Brian Krebs over at SecurityFix has done a nice job focusing on McColo.
Which lead to a couple of their providers "cutting the lines".
Maybe only a shortlived "victory", but I am enjoying it.
A couple of small details:
This is what I get today when trying to connect to a couple of the live domains on the botnet:

Could this be a result of McColo being down?
The infected homePC can't connect to the master sitting in McColo's space? Or is it just a coincidence?
I have no clue.
But I have not spotted any new domains the last days either on the Asprox botnet.
(Which of course does not mean that there aren't any, only that I through my primitive methods have not found them).
Two coincidences at the same time?
I would not be surprised if the botmasters are at McColo.
McColo has hosted at least a few chains in the payment process for child abusers.
The chain goes something like this:
Child abuse-site --> pay.aspire-systems.biz/[code] --> flashbill/flash-bill.[tld] --> bill-support.com
pay.aspire-systems.biz was hosted at 208.72.168.67, McColo.
The domain aspire-systems.biz now seems to be nuked by the registrar (Directi).
flashbill.net still points to 208.72.170.149 on McColo and therefore sleeps with the phishes at the moment (from my part of the world).
But another one was in place when McColo went off the air.
Hosted at the same IP as pay.aspire-systems.biz.
That domain is now hosted at ecatel.net, 89.248.168.80.
Already nicely placed in the Spamhaus Block List, SBL68266
Now eltel.net is on their way routing McColo.
Which has led to some listings in SBL.
In addition to McColo, here are a few other contributing to hosting of at least one of the chains in the payment process:
Try different variations of flash[-]bill.[tld] and you may find other hosts.
But they are moving around and there are several other networks hosting bits and pieces of this gangs operation.
Serving the pedophiles the abused children.
Recent comments
41 weeks 5 days ago
42 weeks 1 day ago
42 weeks 5 days ago
42 weeks 5 days ago
44 weeks 15 hours ago
1 year 22 weeks ago
1 year 22 weeks ago
1 year 25 weeks ago
1 year 25 weeks ago
1 year 26 weeks ago