






|
| Ref: SBL75831 |
| 213.182.197.0/24 is listed on the Spamhaus Block List (SBL) |
|
07-Mar-2010 22:13 GMT | SR14
|
| Phish and malware hosting |
151.im | 213.182.197.235 222.im | 213.182.197.235 252.im | 213.182.197.235 aepi.ru | 213.182.197.235 evamedstore.com | 213.182.197.235 gofast.in | 213.182.197.235 hunro.im | 213.182.197.235 junglemix.in | 213.182.197.235 mail.eirovins.lv | 213.182.197.235 mygener.im | 213.182.197.235 sabl.ru | 213.182.197.235 sprost.im | 213.182.197.235 traffic-exchange.ru | 213.182.197.235
[whois.ripe.net]
inetnum: 213.182.197.0 - 213.182.197.15 netname: Real_Host_NET3 descr: Real Host country: LV admin-c: DB8712-RIPE tech-c: DB8712-RIPE rev-srv: ns.junik.lv rev-srv: ns2.junik.lv status: ASSIGNED PA mnt-by: AS8206-MNT source: RIPE # Filtered
person: Danila Berencev address: Kazakhstan, Almaty , Abay street 2a abuse-mailbox: abuseemaildhcp@gmail.com phone: + 87771697576 nic-hdl: DB8712-RIPE source: RIPE # Filtered
% Information related to '213.182.192.0/19AS8206'
route: 213.182.192.0/19 descr: JUNIK Riga Network part 2 origin: AS8206 mnt-by: AS8206-MNT source: RIPE # Filtered
_________________
Some wonder if this home of the Zeus botnet could be Russian Business Network (RBN)?
_________________________________________
From: http://blog.dynamoo.com/2009/07/real-host-ltd-is-real-sewer.html
Thursday, 23 July 2009 "Real Host Ltd" is a real sewer
"Real Host Ltd" occupies 256 IP addresses in the 213.182.197.* range, hosted in Latvia in an address space apparently leased from Junik Ltd.
The netblock registration details claim to belong to an address in Kazakhstan:
person: Alex Spiridonov address: Kazakhstan, Almaty , Abay street 2a abuse-mailbox: abusemailhost@gmail.com phone: + 87771697576 nic-hdl: SA5926-RIPE source: RIPE # Filtered
This block is of interest because out of hundreds of web sites hosted, there appear to be none at all which are legitimate. And out of all of these, Hit-senders.cn is one of the most interesting because it is currently being used for a zero day Flash/PDF exploit. Many domains are registered to Michell.Gregory2009@yahoo.com who has featured on this blog many times before.
Some other interesting domains are Cashspyware.com, Botnet.su and Iframepartners.com which are pretty much openly operating as black hat sites.
All of these sites are either fraudulent, dangerous to visit or both - so if you receive an email or link pointing to them, leave well alone!
213.182.197.10 Vkontalcte.ru, Private Person, admin@0neway.ru
213.182.197.11 Index683.com, Registration suspended Presentsdelivery.com, Private Person, abuseemaildhcp@gmail.com
213.182.197.12 Barmatuxa.info, Brad Higginbotham, EmersonDuffyZP@gmail.com Bombim.cn, KuserElizabeth, eakuser@yahoo.com Decine.cn, realmaria teresa, popeskusin@yahoo.com
213.182.197.13 0neway.ru, Private Person, onewayru@ya.ru 2todays.com, PrivacyProtect.org 2trades.com, alan pakerson, apakerson@googlemail.com Adulttopvids.info, Lorraine Hoguseir / LueMettterTeam, lorrainefactr@gmail.com Caffemax.com, Private Person, abuseemaildhcp@gmail.com Clicksvideo.com, PrivacyProtect.org Cutietubeee.com, Mark Cristy, evilinside99@gmail.com Dasper.ru, Sergey V Levitskiy, levitcky@gmail.com Dataartsoft.com, John A Backham , igusow@gmail.com Dslcaffe.com, Private Person, abuseemaildhcp@gmail.com Freegirla.com, PrivacyProtect.org Fucksexadult.com, PrivacyProtect.org Gauleyriverraftinginfo.com, Gordon Freeman, evilinside20@gmail.com Googep.com, PrivacyProtect.org Homemadez.com, PrivacyProtect.org Informatoion.com, Tamara Polishuk, kenylotus@yahoo.com Insky.biz, PrivacyProtect.org Koka-tube.info, Budulay Romale, budulay_romale@inbox.ru Linktovideo.com, PrivacyProtect.org Mac-videos.com, PrivacyProtect.org Major-don.com, Carl Lee, levitraviagrashop@rambler.ru Masstrade.us, Yuri, sypiboryrecinih15976@gmail.com Myspnace.com, PrivacyProtect.org Odnoklassniki-and-you.ru, Private Person, newlive09@yandex.ru Online-defence.cn, GuferDerek, asyonurubu@gmail.com Onlylo.com, PrivacyProtect.org Photovideox.com, PrivacyProtect.org Playtstation.com, PrivacyProtect.org Pornsamateur.com, PrivacyProtect.org Serialtxt.com, Breitenbach Margery, breitenbach621@yahoo.com Sexlevitra.com, Carl Lee, levitraviagrashop@rambler.ru Sexmamba.com, Igor Bogdanov, Igor Singleslady.com, Registration suspended Soundrugs.ru, Private Person, workalliance@mail.ru Tdssim.com, Djon Digan, major.leva@yahoo.com Thehat.net, Carl Padilla, thehatnkm@gmail.com Tube84.com, PrivacyProtect.org Tubeee.com, Whois Privacy Protection Service Viagrabe.com, PrivacyProtect.org Video-tube-online.info, Budulay Romale, budulay_romale@inbox.ru Videomoviex.com, PrivacyProtect.org Videos-movie.com, PrivacyProtect.org Vipbabes.com.ua, ?????? ?????????? / Andrei Dehtyareno, may-vit@bk.ru Virgin-x.com, PrivacyProtect.org Wikjipedia.com, Tamara Polishuk, kenylotus@yahoo.com Worldtube.su, Private Person, novikov_ds@bk.ru Xtubex.org, konstantin ololo, scaryscream@gmail.com Yesey.net, Bob AKKAWA, akkawa@gmail.com Yhxoo.com, PrivacyProtect.org Yourko.com, PrivacyProtect.org Youtube19.com, PrivacyProtect.org Youviewx.com, Dedinan Galena, galendediweb78@yahoo.com
213.182.197.14 Cashspyware.com, N/A, faloimitator@list.ru Casinousa.cn, LucasSteven / Cehhost, steven_lucas_2000@yahoo.com Hostnsload.cn, LucasSteven, steven_lucas_2000@yahoo.com Iframepartners.com, Chen Poon, chen.poon1732646@yahoo.com Megavipsite.cn, LucasSteven, steven_lucas_2000@yahoo.com Sitewebsupport.com, Michell, Michell.Gregory2009@yahoo.com
213.182.197.20 Best-casinox.com, MyPrivateRegistration.com Best-prices-pharma.com, Igor Durov, larsontomas@gmail.com Best-prices-pharmacy.net, Oleg Demin, premiumwebart@gmail.com Causas-de-impotencia.com, Private Person, premiumwebart@gmail.com Causas-de-impotencia.net, Private Person, premiumwebart@gmail.com Css-csript.cn, IveevPlansky / SerjCOm, ru@rupoisk.in Dns-lv9720.com, Michell, Michell.Gregory2009@yahoo.com Druggs.net, MyPrivateRegistration.com Druggsonline.com, MyPrivateRegistration.com Drugsbrokerpharma.com, Oleg Demin, premiumwebart@gmail.com Edproductos-en-espana.com, Grigory Panin, gragorybland@gmail.com Erosuka.ru, Private Person, callpartners@gmail.com Farmacia-venta-on-line.com, Private Person, premiumwebart@gmail.com Fly-pro.net, MyPrivateRegistration.com Herbal-impotencecure.com, Oleg Demin, premiumwebart@gmail.com Hzone66.cn, MichellGregory, Michell.Gregory2009@yahoo.com Impotence-natural-cure.com, Oleg Demin, premiumwebart@gmail.com Kamagra-tratamiento-impotencia.com, Mark Nefidov, markglan1@gmail.com Lkll.net, Damir Stolbische, damirmuh@gmail.com Marcusmed.com, Steven Lucas, steven_lucas_2000@yahoo.com Medicamentosgenericosonline.com, Grigory Panin, gragorybland@gmail.com Microsoftprogram.cn, IveevPlansky / SerjCOm, ru@rupoisk.in Onlinemedicamentosgenericos.com, Grigory Panin, gragorybland@gmail.com Pharmacy-drugs-broker.com, Oleg Demin, premiumwebart@gmail.com Pharmacy-drugsbroker.com, Oleg Demin, premiumwebart@gmail.com Pharmacy-pills-rx.com, Igor Durov, larsontomas@gmail.com Pharmacy-pillsrx.com, Igor Durov, larsontomas@gmail.com Rx-onlinestore.com, Igor Durov, larsontomas@gmail.com Rxtrustedtabs.net, Igor Durov, larsontomas@gmail.com Smsgogo.cn, IveevPlansky / SerjCOm, ru@rupoisk.in Superflyaccess.com, MyPrivateRegistration.com Traffcount.cn, LucasSteven / steven_lucas_2000@yahoo.com Treatment-online.com, Aprichev Igor, info@betting-profits.com Trust-ed-tablets.com, Igor Durov, larsontomas@gmail.com Tutuuuu.cn, IveevPlansky / SerjCOm, ru@rupoisk.in Usa-pills-rx.com, Igor Durov, larsontomas@gmail.com Vitofarmatratamientoimpotencia.com, Private Person, markglan1@gmail.com Vkpleer.ru, Private Person, callpartners@gmail.com Vybory2007.ru, Private Person, callpartners@gmail.com Xxzonexx.com. Chen Poon, chen.poon1732646@yahoo.com Yandex2.cn, IveevPlansky / SerjCOm, ru@rupoisk.in
213.182.197.227 Corbsc.com, Chen Poon, chen.poon1732646@yahoo.com Co5v.cn, TiankaiCui, cuitiankai@googlemail.com
213.182.197.228 Chlenopopik.com, Denis Pupkin, pisssun2006@mail.ru
213.182.197.229 3ballslottery.com, Klan Jored, support@hosting-offshore.biz 44mm.ru, Private Person, mik58109117@ya.ru Admins-mail.ru, Private Person, ivttyeivrdyl@yandex.ru Andors.ru, Private Person, 10000002@mail.ru Antighost.cn, null, dasidoruk@mail.ru Avpro-labs.com, PrivacyProtect.org via Erdomain.com Avtoresa.ru, Private Person, 10000002@mail.ru Businessconsulting312.com, Nikolay Viktorovich Stepashin, businessconsulting312.com@hvosting.ua Businesscoorptru.cn, Real Host, abuseemaildhcp@gmail.com Comforttrade.biz, Klan Jored, support@hosting-offshore.biz Dfds-seaways.biz, Klan Jored, support@hosting-offshore.biz [note, domain has been seized by the trademark holder] Digitdbofmusic.org, Petr Karlov, dunkanmac3@mail.ru Elita-online.ru, Private Person, votub@nm.ru Fedion.ru, Private Person, 10000002@mail.ru Firex-labz.com, SharedHSD, roomart2008@yandex.ru Firsttimesite.us, Olah Istvan, olah.istvan.ny@gmail.com Gbd-carrers.com, Aleksej Bagrov, deretx@rambler.ru Gerdok.ru, Private Person, 10000002@mail.ru Gnk-msk2.com, Alexey MIRKINO, 324635647@mail.ru Isell.cc, Jhon Balsmen, ukmcuk@googlemail.com Isellcc.com, Jhon Balsmen, ukmcuk@googlemail.com Kalopes.ru, Private Person, 10000002@mail.ru Kobash.ru, Private Person, 10000002@mail.ru Kovero.ru, Private Person, 10000002@mail.ru Leadingdelivery.com, WhoisPrivacyProtect.com Leapdelivery.net, WhoisPrivacyProtect.com Megatt.cn, LucasSteven, steven_lucas_2000@yahoo.com Midlway.com, Real Host LTD, real2030@gmail.com Molide.ru, Private Person, 10000002@mail.ru Motile.ru, Private Person, 10000002@mail.ru Mssys.net, Klan Jored, support@hosting-offshore.biz Muhamed.cn, Caroline Krajka, caroline.krajka@gmail.com Myeasyhosting.us, Olah Istvan, olah.istvan.ny@gmail.com Newskyag.com, Robert Baker, robertbaker2110@yahoo.com Obosraca.net, Nungoyanrgrr Pimdulya, cumo@mail.ru Ru-r.ru, Anton A Baklanov, pinch18@rambler.ru Slikons.ru, Private Person, 10000002@mail.ru Smsvor.ru, Private Person, n.shahov@yandex.ru Superioradz.info, Bryony, blaze_sanchez3@yahoo.com Swegol.ru, Private Person, 10000002@mail.ru Uni-tele-com.ru, Private Person, n.shahov@yandex.ru Valebe.ru, Private Person, 10000002@mail.ru Vkonlahte.ru, Private Person, eert@inbox.ru Vkortakt.ru, Private Person, asfsdfgsg@yandex.ru Waderos.ru, Private Person, 10000002@mail.ru Webinst.ru, Private Person, 10000002@mail.ru Wedikas.ru, Private Person, 10000002@mail.ru Wedows.ru, Private Person, 10000002@mail.ru Welcomeone.cn, LucasSteven, steven_lucas_2000@yahoo.com Werobin.ru, Private Person, 10000002@mail.ru Wetese.ru, Private Person, 10000002@mail.ru Wldomen.com, Klan Jored, support@hosting-offshore.biz Wogolot.ru, Private Person, 10000002@mail.ru Xaker.cn, Real Host, abuseemaildhcp@gmail.com Xxhackmail.ru, Private Person, 365346546@mail.ru Xxvhost.com, Klan Jored, support@hosting-offshore.biz Yes04ka.cn, Gregory, Michell.Gregory2009@yahoo.com Yourgoogleanalytics.cn, Real Host, abuseemaildhcp@gmail.com Yourgoogleanalytics.us, Olah Istvan, olah.istvan.ny@gmail.com
213.182.197.230 Benzonasoss.com, Aleksey Melnikov, mel1simkov@gmail.com Csollw.com, Aleksey Melnikov, mel1simkov@gmail.com Jlopi.com, Aleksey Melnikov, mel1simkov@gmail.com Joltuiwater.com, Aleksey Melnikov, mel1simkov@gmail.com Kartoshkachamp.com, Aleksey Melnikov, mel1simkov@gmail.com Lipesr.com, Aleksey Melnikov, mel1simkov@gmail.com Minfpafs.com, Aleksey Melnikov, mel1simkov@gmail.com Nerkol.com, Aleksey Melnikov, mel1simkov@gmail.com Updateserversoft.com, Chen Poon, chen.poon1732646@yahoo.com Vizllp.com, Aleksey Melnikov, mel1simkov@gmail.com Vmbs4.com, Aleksey Melnikov, mel1simkov@gmail.com Werkp.com, Aleksey Melnikov, mel1simkov@gmail.com Wherg.com, Aleksey Melnikov, mel1simkov@gmail.com
213.182.197.233 Banished.ru, Private Person, abuseemaildhcp@gmail.com Bargian-hunt.com, Sean McCann, sean.mccann.1@hotmail.com Pornonova.net, Anya Montague, gr4ndth3ft@hotmail.com Proxyrent.cn, Chen Poon, chen.poon1732646@yahoo.com
213.182.197.234 Updategoogle.cn, Real Host LTD, abuseemaildhcp@gmail.com Uppgoogle.cn, Real Host LTD, abuseemaildhcp@gmail.com
213.182.197.235 Aepi.ru, Private Person, polevweb@gmail.com Evamedstore.com, Nikolai Vukolov, baton@bronzemail.net Traffic-exchange.ru, Aleksej D Brozdov, ru-traffic-exchange@gmail.com
213.182.197.236 1gen1.ru, Andrey G Zubkov, a.zubkov@exeda.info 71sense.info, Vicky Chan, chan.wai.kay.1@gmail.com 71soldo.info, Vicky Chan, chan.wai.kay.1@gmail.com 71speed.info, Vicky Chan, chan.wai.kay.1@gmail.com 71spice.info, Vicky Chan, chan.wai.kay.1@gmail.com 7addition.info, Vicky Chan, chan.wai.kay.1@gmail.com 8addition.info, Vicky Chan, chan.wai.kay.1@gmail.com 8addition.org, Vicky Chan, chan.wai.kay.1@gmail.com Add-content-filter.info, PrivacyProtect.org Deonix.biz, Aleksey Melnikov, mel1simkov@gmail.com Doplin.biz, Aleksey Melnikov, mel1simkov@gmail.com Gnbd1.cn, Chen Poon, chen.poon1732646@yahoo.com Hamatauto.biz, Aleksey Melnikov, mel1simkov@gmail.com Hel90.biz, Aleksey Melnikov, mel1simkov@gmail.com Lalalabemsbams.name, Aleksey Melnikov, mel1simkov@gmail.com Tfx2corp.cn, TiankaiCui, cuitiankai@googlemail.com Vip-internal.ru, Private Person, spy-logs-l12@inbox.ru
213.182.197.237 1gigabayt.com, Hau Cheng, haucheng@yahoo.com Beauty-hot-pornxxx.com, Aleksey Melnikov, mel1simkov@gmail.com Downloadoemsoftware.com, Chen Poon, chen.poon1732646@yahoo.com Fire-hot-pornxxx.com, Aleksey Melnikov, mel1simkov@gmail.com Hotflashplayer.com, Aleksey Melnikov, mel1simkov@gmail.com Metroking.ws, Aleksey Melnikov, mel1simkov@gmail.com Oneminute2u.biz, Aleksey Melnikov, mel1simkov@gmail.com Rbckc.com, Aurore Hetu, AuroreHetu@fontdrift.com Scans.cc, PrivacyProtect.org Sexual69.ru, Artur G Antonov, antonov@rbcmail.ru Thebestplayer.biz, Aleksey Melnikov, mel1simkov@gmail.com Verivell.com, Hau Cheng, haucheng@yahoo.com Xtraff.cn, Hau Cheng, haucheng@yahoo.com
213.182.197.238 Agroautoparts.com, Aleksey Melnikov, mel1simkov@gmail.com
213.182.197.243 Einrock.com, Puprov Ivan, captainjs@yandex.ru Geo555.com, Vladim Ivanov, captainjs@yandex.ru Makomset.com, Vladimir Ivanovich, captainjs@yandex.ru Ribcot.com, Sergeev Kirill Nikolaevich, captainjs@yandex.ru
213.182.197.247 Sex-proector.ru, Private Person, toolssoft@mail.ru
213.182.197.249 Feed-place.cn, Gregory, Michell.Gregory2009@yahoo.com Hit-senders.cn, Gregory, Michell.Gregory2009@yahoo.com Search890.com, Chen Poon, chen.poon1732646@yahoo.com Traffic-searches.cn, Chen Poon, chen.poon1732646@yahoo.com Vikd3jj-1.com, Dmitry Ostupin, conroetxwelc@gmail.com Vikd3jj-2.com, Dmitry Ostupin, conroetxwelc@gmail.com Vikd3jj-3.com, Dmitry Ostupin, conroetxwelc@gmail.com Vikd3jj-4.com, Dmitry Ostupin, conroetxwelc@gmail.com Vintorrils-grag1.com, Dmitry Ostupin, conroetxwelc@gmail.com Vintorrils-grag2.com, Dmitry Ostupin, conroetxwelc@gmail.com Vintorrils-grag3.com, Dmitry Ostupin, conroetxwelc@gmail.com
213.182.197.251 Botnet.su, Mihail V Morozov, sdhj3jk@yandex.ru 2k90.cn, Real Host LTD, abuseemaildhcp@gmail.com Abdulabah.cn, LucasSteven, steven_lucas_2000@yahoo.com Babjr.cn, LucasSteven, steven_lucas_2000@yahoo.com D4rkst4r.cn, Real Host LTD, abuseemaildhcp@gmail.com Luks5.cn, LucasSteven / Cehhost, Michell.Gregory2009@yahoo.com Serverinlit.cn, Real Host LTD, abuseemaildhcp@gmail.com
213.182.197.254 Go-file.ru, Grigoriy M Aleksandrov, aleksandrov@mail333.com
Labels: Black Hat, Latvia, Malware, Real Host Ltd, Spam ________________________________________________
RBN?
Removal Procedure
To have record SBL75831 (213.182.197.0/24) removed from the SBL, the Abuse/Security representative of junik.lv (or the Internet Service Provider responsible for supplying connectivity to 213.182.197.0/24) needs to contact the SBL Team by email (use this link) to explain how the spam problem has been terminated (we need to know exactly how the issue has been dealt with and that this spam problem is fully terminated). If the spam problem that caused this listing has been terminated we will normally remove the listing from the SBL without delay.
It is essential that emails to the SBL Team about this SBL listing include this exact ticket information in the email Subject:
If you are a representative of junik.lv, you also need to see: Current Live junik.lv SBL Listings
The SBL is an international anti-spam system maintained by The Spamhaus Project and used by Internet networks to protect users from spam sources and spam services. The SBL lists only IP addresses (not domains, email addresses, names or anything else). If you are unable to send email to someone due to this SBL listing, please contact your Internet Service Provider and show them this page - your Service Provider needs to contact the Spamhaus SBL team to resolve the issue (if you are not the Internet Service Provider, please do not contact us.)
|