VeriSign has tracked down the physical location of RBN's servers. But Western law enforcement officers have so far tried in vain to get their Russian counterparts to pursue the investigation vigorously. "RBN feel they are strongly politically protected. They pay a huge amount of people. They know they are being watched. They cover their tracks," says VeriSign. The head of RBN goes under the internet alias "Flyman". Repeated e-mails to RBN's purported contact addresses asking for comment have gone unanswered.