Skip the navigation
)
Opinion

Exposing Bad Actor Sites That Support Cybercrime

By Alex Lanstein
October 8, 2009 12:04 PM ET

CSO - Today, cyber criminals who operate the most sophisticated stealth malware and botnets rely on a remarkably small number of network and hosting service providers, known to the industry as bad actors. These bad actors supply the infrastructure needed to host drive-by download exploits, command-and-control servers, stolen data drop sites, and other more functional network needs such as DNS and reliable uplinks. Having a stable, controllable network allows malware operators to remove one difficult piece of the puzzle and Internet Service Providers (ISPs) are lining up to take their money. Even given that these networks are very well known, it has proven difficult -- in some cases impossible -- to stop cyber criminals and these bad actors due to legal, economic and technical hurdles.

The cyber crime spree that is underway is supported by bad actors that turn a blind eye to the questionable and criminal activities transpiring over their networks. Research from FireEye and others have exposed notorious examples like McColo, ZlKon, HostFresh and many more. The Federal Trade Commission scored a rare victory when it took down 3fn based on findings that 3fn, "recruits, knowingly hosts, and actively participates in the distribution of spam, child pornography, and other harmful electronic content."

However, these bad actors are difficult to bring to justice due to the international nature of their crimes, the slow response time with which they react to shutdowns and the general lack of funding and focus for cyber law enforcement.

Hosting providers in the Eastern Bloc openly market spam e-mail services, ICQ-based spam and spam hosting among their service offerings since they are well outside the jurisdiction of would-be law enforcement. Meanwhile, their U.S.-based equivalents are much more covert, leveraging hosting fronts, multi-national partnerships, IP space sharing agreements and others to hide the real entity behind a business.

Cybersecurity experts say a handful of ISPs and domain name registrars work closely with cyber criminals to set up malicious websites that sell fake software, host and distribute malware, facilitate botnet communications and other important services to perpetrate these online criminal endeavors. Cyber criminals are making billions by holding companies for ransom using DDoS attacks, selling off confidential information, sending phishing spam, as well as selling storage services for pirated movies, music, and illegal images. The monetization possibilities of malware and botnets are so numerous that the creativity of the cyber criminal is the only limit at this point. Underlying all these schemes is a need for a stable cyber infrastructure to provide the criminals with a platform for their various online businesses.

For example, an Estonia company with a very small /24 allocation, Starline Web Services (that is in turn hosted by Compic) was infamous for allowing malicious content on their network. Earlier in 2009, researchers found that 92.62.100.14 was hosting malicious files and drop zones for ZBot, a notorious banking and backdoor Trojan. Also, on 92.62.100.64, they were hosting redirectors used within an iFrame to send victims to exploit sites, such as directlink2.cn (itself hosted on 92.62.100.66) that used a malicious PDF to attack the Adobe Reader plug-in. Notifying upstream providers like Compic about malware they and their customers were hosting usually gave mixed results at best. Complaints were typically addressed only when backed up by some local authorities, say the Estonian Criminal Police. Unfortunately, it is not possible to get law enforcement involved on every abuse complaint and typically only when the problem has already become egregious. In November 2008, the Estonia CERT team directly stepped in to take down a Srizbi C&C hosted on 92.62.100.97 while it was being hijacked by the FireEye research team. It remained down for about four months and popped back up on the exact same hardware and IP in February. This level of arrogance shows the lack of respect that these actors have for their local CERTs.

Originally published on www.csoonline.com. Click here to read the original story.
This story is reprinted from CSO Online.com, an online resource for information executives. Story Copyright CXO Media Inc., 2006. All rights reserved.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Network Security White Papers
Obtaining Fortune 500 Security without Busting your Budget
Network Security and Compliance on a Budget Made Simple
Controlling the Cost of File Transfers
This solution brief explains why something as seemingly simple and straightforward as a file transfer task turns into such a costly operation. It...
Practice Management: Double Billing Rate and Improve Patient Services
Would you like to double your billing rate and achieve faster payment for services?

Download this customer success story to see how One Health...
Mission Critical Data Explosion and Customer Case Study
Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?

Download this customer success story to see how...
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
All Network Security White Papers
Network Security Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
Redefine Expectations in the Data Center
Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
All Network Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs