Virus Removal - Virus writing and organized crime - follow up

  • http://intensedive.com/install/setup.php?m=d310b08f1d6d&i=1&id=000069000
  • http://intensedive.com/install/setup.php?m=d310b08f1d6d
  • http://intensedive.com/updates/cleaner.dll?m=d310b08f1d6d

The IP address behind these domains is 94.102.63.99. From www.robtex.com we can see the following graph

AS29073 belongs to Ecatel Network which is a well known crimeware friendly ISP.

http://hphosts.blogspot.com/2009/11/crimeware-friendly-isps-ecatel-as29073.html

Ecatel is infamous for the massive hosting of malware and spambots, the most widely used IPs are:

  • 94.102.60.151
  • 94.102.60.152
  • 94.102.60.153
  • 94.102.60.182
  • 94.102.60.43
  • 94.102.60.77

Detailed information on Ecatel activities can be seen here: http://www.sudosecure.net/archives/333

Often Ecatel was involved into fakeAV campaigns, and ZeroAccess drives to fake software download. From sudosecure.net we see a relation with the well-know cybercrime ring, RBN ( Russian Business Network ).

----- end snippet -----

blog comments powered by Disqus

Blog Search

Subscribe in a reader

Enter your email address:

Delivered by FeedBurner

Blog Posts