Feeds

Ukrainian cybercrime-friendly ISP hit by fire after clean-up

How curious

Secure remote control for conventional and virtual desktops

A Ukrainian ISP hit by fire over the weekend was in the process of cleaning up its act after earlier being labelled as a leading haven for cybercrime, PC World reports.

Odessa-based Hosting.ua was hit by a fire on March 27 that resulted in severe damage to its infrastructure and took it offline. HostExploit.com, which tracks the distribution of crimeware on the net, reported late last year that Hosting.ua was the fourth in a rogue's gallery of ISPs that hosted spam, malware or other internet crud.

However, over the last three months the Ukranian ISP had begun cleaning up its act, dropping way down to rank 381 in HostExploit.com's list of shame. Of the 5,381 websites tested on this network over the past three months, 291 of the websites served content that resulted in malicious downloads.

Pressure from law enforcement and upstream providers may have pushed Hosting.ua towards cleaning up its business. Being identified as a haven for cybercrime leads to blacklisting that can affect the site of legitimate customers hosted with an ISP, a security researcher who worked with HostExploit.com who goes by the nickname Jart Armin explained.

Hosting.ua is home to an estimated 500,000 websites. It's unclear when it will be able to restore services to normal. A holding statement on the host site (Google translation below) charts the progress towards restoring services.

Full coverage of the incident will be given later, at a time when there will be a free human resources at the moment we can afford only short messages, to keep everyone informed.

In particular, we want to inform you that, at present, developments, we can conclude that the data remained in a virtual hosting is not corrupted backup servers.

Power lines, diesel generators, switchboards, optical backbone is not affected and have switched to the second premise datacenters, which was scheduled to launch in 3[rd] quarter of 2010.

At present, work is underway to restore the efficiency of virtual hosting and construction of racks to move the unaffected servers. It is primarily about servers with letter indices A, B, C, D, G. Information from the server, the indexes that begin with E and F is beyond repair, users of these servers will provide new dedicated server.

Some of the bad sites formerly hosted with Hosting.ua have migrated to the US, according to HostExploit.com

The cause of the fire is also unknown, but Armin of HostExploit cited unconfirmed reports from the Ukraine suggesting that fire alarms at the site may have been deliberately disconnected, providing circumstantial evidence of arson.

HostExploit.com has pictures of the aftermath of the fire at Hosting.ua in an informative blog entry here. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
10 threats to successful enterprise endpoint backup
10 threats to a successful backup including issues with BYOD, slow backups and ineffective security.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.