Showing posts with label bizcn. Show all posts
Showing posts with label bizcn. Show all posts

Sunday, April 10, 2011

uknsspace.cc

Continuing down the list of name servers from my first blog post, let's analyze uknsspace.cc. This is another Russian Business Network (RBN) domain being used for a nameserver to promote both fraud an malware according to Emerging Threat's RBN IP list. A quick google search on uknsspace.cc shows this domain's use in spreading malware and acts of fraud as a name server, so lets dive right in -

Domain Name: UKNSSPACE.CC
Registrar: BIZCN.COM, INC.
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.UKNSSPACE.CC
Name Server: NS2.UKNSSPACE.CC
Name Server: NS3.UKNSSPACE.CC
Status: CLIENT-XFER-PROHIBITED
Status: CLIENT-DELETE-PROHIBITED
Updated Date: 08-dec-2010
Creation Date: 08-dec-2010
Expiration Date: 08-dec-2011
Domain name: uknsspace.cc

Registrant Contact:
   Ninel Popakina
   Ninel Popakina gravy@ca4.ru
   +73842523612 fax: +73842523612
   ul.Suvorova d.2 kv.59
   Tashtagol Kemerovskaya oblast 652990 RU

Source: centralops.net   
Ninel, another Russian with faked whois registrant information serving up nothing but the RBN's finest forms of fraud and malware. Proving the whois registrant details falsified on this one actually wasn't that hard. Take "Ninel's" phone number and google it (with "-Ninel), and you get this -

WHOIS для kuzbass.net:
Registrant:

Join-stock company Electrosvyaz
   Oktyabrsky 10
   Kemerovo 650066
   RU

   Domain Name: KUZBASS.NET

   Administrative Contact:
      Alexander, Berdnikov           
      Joint-stock company Electrosvyaz
      Oktyabrsky 10
      Kemerovo 650066
      RU
      +73842523612 fax: +73842524310
Source: http://www.rutag.net/site/kuzbass.net (click whois tab)
Look at that! A company that uses the same phone number! Centralops.net shows that kuzbass.net was registered in April of 1997 and has a registration period set until April of 2014. This makes kuzbass.net sound like a legitimate site, and it is (it's a Telecom company). That said, this proves hands down that the whois registrant information for uknsspace.cc has been intentionally falsified. It uses the same phone number as kuzbass, but the registrant information such as address and registrant name are totally different! Let's show why the whois on uknsspace.cc has been intentionally falsified for criminal purposes with a quick search -


Fraud: 
http://scamfraudalert.wordpress.com/2010/12/19/whois-ns1-nnsque-cc/
http://scamfraudalert.wordpress.com/2011/01/12/avon-products-plc-journey-financial-cc/
Link here (too long)
http://ddanchev.blogspot.com/2011/01/keeping-money-mule-recruiters-on-short.html
http://www.delphifaq.com/faq/scams/f1057.shtml?p=68
http://www.fraudwatchers.org/forums/showthread.php?p=127376


Malware: 
Link here (too long)
Link here (too long)


There were quite a few other hits for criminal activity the domain/name server uknsspace.cc, however this is (point in case) an RBN name server with intentionally falsified whois information for the sole purposes of cyber criminal activity. BizCN, this is another one that needs to go down. In fact, I would just kill any sites you registered from the very same registrant of uknsspace.cc. They're just going to provide headaches in the long run.

Thursday, April 7, 2011

LIBUNITAU.CC

Time again to dive back into the list of name servers I gave in my first blog post. Today, we look at the domain LIBUNITAU.CC, another Russian Business Network (RBN) domain being used as a name server according to Emerging Threats RBN IP/NS monitoring list. Diving right in, lets show how the RBN were lying through their teeth with criminal intent when they registered LIBUNITAU.CC to act as a name severs to dish out their malware and other forms of fraud -

