Rixstep
 About | ACP | Buy | Industry Watch | Learning Curve | News | Products | Search | Substack
Home » Learning Curve

The Russians Aren't Coming

They're already there.



Get It

Try It

It's a good thing this isn't the Cold War. The US are namely getting the shit kicked out of them.

It's one thing the RBN hosted Storm worm operation runs rampant over the holiday season and it's totally another how it runs.

Americans hoarded all sorts of obnoxious Rambo signature weapons in their closets in case the Russians were coming; after 911 they did the same thing for the Muslim invasion; but what do they do about their computers?

Clue: the Russians aren't coming - they're already there, you fools.

Счастливых праздников (Happy Holidays)

The Storm people began running a number of greeting card scams right before 25 December. The payloads were a literal cocktail of assorted exploits nestling into Windows systems through the service manager. But what's more interesting is how they got the fly by night domains to work.

Each domain is assisted by thirteen name servers run from Comcast, Road Runner, Verizon, Southwest Bell, Qwest, Charter, SBC, Insight, and a minority representation from the Netherlands, Germany, Hungary, Japan, and Korea. These name servers are simply Windows PCs owned and operated by clueless nimrods.

The following are tables of the DNS servers associated with a number of these domains. Счастливых праздников.

UHAVEPOSTCARD.COM

UHAVEPOSTCARD.COM was registered to 'Kerry Corsten' of 'Los-Angeles' on 23 December.

ns.uhavepostcard.com68.52.93.226c-68-52-93-226.hsd1.tn.comcast.net
ns2.uhavepostcard.com71.194.49.109NET-71-194-0-0-1 [Comcast]
ns3.uhavepostcard.com67.8.56.110110-56.8-67.tampabay.res.rr.com
ns4.uhavepostcard.com68.41.2.40c-68-41-2-40.hsd1.mi.comcast.net
ns5.uhavepostcard.com71.107.40.217pool-71-107-40-217.lsanca.dsl-w.verizon.net
ns6.uhavepostcard.com69.148.251.234adsl-69-148-251-234.dsl.wchtks.swbell.net
ns7.uhavepostcard.com69.247.162.86c-69-247-162-86.hsd1.ks.comcast.net
ns8.uhavepostcard.com68.187.46.12568-187-46-125.dhcp.ftwo.tx.charter.com
ns9.uhavepostcard.com76.111.115.55c-76-111-115-55.hsd1.md.comcast.net
ns10.uhavepostcard.com75.17.124.140adsl-75-17-124-140.dsl.rcsntx.sbcglobal.net
ns11.uhavepostcard.com85.180.72.115e180072115.adsl.alicedsl.de
ns12.uhavepostcard.com86.101.3.252catv-566503fc.catv.broadband.hu
ns13.uhavepostcard.com83.81.49.775351314d.cable.casema.nl

NEWYEARWITHLOVE.COM

NEWYEARWITHLOVE.COM was registered on 26 December to 'Bill Gudzon' of 'Los-Angeles' on 26 December. There is only one 'Gudzon' in all of the US and that's an 'Alecscander' and he's in Connecticut. There is however a major Russian portal with that name.

ns.newyearwithlove.com69.148.251.234adsl-69-148-251-234.dsl.wchtks.swbell.net
ns2.newyearwithlove.com75.17.124.140adsl-75-17-124-140.dsl.rcsntx.sbcglobal.net
ns3.newyearwithlove.com74.140.209.14574-140-209-145.dhcp.insightbb.com
ns4.newyearwithlove.com75.24.24.249adsl-75-24-24-249.dsl.yntwoh.sbcglobal.net
ns5.newyearwithlove.com76.119.119.58c-76-119-119-58.hsd1.ma.comcast.net
ns6.newyearwithlove.com67.180.183.105c-67-180-183-105.hsd1.ca.comcast.net
ns7.newyearwithlove.com69.138.252.207c-69-138-252-207.hsd1.md.comcast.net
ns8.newyearwithlove.com89.136.176.227astral.ro [Romania]
ns9.newyearwithlove.com82.240.196.133gar31-4-82-240-196-133.fbx.proxad.net
ns10.newyearwithlove.com67.8.56.110110-56.8-67.tampabay.res.rr.com
ns11.newyearwithlove.com83.7.208.236ablo236.neoplus.adsl.tpnet.pl
ns12.newyearwithlove.com86.101.3.252catv-566503fc.catv.broadband.hu
ns13.newyearwithlove.com125.14.229.130125-14-229-130.rev.home.ne.jp

FAMILYPOSTCARDS2008.COM

FAMILYPOSTCARDS2008.COM was registered to 'Larry Claus' of 'Los-Angeles' on 29 December.

ns.familypostcards2008.com68.248.157.236adsl-68-248-157-236.dsl.ipltin.ameritech.net
ns10.familypostcards2008.com123.202.159.18123202159018.ctinets.com
ns11.familypostcards2008.com85.217.201.159201-159.thezone.bg
ns12.familypostcards2008.com211.171.10.67bora.net [Korea]
ns13.familypostcards2008.com58.241.229.11jsnetcom.com [China]
ns2.familypostcards2008.com209.91.34.130user-38lm8k2.cable.mindspring.com
ns3.familypostcards2008.com69.181.38.17c-69-181-38-17.hsd1.ca.comcast.net
ns4.familypostcards2008.com81.200.116.58host-81-200-116-58.starnet.ru
ns5.familypostcards2008.com68.40.145.194c-68-40-145-194.hsd1.mi.comcast.net
ns6.familypostcards2008.com220.94.203.81kornet.net [Korea]
ns7.familypostcards2008.com70.242.88.199ppp-70-242-88-199.dsl.okcyok.swbell.net
ns8.familypostcards2008.com130.13.110.121vdsl-130-13-110-121.phnx.qwest.net
ns9.familypostcards2008.com71.234.37.84c-71-234-37-84.hsd1.ct.comcast.net

С Новым Годом (Happy New Year)

So Mr and Mrs Fred and Wilma Willard of Kansas City are going to bed but decide they can leave their PC on. After all Windows crashes a lot less than it used to.

Simultaneously Igor Goulasch of Hungary and Saki Tempura of Japan leave their PCs on and do the same.

All have visions of sugar plums dancing in their heads. С Новым Годом.

About | ACP | Buy | Industry Watch | Learning Curve | News | Products | Search | Substack
Copyright © Rixstep. All rights reserved.