Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 12 November 2008

Internet Landfill: McColo Corporation

Posted on 05:19 by Unknown
Brian Krebs has turned his sights on another Internet Landfill, this time the McColo Corporation. Today his column is titled: Major Source of Online Scams and Spams Knocked Offline. Later this morning, the Washington Post ran a longer story on the topic, Major Source of Internet Spam Yanked Offline: Web Hosting Firm Shuttered After Connection to Spammers is Exposed He mentions in the column that he has been researching McColo for several months, and that when he contacted McColo's upstream providers, Global Crossings and Hurricane Electric, that something interesting happened.

Hurricane Electric's Benny Ng told Krebs:

"We looked into it a bit, saw the size and scope of the problem you were reporting and said 'Holy cow! Within the hour we had terminated all of our connections to them."

Although Global Crossings declined to give Krebs a comment, apparently Krebs has once more accomplished what the entire rest of the security world has been unable to do -- removing another Internet Landfill from the world wide web.

I coined the term "Internet Landfill" in a presentation regarding Krebs earlier amazing work almost single-handedly removing Intercage from the Internet. I explained it by saying:

Every house has a trash can, and every business has a dumpster. There's a little garbage anywhere you look. But when someone buys the land in your neighborhood and decides to make it a garbage dump, or a landfill, usually the citizens in that neighborhood protest. Some places on the Internet, such as Intercage, exist solely to store filth, malware, and crime. Those places should be treated like "Internet Landfills", and their neighbors should rise up and protest their presence in their neighborhood.


In case anyone has a question about what type of organization McColo is, here is a little fact-finding adventure, using the excellent Reverse IP Tools from DomainTools.com, and the ASN information from CIDR-Report.

McColo's Autonomous System Number is AS26780.

At this time, Hurricane Electric is no longer listed as an upstream, but Global Crossing *IS* still showing a listing, connecting AS3549 (GBLX) to AS26780(MCCOLO).

The Netblocks currently published as being at McColo are:

208.66.192.0/22
208.72.168.0/21

All their other netblocks are strangely missing.

(See: http://www.cidr-report.org/cgi-bin/as-report?as=as26780)

All of McColo's "Business" webpages were on the server 208.66.192.100. That IP resolved McColo.biz, .com, .info, .net, and .org.

None of those domain names are currently resolving.


Moving through their Class C addresses . . .




208.66.193.* previously had four major domains:

proxyspy.biz
audiobookss.com
authorstore.org
gente.ru

None of those domain names are currently resolving.




208.66.194.* previously had 94 domain names. Just choosing from a few . . .

bestincestfamily dot com (registered at ESTDomains)
bestincestmovies dot com (registered at ESTDomains)
cheapincestpics dot com (registered at ESTDomains)
eliteincestsite dot com (registered at ESTDomains)
teenincestpics dot com (registered at ESTDomains)

None of those domain names are currently resolving.




208.66.195.* previously had domain names. Again, just choosing a few...

protect-access dot com (registered at ESTDomains)
downloadcopy dot com (registered at ESTDomains)
pantyhosefiesta dot com
wm-chance dot net

The pantyhose sites have been moved already to "Sago Networks, LLC".
WM-chance has also been moved to Sago (November 12th) but is not yet operational in its new location. Its a Russian language online lottery winning site. Some of the other sites in this group show signs of being "in the process" of moving.




207.72.168.* previously had 1,183 domain names. Again, just choosing a few...

Megacaptcha dot biz (registered at EstDomains)
CaptchaToMoney dot biz (registered at EstDomains)
Torrentpump dot com (registered at Directi)
FtvInnocentAngels dot net (registered at EstDomains)
Coastal-health dot com (registered at OnlineNIC, Inc)
Canadianpharmacycorp1 dot com (registered at Xin Net)
Canadianpharmacycorp2 dot com
Canadianpharmacycorp3 dot com
Canadianpharmacycorp4 dot com
(through 10)
Onlinepharmacysolutions-a dot com (registered at Directi)
Onlinepharmacysolutions-b dot com
Onlinepharmacysolutions-c dot com
Onlinepharmacysolutions-d dot com
Rxmania dot com (registered at GoDaddy)
Pay4pills dot com (registered at GoDaddy)
Asc-antispyware dot com (registered at Beijing Innovative)
A-pennystock dot com (registered at GoDaddy)
Incest-rape dot com (registered at GoDaddy)
Little-gays dot com (registered at EstDomains)
Allyoungmovies dot com (registered at EstDomains)
Smallpussy dot name (registered at EstDomains)(*1)
nymphets dot name (registered at EstDomains)
LittleCuties dot name (registered at EstDomains)

*1 - received 19,317 visitors per month according to Compete.com

None of the sites in this group are currently resolving.




