<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Researchers Map Multi-Network Cybercrime Infrastructure</title>
	<atom:link href="http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: nony</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-6567</link>
		<dc:creator>nony</dc:creator>
		<pubDate>Sun, 06 Jun 2010 14:40:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-6567</guid>
		<description>No one is talking about blocking entire countries -- instead, why can&#039;t Russia (for example) do internally what many western countries already do, and simply block or prosecute known criminals?   Send some Russian law enforcement down to VISHCLUB headquarters, serve them with a warrant, unplug their servers and throw them in jail.  I&#039;m sure it&#039;s somehow more complicated than that, but WHY?  Corruption?</description>
		<content:encoded><![CDATA[<p>No one is talking about blocking entire countries &#8212; instead, why can&#8217;t Russia (for example) do internally what many western countries already do, and simply block or prosecute known criminals?   Send some Russian law enforcement down to VISHCLUB headquarters, serve them with a warrant, unplug their servers and throw them in jail.  I&#8217;m sure it&#8217;s somehow more complicated than that, but WHY?  Corruption?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6567" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6567', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6567-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6567" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6567', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6567-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: AlphaCentauri</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4313</link>
		<dc:creator>AlphaCentauri</dc:creator>
		<pubDate>Sun, 21 Mar 2010 02:45:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4313</guid>
		<description>@Tyler: That&#039;s actually a good idea. The stuff posted here is great, but Brian is preaching to the choir.  Readers Digest reaches an entirely different demographic. 

They&#039;ve got a slide show on their website right now about keeping yourself safe online, but it&#039;s very superficial generalities. It won&#039;t change anyone&#039;s behavior, because people already know those things and think they only apply to other people. Brian can tell stories about real people who have been harmed. That&#039;s more engaging reading, and it teaches more effectively. 

You can shut down all the C&amp;C servers you want, but if people keep clicking on ecards and fake password updates, there will always more botnets to take their places. If everyone who subscribes to RD knew how to look up the registration whois for a domain name to find out whether &quot;paypal-registration.com&quot; belongs to Paypal -- or whether it only came into being two days ago using a privacy protected registration -- it would drastically cut down the number of people falling victim to phishing.</description>
		<content:encoded><![CDATA[<p>@Tyler: That&#8217;s actually a good idea. The stuff posted here is great, but Brian is preaching to the choir.  Readers Digest reaches an entirely different demographic. </p>
<p>They&#8217;ve got a slide show on their website right now about keeping yourself safe online, but it&#8217;s very superficial generalities. It won&#8217;t change anyone&#8217;s behavior, because people already know those things and think they only apply to other people. Brian can tell stories about real people who have been harmed. That&#8217;s more engaging reading, and it teaches more effectively. </p>
<p>You can shut down all the C&amp;C servers you want, but if people keep clicking on ecards and fake password updates, there will always more botnets to take their places. If everyone who subscribes to RD knew how to look up the registration whois for a domain name to find out whether &#8220;paypal-registration.com&#8221; belongs to Paypal &#8212; or whether it only came into being two days ago using a privacy protected registration &#8212; it would drastically cut down the number of people falling victim to phishing.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4313" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4313', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4313-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4313" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4313', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4313-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: AlphaCentauri</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4309</link>
		<dc:creator>AlphaCentauri</dc:creator>
		<pubDate>Sun, 21 Mar 2010 02:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4309</guid>
		<description>@Nick: Some U.S. ISPs already block all email from large areas of the world, like Asia and Eastern Europe. But suppose you are an internet provider in Asia, and no matter how proactive you are in keeping your network free of sources of spam, your business customers still can&#039;t send emails to their US clients due to that kind of blocking. What is your motivation to bother keeping your network clean? Now suppose *your* customers&#039; emails are getting through, but not those from your competitor&#039;s network full of open proxies. Business customers in your country will move their accounts to your network to improve their opportunities for international transactions. The increase in customers is a significant incentive for you to continue your responsible policies.

Some of the members at inboxrevenge.com have been making an effort to report any spamvertised site on the various free hosting providers. Russian hosting providers, like Pochta.ru, actually tend to be the fastest to respond to reports (despite the additional expense it must cost them to have English speaking support staff handling the complaints). Microsoft&#039;s Spaces.Live.com, in contrast, allows the spamvertised blogs to stay alive for weeks or months, even when they are selling pirated copies of Microsoft products! 

The point is that there are enlightened, clueless and criminal internet providers in every country. A ham-fisted solution like blocking an entire country doesn&#039;t hurt the criminals much -- they&#039;ve got open proxies that can relay their spam through whatever route is necessary to get to the trojan-infected computers in the U.S. they&#039;re going to use to mail it. But it can be devastating for honest internet users.</description>
		<content:encoded><![CDATA[<p>@Nick: Some U.S. ISPs already block all email from large areas of the world, like Asia and Eastern Europe. But suppose you are an internet provider in Asia, and no matter how proactive you are in keeping your network free of sources of spam, your business customers still can&#8217;t send emails to their US clients due to that kind of blocking. What is your motivation to bother keeping your network clean? Now suppose *your* customers&#8217; emails are getting through, but not those from your competitor&#8217;s network full of open proxies. Business customers in your country will move their accounts to your network to improve their opportunities for international transactions. The increase in customers is a significant incentive for you to continue your responsible policies.</p>
<p>Some of the members at inboxrevenge.com have been making an effort to report any spamvertised site on the various free hosting providers. Russian hosting providers, like Pochta.ru, actually tend to be the fastest to respond to reports (despite the additional expense it must cost them to have English speaking support staff handling the complaints). Microsoft&#8217;s Spaces.Live.com, in contrast, allows the spamvertised blogs to stay alive for weeks or months, even when they are selling pirated copies of Microsoft products! </p>
<p>The point is that there are enlightened, clueless and criminal internet providers in every country. A ham-fisted solution like blocking an entire country doesn&#8217;t hurt the criminals much &#8212; they&#8217;ve got open proxies that can relay their spam through whatever route is necessary to get to the trojan-infected computers in the U.S. they&#8217;re going to use to mail it. But it can be devastating for honest internet users.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4309" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4309', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4309-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4309" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4309', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4309-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4235</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Fri, 19 Mar 2010 05:55:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4235</guid>
		<description>This is what we fear will happen if I understand what many fellow members at my favorite site feel, is that the least interference used to fight the problem the better.

We don&#039;t want a locked down internet bereft of free exchange of ideas. It is this free exchange that gives the free world our leg up. Especially in the economy. I don&#039;t think draconian measures are necessary. Even some mild self policing could help - financial incentives for end users would be very effective, I&#039;d think.

It isn&#039;t like a lot of ISPs have not been pro active, AT&amp;T offers free anti-virus for many of its customers. The only problem is some ISPs make bad selections for the AV solutions they push. However they are better than nothing.</description>
		<content:encoded><![CDATA[<p>This is what we fear will happen if I understand what many fellow members at my favorite site feel, is that the least interference used to fight the problem the better.</p>
<p>We don&#8217;t want a locked down internet bereft of free exchange of ideas. It is this free exchange that gives the free world our leg up. Especially in the economy. I don&#8217;t think draconian measures are necessary. Even some mild self policing could help &#8211; financial incentives for end users would be very effective, I&#8217;d think.</p>
<p>It isn&#8217;t like a lot of ISPs have not been pro active, AT&amp;T offers free anti-virus for many of its customers. The only problem is some ISPs make bad selections for the AV solutions they push. However they are better than nothing.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4235" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4235', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4235-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4235" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4235', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4235-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4234</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Fri, 19 Mar 2010 05:36:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4234</guid>
		<description>MGD,  I notice Hurrican Electric is listed at one of the articles you linked, as attempting to take remedial action in this war. Are they another innocent bystander in this mess? If they are; it would make sense, as they are listed as an ISP on one of the disreputable sites that evidence shows was involved in my case of internet ID theft.

The crooks may be using reputable ISP names in their web pages as a slap in the face of the very folks trying to bring them down. That actually makes sense in this  way of thinking, as a motivation for the defacement and obfuscation of their where-abouts; and putting in a plug against their enemies.</description>
		<content:encoded><![CDATA[<p>MGD,  I notice Hurrican Electric is listed at one of the articles you linked, as attempting to take remedial action in this war. Are they another innocent bystander in this mess? If they are; it would make sense, as they are listed as an ISP on one of the disreputable sites that evidence shows was involved in my case of internet ID theft.</p>
<p>The crooks may be using reputable ISP names in their web pages as a slap in the face of the very folks trying to bring them down. That actually makes sense in this  way of thinking, as a motivation for the defacement and obfuscation of their where-abouts; and putting in a plug against their enemies.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4234" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4234', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4234-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4234" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4234', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4234-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4233</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Fri, 19 Mar 2010 05:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4233</guid>
		<description>Thank you MGD - very interesting and enlightening!</description>
		<content:encoded><![CDATA[<p>Thank you MGD &#8211; very interesting and enlightening!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4233" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4233', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4233-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4233" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4233', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4233-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: MGD</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4231</link>
		<dc:creator>MGD</dc:creator>
		<pubDate>Fri, 19 Mar 2010 04:20:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4231</guid>
		<description>@t.w.

Quote=  &lt;i&gt;&quot;.... The physical location, particularly the Kazakhstan location, has been disputed as also ‘fake detail’ by some security research. ..&quot;

&quot;How reliable is IP address geolocation data? Is all geolocation data still largely self-reported?&quot;&lt;/i&gt;

End Quote

Much of it comes from &quot;Regional Internet Registry&quot; records combined with other sources, including guessing. It is reliable at the country level,  and usually within regions. However if the operator is rogue and intent on masquerading, then it can be defeated. While the Troyak IP range may be assigned to Kazakhstan, the operator and C&amp;C is based in Kiev, Ukraine. Remember that many of these &quot;providers&quot; are the actual cyber criminals themselves, or at best,  are wholly ran as (CCAS) &quot;Cyber Crime As a Service&quot;

With respect to the cyber crime cesspool Troyak, and as I stated last week in this DSLR thread: http://www.dslreports.com/forum/r23933249-Zeus-botnets-suffer-mighty-blow-after-ISP-taken-offline When &quot;Roman Starchenko&quot; registered the matching troyak.org domain on 12/08/2009, he registered it to an address and phone number of an apartment in Kiev, Ukraine.:

Domain: TROYAK.ORG
Sponsoring Registrar:Directi Internet Solutions Pvt. Ltd. 
d/b/a PublicDomainRegistry.com (R27-LROR)

Registrant ID:DI_10792377
Registrant Name:Roman Starchenko
Registrant Organization:Troyak
Registrant Street1:str. Miloslavskaya 17a, 75 ap.
Registrant Street2:
Registrant Street3:
Registrant City:Kiev
Registrant State/Province:Kiev
Registrant Postal Code:01001
Registrant Country:UA
Registrant Phone:+380.630231165
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:Staruy.rom@inbox.ru
Name Server: VETAXA.MANAGEDNS1.ESTBOXES.COM  

Within a few hours of its birth the domain registration was changed to match the Troyak IP registry in Kazakhstan. Clearly an afterthought.

Also, take note that the one of the &quot;Red Flagged&quot; trojan criminal networks in Brian&#039;s diagram:  AS 50369 VISHCLUB is also registered to the same address  in Kazakstan, and coincidentally  the listed contact is using an @troyak.org email address:

Incidentally, up until mid February troyak.org was hosted on IP 195.93.184.1 which also hosted the  nameserver ns.troyak.org and it served vishclub.net as well

That IP was also based in Kiev, Ukraine, also:

inetnum:        195.93.184.0 - 195.93.185.255
netname:        ALYANSHIMIYA-NET
descr:          Alyanshimiya LLC
country:        UA
org:            ORG-AL84-RIPE
admin-c:        DS7111-RIPE
tech-c:         IO303-RIPE
status:         ASSIGNED PI
mnt-by:         ALYANSHIMIYA-MNT
mnt-by:         RIPE-NCC-HM-PI-MNT
mnt-lower:      RIPE-NCC-HM-PI-MNT
mnt-routes:     ALYANSHIMIYA-MNT
mnt-domains:    ALYANSHIMIYA-MNT
source:         RIPE # Filtered

organisation:   ORG-AL84-RIPE
org-name:       Alyanshimiya LLC
org-type:       OTHER
descr:          Alyanshimiya LLC
address:        15 Pecherskiy downstreet
address:        Kiev, Ukraine
phone:          +380 44 2511308
e-mail:         info@udobreniya.com
admin-c:        DS7111-RIPE
tech-c:         IO303-RIPE
mnt-ref:        ALYANSHIMIYA-MNT
mnt-by:         ALYANSHIMIYA-MNT
source:         RIPE # Filtered  

