r183 - 06 Aug 2010 - 03:24:58 - JamesMcQuaidYou are here: TWiki >  Main Web > AllProjects > SnortConfSamples > RussianBusinessNetwork
Russian Business Network

"Call these hosts what you like, we see a large amount of hostile activity from these nets, and get little to no abuse response for takedown. Do what you will with this information." - Matt Jonkman

Emerging Threats Russian Business Network (RBN) Snort Intrusion Detection Rules:

* http://www.emergingthreats.net/rules/emerging-rbn.rules

* http://www.emergingthreats.net/rules/emerging-rbn-BLOCK.rules

Emerging Threats Firewall Rules:

* http://www.emergingthreats.net/fwrules/

Russian Business Network background information compiled by JamesMcQuaid:

From JamesMcQuaid:

          RBN IP Block List:

  • RussianBusinessNetworkIPs.txt Updated 8-6-2010: IP address ranges from which the former customers of the RBN ISP, their malware marketing affiliate networks, emulators, and other organized crime groups exploit consumers. Block at will. Test for your production environment prior to utilization. In cases where a malicious domain occupies an IP address used by many domains, the IP address is not included in this list (due to false positives in Snort and Suricata). Those domains are included in the DNS Blackhole for Smoothwall at http://doc.emergingthreats.net/bin/view/Main/HoneywallSamples

  • RBNIPListOptional.txt Updated 4-2-2010: Crime friendly IP address ranges that most businesses can block in or out at the perimeter firewall.

  • RBNIdentities.txt Registrant nom de guerres associated malicious and infected domains.

From Jart Armin: http://rbnexploit.blogspot.com

From Brian Krebs:

From Spamhaus:

From Dancho Danchev: http://ddanchev.blogspot.com/

From David Bizeul: http://isc.sans.org/presentations/RBN_study.pdf

From Shadowserver: 'Clarifying the "guesswork" of Criminal Activity': http://www.shadowserver.org/wiki/uploads/Information/RBN-AS40989.pdf

Wikipedia: http://en.wikipedia.org/wiki/Russian_Business_Network

-- JamesMcQuaid - 21 June 2010

Topic attachments
I Attachment Action Size Date Who Comment
txttxt RBNIPListOptional.txt manage 1.5 K 02 Apr 2010 - 15:43 JamesMcQuaid  
txttxt RBNIdentities.txt manage 82.2 K 13 Dec 2009 - 19:26 JamesMcQuaid  
txttxt RBN_Observations_2nd_Quarter_2010.txt manage 1121.9 K 06 Jul 2010 - 01:20 JamesMcQuaid  
txttxt RussianBusinessNetworkIPs.txt manage 92.0 K 06 Aug 2010 - 03:24 JamesMcQuaid  
Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r183 < r182 < r181 < r180 < r179 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback