06.02.2015 Views

Russian Business Network study - bizeul.org

Russian Business Network study - bizeul.org

Russian Business Network study - bizeul.org

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Version 1.0.1<br />

RBN <strong>study</strong> – before and after<br />

David Bizeul<br />

Nevacon<br />

Nevacon is an RBN affiliate with a huge role in malware control (update, C&C).<br />

Nevacon is on a different netblock than TCS. Nevacon owns 194.146.204.0/22 IP address block.<br />

Actually, Nevacon is directly hosted on RBN network.<br />

Silvernet<br />

Silvernet seem to be the semi-legitimate ISP used to connect SBT and RBN to a main internet access (IXP).<br />

Connections between Silvernet and SBT are discreet because if this weak link would be shutdown, SBT might be blind<br />

(not for too long…).<br />

Silvernet owns many IP address spaces.<br />

Silvernet is a member of SPB-IX and is connected to a lot of other <strong>Russian</strong> ISP<br />

Linkey<br />

Linkey is a legitimate ISP which might have the same role as Silvernet: give a worldwide connectivity to SBT.<br />

Linkey spread a network zone: as-linkeycus in which RBN affiliates are all indicated. It may be possible that this zone is<br />

given to Linkey via Silvernet as both of them exchange together.<br />

Linkey connects to SPB-IX.<br />

Eltel2<br />

Eltel2 is a very interesting network because it is managed by Eltel which is supposed to be a legitimate <strong>Russian</strong> telecom<br />

company but Eltel2 is also an active partner with RBN through as-joy. Actually, the description of Eltel2 is “JOY<br />

<strong>Network</strong>”<br />

Eltel2 has already broadcasted IP address space 85.249.20.0/22. What is interesting is that this address space belongs<br />

to LugLink.<br />

Luglink<br />

Luglink is a legitimate ISP but it seems to be involved into RBN activities through Eltel2.<br />

Luglink owns 85.249.16.0/21 (and so Eltel2) and this address space is also managed by Eltel.<br />

Eltel<br />

Eltel is a telecom company which manages Luglink, Eltel2 and many others.<br />

Eltel owns several IP address space such as:<br />

81.222.192.0/18 (16384) ELTEL net<br />

85.249.224.0/19 (8192) ELTEL MAN Saint Petersburg<br />

89.112.0.0/19 (8192) ELTEL net<br />

81.9.0.0/20 (4096) ELTEL net<br />

81.9.32.0/20 (4096) ELTEL net<br />

81.9.96.0/20 (4096) ELTEL net<br />

81.222.128.0/20 (4096) ELTEL net<br />

217.170.64.0/20 (4096) ELTEL net<br />

217.170.80.0/20 (4096) ELTEL net<br />

85.249.8.0/21 (2048) Telix<br />

22

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!