Blog for hpHosts, and whatever else I feel like writing about ....

Monday 9 November 2009

Crimeware friendly ISP's: root eSolutions (AS5577, 44042)

Next on the list of cybercrime friendly ISP's, is root eSolutions, who amongst many others, are providing home for a range known as "Financial company "Titan" LTD" (193.169.12.0/23, AS49353 (TITAN)). This range has been the home of many a fake AV, exploits and various other things for longer than I'd like, and seemingly, root eSolutions don't give a hoot. Something we need to change.

Just some of the stuffage seen within this range includes;

20090806203010    193.169.12.3    Failed resolution    getfreescan.info    hxxp://getfreescan.info/l/6c524f9d7dz79n6em

20090810181716    193.169.12.3    Failed resolution    free-scan-now.info    hxxp://free-scan-now.info/l/aa942ab287h74i6bj

20090811153749    193.169.12.3    Failed resolution    getfreescan.info    hxxp://getfreescan.info/s/w05049e908bl78m6ck/setup.exe

20090811160812    193.169.12.3    Failed resolution    getfreescan.info    hxxp://getfreescan.info/s/wfb7b9ffa73p83x6fn/setup.exe

20090811164323    193.169.12.5    Failed resolution    computerdef2009.com    hxxp://computerdef2009.com/comp-def-2009.exe

20090811164808    193.169.12.3    Failed resolution    free-scan-now.info    hxxp://free-scan-now.info/l/c058f54478s76k79x

20090811170543    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/w3dd48ab372o77l6ck/setup.exe

20090811173338    193.169.12.3    Failed resolution    online-pcscan.info    hxxp://online-pcscan.info/l/9be40cee79v7ft75t

20090811173343    193.169.12.3    Failed resolution    online-pcscan.info    hxxp://online-pcscan.info/l/d9fc5b7398y7es6em

20090811182416    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/w0c74b7f788i74i75t/setup.exe

20090811182422    193.169.12.3    Failed resolution    getfeedsonline.in    hxxp://getfeedsonline.in/dp/dBCVn3003PdDtQAcjNU9fwy8TCt3z1MikexZ3L0xn5vvXm4GeA5yF6fvbe8jJ9SEaZC9Vz82RzLy1R0c

20090812173231    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/w142949df8bl72g7bz/setup.exe

20090812190320    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/wf8c1f23d97x7bp7ay/setup.exe

20090812190325    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/wf73b76ce8bl84y79x/setup.exe

20090812190331    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/wd9fc5b7391r7dr76u/setup.exe

20090812190337    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/wbca82e4196w77l6fn/setup.exe

20090812190343    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/wad972f108cm78m72q/setup.exe

20090812190349    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/wa02ffd9193t79n6fn/setup.exe

20090812190354    193.169.12.3    Failed resolution    download-fileupdate.info    hxxp://download-fileupdate.info/s/w18d8042399z7cq7bz/setup.exe

20090815171319    193.169.12.3    Failed resolution    get-files-now.info    hxxp://get-files-now.info/s/wd9fc5b7393t80u71p/setup.exe

20090816115241    193.169.12.3    Failed resolution    scan-for-threats.info    hxxp://scan-for-threats.info/l/28f0b86495v7ft76u

20090816115248    193.169.12.3    Failed resolution    get-free-av.info    hxxp://get-free-av.info/s/w5ef698cd8bl77l6ck/setup.exe

20090819182525    193.169.12.3    Failed resolution    check-for-threats.info    hxxp://check-for-threats.info/l/41f1f19196w74i69h

20090820133056    193.169.12.3    Failed resolution    free-porntube.info    hxxp://free-porntube.info/s/w00ec53c493t78m72q/setup.exe

20090820133102    193.169.12.3    Failed resolution    download-file-secure.info    hxxp://download-file-secure.info/s/wd9fc5b7396w73h7bz/setup.exe

20090824094149    193.169.12.5    Failed resolution    get-free-scan.com    hxxp://get-free-scan.com/l/f61d69478dn7es6ck

20090826012405    193.169.12.25    Failed resolution    updeit.com    hxxp://updeit.com/4/doctor/ubb.php

20090826154350    193.169.12.5    Failed resolution    scanforthreats.com    hxxp://scanforthreats.com/s/w0041146090q72g69h/setup.exe

20090826160715    193.169.12.5    Failed resolution    scanforthreats.com    hxxp://scanforthreats.com/s/w0041146090q72g69h/setup.exe

20090826180147    193.169.12.5    Failed resolution    get-free-scan.com    hxxp://get-free-scan.com/l/f61d69478dn7es6ck

20090828170424    193.169.12.5    Failed resolution    get-free-scan.com    hxxp://get-free-scan.com/l/9be40cee77r83x73r

20090828170429    193.169.12.5    Failed resolution    get-free-scan.com    hxxp://get-free-scan.com/l/c058f54477r79n77v

20090828210742    193.169.12.5    Failed resolution    download-files-now.com    hxxp://download-files-now.com/s/wbac9162b8ak75j6dl/setup.exe

20090828222304    193.169.12.5    Failed resolution    pcscan-online.com    hxxp://pcscan-online.com/l/816b112c97x82w78w

20090829020539    193.169.12.5    Failed resolution    download-files-now.com    hxxp://download-files-now.com/s/w00ec53c491r78m74s/setup.exe

20090829153843    193.169.12.5    Failed resolution    avchecknow.com    hxxp://avchecknow.com/l/52720e0070m7es7bz

20090829153849    193.169.12.5    Failed resolution    securefileshere.com    hxxp://securefileshere.com/s/w0041146073p82w76u/setup.exe

20090829165511    193.169.13.11    Failed resolution    bestautoonlineadvisor.com    hxxp://bestautoonlineadvisor.com

20090830013229    193.169.12.70    Failed resolution    criticalmentality.com    hxxp://criticalmentality.com/?pid=53&sid=260dc2

20090830021533    193.169.12.70    Failed resolution    worldsbestantivirscan.com    hxxp://worldsbestantivirscan.com/download/Antivirus_110s20.exe

20090830022021    193.169.12.70    Failed resolution    beforefornight.com    hxxp://beforefornight.com/?pid=156&sid=3f9ecd

20090830022453    193.169.12.70    Failed resolution    criticalmentality.com    hxxp://criticalmentality.com/?pid=53&sid=260dc2

20090831123232    193.169.12.5    Failed resolution    avchecknow.com    hxxp://avchecknow.com/l/2f2b265670k72g6ck

20090831123238    193.169.12.5    Failed resolution    securefileshere.com    hxxp://securefileshere.com/s/waa942ab27cw73h77v/setup.exe

20090831142528    193.169.12.5    Failed resolution    avchecknow.com    hxxp://avchecknow.com/l/52720e0070m7es7bz

20090901053106    193.169.12.5    Failed resolution    free-scan-here.com    hxxp://free-scan-here.com/l/d9fc5b7398y75j77v

20090901053112    193.169.12.5    Failed resolution    get-safe-files.com    hxxp://get-safe-files.com/s/w8bf1211f96w7ao6ai/setup.exe

20090901233333    193.169.12.5    Failed resolution    get-safe-files.com    hxxp://get-safe-files.com/s/w24b16fed79v83x78w/setup.exe

20090902114057    193.169.12.70    Failed resolution    colonizemoon2010.com    hxxp://colonizemoon2010.com/?pid=53&sid=260dc2

20090902121112    193.169.12.70    Failed resolution    primeareanetworks.com    hxxp://primeareanetworks.com/?pid=110&sid=c371b3

20090902121626    193.169.12.70    Failed resolution    waitforsunrise.com    hxxp://waitforsunrise.com/?pid=57&sid=cac46c

20090902122221    193.169.12.70    Failed resolution    blastertroops2011.com    hxxp://blastertroops2011.com/?pid=21&sid=18b004&uid=108&isRedirected=1

20090903174955    193.169.12.70    Failed resolution    hqvirusscanner5.com    hxxp://hqvirusscanner5.com/download/Antivirus_95.exe

20090904000059    193.169.12.70    Failed resolution    bravemousepride.com    hxxp://bravemousepride.com/?pid=95&sid=4e6ffe

20090904000138    193.169.12.70    Failed resolution    investmenttooltips.com    hxxp://investmenttooltips.com/?pid=162&sid=c3d08e

20090904021853    193.169.12.5    Failed resolution    downloadwinupdates.com    hxxp://downloadwinupdates.com/dp/z5GsSAiQivsLz4KtRKNNM4aoQ3Cmdo3bdVKV1wuQNWkDwyfh4E1jiEmB3j+w/J5+VKb4BXdG6c/FhZX0SwLMo0yyzzemX9FWXzAl/info.jpg

20090906121159    193.169.12.5    Failed resolution    check-pc-2009.com    hxxp://check-pc-2009.com/l/05049e9086g74i75t

20090906121229    193.169.12.5    Failed resolution    download4safe.com    hxxp://download4safe.com:80/s/wefe937786cg7es75t/setup.exe

20090906154106    193.169.12.3    Failed resolution    193.169.12.3    hxxp://193.169.12.3/s/w4f6ffe1391r72g7bz/setup.exe

20090906154112    193.169.12.5    Failed resolution    193.169.12.5    hxxp://193.169.12.5/s/w4f6ffe1391r72g7bz/setup.exe

20090906162219    193.169.12.3    Failed resolution    193.169.12.3    hxxp://193.169.12.3/s/w4f6ffe1391r72g7bz/setup.exe

20090907030516    193.169.12.5    Failed resolution    freeavcheck.com    hxxp://freeavcheck.com/l/d709f38e94u72g6ck

20090907030522    193.169.12.5    Failed resolution    safefilehere.com    hxxp://safefilehere.com/s/w24b16fed8dn73h74s/setup.exe

20090907165530    193.169.12.5    Failed resolution    online-updating.com    hxxp://online-updating.com/s/w39461a1997x74i77v/setup.exe

20090907213334    193.169.12.5    Failed resolution    online-updating.com    hxxp://online-updating.com/s/w39461a1997x74i77v/setup.exe

20090908144450    193.169.12.70    Failed resolution    newcellphones-overview.com    hxxp://newcellphones-overview.com/?pid=28&sid=b1c2f3

20090909020729    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKS0V7FPmkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdJFZwdAqFqd7Q9GQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090909021221    193.169.12.70    Failed resolution    fast-virus-scan9.com    hxxp://fast-virus-scan9.com/download/Soft_58s7.exe

20090909021422    193.169.12.70    Failed resolution    fast-virus-scan7.com    hxxp://fast-virus-scan7.com

20090909021429    193.169.12.70    Failed resolution    fast-virus-scan2.com    hxxp://fast-virus-scan2.com

20090909024842    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKT01rBbmkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdp5awtEvG6R0Q9GQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090909024848    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKT01rBaGkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdppYwdMtF690RdGQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090909024853    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKShFnFPGkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQcZhZw9AjEqN6TdGQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090909033106    193.169.13.11    Failed resolution    homepersonalantivirus.com    hxxp://homepersonalantivirus.com

20090909040812    193.169.12.70    Failed resolution    fast-virus-scan9.com    hxxp://fast-virus-scan9.com/download/Soft_28.exe

20090909181043    193.169.12.70    Failed resolution    spacestations-online.com    hxxp://spacestations-online.com/?pid=79&sid=f85226

20090909181049    193.169.12.5    Failed resolution    free-checkpc.com    hxxp://free-checkpc.com/l/e7b24b116ek83x77v

20090909181055    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/we7b24b117cy84y68g/setup.exe

20090909181108    193.169.12.5    Failed resolution    free-scan-pc.us    hxxp://free-scan-pc.us/s/w0bb4aec172m78m73r/setup.exe

20090910170302    193.169.12.70    Failed resolution    storyofthesuccess1.com    hxxp://storyofthesuccess1.com/?pid=28&sid=b1c2f3

20090910170316    193.169.12.70    Failed resolution    clean-all-spyware10.com    hxxp://clean-all-spyware10.com/download/Soft_28.exe

20090910221731    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKR0VTDOWkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdp5bwtMvEq57Q9GQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090910221739    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKR0VTDb2kDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdJxfxdciF6R0QtGQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090910221746    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAiWivsLz4KtRKNNM4aoQ3Cmdo3bdVKR0VTEPmkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdJhayNEjGqJ1R9GQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090910221752    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAiWivsLz4KtRKNNM4aoQ3Cmdo3bdVKR0VTDbGkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQc5tZw9suEad5UoTeFso8JlZ+DHmo+zhqBXtgTOP1u84=/info.jpg

20090910222350    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/wdc912a2590q85z6ck/setup.exe

20090910222357    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/wcf004fdc7dz7bp78w/setup.exe

20090910222404    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/w5ef698cd8bl77l6ck/setup.exe

20090910222410    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/w004114607bx7es72q/setup.exe

20090910223853    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAuUivsLz4KtRKNNM4aoQ3Cmdo3bdVKRjFjENWkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdJ1YxdYrF6J7TNGQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090910224044    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/wbeed13608ak80u75t/setup.exe

20090910224346    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAiWivsLz4KtRKNNM4aoQ3Cmdo3bdVKRgg7CPmkDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQdppexdErEaZ4TNGQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090910224352    193.169.12.5    Failed resolution    updatepcnow.com    hxxp://updatepcnow.com/dp/z5GsSAiQivsLz4KtRKNNM4aoQ3Cmdo3bdVKRgg7Bb2kDw2rtuUE4yB6VlzTjqp5nUaXwAnxUtsLcmdGnEDTNs1/qz2a7P5UCdz4gT1/Gcl+Xhhmnqi7M7vblESNEw3I1/h1y77qQcZleyNQsFqN+TdGQHtEjMREiYk+//ydgAzUbfeH9+9YN/info.jpg

20090910224631    193.169.12.5    Failed resolution    free-scan-pc.us    hxxp://free-scan-pc.us/s/w0bb4aec172m78m73r/setup.exe

20090910224642    193.169.12.5    Failed resolution    safe-fileshere.com    hxxp://safe-fileshere.com/s/we7b24b117cy84y68g/setup.exe

20090912020905    193.169.12.5    Failed resolution    getfeedsonline.in    hxxp://getfeedsonline.in/dp/dBCVn3003PdDtQAcjNU9fwy8TCt3z1MikexZ3L0xn5vvXm4GeA5yF6fvbe8jJ9SEaZC9Vz82RzLy1R0cKuhGlf2PWRPayTjfnOv9/new.jpg

20090912173916    193.169.13.6    Failed resolution    download-secure-here.com    hxxp://download-secure-here.com/s/wbca82e418eo7dr71p/setup.exe

20090917154146    193.169.13.23    Failed resolution    193.169.13.23    hxxp://193.169.13.23/counter/lan.exe

20090917154929    193.169.13.6    Failed resolution    clear-update-system.com    hxxp://clear-update-system.com/s/w138bb0697cy75j70o/setup.exe

20090917162650    193.169.13.11    Failed resolution    autoonlineadvisor.net    hxxp://autoonlineadvisor.net/


Other ranges root eSolutions have include (and yep, there's malware on all of them);

91.214.44.0/22
195.24.72.0/21
212.117.160.0/19

Personally I recommend blackholing the lot of them, but I tend to take a zero tolerance approach, especially in cases such as this where the ISP's seem to care more about the money than anything else, and as such, don't bother either responding to abuse reports, or killing the malicious content and booting the clients responsible.

In the meantime, I'd absolutely love to hear both theirs and their clients explanations for their being nothing but malicious content on the vast majority of the ranges. Should make for interesting reading.

No comments: