Blog for hpHosts, and whatever else I feel like writing about ....

Thursday, 21 January 2010

SEVAHOST-AS Seva-Host Ltd (AS49313) and SMS Fraud

I received an e-mail earlier, pointing to an Angelfire hosted site;

yzisuteq.angelcities.com/utakeseh.html

Expecting malware or fake meds, I decided to take a look to see which of the two it was. Surprisingly I was wrong - it was neither. The site leads to mobilnaked.com, a site completely in Russian (and annoyingly, given most of the text is actually image based, untranslatable with Google). Remembering a previous episode and something my friend Dmitry at Kaspersky advised me, I took a closer look.

mobilnaked.com claims to offer a program for your mobile phone, that will allow you to see through everyones clothes (errr, yeah, you can see where this is going). Indeed, shown on the site is a woman dancing, and someone holding a phone in front of her, showing her clothing magically removed whilst she's dancing, and all via the program offered by the site.

However, to get this miracle program, you've got to send them an SMS at a charge of approx £0.14GBP. The real cost however, is likely MUCH higher (indeed, the one Dmitry looked at for me, actually cost you closer to £5, though that one was claiming to be a rogue!!, ah the joys).

The short codes (numbers) you are told to send the SMS to (for those in the UK) are 79067 or 69067. There is of course, a list of others (/download.php), that appear to be used for other countries;

NB: The numbers encased in [], match up with the short code, cost, country etc

var jph=newArray();
jph[27]='19995577';
jph[5]='930399999';
jph[30]='1003';
jph[24]='7259';
jph[7]='7796';
jph[6]='1098';
jph[23]='79067';
jph[15]='90645045';
jph[9]='82300';
jph[10]='1945';
jph[25]='4070';
jph[12]='5339';
jph[4]='9915';
jph[3]='1171';
jph[17]='1874';
jph[16]='1645';
jph[26]='141991';
jph[29]='2332';
jph[19]='7117';
jph[18]='2322';
jph[20]='7910';
jph[21]='4565';
jph[1]='7122';
jph[2]='5373';
jph[13]='179479';
jph[14]='83868';
jph[31]='1600';
jph[8]='9090199';
jph[28]='9292';
jph[22]='72170';
jph[11]='17013';
var japh=newArray();
japh[27]='19995577';
japh[5]='930399999';
japh[30]='7001';
japh[24]='7255';
japh[7]='7796';
japh[6]='1098';
japh[23]='69067';
japh[15]='90645045';
japh[9]='82300';
japh[10]='1945';
japh[25]='4070';
japh[12]='5339';
japh[4]='9916';
japh[3]='1171';
japh[17]='1873';
japh[16]='1624';
japh[26]='141991';
japh[29]='7250';
japh[19]='7117';
japh[18]='2322';
japh[20]='7910';
japh[21]='4565';
japh[1]='7132';
japh[2]='7250';
japh[13]='179479';
japh[14]='83868';
japh[31]='1600';
japh[8]='9090150';
japh[28]='9292';
japh[22]='72170';
japh[11]='17012';
var jm=newArray();
jm[27]='wm771270';
jm[5]='4049270';
jm[30]='wm771270';
jm[24]='wm771270';
jm[7]='4049270';
jm[6]='4049270';
jm[23]='4049270';
jm[15]='4049270';
jm[9]='dx353270';
jm[10]='4049270';
jm[25]='wm5771270';
jm[12]='4049270';
jm[4]='4049270';
jm[3]='4049270';
jm[17]='4049270';
jm[16]='4049270';
jm[26]='wm771270';
jm[29]='wm771270';
jm[19]='4049270';
jm[18]='4049270';
jm[20]='4049270';
jm[21]='4049270';
jm[1]='353270';
jm[2]='771270';
jm[13]='4049270';
jm[14]='4049270';
jm[31]='wm771270';
jm[8]='4049270';
jm[28]='wm771270';
jm[22]='4049270';
jm[11]='4049270';
var jv=newArray();
jv[27]='AUD';
jv[5]='EURO';
jv[30]='AMD';
jv[24]='BYR';
jv[7]='EURO';
jv[6]='BGN';
jv[23]='GPB';
jv[15]='HUF';
jv[9]='EURO';
jv[10]='DKK';
jv[25]='ILS';
jv[12]='EURO';
jv[4]='KZT';
jv[3]='USD';
jv[17]='LVL';
jv[16]='LTL';
jv[26]='USD';
jv[29]='MDL';
jv[19]='EURO';
jv[18]='NOK';
jv[20]='PLT';
jv[21]='EURO';
jv[1]='рублей';
jv[2]='гривен';
jv[13]='EURO';
jv[14]='EURO';
jv[31]='EURO';
jv[8]='CZK';
jv[28]='CHF';
jv[22]='SEK';
jv[11]='EEK';
var jc=newArray();
jc[27]='0.08';
jc[5]='0.05';
jc[30]='26.6';
jc[24]='135';
jc[7]='0.05';
jc[6]='0.07';
jc[23]='0.14';
jc[15]='18.33';
jc[9]='0.14';
jc[10]='0.53';
jc[25]='0.18';
jc[12]='0.04';
jc[4]='20.67';
jc[3]='0.16';
jc[17]='0.28';
jc[16]='0.28';
jc[26]='0.03';
jc[29]='0.8';
jc[19]='0.04';
jc[18]='0.53';
jc[20]='0.3';
jc[21]='0.07';
jc[1]='10';
jc[2]='0.83';
jc[13]='0.05';
jc[14]='0.08';
jc[31]='0.01';
jc[8]='2.77';
jc[28]='0.08';
jc[22]='0.53';
jc[11]='1.41';

function getText(id)
{
    $('#smsMsg').text(jm[id]);
    $('#smsNum').text(jph[id]);
    if(jph[id]!=japh[id])
    {
       $('#smsAdvNum').text(japh[id]);
       $('#orText').text('или');
    }
    else
    {
       $('#orText').text('');
       $('#smsAdvNum').text('');
    }
    $('#smsCost').text(jc[id]);
    $('#smsVal').text(jv[id]);
    
    if(id==24)
    {
       $('span#byCountry').show();
       $('span#BYhide').hide();
       
       
    }
    else
    {
       $('span#byCountry').hide();
       $('span#BYhide').show();
       
    }
}


The scam is run, from what I can find, by Sergey S Pirozhnikov (papa.racot@gmail.com), owner of smsdostup.ru and sms911.ru (and several others apparently, still looking into that), registered in 2007 and 2008 via RegTime (surprise surprise) and NAUNET (associated with spam, Zeus and other criminal activities), and hosted at 92.241.166.5 and 92.241.166.166 respectively.

inetnum: 92.241.166.0 - 92.241.166.255
netname: RM-INVEST
descr: RM-INVEST Ltd
country: RU
admin-c: PIRO1-RIPE
tech-c: PIRO1-RIPE
status: ASSIGNED PA
mnt-by: RU-WEBALTA-MNT
source: RIPE # Filtered

person: Sergey Pirozhnikov
address: Kazanskaya, 7,
193000 St.Petersburg,
RUSSIAN FEDERATION
mnt-by: RU-WEBALTA-MNT
phone: +7 (911) 400-16-11
nic-hdl: PIRO1-RIPE
source: RIPE # Filtered

route: 92.241.160.0/19
descr: Wahome IP's =)
origin: AS41947
mnt-by: RU-WEBALTA-MNT
source: RIPE # Filtered


You'll also have noticed the link to ephelp.ru, which as you've guessed, is also involved. ephelp.ru was also registered in 2008 (again via NAUNET) by someone that apparently doesn't want to be known. It's hosted at 91.212.210.192.

Getting back to mobilnaked.com et al. They do of course, provide a "rules" page, which when translated reads (I've formatted it for readability);

Terms of Use mobilnaked.com:

Terms

Terms of Use mobilnaked.com: Terms This User Agreement (hereinafter "Agreement") governs the relationship between «mobilnaked.com» (hereinafter "Service" or "Site"), which is located at mobilnaked.com, and natural or legal person (hereinafter "User") on the Internet.

1. Subject user agreement to the User Services offers its services on terms that are the subject of this Agreement. Agreement may be changed Site «mobilnaked.com» unilaterally and without notice to User.

2. Description of Services Based on Service Agreement provides its services to users who have access to the Internet and pre-installed software to work with web-interface available exclusively at mobilnaked.com. «Mobilnaked.com» - this is a joke gaming service that gives users access to the Java-application for a fee. mobilnaked.com provides user access to the Java-application after the payment made by the user. It is a software application provided by the white-pc user how to help to optimize computer performance. Animated objects are part of the registration site.

3. Entry into force, the Agreement shall enter into force as soon as the User acknowledges and accepts the rules of the Site «mobilnaked.com», by sending an appropriate SMS message. By accessing imply its consent to this Agreement. Using services of Service means that you have read and agree with the Agreement, even if the user has not finished the stage of registration.

4. Obligations and responsibilities of the user after registration user receives a key to access the personal information section. Service reserves the right not to allow the use of certain passwords or remove these passwords without prior notice. User is responsible for the security of your password and all information publicly published by the User through the Service, including but not limited to comments on the Site «mobilnaked.com».

5. To gain access you need to send 3 SMS to short number. * Price per page of payment is for 1 day. * Access to the software available for 90 (ninety) days. . Lump sum user pays the entire period of use uslugoy. Oplata Service Service To gain access you need to send 3 SMS to short number. The cost of an SMS message to service number 9690 and 9691 is approximately 300 rubles (for Russia);

Info short numbers and tariffs - to http://www.nlinfo.ru. Cost of SMS to 7122 for the operator MTS is 258.3 rubles without VAT, for the rest of about 250 rubles depending on the operator. The approximate cost of a SMS to number 1874 for Latvia - 3.3 lats NDS.Ctoimost window without payment is for 1 test. Cost of SMS to 4171 for Ukraine - 30 hryvnia VAT excluding duty to the pension fund in the amount of 7.5% of the cost of SMS without NDS.Pri accessing the subscriber is able to conduct 100 inspections. The exact cost of SMS, you can check with your mobile operator or website:

http://sms911.ru

6. DISCLAIMER OF WARRANTIES

a) The user uses the service «mobilnaked.com» at your own risk. Facilities & Services «mobilnaked.com» The user is provided on an "as is". Service
«mobilnaked.com» does not assume any liability, including but not limited to the search results match the user's request,

b) Site «mobilnaked.com» represents a source of information that is entertaining. All information presented on this site is partly fictitious and should not be taken seriously;

c) Service «mobilnaked.com» does not warrant that: services «mobilnaked.com» will comply with your requirements, the quality of services of Service «mobilnaked.com» will match User's expectations, the results obtained by the User on the Site «mobilnaked.com» will be accurate; software bugs in the site «mobilnaked.com» will be corrected;

d) Service Rules

«mobilnaked.com» does not return the amount of money spent by the User;

d) Service «mobilnaked.com» is not responsible for any damages, direct, indirect, actual or consequential damages related to the Service, lost profits and other risks, even if the service and its owners have been advised of the possibility of such damages, or if such damages were foreseeable. Thus, the user assumes all risks associated with use of the Service «mobilnaked.com».


As you've no doubt noticed, this miracle application doesn't exist at all. You've been scammed, and will continue to be, given it's not a single SMS you've got to send. It's apparently a "joke gaming service" (some joke huh?), that provides you with some "java application" once you've been gullible enough to pay them via SMS.

There is of course, as there always is with this type of thing, a long list of other domains involved, and for your viewing pleasure, here they are.

adult-movierus.com
adult-videosru.com
adult-vidsrus.com
adult-xmovies.com
bestxfiles.com
bestxfilesru.com
ephelp.ru
eromamba.com
glubokie-glotki.com
hardsexru.com
helpscrus.com
hotmovierus.com
hotmovsrus.com
need4seks.com
needforsexxx.com
sevadns.com
sevadns.net
seva-host.com
rushomex.com
rushomexxx.com
rushotgirls.com
rusxgirls.com
rusxxxgirls.com
ruxxxgay.com
sc-traffic.com
sevadns.com
sevadns.net
seva-host.com
sevahost.net
forewa.ru
mxlove.ru
mobilpoisk.com
sex-klassniki.com
sexklassniki.com
euromixxx.com
eropays.ru
eropays2.com
erolesbi.com
erogayxxx.com
ero-pays.com
sexcashrus.com
sexcashv2.com
sms4videorus.com
sms911.ru
smsdostup.ru
xxxodnoklassniki.com
xxxrusvideo.com
xxxruvideo.com
xxx-telkiru.com
xxx-telkirus.com
ero-bdsm.com
sms2movierus.com
sms-datalizer.com
sms-poiski.com
sms-poiskrus.com
sms-proverki.com
russserotika.com
ruserotika.com
sexcashvip.com
vip-traffic.com


A few of these are no longer alive (failing to resolve). You'll find the validation results (domains were verified as of a few seconds ago) at;

http://hosts-file.net/misc/hpObserver_results_-_AS49313_Sevahost_fraud.html

I'm in no doubt that there's alot more I've not yet identified.

So who is providing the upstream connectivity for Seva-Host, and why are they allowing this? Well, the connectivity is provided courtesy of AS47143 TDHN Transit Data Hyper Network, an ISP with ties to other well known criminal organizations, such as root eSolutions, Kabelfoon, WEDARE We Dare BV, amongst many others (it's worth noting aswell, TDHN also have ties to a plethora of LEGIT companies aswell).

A tracert result is also showing Seva-host have connections to UK based firm, c4l.co.uk. Their offices are apparently closed now (ISP's really should learn to run 24/7, abuse and technical issues aren't time specific .....), but I'll be looking into that too.

In the meantime, I'd strongly urge everyone blackhole Seva-Host Ltd's entire range. There's not a single legit domain present, so you're not going to miss anything.

No comments: