Showing posts with label Russia. Show all posts
Showing posts with label Russia. Show all posts

Sunday, April 10, 2011

zonensuk.cc

Time for my last post regarding the list of nameservers I gave in my first blog post. Today we look at zonensuk.cc, another Russian Business Network (RBN) domain being used as a name server to perpetrate acts of fraud and malware dispersal. Our confirmation that this is an RBN domain/name server comes from Emerging Threat's RBN IP list. A quick google search on zonensuk.cc shows plenty of malware and fraud activity, so lets dive right in -
Domain Name: ZONENSUK.CC
Registrar: BIZCN.COM, INC.
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.ZONENSUK.CC
Name Server: NS2.ZONENSUK.CC
Name Server: NS3.ZONENSUK.CC
Status: CLIENT-XFER-PROHIBITED
Status: CLIENT-DELETE-PROHIBITED
Updated Date: 08-dec-2010
Creation Date: 08-dec-2010
Expiration Date: 08-dec-2011
Registrant Contact:
   Olga Veresova
   Olga Veresova rooms@ppmail.ru
   +78123274547 fax: +78123274547
   ul.Komsomola d.13 kv.26
   Sankt-Peterburg Sankt-Peterburg 195009
   RU
Source: centralops.net
What a surprise, googling Olga's street address I see plenty of hits for fake pharmacy and sofware websites... but the shocker is google leads me right back to my very own blog spot here to the post about FOLOWDNS.CC (another domain with falsified whois information being used by the RBN for their cyber crime). Boom! This proves zonensuk.cc has intentionally falsified registrant information for criminal intent in one blow. Let's throw some more stones through this glass house though -
Domain name: trvlftnow.com
Registrant Contact:
   Vladimir Silyanov
   Vladimir Silyanov epic@ca4.ru
   +78123274547 fax: +78123274547
   ul.Rudneva d.3 k.2 kv.119
   Sankt-Peterburg Sankt-Peterburg 194291
   RU
Created: 2011-03-15
Expires: 2012-03-15
Same phone number that zonensuk.cc, however it's a way different registrant name and address. This proves falsified whois registrant information. We see the same thing here for a fake phramacy... again same phone number but entirely different whois registrant address and name. So, with intentionally falsified whois registrant information for zonensuk.cc shown above, lets show what zonensuk.cc is being used for as a name server with a quick google search -

Fraud:
Link here (too long)
Link here (too long)
http://scamfraudalert.wordpress.com/2011/01/12/avon-products-plc-journey-financial-cc/
http://ddanchev.blogspot.com/2011/01/keeping-money-mule-recruiters-on-short.html
http://www.fraudwatchers.org/forums/showthread.php?p=127376

Malware:
http://support.clean-mx.de/clean-mx/viruses.php?domain=online-solutionsllc.cc&sort=first%20desc
http://support.clean-mx.de/clean-mx/viruses.php?domain=pegasltdunion.cc&sort=email%20desc

Again, there were plenty of other hits for malware and fraud activity on zonensuk.cc, a domain being used as a name server to spread malware and fraud. BizCN, again, just delete these registrants I've been mentoning in my blog posts entirely from your registry. These customers will only bring a business like yours problems in the long run with the amounts of falsified whois registrations they shell out for criminal intent.

uknsspace.cc

Continuing down the list of name servers from my first blog post, let's analyze uknsspace.cc. This is another Russian Business Network (RBN) domain being used for a nameserver to promote both fraud an malware according to Emerging Threat's RBN IP list. A quick google search on uknsspace.cc shows this domain's use in spreading malware and acts of fraud as a name server, so lets dive right in -

Domain Name: UKNSSPACE.CC
Registrar: BIZCN.COM, INC.
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.UKNSSPACE.CC
Name Server: NS2.UKNSSPACE.CC
Name Server: NS3.UKNSSPACE.CC
Status: CLIENT-XFER-PROHIBITED
Status: CLIENT-DELETE-PROHIBITED
Updated Date: 08-dec-2010
Creation Date: 08-dec-2010
Expiration Date: 08-dec-2011
Domain name: uknsspace.cc

Registrant Contact:
   Ninel Popakina
   Ninel Popakina gravy@ca4.ru
   +73842523612 fax: +73842523612
   ul.Suvorova d.2 kv.59
   Tashtagol Kemerovskaya oblast 652990 RU

Source: centralops.net   
Ninel, another Russian with faked whois registrant information serving up nothing but the RBN's finest forms of fraud and malware. Proving the whois registrant details falsified on this one actually wasn't that hard. Take "Ninel's" phone number and google it (with "-Ninel), and you get this -

WHOIS для kuzbass.net:
Registrant:

Join-stock company Electrosvyaz
   Oktyabrsky 10
   Kemerovo 650066
   RU

   Domain Name: KUZBASS.NET

   Administrative Contact:
      Alexander, Berdnikov           
      Joint-stock company Electrosvyaz
      Oktyabrsky 10
      Kemerovo 650066
      RU
      +73842523612 fax: +73842524310
Source: http://www.rutag.net/site/kuzbass.net (click whois tab)
Look at that! A company that uses the same phone number! Centralops.net shows that kuzbass.net was registered in April of 1997 and has a registration period set until April of 2014. This makes kuzbass.net sound like a legitimate site, and it is (it's a Telecom company). That said, this proves hands down that the whois registrant information for uknsspace.cc has been intentionally falsified. It uses the same phone number as kuzbass, but the registrant information such as address and registrant name are totally different! Let's show why the whois on uknsspace.cc has been intentionally falsified for criminal purposes with a quick search -


Fraud: 
http://scamfraudalert.wordpress.com/2010/12/19/whois-ns1-nnsque-cc/
http://scamfraudalert.wordpress.com/2011/01/12/avon-products-plc-journey-financial-cc/
Link here (too long)
http://ddanchev.blogspot.com/2011/01/keeping-money-mule-recruiters-on-short.html
http://www.delphifaq.com/faq/scams/f1057.shtml?p=68
http://www.fraudwatchers.org/forums/showthread.php?p=127376


Malware: 
Link here (too long)
Link here (too long)


There were quite a few other hits for criminal activity the domain/name server uknsspace.cc, however this is (point in case) an RBN name server with intentionally falsified whois information for the sole purposes of cyber criminal activity. BizCN, this is another one that needs to go down. In fact, I would just kill any sites you registered from the very same registrant of uknsspace.cc. They're just going to provide headaches in the long run.

Monday, April 4, 2011

dnsukrect.com

Again, moving off of my first blog post, it's time to examine dnsukrect.com (another domain being used as a name server for fraudulent, malware pushing money recruitment sites).  As demonstrated with the last two name servers I wrote about (here and here), it would be safe to assume that all 14 name servers I plan on covering will be associated with or run by the multifaceted, cyber crime friendly, bulletproof host the Russian Business Network (RBN). Dnsukrect.com is no different, and was found to be in the Emerging Threats RBN watch list here.

Let's start by diving right into the whois registrant details of dnsukrect.com -
Domain Name: DNSUKRECT.COM
Registrar: NICS TELEKOMUNIKASYON TICARET LTD.STI.
Whois Server: whois.nicproxy.com
Referral URL: http://www.nicproxy.com
Name Server: NS1.DNSUKRECT.COM
Name Server: NS2.DNSUKRECT.COM
Name Server: NS3.DNSUKRECT.COM
Status: ok
Updated Date: 27-jan-2011
Creation Date: 27-jan-2011
Expiration Date: 27-jan-2012
DOMAIN: DNSUKRECT.COM
owner-contact:CID-129136DNS
owner-organization:Oksana Boiko
owner-name:Oksana
owner-lname:Boiko
owner-street:ul.Pobedy d.3 kv.81
owner-city:Stroitel
owner-state:Belgorodskaya oblast
owner-zip:309070
owner-country:RU
owner-phone:+7.4722311731
owner-fax:+7.4722311731
owner-email:code@yourisp.ru
Source: centralops.net
Upon googling Mr. Boiko's street address, you will find links noting sites that have been set up for malware dispersal. No shock there, we're talking about the RBN. Googling his whole address, it won't pull up on google maps. So I highly doubt the street even exists in Stroitel Russia, meaning the whois registrant information has been falsified for illegal and fraudulent purposes. On that note, what happens when you google Boiko's phone number? Aside from being greeted by quite a few reports of fake pharmacies and malware dispersal sites, there were some more things to suggest falsified whois registrant information for criminal activity.
Domain Name : DISCOUNTPHARMACYPILLS.COM 
Registrant: Nataliya Guzik
Nataliya Guzik (tw@free-id.ru)
ul.Pochtovaya d.76 kv.28
Belgorod Belgorodskaya oblast, 308013
RU Tel. +7.4722311731 Fax. +7.4722311731
Creation Date : 11/3/2010 7:04:54 PM
Expiration Date : 11/3/2011 7:04:54 PM
Source: http://discountpharmacypills.com.w3spy.net/
Notice two things here, Mr. Boiko is now named Nataliya Guzik (sexy name Boiko) and his place of residence has changed drastically all within a year. Also he's (she?) has quite a few email addresses, in this case it was used to register a fake pharmacy (looks like Natalia started another one here too). This hands down, proves falsified whois registrant information. We're not done here though, let's look at another site "Nataliya" registered for malware dispersal 5 days after Mr. Boiko registered dnsukrect.com

Registrant:
Nataliya Guzik above@yourisp.ru +7.4722311731
Nataliya Guzik
ul.Pochtovaya d.76 kv.28
Belgorod,Belgorodskaya oblast,RU 308013
Domain Name:quvujykolenuja.com
Record last updated at
Record created on 2011/2/28
Record expired on 2012/2/28
Source: link here (too long)
Totally different address, totally different name, all registered within the same time period, and all for the purposes of cyber criminal activity. This is hands down falsified whois registrant activity for illegal purposes.

So, we've already shown that the whois registrant information has been falsified for the name server dnsukrect.com. Let's show what kind of illegal activity takes place on this name server -

Phishing:
http://www.siteadvisor.com/sites/dnsukrect.com/postid?p=7305091

Fraud:
http://scamfraudalert.wordpress.com/2011/02/03/
http://scamfraudalert.wordpress.com/2011/02/21/lilac-llc-company/
http://scamfraudalert.wordpress.com/2011/02/03/gogo-group-inc-cc-gogo-teamant-com/
http://ddanchev.blogspot.com/2011/03/keeping-money-mule-recruiters-on-short.html

Malware:
http://rss.uribl.com/ns/dnsukrect_com.html
link here (too long!)
http://amada.abuse.ch/?search=renaissance-llc.cc
http://support.clean-mx.de/clean-mx/viruses?id=761523

There were plenty of other google hits for this kind of activity, I'm pretty sure if you made it this far down the post you know how to google for it. That said, again we see a registrar fail in that whois registrant information has been falsified while the slime of the internet's charred underbelly run rampant dispersing their malware and other forms of fraud. NICS TELEKOM, it's time to see if you want your name associated with this lot.

Coming soon to a blog post near you, a short story about a name server/domain named uknamo.com .