Blog for hpHosts, and whatever else I feel like writing about ....

Thursday 10 December 2009

BlueConnex/EuroConnex (AS29550): Riccom LTD (91.212.107.*, AS49038, riccom-cy.org)

Dear BlueConnex/EuroConnex, I wonder if you'd mind explaining to the ladies and gents of the internet, why you have STILL not booted Riccom? Why you continue providing connectivity for them, despite their not being a single legit domain within their IP range!.

BlueConnex/EuroConnex's still providing connectivity is the reason they got a mention in the crimeware friendly ISP's listings, and sadly, to date, there has still not been so much as an auto-response to e-mails sent to them.

There's a whole host of malicious goodness currently over there, and amongst them, is malware-url.com, which of course, is a malicious version of the real malwareurl.com, run by my friend Anthony (you'll also notice, it's exactly the same impersonation as the one documented concerning malwaredomainlist.com).



malware-url.com by the way, takes you through;

hxxp://veteransdaystew.com/buy.php?id=
hxxps://secure.netpaymentprocess.com/bill/payment/

veteransdaystew.com is hosted at 91.212.226.187 (AS5577 91.212.226.0/24 ROOT root eSolutions), and secure.netpaymentprocess.com is hosted at 217.23.9.202 (AS49981 217.23.0.0/20 WORLDSTREAM WorldStream). The SSL certificate is provided by Thawte (anyone awake over there?).

Then there's malware-scaner-online.com, also valid as;

malware-scaner-online.net
malware-scaner-online.org
malware-scaner-online.biz

All of which, resolve to 91.212.107.38. And of course, all of which, will give your PC some malicious goodness it'll never forget;

Wepawet results: malware-scaner-online.biz
http://wepawet.cs.ucsb.edu/view.php?hash=a2913104bc85687b33d48a621f1563c1&t=1260497205&type=js

Virus Total results (18/41): win_protection_update.exe
http://www.virustotal.com/analisis/d22290ed9780e371e0ae6cfc93a35429f97f0c9f2227ec788d4ddde5ba0cb3a3-1260467532

There's currently well over 500 domains in hpHosts for the Riccom range, with 700 or so, in the historical records.

Historical records for: 91.212.107.0/24
http://hosts-file.net/?s=91.212.107.&view=history

hpHosts listings for: 91.212.107.0/24
http://hosts-file.net/?s=91.212.107.&view=matches

Note: I've still not gotten round to writing the monitor to keep the IP's in hpHosts, up to date, so it's possible some of the domains are either dead, or have moved elsewhere. The current validation results for those listed in hpHosts, as of 2 seconds ago, can be found at;

hpObserver validation results for: 91.212.107.0/24
http://hosts-file.net/misc/hpObserver_results_-_BlueConnex_91.212.107.0-255.html

The current list of domain names for those that want them, is;

