Infamous porn and phishing ISP rolls Bank of India

By Liam Tung, ZDNet Australia
Tuesday, September 04, 2007 09:12 AM

Security firm SunBelt, which discovered the Bank of India's hacked Web site was serving dangerous malware, says the infamous Russian Business Network (RBN)--an ISP linked to child pornography and phishing--is behind the attack.

The service provider in question has developed a notorious reputation, with Verisign classifying it as "the baddest of the bad" in the ISP world in June 2006.

According to Verisign threat intelligence analyst Kimberly Zenz, RBN is different to other service providers because "unlike many ISPs that host predominately legitimate items, RBN is entirely illegal."

"A scan of RBN and affiliated ISPs' Net space conducted by VeriSign iDefense analysts failed to locate any legitimate activity. Instead, [our] research identified phishing, malicious code, botnet command-and-control (C&C), denial of service (DoS) attacks and child pornography on every single server owned and operated by RBN," Zenz wrote in a recent report.

Zenz added that the RBN almost exclusively attacks non-Russian financial institutions and its leaders' family ties with a "a powerful St Petersburg politician" effectively offer it immunity from prosecution.

In an interview with ZDNet Australia, Patrik Runald, senior security specialist at F-Secure, said: "No one knows who the RBN is. They are a secret group based out of St Petersburg that appears to have political connections. The company doesn't legitimately exist. It's not registered and provides hosting for everything that's bad."

"Their network infrastructure is behind a lot of the bad stuff we're seeing and it has connections to the MPack group [a well-known group of cybercriminals which used Mpack software to steal confidential data]," said Runald.

Runald said that in the case of the Bank of India's hacked Web site, RBN used an IFrame to launch another window which then pushed victims to a Web page containing malicious code.

"That page contained links to three other pages on other servers," said Runald. "At the time we started looking into it two out of three URLs had been taken down. The one remaining was trying to use an exploit from 2006 to affect systems with a Trojan downloader. Once infected, that downloader would go out and download another piece of malware, including other downloaders," said Runald.

The Trojans used in this case were designed to steal passwords from PCs and upload Trojan proxies in aide of developing a botnet.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Hands-on programming: Extract plain text from documents with Syncfusion's components

Web Development

Justin James recently tried Syncfusion's Essential DocIO and Essential PDF to help him extract text from documents he downloaded from the Internet. Here's the code he wrote to get the plain text.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web