Feeds

ICANN cast as online scam enabler

And now a word for our illegal online pharmacy sponsor

Choosing a cloud hosting partner with confidence

Note: Officials at LogicBoxes and Directi take strong exception to the reports discussed in this story. Their objections are detailed in this follow-up story.

Two recently issued reports portray the Internet Corporation for Assigned Names and Numbers (ICANN) as a bureaucracy that enables cyber criminals.

In one report (PDF), researchers Jart Armin, James McQuaid and Matt Jonkman detail how one of ICANN's prized sponsors has ties to one of the net's more prolific sources of malware and illegal online pharmacies. It's called LogicBoxes, and over the past two years, ICANN has listed it as a sponsor for meetings that took place in Los Angeles and Delhi, India.

It turns out that LogicBoxes has an association with Atrivo, a network provider that also goes by the name of Intercage. According to the study, a random sampling of 2,600 addresses hosted by Atrivo revealed 7,340 malicious web links, 910 infected websites, 310 malicious binaries, and 113 botnet command and control servers. As an autonomous systems (AS) provider, the Concord, California-based company controls a large number of IP addresses.

The report details how Atrivo works with a rogue's gallery of other companies to enable anonymous sites that punt scareware, malware and online sites pushing Viagra and other sites. Other companies include Hostfresh, EstHost, EstDomains and PrivacyProtect.

In an email to The Register, Atrivo principal Emil Kacperski declined to comment.

A second report issued by an outfit known as Knujon (that's "no junk" spelled backwards) details 48 phantom domain name registrars whose sole purpose seems to be the registration of addresses used in spam and malware campaigns. All of them can be linked back to the Directi Group, which has long been a prolific provider of URLs to scammers.

According to Knujon, the 48 registrars are violating ICANN's own rules requiring them to clearly identify their business name and business address. That's something registrars are reluctant to do when they're spewing out sites as unpopular as these.

ICANN is the government-appointed group that accredits registrars. A spokesman for the group didn't return our calls for comment.

Yes, we realize the net is a big place and it's not possible to know the reputation of every group ICANN accredits or takes money from. But it's not unreasonable to expect the gatekeeper to enforce its own rules, especially given the proliferation of sites pushing spam, malware and other scams. And while ICANN did nothing wrong accepting sponsorship money from LogicBoxes, it's fair to say the the relationship doesn't look good, so long as LogicBoxes continues to keep company with the likes of Directi and Atrivo.

So next time you receive a spam or a popup fraudulently claiming your PC is hosed, think of ICANN. ®

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
China is ALREADY spying on Apple iCloud users, watchdog claims
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.