Queried whois.nic.cc with "dom libunitau.cc"...
Domain Name: LIBUNITAU.CC
Registrar: BIZCN.COM, INC.
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.LIBUNITAU.CC
Name Server: NS2.LIBUNITAU.CC
Name Server: NS3.LIBUNITAU.CC
Status: CLIENT-XFER-PROHIBITED
Status: CLIENT-DELETE-PROHIBITED
Updated Date: 11-jan-2011
Creation Date: 11-jan-2011
Expiration Date: 11-jan-2012
Registrant Contact:
Petr Anisimov
Petr Anisimov ached@yourisp.ru
+78123342003 fax: +78123342003
ul.P.Germana d.18 kv.19
Sankt-Peterburg Sankt-Peterburg 198205
RU
Source: centralops.net
Petr Anisimov, I'm getting tired of all these Russian names, let's just call him Pete for shorts. Taking a quick google on Pete's street address definitely shows Pete dabbling fraud and malware. It would make sense that the whois registrant details would be intentionally falsified with criminal intent here, as "Pete" works for the multifaceted cyber crime host the RBN. So what does a google search on Pete's phone number (Google: +78123342003 OR +7.8123342003) show? Our first clue towards falsified information leads to a domain serving up malware -
Domain: kbgg.in 
Domain ID:D3358497-AFIN
Domain Name:KBGG.IN
Created On:23-Mar-2009 13:57:27 UTC
Last Updated On:23-May-2009 03:26:15 UTC
Expiration Date:23-Mar-2010 13:57:27 UTC
Sponsoring Registrar:Netlynx Technologies Pvt. Ltd. (R62-AFIN)
Status:OK
Registrant ID:DI_9562832
Registrant Name:Evgeniy Veter
Registrant Organization:Evgeniy Veter
Registrant Street1:Savushkina str. d.107 kv.94
Registrant Street2:
Registrant Street3:
Registrant City:Sankt-Peterburg
Registrant State/Province:Sankt-Peterburg
Registrant Postal Code:197374
Registrant Country:RU
Registrant Phone:+7.8123342003
Registrant Phone Ext.:
Registrant FAX:+7.8123342003
Registrant FAX Ext.:
Registrant Email:inhale@bronzemail.net
Source: http://www.malwareurl.com/listing.php?domain=kbgg.in
Notice two things here. First off, that's an entirely different name (Evgeniy Veter) and address, however is the same phone number as Pete's... suggesting falsified registrant name for criminal intent. Secondly, the domain itself confirms criminal intent. We find another domain with the same registrant details for "Veter" here, yet again serving up malware. Continuing along this trend, we find another domain yet again suggesting falsified registrant name for LIBUNITAU.CC -

Registrant:
Pyotr Anisimov raced@corporatemail.ru +7.8123342003
Pyotr Anisimov
ul. P.Germana d.18 kv.19
Sankt-Peterburg,Sankt-Peterburg,RUSSIAN FEDERATION 198205

Domain Name:tarhujelafert.com
Record last updated at 2009-08-17 09:16:18
Record created on 2009/8/10
Record expired on 2010/8/10
Source: Link here (too long)
Notice the difference in names here? Pyotr Anisimov registered a domain named tarhujelafert.com to dish up malware, and he uses the very same registrant details as Petr Anisimov (who registered LIBUNITAU.CC to act as a name server for cyber criminal activity for the RBN). Granted, Pyotr and Petr are pretty close in name, and in Russian are the same as Peter. However look at the time line here, on 8/2009 Peter/Pete registered a domain (tarhujelafert.com) to serve up malware. On 5/2009 and 8/2009 Evgeniy Veter, using the same phone number as Peter but a different registrant address, registered two domains (kbgg.in & cc-payment-sys24.com) to serve up malware.

This is classic and intentionally falsified whois registrant details for criminal intentions. The time line fits, and the key parts of registrant details (name, address, phone number, and email) have problems staying consistent in all of their aspects. That said, lets move on to showing how the RBN is using LIBUNITAU.CC as a name server with a quick google search -

Malware: 
Link here (too long)
http://amada.abuse.ch/?search=royalthelmas-teamant.asia (two name servers registered by BizCN!)
http://amada.abuse.ch/?search=bredgarcorp-ant.be (two name servers registered by BizCN!)

Fraud: 
link here (too long)
http://ddanchev.blogspot.com/2011/03/keeping-money-mule-recruiters-on-short.html
http://db.aa419.org/fakebanksview.php?key=56098
http://www.delphifaq.com/faq/scams/f1057.shtml?p=72
http://forum.autosec4u.info/showthread.php?tid=3690&pid=16199 (German)

This is now strike 3 for the registrar BizCN, as they registered the name domain LIBUNITAU.CC. Libunitau.cc is being used by the RBN for a name server used in cyber criminal activity, as is AUUSDEC.CC and FOLOWDNS.CC. BizCN, I would suggest you look at my first blog post. In it, towards the very end, you'll find a list of domains being used as name servers by the Russian Business Network for the sole purposes of dishing out malware and fraud. Save yourself the time BizCN, look at the name server section in my first blog post, find the ones that you registered, and place them on client hold... as I'll be going through each and every one of them.

Wednesday, April 6, 2011

FOLOWDNS.CC

Time for another analysis of some of the Russian Business Network's (RBN) nameservers I talked about in my first blog post. Today we will be looking at the domain FOLOWDNS.CC, a confirmed RBN name server according to Emerging Threat's RBN IP List Update on 2-6-2011. A quick google search on FOLOWDNS.CC does show multiple hits for malware dispersal and fraud, but then again why should we be shocked. The RBN promotes this stuff, it's their job (of sorts) to do this. Diving right in, let's take a look at the whois registrant details for FOLOWDNS.CC -
Domain Name: FOLOWDNS.CC
Registrar: BIZCN.COM, INC.
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.FOLOWDNS.CC
Name Server: NS2.FOLOWDNS.CC
Name Server: NS3.FOLOWDNS.CC
Status: CLIENT-XFER-PROHIBITED
Status: CLIENT-DELETE-PROHIBITED
Updated Date: 11-jan-2011
Creation Date: 11-jan-2011
Expiration Date: 11-jan-2012
Registrant Contact:
Nikolaj Stolbikov
Nikolaj Stolbikov dyed@bz3.ru
+78123274547 fax: +78123274547
ul. Marshala Kazakova d.1 k.2 kv.360
Sankt-Peterburg Sankt-Peterburg 198302
RU
Source: centralops.ne
Nikolaj Stolbikov huh? Great! Another Russian name, let's just call him Nick. Googling Nick's street address shows plenty of hits for fraud, malware, fake pharmacy websites, and some phishing. Shocking! Of those results, we find some interesting things where Nick seems to have changed his name to Sergey for a fake pharmacy website -
DOMAIN: PHARMACYPILLSSITE.NET
RSP: DNReg Limited
owner-contact: P-SKK1691
owner-fname: Sergey
owner-lname: Kulakov
owner-street: ul.Marshala Kazakova d.1 k.2 kv.308
owner-city: Sankt-Peterburg
owner-state: Sankt-Peterburg
owner-zip: 198302
owner-country: RU
owner-phone: 7.8121023240
owner-fax: 7.8121023240
owner-email: gouge@maillife.ru
Source: http://whois.domaintools.com/pharmacypillssite.net
This would suggest a willfully falsified whois registrant information when it comes to the name of true owner of FOLOWDNS.CC. Then again the whole thing is falsified as this is the RBN, a group of cyber criminals whose bread and butter relies in staying off the radar when it comes to personal information. Also of consequence, google maps can't seem to find the address at all. That would suggest a falsified address. Still, translating the address into Russian we do find a street with a similar name on google maps here, proving that at least the k. 2 kv. 308 was not needed. We also find that this is a shopping center, not someone's personal place of residence. In this place, we do find the following business -
Mail of Russia, [UFPS] of Saint Petersburg I of Leningrad region,
Kirov inter-district post office, the department of the postal communication of № 198302

Address (Russian):
1, ул. Маршала Казакова, к. 1, г. Санкт-Петербург, Saint Petersburg, Russia
198302

Address (English):
1, ul of marshal Zazakov, k. 1,
Saint Petersburg, Russia 198302

FOLOWDNS.CC Registrant Address:
ul. Marshala Kazakova d.1 k.2 kv.360
Sankt-Peterburg Sankt-Peterburg 198302
So we can say this for sure: the registrant address for FOLOWDNS.CC is incorrect in format and locale, proving that the address is non-existent. Why should we believe it to be true anyway? This is a site registered to act as a name server for criminals. Their intention is to falsify whois registrant information while they commit their crimes. Hence the shotty registrant names and address.

Now if you've read my previous posts, you'll notice I google the registrant's phone number. We've sufficiently proven that the whois registrant information for FOLOWDNS.CC has been falsified in registrant name and address, but lets put some more stones through this glass house. The first one that comes up after googling +78123274547 -
Domain name: capsuletabletsdrugstore.com
Registrant Contact: Olga Veresova
Olga Veresova khaki@bigmailbox.ru
+78123274547 fax: +78123274547
ul.Komsomola d.13 kv.26
Sankt-Peterburg Sankt-Peterburg 195009 RU
Source: http://capsuletabletsdrugstore.com.w3spy.net/
Look at that, a totally new address and name used to register a fake pharmacy, yet the phone number used (+78123274547) is the same as the one used to register FOLOWDNS.CC. In fact you find more glaring examples of this falsified whois registrant details for criminal intent here, here (another new name and address for a fake pharmacy), and here.

I could go on proving the whois registrant details for FOLOWDNS.CC have been falsified with criminal intent, but lets show how the RBN is using FOLOWDNS.CC as a name server. A google search on it shows some rather heavy usage in the cyber criminal arena -

Fraud:
http://scamfraudalert.wordpress.com/2011/01/31/money-visual-llc-money-visualuk-cc/
http://scamfraudalert.wordpress.com/category/employment-alerts/scam-job-alert/page/3/
http://www.fraudwatchers.org/forums/showthread.php?p=126019
http://ddanchev.blogspot.com/2011/01/keeping-money-mule-recruiters-on-short.html
http://db.aa419.org/fakebanksview.php?key=56024

Malware:
http://forum.autosec4u.info/showthread.php?tid=3708&pid=16494#pid16494 (German)
http://amada.abuse.ch/?search=fintec-ltd.cc
http://amada.abuse.ch/?search=lilac-groupllc.cc
http://support.clean-mx.de/clean-mx/viruses.php?domain=throne-groupllc.cc&sort=first%20desc

BIZCN.COM,this is strike number two for you, as I already showed you registering another RBN domain being used for a name server here (whois info was falsified on that one as well). How FOLOWDNS.CC got past any checks for falsified whois registrant with BizCN in conjunction with all of the cyber criminal activity this domain is taking place in by acting as a name server for the RBN is beyond me. Trust me when I say this BizCN, you don't even want your name associated with this lot.

Monday, April 4, 2011

AUUSDEC.CC

This is a continuation of my first blog post. I ended by noting some interesting name servers that money mule recruiters and malware operators/deployers were using for their fake websites. In this blog post, I have decided to take a look at AUUSDEC.CC. The whois registrant information for this name server gives the following -

Domain name: auusdec.cc
Registrant Contact:
   Andrej Morov
   Andrej Morov gk@ppmail.ru
   +74956211281 fax: +74956211281
   Schelkovskij pr. d.11 k.1 kv.3
   Moscow Moscow 105425
   RU
Domain Name: AUUSDEC.CC
   Registrar: BIZCN.COM, INC.
   Whois Server: whois.bizcn.com
   Referral URL: http://www.bizcn.com
   Name Server: NS1.AUUSDEC.CC
   Name Server: NS2.AUUSDEC.CC
   Name Server: NS3.AUUSDEC.CC
   Status: CLIENT-XFER-PROHIBITED
   Status: CLIENT-DELETE-PROHIBITED
   Updated Date: 11-jan-2011
   Creation Date: 11-jan-2011
   Expiration Date: 11-jan-2012

Now, the only thing a registrar has to be concerned about is registrant information being falsified for illegal purposes. I will have no problem showing that this whois registrant has been involved in plenty of illegal online activity for some time now. Proving his registrant information has been falsified may take some time though. I'll say this much, the address cannot be found on google maps. Now, a quick google search of the phone number (+74956211281) shows some interesting stuff for quite a few  malware domains and fake pharmacies. Of total interest though is the following whois registrant discrepancy-

Domain name: pnc-demo.net
Registrant Contact:
   Nikolay Vukolov
   Nikolay Vukolov - prove@bigmailbox.ru
   +74956211281 fax: +74956211281
   ul. 1-aya Magistralnaya d.22 kv.53
   Moskva Moskva 123007
   RU
Created: 2010-03-31
Expires: 2011-03-31
Source: http://whois.domaintools.com/pnc-demo.net

Notice how this phone number (used to register both AUUSDEC.CC and pnc-demo.net) has differences in registrant name, address, and email? Also notice how close the site registration times were less than one year apart. This goes towards proving falsified whois. Lets put another nail in this coffin and prove falsified whois registrant information -

Domain name: asdeachreaz.com
Registrant Contact:
   Nikolay Vukolov
   Nikolay Vukolov - sued@cheapbox.ru
   +74956211281 fax: +74956211281
   ul.1-aya Magistralnaya d.22 kv.53
   Moscow Moscow 123007
   RU
Created: 2010-11-17
Expires: 2011-11-17
Source: http://whois.domaintools.com/asdeachreaz.com

Again, the mysterious Nikolay Vukolov, using the same phone/fax number as our Andrej Morov registers another the domain asdeachreaz.com with completely different registrant information. This time, asdeachreaz.com and AUUSDEC.CC were created some 2 months apart. Also of interest, googling the term "ul.1-aya Magistralnaya d.22 kv.53" brings up quite a few fake pharmacy websites and malware domains for good 'ol Nikolay.  I think it's safe to assume Nikolay and Andrej are in the same business.

From here, we can assume that the whois registrant information on AUUSDEC.CC has been falsified. Now what's left is showing how this server has had it's whois registrant information falsified for illegal purposes such as phishing, malware deployment, and other forms of fraud.

First off, lets google Andrej Morov's registrant information. First, we start with "Schelkovskij pr. d.11 k.1 kv.3" and see how many fraud hits we get there -

http://whois.domaintools.com/pillsprescriptionmarket.com  *fake online pharmacy*
http://whois.domaintools.com/pillstoretabletssite.com *fake online pharmacy*
http://whois.domaintools.com/pillfreetabletsworld.com *fake online pharmacy*
http://www.malwareurl.com/listing.php?domain=noiceanimakae.com  *malware*
etc etc (do a google search and you'll find tons of other fake sites and malware for this address)

So I think it's now safe to say you don't want to have anything to do with Andrej Morov/Nikolay Vukolov's sites. Now let's google AUUSDEC.CC and see how many fraud hits we get to finish this off -

Fraud:
http://scamfraudalert.wordpress.com/2011/02/03/
cached delphifaq.com thread (note: site is probably under DDoS like the site's I listed in my first post... also on the list of blocked sites these guys make their malware block by changing the hosts file)
scamfraudalert.com cached thread (again site blocked by these malware makers when they change the hosts file on any machine they infect, site also appears under DDoS see my first blog post)

Malware:
http://support.clean-mx.de/clean-mx/viruses.php?domain=paultonsgroup-ltd.info&submit=query
http://support.clean-mx.de/clean-mx/viruses.php?domain=worldofart-ltd.info&sort=id%20desc
http://amada.abuse.ch/?search=worldofart-ltd.info
http://amada.abuse.ch/?search=paultonsgroup-ltd.info

To be honest, there were quite a few google hit results for the fraud and malware offered on AUUSDEC.CC. I could go through them all, but I found one jewel that sums this up (plus I was getting tired of trying to do research on sites that are currently under DDoS by these malware operators). That site was the following -

http://doc.emergingthreats.net/pub/Main/RussianBusinessNetwork/RBN_IP_List_Update_2-6-2011.txt

Emerging Threats has been following one of the most infamous cyber crime organizations out there for a while now, the infamous Russian Business Network (wikipedia article here, Dancho Danchev break down here). The fact that AUUSDEC.CC is listed by Emerging Threats as part of the Russian Business Network (RBN) is not shocking due to the way this name server operates. What is scary here is the fact that these name servers have been online for so long with falsified registration, catering to the charred underbelly of the internet (fraud artists and cyber criminals). Then again, lets consider the registrar, bizcn.com. The McAfee site advisor notes that this company has run phishing and browser exploits in the past (link here). There has also been some interesting data on how this company's services has been used in spamming and the ZeuS botnet.

Needless to say, this name server needs to get trashed by the registrar. I doubt it will happen, but the knowledge will at least be out there.