IMO,  from a security perspective, it is irresponsible not to block data at border routers, to or from these networks, or their peers, many do.

MGD</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>@t.w.</p>
<p>Quote=  <i>&#8220;&#8230;. The physical location, particularly the Kazakhstan location, has been disputed as also ‘fake detail’ by some security research. ..&#8221;</p>
<p>&#8220;How reliable is IP address geolocation data? Is all geolocation data still largely self-reported?&#8221;</i></p>
<p>End Quote</p>
<p>Much of it comes from &#8220;Regional Internet Registry&#8221; records combined with other sources, including guessing. It is reliable at the country level,  and usually within regions. However if the operator is rogue and intent on masquerading, then it can be defeated. While the Troyak IP range may be assigned to Kazakhstan, the operator and C&amp;C is based in Kiev, Ukraine. Remember that many of these &#8220;providers&#8221; are the actual cyber criminals themselves, or at best,  are wholly ran as (CCAS) &#8220;Cyber Crime As a Service&#8221;</p>
<p>With respect to the cyber crime cesspool Troyak, and as I stated last week in this DSLR thread: <a href="http://www.dslreports.com/forum/r23933249-Zeus-botnets-suffer-mighty-blow-after-ISP-taken-offline" rel="nofollow">http://www.dslreports.com/forum/r23933249-Zeus-botnets-suffer-mighty-blow-after-ISP-taken-offline</a> When &#8220;Roman Starchenko&#8221; registered the matching troyak.org domain on 12/08/2009, he registered it to an address and phone number of an apartment in Kiev, Ukraine.:</p>
<p>Domain: TROYAK.ORG<br />
Sponsoring Registrar:Directi Internet Solutions Pvt. Ltd.<br />
d/b/a PublicDomainRegistry.com (R27-LROR)</p>
<p>Registrant ID:DI_10792377<br />
Registrant Name:Roman Starchenko<br />
Registrant Organization:Troyak<br />
Registrant Street1:str. Miloslavskaya 17a, 75 ap.<br />
Registrant Street2:<br />
Registrant Street3:<br />
Registrant City:Kiev<br />
Registrant State/Province:Kiev<br />
Registrant Postal Code:01001<br />
Registrant Country:UA<br />
Registrant Phone:+380.630231165<br />
Registrant Phone Ext.:<br />
Registrant FAX:<br />
Registrant FAX Ext.:<br />
Registrant Email:Staruy.rom@inbox.ru<br />
Name Server: VETAXA.MANAGEDNS1.ESTBOXES.COM  </p>
<p>Within a few hours of its birth the domain registration was changed to match the Troyak IP registry in Kazakhstan. Clearly an afterthought.</p>
<p>Also, take note that the one of the &#8220;Red Flagged&#8221; trojan criminal networks in Brian&#8217;s diagram:  AS 50369 VISHCLUB is also registered to the same address  in Kazakstan, and coincidentally  the listed contact is using an @troyak.org email address:</p>
<p>Incidentally, up until mid February troyak.org was hosted on IP 195.93.184.1 which also hosted the  nameserver ns.troyak.org and it served vishclub.net as well</p>
<p>That IP was also based in Kiev, Ukraine, also:</p>
<p>inetnum:        195.93.184.0 &#8211; 195.93.185.255<br />
netname:        ALYANSHIMIYA-NET<br />
descr:          Alyanshimiya LLC<br />
country:        UA<br />
org:            ORG-AL84-RIPE<br />
admin-c:        DS7111-RIPE<br />
tech-c:         IO303-RIPE<br />
status:         ASSIGNED PI<br />
mnt-by:         ALYANSHIMIYA-MNT<br />
mnt-by:         RIPE-NCC-HM-PI-MNT<br />
mnt-lower:      RIPE-NCC-HM-PI-MNT<br />
mnt-routes:     ALYANSHIMIYA-MNT<br />
mnt-domains:    ALYANSHIMIYA-MNT<br />
source:         RIPE # Filtered</p>
<p>organisation:   ORG-AL84-RIPE<br />
org-name:       Alyanshimiya LLC<br />
org-type:       OTHER<br />
descr:          Alyanshimiya LLC<br />
address:        15 Pecherskiy downstreet<br />
address:        Kiev, Ukraine<br />
phone:          +380 44 2511308<br />
e-mail:         <a href="mailto:info@udobreniya.com">info@udobreniya.com</a><br />
admin-c:        DS7111-RIPE<br />
tech-c:         IO303-RIPE<br />
mnt-ref:        ALYANSHIMIYA-MNT<br />
mnt-by:         ALYANSHIMIYA-MNT<br />
source:         RIPE # Filtered  </p>
<p>IMO,  from a security perspective, it is irresponsible not to block data at border routers, to or from these networks, or their peers, many do.</p>
<p>MGD</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4231" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4231', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4231-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4231" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4231', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4231-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4230</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Thu, 18 Mar 2010 20:22:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4230</guid>
		<description>Let&#039;s hope not. You are talking about blocking entire countries the way Iran and China do. You are talking about creating a planet of division - a planet with no means of full communication.

This is the length you will go to. Instead of getting your operating system act together.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>Let&#8217;s hope not. You are talking about blocking entire countries the way Iran and China do. You are talking about creating a planet of division &#8211; a planet with no means of full communication.</p>
<p>This is the length you will go to. Instead of getting your operating system act together.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4230" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4230', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4230-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4230" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4230', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4230-down" style="font-size:14px; color:#990033;">4</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: wahnula</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4228</link>
		<dc:creator>wahnula</dc:creator>
		<pubDate>Thu, 18 Mar 2010 19:02:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4228</guid>
		<description>It looks like governments may not be necessary...Troyak has just been de-peered again:

http://www.net-security.org/secworld.php?id=9039

This is the kind of self-policing that the Internet needs to survive without government intervention.  Once the bad guys are exposed (after losses of millions by the public) it seems that nobody wants to be associated with them.  Let&#039;s hope this example stands the test of time.</description>
		<content:encoded><![CDATA[<p>It looks like governments may not be necessary&#8230;Troyak has just been de-peered again:</p>
<p><a href="http://www.net-security.org/secworld.php?id=9039" rel="nofollow">http://www.net-security.org/secworld.php?id=9039</a></p>
<p>This is the kind of self-policing that the Internet needs to survive without government intervention.  Once the bad guys are exposed (after losses of millions by the public) it seems that nobody wants to be associated with them.  Let&#8217;s hope this example stands the test of time.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4228" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4228', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4228-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4228" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4228', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4228-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/comment-page-1/#comment-4225</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Thu, 18 Mar 2010 14:27:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1798#comment-4225</guid>
		<description>Brian,

As always, thanks for your incredible threat analysis and reporting. An earlier fan mentioned vanity fair, which made me think about another avenue to share your insights; Reader&#039;s Digest. They have articles exposing scams from time to time and have regular articles by health professionals, etc. I think timely articles from you in that media would also be well received and reach a greater audience.

Keep up the good work.</description>
		<content:encoded><![CDATA[<p>Brian,</p>
<p>As always, thanks for your incredible threat analysis and reporting. An earlier fan mentioned vanity fair, which made me think about another avenue to share your insights; Reader&#8217;s Digest. They have articles exposing scams from time to time and have regular articles by health professionals, etc. I think timely articles from you in that media would also be well received and reach a greater audience.</p>
<p>Keep up the good work.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4225" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4225', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-4225-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4225" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4225', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-4225-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 7/23 queries in 0.013 seconds using memcached
Object Caching 957/975 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-12 06:46:14 -->