208.72.169.* had 118 domains registered.

Angelgirlspic.com
Searchportalsite.com

Emailru.info
Emailrus.info
Mailfreedom4u.net
Mailblogal.info
Quickmailbox.info
Ruslandmail.info

DomainsUAgroups dot com

and some NOTORIOUS nameserver domains, which are said to belong to Leo Kuvayev, such as:

Jioketinjdesapionkderunjsa.com
Kedfinhderionkadesunpas.com
Vertunhandesikolasderun.com

None of the sites in this group are currently resolving.




208.72.170.* has 22 domain names, including:

cinema4free dot com
flashbill dot net
inc-rep dot biz
asapload dot com
theypay dot biz

playpokeronline-casinos dot com
gamble-poker-holdem dot com
texasholdem-vip dot com

None of the sites in this group are currently resolving.




208.72.171.* has only 4 domain names:

br-ladies dot com
ru-ladies dot com
kharkovblacklist dot com
uapeople dot com




208.72.172.* has 132 domain names. Most all of them have the word "sex" in the title of the domain name. Many of them have been used to fill blog comment and address books with "SEO spam" (Search Engine Optimization spam), such as the domain:

NicoleHDUncut dot com which has over 19,000 websites pointing back to it, mostly in comment spam.

Pornntube dot com
Sexntube dot com
Tubepornporn dot com
Just-sex-2008 dot com
Hot-girl2008 dot com
FtvHeavenFemme dot net
GoGetFreePorn dot com

clsoft dot net <== encryption software, makers of "cl secrets keeper" and "cl private disk"




208.72.175.* has 12 domain names:

dreamsservices dot com
FianceeOnline dot com
Rudreams dot com
Ukrainefiancee dot com
etc.

None of these sites are currently resolving




Is this the end of McColo? Probably not. Like the Intercage fiasco, we will probably see loud and public outcries of discrimination followed by mournful apologies and promises to do better, each accompanied with a short-lived resurrection, which will terminate again as soon as the new providers understand what sort of filth they are accomodating, and how the Neighbors (that's you and I, folks) feel about having this trash on OUR Internet.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Indictments reveal $77 Million in Illegal Pill Sales
    Congratulations to the Daytona Beach FBI, US Attorney Robert O'Neill, and their colleagues at IRS and FDA. The Daytona Beach News report...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • Morocco based "Team Evil" reroutes prominent Israeli websites
    After more than 10,000 websites being defaced in protest of Israeli actions in Gaza, Morrocco-based defacement team "Team Evil" ha...
  • Minipost: Google v. Pacific WebWorks
    I blogged recently about the "Google Jobs" scammers who were abusing Twitter, Blogspot, Google Reader, and spaces.live.com by crea...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • WIRED: November Jargon Watch & Forensics?
    One of my NASA buddies (hi, Lisa!) dropped by last week for coffee and to catch up on the world of information management. When I introduce...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ►  2013 (17)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (109)
    • ►  December (7)
    • ▼  November (17)
      • Mumbai Bombings: Coordinated Bombings in India are...
      • Bank of America Demo Account - DO NOT CLICK
      • AsProx: The Phisher King?
      • Igor Klopov sentenced
      • Facebook Users Beware
      • Enlisting YOUR BANK to steal your identity
      • Post McColo Spam - What do we see?
      • Unprecedented Drop in Spam
      • Internet Landfill: McColo Corporation
      • Microsoft Reveals Malware and Spam Trends
      • Election Malware and Obama Pill Ads?
      • Election Malware Targets Sore Losers - McCain Vide...
      • Yesterday's Obama Spammer Now Imitates Colonial Bank
      • Computer Virus masquerades as Obama Acceptance Spe...
      • ICE: Operation Predator - Solving Intertwined Chil...
      • More Merger Malware Wachovia Wells Fargo
      • MS08-067: New RPC Worm from China
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile