Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Spam, DDos and the RBN nazis
02-26-2008, 08:56 PM (This post was last modified: 02-27-2008 02:33 AM by LoopRadar.)
Post: #1
Spam, DDos and the RBN nazis
In light of the recent ddos attacks and the continual problem with spam in the forum I thought I would share some basic info on who these forces are.
Indeed this is highly organized and professional criminals with some nasty political stances.
This is a brief introduction, but it might be expanded upon later. (Input is welcome.)

First, what is dos/ddos?:
ddos stands for "Distributed Denial of Service"
http://learn-networking.com/network-securi...service-attacks
(Scroll down to the DDoS section in particular.)

Most of the spam and ddos attacks we see today comes from botnets like 'Storm':
http://en.wikipedia.org/wiki/Storm_botnet
One of the most famous ddos attacks to date was the attack on Estonia in May 2007 in which most of the countries internet and networking capabilities was disabled.
Recently 'Prolexic technologies' reported an upwards of 7000 attacks daily.
The anti-spam org. spamhaus.org has also been targeted as has various 'Honeypot' Projects.
Other popular attack-vectors used by spammers include the "Profile Spam", the "Bot" or the "Referrer" approach.
Though it should be noted that these are not at the same level of intensity or sophistication, but might still originate from the same sources.

The botnet is maintaned by spreading rootkits or 'Trojans', mainly via spam e-mail and social engineering thechniques. Once launched the rootkit takes control over essential network functions on the victims computer which then becomes a 'node' in this wast botnet:
http://www2.gmer.net/mbr/
(And remember kids, MBR runs on Microsoft PC's ONLY. However, the press likes to ignore this fact.)
A good resource for dealing with a suspected infection:
http://www.gmer.net/index.php
(I would recommend all 'Windows' users to consider using 'Gmer'.)

Storm was created, and is run and maintained by the 'Russian Business Network' (RBN):
http://en.wikipedia.org/wiki/Russian_Business_Network
They even rent their services, also known as "ddos reselling", to third parties who in turn can use the (Storm) botnet to attack or extort anyone they feel like. E.g:
http://www.talkgold.com/forum/showthread.php?t=205589
Quote:am a long standing and respected member of TalkGold who feels it
necessary to expose a DDoS botnet criminal who is actively involved in
extortion against major HYIP's and monitor services. This user "shark"
who represents goldpoll.com and goldentalk.com claims to be under
consistent DDoS. In reality, he most likely receives no DDoS as he is
actually the one committing the attacks against other sites. This
crime is serious and no one who actually knows about this dares to
speak at the risk of receiving a DDoS attack of 6 Gbps or more.
and:
http://www.hothyips.com/details/Golden+Pat...nvest.6498.html
(Yeah, souns like a good "investment", doesn't it?)
Quote:February 19, 2008 (Computerworld) The Russian Business Network, a notorious hacker and malware hosting network, runs a protection racket that extorts as much as $2,000 a month in fees for "protective Web services" from borderline sites, a researcher alleged today.
Backed by high-level russian politicians they don't have much to fear and can continue to act as they please.
Quote:ACCORDING to VeriSign, one of the world's largest internet security companies, RBN, an internet company based in Russia's second city, St Petersburg, is "the baddest of the bad". In a report seen by The Economist, VeriSign's investigators unpick an extraordinary story of blatant cybercrime that implies high-level political backing.

In one sense, RBN (Russian Business Network) does not exist. It has no legal identity; it is not registered as a company; its senior figures are anonymous, known only by their nicknames. Its web sites are registered at anonymous addresses with dummy e-mails. It does not advertise for customers. Those who want to use its services contact it via internet messaging services and pay with anonymous electronic cash.
---
RBN even fights back. In October 2006, the National Bank of Australia took active measures against Rock Phish, both directly and via a national anti-phishing group to which the bank's security director belonged. RBN-based cybercriminals replied by crashing the bank's home-page for three days.

What can be done? VeriSign has tracked down the physical location of RBN's servers. But Western law enforcement officers have so far tried in vain to get their Russian counterparts to pursue the investigation vigorously. "RBN feel they are strongly politically protected. They pay a huge amount of people. They know they are being watched. They cover their tracks," says VeriSign. The head of RBN goes under the internet alias "Flyman"; his uncle is thought to be a senior St Petersburg politician. Repeated e-mails to RBN's purported contact addresses asking for comment have gone unanswered.
Source HERE

It it obviously very capable individuals behind this.
Quote:So what is new? Well the exploit sites are now using a fast-flux P2P botnet and the exploit is polymorphic i.e. the ability to alter its form and mutate.
Source HERE
'RBN' is also known for their "bulletproof" hosting of, among other, drug-selling and child pornography sites.
Not only that, several major Internet providers such as Tiscali.uk, SBT Telecom, Aki Mon Telecom and Nevacon LTD. have been called on providing services to RBN.
So not only does Microsoft provide a level of security that is laughable to it's customers, but the ISP's are also complicit in this crimewave.
Microsofts shady business practice as a whole has been well documented all over the web, so I'll suffice to say they are not worth your time, your money or your peace of mind.
Quote:...was the case with the recent attack against the Bank of India, in which attackers compromised the bank's Web site using Mpack, a veritable Swiss Army knife of Web browser exploits. When Microsoft Windows users visits an Mpack-infected site with a browser or Windows installation that is not updated with the latest security patches, Mpack uses those flaws to silently install password-stealing software on visitors' machines.
Source HERE
Seriously, you don't need more. Just stay away from them.

RBN's political/ideological connections to the russian nazi group '1488 RU' is also apparent, both in terms of hosting, protecting and possibly financing:
"A violent, and very well financed Russian Nazi group. The 14 represents the 14-word slogan: "We must secure the existence of our people and a future for White children” and 88 represents eighth letter of the alphabet, with HH standing for Heil Hitler."
[Image: RBNexploit_jidov1488.jpg]
Quote:(RU) Друзья, мы рады сообщить Вам, что теперь сайт 1488.ru доступен из доменной зоны Jidov.net . Развитие проекта идет полным ходом. Благодарим Вас за внимание к нашему ресурсу. Скоро мы сможем предложить Вам регистрацию доменов третьего уровня в наших доменных зонах (Ваш ник.1488.ru и Ваш ник.jidov.net). Так же, мы готовы предложить вам размещение банеров на страницах нашего ресурса.

(EN) Friends, we are glad to report to you that now the site to 1488.ru is accessible from the domain zone Jidov.net. The development of design occurs full speed. We thank you for the attention to our resource. Soon we will be able to propose to you registration it is pre-barter the third level in our domain zones (your nik.1488..ru and your it nik..jidov.net). So, we are prepared to propose to you the arrangement of banners for the pages of our resource.
(Funny sidenote for the paranoid among us; Try searching for 'youtube' and '1488.ru' and see what comes up. :ouch:)
1488 are also linked to other ultra right wing groups and seem to be doing a lot of netwoking not only on-line.

Hopefully this will help people realize the seriousness of the situation and make them take the appropriate steps to, at least, avoid aiding in the continued expansion and power of this criminal conspiracy.
Beware of fake anti-spyware/anti-virus or "too-good-to-be-true" security software and fake codecs. And under any circumstance do not click on links in spam or e-mail from unknown sources or that does not contain a pgp signature.


LR

Note: Phrases or words contained within ' and ' are good for googling. :wink:
Edit: Post updated and expanded.

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
02-27-2008, 01:58 AM
Post: #2
Spam, DDos and the RBN nazis
Quote:thanks LR. using gmer now. you know you're shit for sure. many thanks
Thank you nik.
I've updated the post with some more info and resources already.

LR

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
02-27-2008, 03:35 AM
Post: #3
Spam, DDos and the RBN nazis
I ran gmer and it gave a listing.

I did a scan and got a bigger listing.

Some items in firefox was listed.

Some are connected with recognizable functions like avg7.

These may be normal XP functions.

FooStevens mp3Lyne mp3
T&L Pg1Pg2Pg3Pg4Pg5JFK IIJFK JR9/11 Mysteries&The City& of Mr Redshield
&Ether Physics& by William R. Lyne &Pentagon Aliens& by William R Lyne and interview
The Lyne Web Page an ebook The TeslaandLyne YouTube Channel
Nazi Saucer Photos link update soonT&L CC Blog
A Tesla Tale from his killer?...after the FOO appeared Tesla had to go
Brief, one page, research summary by William R. LyneHitler's Flying Discs
Alex Jones' Terrorstorm: Final Cut Special Edition, Re-Mixed + Re-Mastered
Tesla and America..nine parts by William R. Lyne Lyne on CC TrackerLyne Online
Work honestly for wicked money - Jesus, Luke 16
http://www.whatreallyhappened.com/ The Greatest Story Ever DeniedScience Dictatorship
Visit this user's website Find all posts by this user
Quote this message in a reply
02-29-2008, 04:53 AM
Post: #4
Spam, DDos and the RBN nazis
I don't believe this shit sometimes. A bank gets ddos'd and does fuck all. If it were my bank, RBN's upstream provider would have a 100,000 $ dead or a live bounty on his head. I'd simply tell the fucker to drop RBN or prepare his will.
Quote this message in a reply
03-10-2008, 10:58 PM (This post was last modified: 03-11-2008 02:04 AM by LoopRadar.)
Post: #5
Spam, DDos and the RBN nazis
Important update (Ctrl et al, take note.)

Add to/make blocklist.
Remember to update from:
http://doc.emergingthreats.net/
and in particular:
http://www.emergingthreats.net/rules/bleed...rbn-BLOCK.rules

Quote:#
# $Id: bleeding-rbn-BLOCK.rules $
# Emerging Threats RBN rules.
#
# Rules to detect known Russian Business Network (RBN) hosts. These lists are updated daily or better from many sources
#
# We do not necessarily declare that these hosts are all bad, or that RBN is inherently an evil organization. Use this
# information as you see fit.
#
# More information available at doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork
#
# Please submit any feedback or ideas to emerging@emergingthreats.net or the emerging-sigs mailing list
#
#*************************************************************
#
# Copyright © 2003-2008, Emerging Threats
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
# following conditions are met:
#
# * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
# disclaimer.
# * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
# following disclaimer in the documentation and/or other materials provided with the distribution.
# * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
# from this software without specific prior written permission.
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
# INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
# DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
# SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
# WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
# USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#

#general hosts
alert ip [58.65.233.0/24,58.65.239.66/31,65.99.192.0/20,65.254.48.0/20,66.232.96.0/19,66.252.0.0/19,69.50.160.0/
19,81.94.16.0/20,81.95.128.0/19,85.249.23.0/24,85.255.112.0/24,85.255.116.0/24,85.255.121.0/
24,88.201.208.0/20,194.146.204.0/22,194.226.64.0/20,194.226.96.0/24,195.114.16.0/23,195.64.140.0/
23,195.64.162.0/23,208.72.160.0/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Traffic - Hosting Nets - BLOCKING"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold:type limit, track by_src, seconds 60, count 1; sid:2407000; rev:8; fwsam:src, 24 hours;)

#individual general hosts
alert ip [62.140.208.131,62.140.208.197,62.154.15.154,65.254.54.178,66.252.1.255,67.18.17
9.15,67.19.24.168,
67.19.24.169,67.19.24.170,67.19.24.171,67.19.24.172,67.19.24.173,67.19.24.174,67​
.19.24.175,
67.19.72.205,67.19.72.206,67.137.217.219,72.10.164.69,72.20.14.3,72.20.25.134,74​
.54.31.196,
80.70.239.253,84.45.24.53,84.45.47.130,84.45.90.141,85.133.4.138,89.149.186.77,8​
9.149.186.81,
89.149.186.89,193.93.232.6,193.93.232.6,195.66.226.151,213.200.78.66,213.200.79.​
194,213.200.80.46,
216.180.244.179,217.118.119.26] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Traffic - Individual Hosts - BLOCKING"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold:type limit, track by_src, seconds 60, count 1; sid:2407001; rev:8; fwsam:src, 24 hours;)

#chinese
alert ip [91.196.232.0/22,91.194.140.0/23,91.198.71.0/24,91.193.40.0/22,91.193.56.0/22,193.33.128.0/
23,194.110.69.0/24,91.195.116.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Traffic - Chinese Nets - BLOCKING"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold:type limit, track by_src, seconds 60, count 1; sid:2407002; rev:8; fwsam:src, 24 hours;)

#Panamanian/Central America
alert ip [200.115.160/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Traffic - Central American Nets"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold:type limit, track by_src, seconds 60, count 1; sid:2407004; rev:2; fwsam:src, 24 hours;)

#Anserin/Torpig/Sinowal hosts
alert ip [72.232.197.83] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Traffic - Known Trojan C&Cs - BLOCKING"; reference:url,doc.emergingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold:type limit, track by_src, seconds 60, count 1; sid:2407003; rev:8; fwsam:src, 24 hours;)




# VERSION 37

# Updated 2008-03-06 19:56:19

alert ip [190.15.72.0/21,190.15.73.221,190.15.73.222,190.15.73.223,190.15.73.251,190.15.73.252,193.33.​
128.0/
23,193.39.113.199,193.39.113.2,193.93.232.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (1)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407005; rev:37; fwsam: src, 24 hours;)
alert ip [193.93.235.5,194.110.69.0/24,194.126.174.124,194.146.204.0/22,194.226.64.0/20,194.226.96.0/
24,194.67.0.0/18,194.67.27.115,194.67.27.125,194.67.28.250]
any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (2)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407006; rev:37; fwsam: src, 24 hours;)
alert ip [194.67.28.62,194.67.35.133,194.67.35.250,195.114.16.0/23,195.225.176.68,195.225.177.54,
195.225.177.7,195.3.144.30,195.3.144.77,195.64.140.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (3)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407007; rev:37; fwsam: src, 24 hours;)
alert ip [195.64.162.0/23,195.66.226.151,200.115.160.0/20,203.117.0.0/16,203.121.0.0/17,204.251.15.190,
206.161.200.34,206.161.200.36,207.226.173.114,207.226.173.67] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (4)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407008; rev:37; fwsam: src, 24 hours;)
alert ip [207.44.185.10,208.48.15.11,208.48.15.13,208.48.15.62,208.72.160.0/20,208.72.168.0/21,208.72.170.189,
209.8.30.2,209.85.84.199,212.24.53.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (5)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407009; rev:37; fwsam: src, 24 hours;)
alert ip [213.132.196.200,213.132.196.211,213.200.78.66,213.200.79.194,213.200.80.46,213.
99.178.180,
216.118.117.68,216.180.244.179,216.195.44.0/24,216.195.49.100] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (6)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407010; rev:37; fwsam: src, 24 hours;)
alert ip [216.195.49.159,216.195.49.88,216.195.50.159,216.195.50.162,216.195.50.238,216.1
95.50.51,
216.195.50.56,216.195.50.81,216.255.176.0/20,216.255.185.237] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (7)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407011; rev:37; fwsam: src, 24 hours;)
alert ip [216.255.190.74,216.7.89.12,216.8.177.26,217.118.119.26,58.65.232.0/21,58.65.233.0/24,58.65.234.17,
58.65.234.18,58.65.235.177,58.65.235.178] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (8)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407012; rev:37; fwsam: src, 24 hours;)
alert ip [58.65.235.41,58.65.235.81,58.65.237.121,58.65.237.17,58.65.238.100,58.65.238.10
1,58.65.238.18,
58.65.238.59,58.65.238.66,58.65.238.98] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (9)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407013; rev:37; fwsam: src, 24 hours;)
alert ip [58.65.239.27,58.65.239.66,62.140.208.131,62.140.208.197,62.154.15.154,63.243.18
8.2,63.243.188.3,
63.243.188.82,64.111.192.0/20,64.111.208.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (10)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407014; rev:37; fwsam: src, 24 hours;)
alert ip [64.111.209.0/24,64.111.210.0/24,64.111.211.0/24,64.111.216.0/21,64.28.176.0/20,64.28.177.74,
64.28.180.0/24,64.28.181.0/24,64.28.182.106,64.28.182.107] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (11)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407015; rev:37; fwsam: src, 24 hours;)
alert ip [64.28.182.122,64.28.182.146,64.28.182.151,64.28.182.163,64.28.182.195,64.28.182
.196,64.28.182.66,
64.28.182.68,64.28.182.8,64.28.183.162] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (12)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407016; rev:37; fwsam: src, 24 hours;)
alert ip [64.28.183.44,64.28.183.45,64.28.183.99,64.28.184.0/24,64.71.133.0/24,65.254.48.0/20,65.254.54.178,
65.99.192.0/20,66.232.96.0/19,66.244.254.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (13)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407017; rev:37; fwsam: src, 24 hours;)
alert ip [66.252.0.0/19,66.252.1.255,66.29.15.141,66.45.254.244,66.45.254.245,67.137.217.219,67.18.17​
9.0/24,
67.19.24.0/24,67.19.24.168,67.19.24.169] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (14)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407018; rev:37; fwsam: src, 24 hours;)
alert ip [67.19.24.170,67.19.24.171,67.19.24.172,67.19.24.173,67.19.24.174,67.19.24.175,6
7.19.51.0/24,
67.19.72.205,67.19.72.206,67.43.236.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (15)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407019; rev:37; fwsam: src, 24 hours;)
alert ip [67.55.64.0/19,69.20.117.228,69.20.68.36,69.22.162.0/23,69.22.168.0/21,69.22.184.0/22,69.31.128.2,
69.31.40.0/21,69.31.64.0/20,69.39.224.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (16)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407020; rev:37; fwsam: src, 24 hours;)
alert ip [69.42.216.122,69.50.160.0/19,69.50.166.196,69.50.168.102,69.50.168.98,69.50.168.99,69.50.170.174,
69.50.170.82,69.50.176.227,69.50.176.228] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (17)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407021; rev:37; fwsam: src, 24 hours;)
alert ip [69.50.176.229,69.50.188.3,69.50.188.4,72.10.164.69,72.20.0.0/19,72.20.110.8,72.20.14.3,72.20.25.134,
72.232.197.83,74.54.31.196] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (18)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407022; rev:37; fwsam: src, 24 hours;)
alert ip [77.91.224.0/21,77.91.225.14,77.91.225.18,77.91.225.2,77.91.225.20,77.91.225.3,77.91.225.30,7​
7.91.225.4,
77.91.225.5,77.91.225.6] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (19)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407023; rev:37; fwsam: src, 24 hours;)
alert ip [77.91.225.7,77.91.225.8,77.91.225.9,77.91.226.5,77.91.226.6,77.91.226.7,77.91.2
27.178,77.91.227.202,
77.91.227.203,77.91.227.208] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (20)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407024; rev:37; fwsam: src, 24 hours;)
alert ip [77.91.227.209,77.91.227.211,77.91.227.246,77.91.227.247,77.91.227.253,77.91.228
.106,77.91.228.110,
77.91.228.111,77.91.228.121,77.91.228.122] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (21)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407025; rev:37; fwsam: src, 24 hours;)
alert ip [77.91.228.125,77.91.228.126,77.91.228.130,77.91.228.131,77.91.228.139,77.91.228
.140,77.91.228.141,
77.91.228.142,77.91.228.155,77.91.228.156] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (22)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407026; rev:37; fwsam: src, 24 hours;)
alert ip [77.91.228.180,77.91.228.44,77.91.228.51,77.91.228.53,77.91.228.7,77.91.229.103,
77.91.229.106,
77.91.229.107,8.15.231.110,80.70.224.0/20] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (23)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407027; rev:37; fwsam: src, 24 hours;)
alert ip [80.70.239.253,81.29.241.9,81.29.249.38,81.94.16.0/20,81.95.128.0/19,81.95.144.0/20,81.95.144.182,
81.95.144.3,81.95.145.186,81.95.146.250] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (24)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407028; rev:37; fwsam: src, 24 hours;)
alert ip [81.95.147.182,81.95.147.202/31,81.95.148.130/31,81.95.148.132/31,81.95.148.18,81.95.149.110/31,
81.95.149.171,81.95.149.178,81.95.149.181,81.95.149.27] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (25)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407029; rev:37; fwsam: src, 24 hours;)
alert ip [81.95.153.243,81.95.154.41,81.95.156.0/22,82.114.64.251,82.146.56.140,83.222.0.0/19,84.45.24.53,
84.45.47.130,84.45.90.141,85.133.4.138] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (26)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407030; rev:37; fwsam: src, 24 hours;)
alert ip [85.17.173.219,85.249.23.0/24,85.255.112.0/20,85.255.112.0/21,85.255.114.202,85.255.114.206,
85.255.115.178,85.255.115.180,85.255.116.0/24,85.255.117.202] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (27)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407031; rev:37; fwsam: src, 24 hours;)
alert ip [85.255.117.205,85.255.117.60,85.255.117.62,85.255.118.0/24,85.255.119.125,85.255.119.126,
85.255.119.251,85.255.119.254,85.255.119.66,85.255.119.67] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (28)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407032; rev:37; fwsam: src, 24 hours;)
alert ip [85.255.120.106,85.255.120.107,85.255.120.50,85.255.121.0/24,87.117.252.11,87.117.255.20,
87.117.255.30,88.201.208.0/20,88.255.90.0/24,88.255.94.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (29)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407033; rev:37; fwsam: src, 24 hours;)
alert ip [88.255.94.210,89.149.186.77,89.149.186.81,89.149.186.89,89.208.19.194,91.192.10
6.0/23,91.193.40.0/
22,91.193.56.0/22,91.194.140.0/23,91.195.116.0/23] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (30)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407034; rev:37; fwsam: src, 24 hours;)
alert ip [91.196.232.0/22,91.198.71.0/24] any -> $HOME_NET any (msg:"ET RBN Known Russian Business Network Monitored Domains - BLOCKING (31)"; reference:url,doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork; threshold: type limit, track by_src, seconds 60, count 1; sid:2407035; rev:37; fwsam: src, 24 hours;)
Source HERE
Also check THIS

And:
Quote:To cover traffic from the RBN's fake anti-spyware tools (partially within Spamhaus XBL):

IP Range start IP range end AS # Name

64.28.176.0 64.28.191.255 AS27595 INTERCAGE 69.22.162.0 69.22.163.255 AS27595 INTERCAGE 69.22.168.0 69.22.175.255 AS27595 INTERCAGE 69.22.184.0 69.22.187.255 AS27595 INTERCAGE 69.31.64.0 69.31.79.255 AS27595 INTERCAGE 69.50.160.0 69.50.191.255 AS27595 INTERCAGE 85.255.113.0 85.255.117.255 AS27595 INTERCAGE 85.255.118.0 85.255.118.255 AS27595 INTERCAGE 216.255.176.0 216.255.191.255 AS27595 INTERCAGE

58.65.239.66 - RBN domain involved in the Bank of India hack. 58.65.234.17 and 58.65.234.18 - RBN domains for iFrame Cash (see Spamhaus Rosko) 58.65.232.0 - 58.65.239.255 = HOSTFRESH RBN alternative hosting (supposedly Hong Kong based, but Intercage / Estdomains etc. linkage)

200.115.160.0/20 AS26426 OPTYNEX (Central American-based Estdomains and Neo-Nazi linkage)

-- JamesMcQuaid - 24 Jan 2008
Source HERE
The Neo-Nazi's march on.
In particular note the new Chinese ip-ranges. The RBN have been busy bribing their way onto the Chinese ISP's. How they manage the registrars for domain management etc. is clouded in a misty shroud of, you guessed it, hard cash and/or bribery... (Child-pron exposé, anyone?)
Watch the continued silence by the MSM and good luck.

Thank's

LR

Edit: RBN's Chinese friends (i.e. domain reg/admin):
http://china-channel.com/

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
03-11-2008, 12:41 AM (This post was last modified: 03-11-2008 01:10 AM by LoopRadar.)
Post: #6
Spam, DDos and the RBN nazis
Quote:I don't believe this shit sometimes. A bank gets ddos'd and does fuck all. If it were my bank, RBN's upstream provider would have a 100,000 $ dead or a live bounty on his head. I'd simply tell the fucker to drop RBN or prepare his will.
http://sunbeltblog.blogspot.com/2007/09/up...k-of-india.html

LR

Edit: Not so simple...
Quote:In order to exchange traffic, each network has to negotiate agreements with its peers so that they can communicate
each other. This agreement is called peering. There are three peering categories:
• Peer directly or swap: this is when both peers will agree on the fact that they’ll use each other link to
promote their business.
• Transit: you pay money to another network to access somewhere else.
• Customer : another network pays you to access somewhere else
As we’ll see later RBN has become master in dealing peering settlement with other ISPs. Thanks to these settlements,
RBN has acquired the ability to reach or be reached from several ISPs.

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
03-11-2008, 11:47 PM
Post: #7
Spam, DDos and the RBN nazis
Hello Turkey.
The Shadowserver Foundation Wrote:Saturday, 1 March 2008

Russian Business Network (RBN)

In the last few months, there has been a significant amount of press coverage given to insidious cyber activity associated with the segment of the Internet known as the “Russian Business Network,” or RBN. Previous studies have suggested that the RBN has ties to nearly every area of cybercrime, including: phishing, malware, DDOS activity, pornography, botnets, and anonymization.

In November 2007, media reporting indicated that a large portion of the RBN “went dark.” Since that time, the Shadowserver Foundation has been more closely analyzing outlying networks implicated as being associated with RBN. One of these suspected outliers is AS9121, known as TurkTelekom. SecurityZone.org reported in early December 2007 that while not everything in TurkTelekom appears to be malicious, there are some ranges that are “particularly bad” and analysis of Shadowserver Foundation data agrees. Several subranges quickly stand out as being deeply involved in malicious cyber activity: 88.255.90.0/24 and 88.255.94.0/24. IP registration indicates these ranges are listed under the name “ABDALLAH INTERNET HIZMETLERI” (AIH).
IP ranges:
88.255.90.0/24
and 88.255.94.0/24

For whatever it's worth...:smirk:

LR

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
03-14-2008, 07:22 AM
Post: #8
Spam, DDos and the RBN nazis
How does one use the rules from emergingthreats?
Quote this message in a reply
04-04-2008, 04:16 AM
Post: #9
Spam, DDos and the RBN nazis
There is a high probability that RBN building is located at:

Russian Business Network
12 Levashovskiy prospect.
197110 Saint-Petersburg
Russia

(More on the individuals in charge of RBN to follow shortly.)

LR

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
04-04-2008, 05:00 PM (This post was last modified: 04-04-2008 07:50 PM by LoopRadar.)
Post: #10
Spam, DDos and the RBN nazis
Here we go!

The people in charge:

Nikolay Ivanov:
Nikolay Ivanov is strongly involved into RBN.
Indeed, he is or has been the registrant for most
RBN entities’ domains (rbnnetwork.com, akimon.com
and sbttel.com). It is possible that this personal website
is the home page of the same Nikolay Ivanov:
http://nikolay-ivanov.narod.ru
Nikolay Ivanov seems to be liable for everything relating
to RBN communication (support, whois record...). It is
highly probable that Nikolay Ivanov use the pseudo
nickname Tim Jarret to communicate with others.

---
"We can't understand on which basis these organizations have such an
opinion about our company," Jaret of the Russian Business Network told
Wired in an e-mail interview. "We can say that this is subjective opinion
based on these organizations' guesswork.”
-’Jaret’ an RBN Spokesman
---

Vladimir Kuznetsov:
[Image: foto1.jpg]
Vladimir Kuznetsov is very implicated in DNS registration for Datapoint/Infobox.
Vladimir Kuznetsov is supposed to have been one of the leaders of RockPhish Group according to
iDefense.
Vladimir Kuznetsov has its own website: http://kuznetsov.spb.ru/
Domain names below may be his own:

6i.com
6ymuk.ru
Afiha.com
Agitmedia.com
Angaragroup.com
Canonis.com
Cruiseflare.com
Ellissexton.com
Extremal.info
Infobox.org
Internetmediainvestmentgroup.com
Iporcapital.com
Iporussia.us
Mediaheap.com
Moskva.biz
Over-d.com
Ponochka.com
Rurecord.com
Rus-green.info
Shoe-markets.com
Spb.biz
Sviaz.biz
Sviaz.info
Vladimirkuznetsov.com
Webservicereview.com
Yanzex.net
Zabava-bar.com
Zunuzin.com.

---
“It is now public knowledge that AbdAllah Internet Hizmetleri is under
the control of RBN.”
- Spacequad AntiSpam Services
---

Alexei Bakhtiarov:
As Vladimir Kuznetsov, Alexei Bakhtiarov is one of the two most important members
of Infobox. Alexei is also very involved in whois registration because we can find 100 domains where he
is registrant. Whole Datapoint address range has been registered by Alexei Bakhtiarov. This guy may be
the Datapoint CTO as we can see an interview from him about a DDOS attack:
http://www.spiegel.de/international/world/...,497841,00.html


Stepan Kucherenko:
Stepan Kucherenko is supposed to be the technical guy. He may lead the IT staff.
He has also be mentioned in the network whois of TwoCoinsSoftware (81.95.144.0/22). He may be one
of the RBN leaders. Stepan Kucherenko may also have some personal relations into Peterstar that are
used to get easier Internet access.


Flyman:
According to iDefense/Verisign, flyman is the main RBN leader.
http://www.theage.com.au/news/business/fro...5043032049.html
He could be the real brain of this complex organization.
He is well known by law enforcement because of child pornography.
Although pursues have already been attempted against him, he has very strong political protection that can offer him to continue to develop its traffic without being worried by polices.

http://www.guardian.co.uk/technology/200...news.crime Wrote:It is thought that the RBN's leader and creator, a 24-year-old known as Flyman, is the nephew of a powerful and well-connected Russian politician. Flyman is alleged to have turned the RBN towards its criminal users.

(The above as opposed to the following fake/goosechase info:

RBN (81.95.144.0)

role: RBusiness Network Registry
address: RBusiness Network
address: The Century Tower Building
address: Ricardo J. Alfari Avenue
address: Panama City
address: Republic of Panama
phone: +1 401 369 8152

person: John Kerch
address: Republic of Panama
e-mail: ripe@rbnnetwork.com
phone: +1 401 369 8152
mnt-by: RBN-MNT

person: Joseph Igopolo
address: Republic of Panama
e-mail: support@rbnnetwork.com
phone: +1 401 369 8152
mnt-by: RBN-MNT

NEVACON (194.146.204.0/24)

person: Josh Buslow
address: Republic of Panama
phone: +1 505 559 4493
e-mail: ripe@nevacon.net
mnt-by: NEVSKCC-MNT

person: Tony Root
address: Republic of Panama
phone: +1 505 559 4493
e-mail: support@nevacon.net
mnt-by: NEVSKCC-MNT

SBT-TELECOM (81.95.156.0/22)

person: Kisho Kato
address: Seychelles, Victoria
phone: +1 203 903 0125
e-mail: kisho@sbttel.com
mnt-by: SBT-MNT

person: Malik Sasho
address: Seychelles, Victoria
phone: +1 203 903 0125
e-mail: malik@sbttel.com
mnt-by: SBT-MNT

....)


Further possible affiliates and associates (compare to list(s) above, pending further investigation/confirmation):

Akimon (81.95.152.0/23) (Akimon is veryfied RBN.)

person: Sergey Startsev
address: Russia, St.Petersburg
phone: +7 903 0983277
e-mail: ripe@akimon.com
mnt-by: AKIMON-MNT

person: Nikolay Obraztsov
address: Russia, St.Petersburg
phone: +7 903 0983306
e-mail: support@akimon.com
mnt-by: AKIMON-MNT


SilverNet (89.223.88.0/21) (SN is veryfied RBN.)

address: 7/5
address: Bogatyrsky pr.
address: 197341 Saint-Petersburg
address: Russia
phone: +7 812 4381058
phone: +7 812 4485354
fax-no: +7 812 4381058

person1: Pavel Sokolov
address: 7/5
address: Bogatyrsky pr.
address: 197341 Saint-Petersburg

person2: Vladimir Manov
address: 7/5
address: Bogatyrsky pr.
address: 197341 Saint-Petersburg

Online Invest group LLC (195.64.162.0/23) (DDos/extortion/money-laundering)

address: 17653 St. Petersburgh Russia
address: pr. Metallistov 12 of. 32
e-mail: admin@domhost.com.ru
mnt-by: onlineinvest-mnt

person: Main Technichal Account
address: 17653 St. Petersburgh Russia
address: pr. Metallistov 12 of. 32
phone: +78129486712

Credolink (80.70.224.0/24)

address: 28/2, Komendantskiy pr. St.Petersburg, 197372, Russia

phone: +7 812 4384600
fax-no: +7 812 4384602
remarks:
SPAM issues - abuse@mns.ru
Mail and News issues - postmaster@mns.ru
Customer support - support@mns.ru
Hosting issues - hosting@mns.ru
e-mail: noc@mns.ru

Delta Systems (193.93.232.0/22)

address: 190000, 39 Kazanskaya st.
address: St. Petersburgh Russia
e-mail: admin@deltasys.ru

RusTelecom (195.114.8.0/23)

address: Volodarskogo str. 21 Sestroreck , Russia
e-mail: info@rustelecom.net
mnt-by: RUSTELECOM-MNT

person: Main Technichal Account
phone: +79217872403
nic-hdl: RUST2-RIPE

DATAPOINT (85.249.128.0/20)

person: Vladimir E Kuznetsov
address: 29, Viborgskaya nab.,
address: 198215 Saint Petersburg, Russia
phone: +7 812 3312999
fax-no: +7 812 3312999
e-mail: abuse@infobox.ru
e-mail: vova@kuznetsov.spb.ru

person: Rustam A Narmanov
address: 29, Viborgskaya nab.,
address: 198215 Saint Petersburg, Russia
phone: +7 812 3312999
fax-no: +7 812 3312999
e-mail: rustam@infobox.ru

---

All letters, postcards and «gift-wrapped» items to be shipped to the following address:

Russian Business Network
12 Levashovskiy prospect.
197110 Saint-Petersburg
Russia


Thank you.

LR

Sources, tools and references:
David Bizeul (provided the names first; verified!)
The Shadowserver Foundation
trendmicro.com
research.sunbelt-software.com http://blog.washingtonpost.com/securityfix...business_n.html
http://www.spacequad.com/article.php/open_letter
http://www.securityzone.org/?p=26
http://www.theregister.co.uk/2007/11/08/rbn_offline/
http://www.joewein.net/fraud/host-abdallah-internet.htm
http://ddanchev.blogspot.com/2007/11/sca...ystem.html
http://www.bobbear.co.uk/progoldinvestments.html
http://ddanchev.blogspot.com/2007_10_01_archive.html
(google cached documents now expired)
http://www.bobbear.co.uk/happykids.html
http://boardreader.com/tp/phishing+report.html
http://getpaidforum.com/forums/index.php?s...8560&pid=48
99207&st=0&#entry4899207
(Interesting...!)
http://www.threatexpert.com/report.aspx?ui...65-3ea604cf7857
http://64.233.167.104/search?q=cache:WlwSG....90.170&hl=
http://www.bobbear.co.uk/ultragame.html
http://blog.wired.com/27bstroke6/2007/10/c...oversial-r.html
http://news.netcraft.com/
http://www.siteadvisor.com/
http://cidr-report.org/
http://iptoolbox.fr/
hostip.info
robtex.com
asn.cymru.com/
centralops.net/co/
traceroute.org
http://relcom.net/INFO/NOC-IP/lg/lg0.html
ripe.net
http://www.domaintools.com
http://www.google.com
http://c.asselin.free.fr
spamhaus.org
http://www.cio.com/article/135500/
http://labs.idefense.com/intelligence/re...papers.php
http://badmalweb.com/
http://rbnexploit.blogspot.com/

(All info gathered from sources above, veryfied and confirmed by my own reaserch.)

Edit: Forgot some obvious sources. Added at the end of the list above.
(Credit to, where credits due.... Sorry.) :smile:
Edit 2: Added pic of Kuznetsov.
Edit 3: Added quote from 'guardian' on Flyman.

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
04-04-2008, 08:08 PM (This post was last modified: 04-04-2008 08:11 PM by LoopRadar.)
Post: #11
Spam, DDos and the RBN nazis
:RTFM:

And I'm off for a pint and real-humans-beans-interaction... :tongue:

LR

P.S. No I'm not answering e-mails on this. (Well, not stoopid ones, anyways...)

Edit: *mumbles to self*: "paranoid bloody fools. Imma get a new e-mail acc. soon..."

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
04-05-2008, 02:49 AM
Post: #12
Spam, DDos and the RBN nazis
Quote::RTFM:

And I'm off for a pint and real-humans-beans-interaction... :tongue:

LR

P.S. No I'm not answering e-mails on this. (Well, not stoopid ones, anyways...)

Edit: *mumbles to self*: "paranoid bloody fools."

There aren't two O's in STUPID.
Sorry you bloody fool, I couldn't resist. :tongue:
Quote this message in a reply
04-05-2008, 03:18 AM
Post: #13
Spam, DDos and the RBN nazis
Quote:
Quote::RTFM:

And I'm off for a pint and real-humans-beans-interaction... :tongue:

LR

P.S. No I'm not answering e-mails on this. (Well, not stoopid ones, anyways...)

Edit: *mumbles to self*: "paranoid bloody fools."

There aren't two O's in STUPID.
Sorry you bloody fool, I couldn't resist. :tongue:
:scream:HAHAHA!

LR

[Image: t_RBNexploitim_80ea8b4.jpg]
88.255.90.0/24 and 88.255.94.0/24 - Abdallah Internet Hizmetleri/RBN nazi's
Visit this user's website Find all posts by this user
Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 1 Guest(s)