Maxim Goncharov, BPHS pac_sec

56
2015 Maxim Goncharov [email protected] BPHS Maxim Goncharov bullet proof hosting services Criminal Hideouts for Lease Bulletproof Hos4ng Services

Transcript of Maxim Goncharov, BPHS pac_sec

Page 1: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

BPHSMaxim Goncharov

bullet proof hosting services

CriminalHideoutsforLeaseBulletproofHos4ngServices

Page 2: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

2

What is BPHS?

Hardware VPS

Any type of content

С2 Spam Adult DMCA SEO Drop

Page 3: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

Germany

3

Infrastructure of BPHS?

Attacker Victime

Page 4: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

RussiaPanama

4

Infrastructure of BPHS?

Attacker Victime

BPHS Target

Page 5: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

5

BPHS Categorisation

CAT 1 CAT 2 CAT 3

Page 6: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

6

BPHS Categorisation

Done on purpose

Stolen credentials

Violating the terms of service

CAT 1

CAT 2

CAT 3

Page 7: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

7

They know what they’re doing

Describe what they do not doing

Explain geographical specification

All types of activities

Done on purposeCAT 1

Page 8: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

8

Bruteforce

proxy malicious traffic

SEO activities

Drop zones

Stolen credentialsCAT 2

Page 9: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

9

CAT 2 Stolen credentials

Page 10: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

10

CAT 3 Violating the terms of service

Page 11: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

11

BPHS advertising

SEO

Page 12: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

12

Page 13: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

13

BPHS advertising

Dedicated

VPN

Page 14: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

14

Page 15: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

15

BPHS advertising

DMCA

Digital Millennium Copyright Act

Page 16: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

16

BPHS advertising

Digital Millennium Copyright Act

Page 17: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

17

Page 18: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

18

BPHS advertising

C2

my.Galkahost.com

Page 19: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

19

Page 20: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

20

BPHS advertising

SPAM

spamz.ru

Page 21: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

21

Page 22: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

22

Types of Activities?

Fake

DMCA

Torrents

SEO

VPN

Brutforce

SPAM

Malware Dropzone

Exploit

C2

Child Pornography

Page 23: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

23

BPHS Toxic levels

Fake

DMCA

Torrents

SEO

VPN

Brutforce

SPAM

Malware Dropzone

Exploit

C2

Child Pornography

Page 24: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

24

Some BPHS operational details

Types of ads on the forums

Legitimate search engine ads

underground forums

Page 25: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

25

Some BPHS operational details

Support at BPHS

ICQ

Jabber

Javascript

24/7

Page 26: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

26

Some BPHS operational details

DDoS mitigation at BPHS

Page 27: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

27

Some BPHS operational details

Hide Real IP

White Hat services

Multi Level Proxy protection

Page 28: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

28

Political/Regional specifications.

“We do not accept/allow on our servers child pornography and projects which can cause damage to Russian Federation / Ukraine / Belorussia. We also will not be happy in case of our IP addresses will appear to often in Blacklists of Spamhaus. Violation of these two rules can cause permanent interruption in the services you rent from us. All other activities not mentioned - are allowed.”

Page 29: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

29

Use Case

Page 30: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

30

Page 31: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

31

Page 32: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

32

Child Pornography no go, but…

Location decided by sales/support

Host anything

No Attacks on RU or UA

Radware

Cacti/Zabbix

Out of the box configuration for:

Zeus

Citadel

Carberp

Page 33: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

33

Page 34: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

34

nickname sosweet

Page 35: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

35

randservers.comrandservers.com

Page 36: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

36

Page 37: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

37

randservers

sosweet

Page 38: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

38

Page 39: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

39

Page 40: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

Page 41: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

Page 42: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

We hold absolute every type of content if we hosting in Ukraine

Page 43: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

43

randservers

BPHS Classification

Toxic Level T1

Category CAT1

GEO Loc UA

GEO Act GLOBAL

Price $100/$300

Popularity High

Longevity 7 years

Page 44: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

44

Detection

Page 45: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

45

Page 46: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

46

Page 47: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

47

AS7643VietNam Data Communication Company (VDC)

http://vinahost.vn/

Page 48: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

48

Page 49: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

49

Page 50: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

50

“Bad” site

ASN

Check Malware with IP range

CAT1 CAT2 CAT3

Conclusion

algorithm #1

Page 51: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

51

Domain Name Registrar

ASN

Reverse DNS

“Bad” domain name

Name Server

algorithm #2

Page 52: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

52

OVH Statistics

Unique IPs seen All IPs researched

Botnet IPs seen

1.080.576185.311

1.238

Page 53: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

53

OVH Statistics

Page 54: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

54

c2 zeus asproxgrum festi salitystorm zeroaccess koobfacebagle flame kelihoscutwail gumblar virutakbot bredolab mariposanitol waledac lethic

Name of Botnet IPsc2 688

zeus 185asprox 129

grum 74festi 30

sality 30storm 30

zeroaccess 22koobface 10

bagle 6flame 6

kelihos 5cutwail 4

gumblar 4virut 4

akbot 2bredolab 2mariposa 2

nitol 2waledac 2

lethic 1

OVH Statistics

Page 55: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

55

1 ccihosting.com Panama Credit Card, PayPal, Bank Transfer, Liberty Reserve, Western Union

5 N/A N/A

2 goip.com Beliz -> Netherlands PayPal, Skrill CC 3 Elcatel internetbs.net

3 webcare360.com Pakistan / Romaina PayPal, Moneybookers, Payza (AlertPay)

4 N/A N/A

4 cinipac.com Malaysia -> USA / Malaysia / Romania / Iceland Paysafecard, Ukash, Liberty Reserve, Webmoney, Moneybookers, Bitcoin, Paypal, Cash by Post

3 N/A N/A

5 panamaserver.com Panama All 10 N/A N/A

6 katzglobal.com US / Malaysia -> India / Malaysia / China / Hong Kong / Singapore / Australia / USA

All 10 N/A N/A

7 shinjiru.com Malaysia -> Malaysia / Singapore / Netherlands / Luxembourg / Lithuania

Credit Card, Western Union, Paypal, Liberty Reserve, Wired Transfer, Mail Payment, Moneybookers

6 N/A N/A

8 offshorehosting.com Hong Kong / Malaysia -> Hong Kong N/A 10 N/A N/A

10 wrzhost.com USA-> Netherlands / Russia / Germany / Switzerland / Hong Kong

MoneyBookers, Liberty Reserve, PayPal, Payza

9 N/A N/A

11 koddos.com Belize / Netherlands -> Netherlands PayPal, Credit Card, Liberty Reserve, Perfectmoney, SolidTrustPay

9 N/A N/A

12 prq.se Sweden PayPal, Credit Cards, Wiretransfer

10 N/A N/A

13 hostingpanama.com Panama N/A 8 N/A N/A

14 hostimvse.ru Romania / Russia -> Netherlands All 10 Elcatel / Voxility N/A

15 uxar-host.ru Litva -> USA / NEtherlands All 5 N/A N/A

16 bulletproof-web.ru Europe N/A 10 OVH / Hetzner N/A

17 blackservers.org Russia -> Romania Webmoney Qiwi Bitcoin 25 N/A N/A

Page 56: Maxim Goncharov, BPHS pac_sec

2015 Maxim Goncharov [email protected]

56

Questions