Kneecapped malware host tries to rise again

By Angela Gunn | Published September 25, 2008, 9:46 AM

InterCage (a.k.a., Atrivo), the network provider notoriously fingered as a major purveyor of malware, found its way back online after a days-long shutdown cheered by anti-malware and anti-spam activists.

Could pulling just one firm offline make a noticeable dent in the malware trafficking problem? That may depend on whether Sunday's move by former upstream provider Pacific Internet Exchange (PIE) to cut InterCage's connection makes an impression on owner Emil Kacperski.

Reports on Monday had the ISP's president and CEO bewailing his fate, saying, "I'm basically got to start all over." On Tuesday -- mission apparently accomplished -- a front page for the InterCage site turned up as a client of UnitedLayer Inc...but by late Wednesday, that page had vanished again. As of Wednesday evening, the site's status was uncertain, and representatives of UnitedLayer were unavailable for comment.

Why InterCage? As documented in a report undertaken by multiple anti-malware concerns and put together by HostExploit.com (PDF available here), the California firm sits at a bottleneck in the matrix of registrars, ISPs, and host services that do business with firms trading in botnets and similar unsavory wares.

The 40-page report, issued on August 28, summarizes InterCage's (Atrivo's) reputation bluntly: "A main conduit for financial scams, identity theft, spam and malware." Spamhaus, the anti-spam watchdog, is even more blunt in its own listing for InterCage's IP address: "Too much spam and crime -- routing must cease."

The numbers the report compiled were both hard and harsh. Looking at a sample 10% of Atrivo's 26,000 registered domains, the study mechanisms happened to scoop up 31 binaries -- all of which were known malware. The sample included 910 infected Web sites; 1,130 botnet command-and-control servers, and 7,340 links to malicious or simply fake "security" products, not including porn sites.

In addition, spam-incident reports at CastleCops say that Kacperski has been resistant to accepting and responding to spam complaints. HostExploit's writers snarked, "We have seen an earlier statement from Emil Kacperski on behalf of Atrivo stating, 'We will shut down and take offline any servers that have malicious software or causing harm to anyone. But of course we need proof that this is the case.' -- Well Emil we have the proof."

Kacperski had (unsurprisingly) strongly disputed the findings. But as a succession of upstream providers -- Bandcon, Global Networks, WVFiber -- dropped him in the wake of the report, he turned to PIE for transit services. PIE had only been providing those for a few days when Spamhaus added a block of that company's IP addresses to its famous blocklist; soon after, PIE lost its taste for InterCage's business.

Which suits the writers of the HostExploit report just fine. "It should be stressed such activities could not occur if commercial third parties or other organizations did not collaborate...Within a conventional criminal comparison, the supplier of the unregistered handgun used in a crime is also responsible for that crime."

So did malware propagation levels drop between Sunday morning -- specifically when PIE pulled the plug, and Tuesday when UnitedLayer stepped in? Premlimary reports are unclear. But any beneficial change may linger, if a chastened Kacperski holds to his promise to drop business relations with Esthost, the Eastern European Web host to which much of InterCage's problematic traffic has been linked.

A call to the number listed on the transitory InterCage/Atriva page led to voice mail for, allegedly, Emil Kacperski, but at press time BetaNews had received no response or comment on the status of the service.

Comments

View comments by with a score of at least

Oh look who decided to drop by, Hollywood_'s spamming cousin.

Score: 0

|

The admins are dropping the ball again...

Score: 0

|

this has nothing to do with a mac, there are more windows users so there is more money in malware for windows DUH!

Score: 0

|

If you're on a Mac who really cares? You're forever immune to malware.

(Now, now Windoze users there's no need to swear and curse at us privileged Mac users. It's not our fault that Apple builds Mac OS X on top of a rock solid UNIX foundation.)

http://www.apple.com/mac...echnology/security.html

Score: 0

|

True for most part. My concern is when mac usage picks up, then there will be a case for 'developers' to write malware for you guys.

Not so immune after all...

Score: 0

|

Gee, and no one runs to this idiot's rescue?

...If only he had tried to post an app to Apple's iPhone...

Score: 0

|

If this spammer was using Windows servers, maybe Tool will defend him. :P

In all seriousness, though..

Within a conventional criminal comparison, the supplier of the unregistered handgun used in a crime is also responsible for that crime."

Ummm, that's a completely bogus analogy. It wasn't the law that acted against PIE, it was a widely used blacklist. Even if the analogy was workable its like saying that a guy who sells a used gun to somebody could somehow see the future where the buyer commits a crime with that gun. Not even CA law (last I heard) works that way. Unless the seller actually knows theirs a crime being planned, all he can be charged with is selling an unlicensed weapon (in states and municipalities where that applies).

Score: 0

|

But the Windows servers couldn't be enterprise servers. You see, the business world of IT is off limits on this site, as is talk of understanding the financial underpinnings of tech decisions!

They could only be an individual's desktop...

You see, Tool is loathe to defend Windows in the Enterprise where it is outclassed by almost every commercial OS available, featuring many capabilities with the exception of the ability to play the games about which the Windows world (and users) revolve. ;-)

So more advanced capabilities only confuse people with the anathema of more functional choices. And after all, how can another OS compete if they do not play Windows games? Hey, they have lofty priorities in OS design...as long as they don't encounter an errant driver or wild pointer! LOL!

Score: 0

|

The guy hasn't even posted on this and you all are still complaining about him....ha

Score: 0

|

You are SO wrong! Go check out the 'slimming down windows 7' thread!

Sorry, as it does assume that one has read the threads and knows about that which they are commenting upon...

...And like your posts are worth commenting about?

Score: 0

|

Just for your info, you sell a gun or a car and if that new 'owner' commits a crime with it before you go down to the proper office and actually formally transfer the ownership of the property - as too many folks do in their 'sidewalk' sales - you are libel for any actions the other guy commits using the property.

And with guns, simply having them accessible makes you libel for another's use of the gun.

Funny, the same is true regarding personal data stored in an entity's system. Someone breaks/hacks in and steals it, and you are held libel for damages.

Hmmm...note any trends or precedence here?

Score: 0

|

You're whining again.

Score: 0

|

What's wrong? Didn't Spore install?

Score: 0

|

Haven't tried it.

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.