06.02.2015 Views

Russian Business Network study - bizeul.org

Russian Business Network study - bizeul.org

Russian Business Network study - bizeul.org

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Version 1.0.1<br />

New York, NY 10018,-,- -<br />

RBN <strong>study</strong> – before and after<br />

David Bizeul<br />

Domain servers in listed order:<br />

ns1.infobox.<strong>org</strong> ns2.infobox.<strong>org</strong><br />

All affiliates domain names have been checked using whois history and it’s interesting to observe that rbnnetwork.com,<br />

nevacon.net, akimon.com, sbttel.com, 4user.net, 4stat.<strong>org</strong> and eexhost.com are now all using Absolutee services for<br />

anonymizing whois data.<br />

Of course, absolute.com seems to be used for nothing good as you can see here [ 41 ]. There are many user reporting<br />

malware or financial fraud relating to domains registered with Absolutee services.<br />

6. Information correlation and assumptions<br />

At this step of the <strong>study</strong>, general assumptions can be exposed with collected and analyzed evidences.<br />

• RBN team possess and use the following domains: rbnnetwork.com, nevacon.net, akimon.com and<br />

sbttel.com<br />

• Most of RBN core affiliates have progressively blurred their public information so that it can’t be analyzed<br />

easily. They use anonymizer services to do that.<br />

• Most of RBN core affiliates have decided to redirect their websites to localhost address in order to prevent<br />

security companies to investigate on their activities.<br />

• RBN uses Datapoint/Infobox as a hosting and name service provider. Datapoint and Infobox may be the<br />

same company.<br />

• Some people can be identified as being strongly involved into RBN activities.<br />

41<br />

http://www.google.com/search&q=absolutee.com<br />

35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!