r61 - 04 Dec 2008 - 12:09:26 - JamesMcQuaidYou are here: TWiki >  Main Web > AllProjects > SnortConfSamples > RussianBusinessNetwork
Emerging Threats Russian Business Network (RBN) Snort Intrusion Detection Rules:

* http://www.emergingthreats.net/rules/emerging-rbn.rules

* http://www.emergingthreats.net/rules/emerging-rbn-BLOCK.rules

"Call these hosts what you like, we see a large amount of hostile activity from these nets, and get little to no abuse response for takedown. Do what you will with this information." - Matt Jonkman

Russian Business Network background information compiled by JamesMcQuaid:

From JamesMcQuaid:

From Jart Armin: http://rbnexploit.blogspot.com

From Brian Krebs:

From Spamhaus:

From Dancho Danchev: http://ddanchev.blogspot.com/

From David Bizeul: http://isc.sans.org/presentations/RBN_study.pdf

From Shadowserver: 'Clarifying the "guesswork" of Criminal Activity': http://www.shadowserver.org/wiki/uploads/Information/RBN-AS40989.pdf

Wikipedia: http://en.wikipedia.org/wiki/Russian_Business_Network

To cover traffic from the RBN's fake anti-spyware tools (partially within Spamhaus XBL):

IP Range start IP range end AS # Name

64.28.176.0 64.28.191.255 AS27595 INTERCAGE 69.22.162.0 69.22.163.255 AS27595 INTERCAGE 69.22.168.0 69.22.175.255 AS27595 INTERCAGE 69.22.184.0 69.22.187.255 AS27595 INTERCAGE 69.31.64.0 69.31.79.255 AS27595 INTERCAGE 69.50.160.0 69.50.191.255 AS27595 INTERCAGE 85.255.113.0 85.255.117.255 AS27595 INTERCAGE 85.255.118.0 85.255.118.255 AS27595 INTERCAGE 216.255.176.0 216.255.191.255 AS27595 INTERCAGE

58.65.239.66 - RBN domain involved in the Bank of India hack. 58.65.234.17 and 58.65.234.18 - RBN domains for iFrame Cash (see Spamhaus Rosko) 58.65.232.0 - 58.65.239.255 = HOSTFRESH RBN alternative hosting (supposedly Hong Kong based, but Intercage / Estdomains etc. linkage)

200.115.160.0/20 AS26426 OPTYNEX (Central American-based Estdomains and Neo-Nazi linkage)

-- JamesMcQuaid - 13 July 2008

Topic attachments
I Attachment Action Size Date Who Comment
txttxt 4000RBNDomainsAndObjects.txt manage 83.1 K 24 Jan 2008 - 02:19 JamesMcQuaid 4,000 RBN Domains and Objects
elseEXT Atrivo-Smoothwall-config manage 3.3 K 18 Jun 2008 - 01:05 JamesMcQuaid  
txttxt Atrivo-config-hosts.txt manage 856.3 K 18 Jun 2008 - 01:04 JamesMcQuaid  
elseEXT Atrivo-domains manage 521.9 K 18 Jun 2008 - 01:03 JamesMcQuaid  
txttxt Atrivo-domains.txt manage 521.9 K 18 Jun 2008 - 01:03 JamesMcQuaid  
txttxt Atrivo-hosts.txt manage 755.8 K 18 Jun 2008 - 01:05 JamesMcQuaid  
txttxt Atrivo_IP_Space.txt manage 0.4 K 18 Jun 2008 - 01:04 JamesMcQuaid  
txttxt RBNAttackIPs.txt manage 15.8 K 24 Jan 2008 - 02:55 JamesMcQuaid Recent DOS attacks
txttxt RBNExploitDomains.txt manage 233.8 K 18 Aug 2008 - 21:58 JamesMcQuaid  
txttxt RBN_Commercial_Pedophile_Payment_Systems.txt manage 2.0 K 12 Jun 2008 - 03:00 JamesMcQuaid RBN Commercial Pedophile Payment Systems (and DNS responders)
txttxt RussianBusinessNetworkIPs.txt manage 20.4 K 04 Dec 2008 - 12:09 JamesMcQuaid  
txttxt TopLevelDomains.txt manage 0.4 K 24 Jan 2008 - 02:27 JamesMcQuaid Top Level Domains
txttxt badblogspotsubdomains.txt manage 186.8 K 16 Mar 2008 - 15:25 JamesMcQuaid These subdomains were created by an automated process following Google's captcha application was cracked.
txttxt badblogspotsubdomains_bindformat.txt manage 1136.2 K 16 Mar 2008 - 16:05 JamesMcQuaid In zone file Bind format.
elseEXT bindzone manage 13930.1 K 12 Jun 2008 - 03:14 JamesMcQuaid  
elseconf blackhole.conf manage 3497.7 K 24 Jan 2008 - 12:40 JamesMcQuaid  
txttxt blacklist.txt manage 29.1 K 13 Apr 2008 - 10:05 JamesMcQuaid  
Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r61 < r60 < r59 < r58 < r57 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback