Related Stories

  • US standards drive Canadian information security
    An absence of legislation and the presence of the laissez-faire attitude has resulted in Canada being rather lax when it comes to information security compliance. Robin Arnfield looks at how US standards are driving the Canadian information security marketplace
  • Zero Day of the Dead
    The data load that has accompanied the globalization of trade would make even Atlas stagger. And that’s without the added burden of counter-terrorisAs you read this, zombie programs are flitting across the internet like a pestilence to infect and drain the life from innocent computer systems. Yet, for all the aggravation and grief they cause, you may never know you are part of a global invasion of the system snatchers, says William Knight. Unless…
  • The black art of digital forensics
    What makes a good digital forensics specialist? Steve Gold looks at some of the latest applications and investigates how the forensic investigator’s role has evolved in order to comply with changing customer priorities
  • Nine lives - when malware becomes self-modifying
    As the Conficker (aka Downadup and Kido) worm proved when it first appeared in October 2008, there's more to a piece of malware code than meets the eye, especially when it is self-updating. But can self-updating also mean self-modifying? Steve Gold investigates whether an IT security manager's nightmare has become programming reality...
  • Educating children on data protection
    The use of biometrics and CCTV in school classrooms - installed to protect pupils - may just as easily put them at risk of other dangers. What, then, can be done to prepare our children for the big wide world of data protection? Rob Stringer reports…

News

Ukrainian ISP servers shut down

04 February 2009

UkrTeleGroup, an infamous internet service provider in the Ukraine, has had its primary IP connection "depeered" by FiberNet, the Miami-based uplink provider.

The ISP's servers were reportedly at the centre of a set of botnets operated by the Zlob (aka DNSChanger) family of Trojans.
Tim Fitzpatrick, a spokesperson for the FPL Group, FiberNet's parent operation, is quoted by the Washington Post as saying that UkrTeleGroup's peering connections were terminated due to its violation of the company's terms of agreement.
The DNSChanger Trojan usually consists of 1.5 kilobytes file that is designed to change the 'NameServer' Registry key value to a custom IP address.
This IP address, Infosecurity understands, is usually encrypted in the body of a Trojan. As a result of this change a victim's PC will contact the newly assigned DNS server to resolve names of different web servers.
The web server IP addresses are generally found to be fake, and are really web sites designed to capture personal data that includes payment card details and social security numbers.
This is not the first time that an Eastern European ISP has had its internet connection revoked.
Last year saw estDomains, the infamous McColo ISP, which served as a home for the command and control servers for multiple botnets, was disconnected from the internet.
 

 

This article is featured in:
Data Loss Internet and Network Security Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.