black-list-websites.com
bysivak.cn
byxzeq.cn
byzivte.cn
cafgouh.cn
cakdoz.cn
cakevy.cn
cakuqe.cn
camjyel.cn
cecxoyk.cn
cecyde.cn
ceduszi.cn
cekfaq.cn
cekrin.cn
celwahy.cn
cepamwi.cn
cepula.cn
ceqywis.cn
cerwyk.cn
cifebi.cn
cigzaon.cn
deferr.info
dotqyuw.cn
dovnaji.cn
dovzyag.cn
download-free-online.com
download-free-scanner.biz
download-free-scanner.info
download-free-scanner.net
download-free-scanner.org
download-scanner-free.biz
download-scanner-free.com
download-scanner-free.info
download-scanner-free.org
dozabes.cn
ducyqan.cn
dusyti.cn
duvaba.cn
duvegy.cn
duwbiec.cn
duxsoez.cn
duzebyn.cn
dybapi.cn
dybaqhi.cn
dybulhe.cn
dyckeqi.cn
dycotda.cn
dyfpilu.cn
dyjurwe.cn
dyjzeti.cn
dykazif.cn
dykqupo.cn
dymsem.cn
dyqkuam.cn
dyqunre.cn
dyrajko.cn
dyrmilu.cn
dyshir.cn
dytrevu.cn
dyzani.cn
ebaetu.cn
ebeama.cn
ebejar.cn
ebeoxuw.cn
ebeozag.cn
ebiuhas.cn
eboezu.cn
ebogumi.cn
ebureky.cn
eceiqak.cn
ecezofu.cn
ecibuaj.cn
ecoaly.cn
ecoydo.cn
ecyarzo.cn
ecygaf.cn
ecyigud.cn
ecyujo.cn
edociv.cn
edoeqnu.cn
ekrsoft.in
epuneyv.cn
epuvyiz.cn
eqadozu.cn
eqaofed.cn
eqaone.cn
eqayweh.cn
eqibuym.cn
eqidax.cn
eqiovak.cn
eqoabce.cn
eqoumiv.cn
erauso.cn
ereuqba.cn
ereuwzo.cn
eriolyh.cn
erixune.cn
eroisyw.cn
eroyjgi.cn
erqsoft.in
erujale.cn
eruqav.cn
eruqief.cn
eryase.cn
erygibo.cn
erymezo.cn
erypuin.cn
erywiza.cn
esaowy.cn
esuteyb.cn
esyeziw.cn
esyofo.cn
esyviq.cn
etexyaj.cn
eteyxuz.cn
eticod.cn
etobez.cn
etoubal.cn
etuacwo.cn
etuexyp.cn
etupet.cn
etuyzal.cn
etyaha.cn
etyawjo.cn
etykauw.cn
etyupy.cn
etywuq.cn
evaolux.cn
evaopsu.cn
evuxyv.cn
evyazi.cn
evykoas.cn
ewaevuf.cn
ewalepi.cn
free-download-web.com
free-online-scanner.biz
free-online-scanner.com
free-online-scanner.info
free-online-scanner.org
free-scanner-online.biz
free-scanner-online.info
free-scanner-online.net
free-scanner-online.org
free-web-download.com
g-antivirus.com
general-av.com
generalavs.com
gen-pay.com
gobackscan.com
godirscan.com
godoerscan.com
goeachscan.com
goeasescan.com
gofatescan.com
golookscan.com
gomutescan.com
gonamescan.com
goneatscan.com
gopickscan.com
goscanadd.com
goscancode.com
goscandir.com
goscandoer.com
goscanease.com
goscanlike.com
goscanmute.com
goscanneat.com
goscanpick.com
goscansole.com
goscantech.com
goscantrio.com
goscanxtra.com
gosolescan.com
gotrioscan.com
goxtrascan.com
iantiviruspro.com
iantivirus-pro.com
ia-pro.com
ipod-movies-videos.info
iqmediamanager.com
kebfoki.cn
kebquty.cn
keturma.cn
kevsopi.cn
kijxayt.cn
kiluxso.cn
kipuxo.cn
kirdabe.cn
kireja.cn
kirgune.cn
kiwraux.cn
kixyhce.cn
kizxyun.cn
kocepal.cn
kocwiyg.cn
kogiteq.cn
kogivet.cn
kohkiv.cn
kohsuby.cn
komsehi.cn
komvyl.cn
komxaiv.cn
kopeka.cn
kusoft.eu
lisoft.eu
lynden-heights.com
mail.iqmediamanager.com
malware-scaner-online.biz
malware-scaner-online.com
malware-scaner-online.net
malware-scaner-online.org
mx.moskva.fm
mxout.moskva.fm
newtunesclub.com
online-scanner-free.org
online-spyware-remover.biz
online-spyware-remover.info
online-spyware-remover.org
onlinetubeporn.biz
onlinetubeporn.info
onlinetubeporn.org
pay-av.com
piter.fm
pohsoft.in
porn-online-tube.com
porn-tube-online.biz
porn-tube-online.com
porn-tube-online.info
porn-tube-online.org
qlwsoft.in
rousen.info
scanner-download-free.com
scanner-free-download.biz
scanner-free-download.com
scanner-free-download.info
scanner-free-download.org
scanner-free-online.biz
scanner-free-online.com
scanner-online-free.biz
scanner-online-free.com
scanner-online-free.info
scanner-online-free.org
sex-tube-online.com
silverlight-update.com
software-scaner-online.net
spyware-online-remover.biz
spyware-online-remover.info
spyware-online-remover.org
tube-online-porn.biz
tube-online-porn.com
tube-online-porn.info
tube-online-porn.net
tube-online-porn.org
tubepornonline.biz
tube-porn-online.biz
tubepornonline.info
tube-porn-online.info
tube-porn-online.net
tubepornonline.org
tube-porn-online.org
unsoft.eu
web-download-free.com
web-free-download.com
woptimizer.com
www.bysivak.cn
www.byxzeq.cn
www.byzivte.cn
www.cafgouh.cn
www.cakdoz.cn
www.cakevy.cn
www.cakuqe.cn
www.camjyel.cn
www.cecxoyk.cn
www.cecyde.cn
www.ceduszi.cn
www.cekfaq.cn
www.cekrin.cn
www.celwahy.cn
www.cepamwi.cn
www.cepula.cn
www.ceqywis.cn
www.cerwyk.cn
www.cifebi.cn
www.cigzaon.cn
www.deferr.info
www.dotqyuw.cn
www.dovnaji.cn
www.dovzyag.cn
www.download-free-online.com
www.download-free-scanner.biz
www.download-free-scanner.info
www.download-free-scanner.net
www.download-free-scanner.org
www.download-scanner-free.biz
www.download-scanner-free.com
www.download-scanner-free.info
www.download-scanner-free.org
www.dozabes.cn
www.ducyqan.cn
www.dusyti.cn
www.duvaba.cn
www.duvegy.cn
www.duwbiec.cn
www.duxsoez.cn
www.duzebyn.cn
www.dybapi.cn
www.dybaqhi.cn
www.dybulhe.cn
www.dyckeqi.cn
www.dycotda.cn
www.dyfpilu.cn
www.dyjurwe.cn
www.dyjzeti.cn
www.dykazif.cn
www.dykqupo.cn
www.dymsem.cn
www.dyqkuam.cn
www.dyqunre.cn
www.dyrajko.cn
www.dyrmilu.cn
www.dyshir.cn
www.dytrevu.cn
www.dyzani.cn
www.ebaetu.cn
www.ebeama.cn
www.ebejar.cn
www.ebeoxuw.cn
www.ebeozag.cn
www.ebiuhas.cn
www.eboezu.cn
www.ebogumi.cn
www.ebureky.cn
www.eceiqak.cn
www.ecezofu.cn
www.ecibuaj.cn
www.ecoaly.cn
www.ecoydo.cn
www.ecyarzo.cn
www.ecygaf.cn
www.ecyigud.cn
www.ecyujo.cn
www.edociv.cn
www.edoeqnu.cn
www.edoqeg.cn
www.epuneyv.cn
www.epuvyiz.cn
www.eqadozu.cn
www.eqaofed.cn
www.eqaone.cn
www.eqayweh.cn
www.eqibuym.cn
www.eqidax.cn
www.eqiovak.cn
www.eqoabce.cn
www.eqoumiv.cn
www.erauso.cn
www.ereuqba.cn
www.ereuwzo.cn
www.eriolyh.cn
www.erixune.cn
www.eroisyw.cn
www.eroyjgi.cn
www.erujale.cn
www.eruqav.cn
www.eruqief.cn
www.eryase.cn
www.erygibo.cn
www.erymezo.cn
www.erypuin.cn
www.erywiza.cn
www.esaowy.cn
www.esuteyb.cn
www.esyeziw.cn
www.esyofo.cn
www.esyviq.cn
www.etexyaj.cn
www.eteyxuz.cn
www.eticod.cn
www.etobez.cn
www.etoubal.cn
www.etuacwo.cn
www.etuexyp.cn
www.etupet.cn
www.etuyzal.cn
www.etyaha.cn
www.etyawjo.cn
www.etykauw.cn
www.etyupy.cn
www.etywuq.cn
www.evaolux.cn
www.evaopsu.cn
www.evuxyv.cn
www.evyazi.cn
www.evykoas.cn
www.ewaevuf.cn
www.ewalepi.cn
www.free-download-web.com
www.free-online-scanner.biz
www.free-online-scanner.com
www.free-online-scanner.info
www.free-online-scanner.org
www.free-scanner-online.biz
www.free-scanner-online.info
www.free-scanner-online.net
www.free-scanner-online.org
www.free-web-download.com
www.g-antivirus.com
www.general-av.com
www.generalavs.com
www.gen-pay.com
www.gobackscan.com
www.godirscan.com
www.godoerscan.com
www.goeachscan.com
www.goeasescan.com
www.gofatescan.com
www.golookscan.com
www.gomutescan.com
www.gonamescan.com
www.goneatscan.com
www.gopickscan.com
www.goscanadd.com
www.goscanback.com
www.goscancode.com
www.goscandir.com
www.goscandoer.com
www.goscanease.com
www.goscanlike.com
www.goscanmute.com
www.goscanneat.com
www.goscanpick.com
www.goscansole.com
www.goscantech.com
www.goscantrio.com
www.goscantune.com
www.goscanxtra.com
www.gosolescan.com
www.gotrioscan.com
www.goxtrascan.com
www.inavpro.com
www.ipod-movies-videos.info
www.iqmediamanager.com
www.kebfoki.cn
www.kebquty.cn
www.keturma.cn
www.kevsopi.cn
www.kijxayt.cn
www.kiluxso.cn
www.kipuxo.cn
www.kirdabe.cn
www.kireja.cn
www.kirgune.cn
www.kiwraux.cn
www.kixyhce.cn
www.kizxyun.cn
www.kocepal.cn
www.kocwiyg.cn
www.kogiteq.cn
www.kogivet.cn
www.kohkiv.cn
www.kohsuby.cn
www.komsehi.cn
www.komvyl.cn
www.komxaiv.cn
www.kopeka.cn
www.kusoft.eu
www.lisoft.eu
www.lynden-heights.com
www.malware-scaner-online.biz
www.malware-scaner-online.com
www.malware-scaner-online.net
www.malware-scaner-online.org
www.newtunesclub.com
www.online-scanner-free.org
www.online-spyware-remover.biz
www.online-spyware-remover.info
www.online-spyware-remover.org
www.onlinetubeporn.biz
www.onlinetubeporn.info
www.onlinetubeporn.org
www.pay-av.com
www.pohsoft.in
www.porn-online-tube.com
www.porn-tube-online.biz
www.porn-tube-online.com
www.porn-tube-online.info
www.porn-tube-online.org
www.rousen.info
www.scanner-download-free.com
www.scanner-free-download.biz
www.scanner-free-download.com
www.scanner-free-download.info
www.scanner-free-download.org
www.scanner-free-online.biz
www.scanner-free-online.com
www.scanner-online-free.biz
www.scanner-online-free.com
www.scanner-online-free.info
www.scanner-online-free.org
www.sex-tube-online.com
www.software-scaner-online.net
www.spyware-online-remover.biz
www.spyware-online-remover.info
www.spyware-online-remover.org
www.tube-online-porn.biz
www.tube-online-porn.com
www.tube-online-porn.info
www.tube-online-porn.net
www.tube-online-porn.org
www.tubepornonline.biz
www.tube-porn-online.biz
www.tubepornonline.info
www.tube-porn-online.info
www.tube-porn-online.net
www.tubepornonline.org
www.tube-porn-online.org
www.unsoft.eu
www.web-download-free.com
www.web-free-download.com
www.w-optimizer.com


If you know of a domain that's also hosted on this range, that is not listed in hpHosts, please do feel free to drop by the hpHosts forums and let me know.

The net-block info for this range is;

inetnum: 91.212.107.0 - 91.212.107.255
netname: Riccom-NET
descr: Riccom LTD
descr: The research center of Cyprys
country: CY
org: ORG-RL70-RIPE
admin-c: MC16000-RIPE
tech-c: MC16000-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-by: MNT-RICCOM
mnt-lower: RIPE-NCC-END-MNT
mnt-routes: MNT-RICCOM
mnt-routes: blueconnex-mnt
mnt-routes: MNT-EUKHOST
mnt-domains: MNT-RICCOM
source: RIPE # Filtered

organisation: ORG-RL70-RIPE
org-name: Riccom LTD
org-type: OTHER
address: 89 Digenis Akritas Ave, Nicosia, Cyprus
abuse-mailbox: ipadmin@riccom-cy.org
mnt-ref: MNT-RICCOM
mnt-by: MNT-RICCOM
source: RIPE # Filtered

person: Marios Christos
address: 89 Digenis Akritas Ave, Nicosia, Cyprus
phone: +357-02-447121
nic-hdl: MC16000-RIPE
mnt-by: MNT-RICCOM
source: RIPE # Filtered

:: Information related to '91.212.107.0/24AS29550'

route: 91.212.107.0/24
descr: Riccom route object
mnt-by: MNT-RICCOM
mnt-by: blueconnex-mnt
origin: AS29550
mnt-by: MNT-EUKHOST
source: RIPE # Filtered


Additional resources

MalwareURL: AS49038
http://www.malwareurl.com/listing.php?as=AS49038

MalwareURL: AS29550
http://www.malwareurl.com/listing.php?as=AS29550

MalwareDomainList: AS29550
http://www.malwaredomainlist.com/mdl.php?search=29550&colsearch=All&quantity=50

Clean-MX: 91.212.107.*
http://support.clean-mx.de/clean-mx/viruses.php?sort=firstseen desc&review=91.212.107.%

No comments: