| View previous topic :: View next topic |
| Author |
Message |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2705
|
Posted: Thu Dec 27, 2007 4:55 pm Post subject: |
|
|
Regardless of the laws in Russia, they can create their own acceptable use policies and anyone who registers a domain with them must agree to them. If distributing malware doesn't violate their corporate AUP, they are purposefully siding with the criminals. They've got enough pages of documents specifying how they are going to get paid, and it seems the only penalty even for false whois information is that they won't let you renew or transfer the domain.
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1725 Location: Japan
|
Posted: Fri Dec 28, 2007 1:18 am Post subject: |
|
|
And while we are fighting yesterday's domain name, "they" are already a step ahead: 'newyearcards2008.com' offering download file 'happynewyear2008.exe'.
Registrar: ANO REGIONAL NETWORK INFORMATION CENTER DBA RU-CENTER
Registered: 2007-12-26
Hosted again on countless hijacked machines all over the world.
Reported to MIRT.
Complaint sent to nic.ru by email & fax.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2884
|
Posted: Fri Dec 28, 2007 6:03 am Post subject: |
|
|
Botnet Scanner report
Scanned the fast-flux network of infected IPs used for the Storm New Years cards infection for 2 days.
IPs detected: 3715
IPs reported: 3715
Reports sent to ISPs: 600
ISPs with largest number of infections:
1. SBC Global (US) (Pacbell, Ameritech, SWBell etc)
2. Comcast (US)
3. RoadRunner (US)
|
|
| Back to top |
|
 |
maques
Trooper

 Joined: Dec 27, 2007 Posts: 10 Location: Hungary
|
Posted: Fri Dec 28, 2007 3:55 pm Post subject: |
|
|
New domain: newyearwithlove.com
|
|
| Back to top |
|
 |
brewt
SIRT Handler Premium Member
 Joined: May 29, 2007 Posts: 779 Location: USA
|
|
| Back to top |
|
 |
maques
Trooper

 Joined: Dec 27, 2007 Posts: 10 Location: Hungary
|
Posted: Fri Dec 28, 2007 9:35 pm Post subject: |
|
|
Open letter to RU-CENTER [tld-ncc /@/ nic.ru]
( /postx211215-0-30.html)
According to your policy described at:
http://www.nic.ru/about/en/servpol.html#2.2
In reference to:
"2.1.1. User shall not perform any actions that may result in:
d) damage or the possibility of damage to any other User or any third party;"
I would like to ask you, in the name of the Internet Community to apply the following:
"2.3.1. RU-CENTER may apply the following sanctions to Users that violate the provisions of Subsection 2.1:
a) suspend or refuse the provision of any or all Services;
b) take steps to stop User from violating the Terms of Use."
to the following domains:
uhavepostcard.com
merrychristmasdude.com
happycards2008.com
newyearcards2008.com
newyearwithlove.com
and any other that you might be aware of, registered in the last days with the same method, characteristics [name/relation to new year] and/or data like the above ones.
Thank you for your cooperation.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2884
|
Posted: Sat Dec 29, 2007 7:34 am Post subject: |
|
|
The Russian CERT Center is also notified of the requirement to remove those domain names.
Whack a few more moles
|
|
| Back to top |
|
 |
Randy67
Corporal

 Joined: May 18, 2006 Posts: 53 Location: USA
|
Posted: Sat Dec 29, 2007 5:33 pm Post subject: new domain |
|
|
To the tune of celebration. A very happy New Year
hxxp://familypostcards2008.com/
If it's of any use, here's the SpamCop.net URL for the spam.
h$$p://www.spamcop.net/sc?id=z1590044173z1933822cb8dbec0d9901468b4e3972aez
|
|
| Back to top |
|
 |
maques
Trooper

 Joined: Dec 27, 2007 Posts: 10 Location: Hungary
|
Posted: Sun Dec 30, 2007 2:55 pm Post subject: |
|
|
New one: freshcards2008[.com]
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2705
|
Posted: Sun Dec 30, 2007 3:46 pm Post subject: |
|
|
(oops -- duplicate)
I had been checking these daily variants with Virustotal and Jotti and posting the poorly detected one (all of them) on the unknown files forum, but their new sites won't let you do it without turning off noscripts. Since I know zilch about java, I haven't wanted to try that.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2884
|
|
| Back to top |
|
 |
roberto78 Warnings : 1 Sergeant

 Joined: Feb 20, 2007 Posts: 113
|
Posted: Mon Dec 31, 2007 6:09 pm Post subject: News from spamhaus.org on the Storm Worm Botnet: |
|
|
From spamhaus.org:
| Quote: | | "While many registrars are very cooperative, others have not yet addressed the problem. In this case the Storm worm people have registered their domains through Nic.ru. This does not look like a coincidence, because thus far Spamhaus has been unable to establish contact with Nic.ru to have the domains involved shut down. Of course it is the holiday season, but we assume that even Nic.ru has a 24/7 staff to keep things running and to react to serious issues." |
| Quote: | | "This is a very serious issue, involving a massive flood of spam designed to infect many thousands of end-user machines. Due to the fast-flux nature of the hosting only Nic.ru can effectively put a halt to this malware disguised as a fake greeting card, stop thousands of internet users from becoming infected with the Storm worm and becoming senders of spam right after that. Unfortunately, Nic.ru has failed to react to all of our efforts at contacting them. Given the huge impact of the Storm worm, the impact Nic.ru can have by suspending the domains involved and their failure to react promptly, Spamhaus has no other option than to list critical parts of their infrastructure in SBL to get their attention. Holiday season or not, organizations like Nic.ru need to react when alerted to serious problems like these." |
News from spamhaus.org on the Storm Worm Botnet:
http://www.spamhaus.org/news.lasso?article=624
|
|
| Back to top |
|
 |
roberto78 Warnings : 1 Sergeant

 Joined: Feb 20, 2007 Posts: 113
|
|
| Back to top |
|
 |
chao284
Guest IP: 24.16.*.*
|
Posted: Sat Jan 05, 2008 12:27 am Post subject: |
|
|
roberto78
One problem, as since last night I have been unable to connect to spamhaus, it keeps timing out and my tracert says the domain is still active, could this mean my ISP might harboring a DDoS bot the Storm Worm is using that is causing spamhaus to timeout my connection?
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2705
|
Posted: Sat Jan 05, 2008 2:02 am Post subject: |
|
|
I can get Spamhaus fine right now, and it was okay last night for me, too. Comcast certainly has plenty of storm-infested computers on their network, and spamhaus is under pretty much perpetual DDoS from what I understand. But because Comcast has so many users on dynamic IP addresses, it's harder for DDoS targets to just block entire IP ranges as they are also blocking a lot of legitimate users. It's possible that the last time you logged on, you were assigned an IP address recently used by a bot. You could find out by trying a proxy, or disconnecting from the internet long enough to get a new IP address assigned. Also, I don't know the details of cable internet -- do other people in your neighborhood share the same IP address?
Or, you could be infected yourself.
|
|
| Back to top |
|
 |
|
|