The Register® — Biting the hand that feeds IT

Feeds

Ukrainian cybercrime-friendly ISP hit by fire after clean-up

How curious

Customer Success Testimonial: Recovery is Everything

A Ukrainian ISP hit by fire over the weekend was in the process of cleaning up its act after earlier being labelled as a leading haven for cybercrime, PC World reports.

Odessa-based Hosting.ua was hit by a fire on March 27 that resulted in severe damage to its infrastructure and took it offline. HostExploit.com, which tracks the distribution of crimeware on the net, reported late last year that Hosting.ua was the fourth in a rogue's gallery of ISPs that hosted spam, malware or other internet crud.

However, over the last three months the Ukranian ISP had begun cleaning up its act, dropping way down to rank 381 in HostExploit.com's list of shame. Of the 5,381 websites tested on this network over the past three months, 291 of the websites served content that resulted in malicious downloads.

Pressure from law enforcement and upstream providers may have pushed Hosting.ua towards cleaning up its business. Being identified as a haven for cybercrime leads to blacklisting that can affect the site of legitimate customers hosted with an ISP, a security researcher who worked with HostExploit.com who goes by the nickname Jart Armin explained.

Hosting.ua is home to an estimated 500,000 websites. It's unclear when it will be able to restore services to normal. A holding statement on the host site (Google translation below) charts the progress towards restoring services.

Full coverage of the incident will be given later, at a time when there will be a free human resources at the moment we can afford only short messages, to keep everyone informed.

In particular, we want to inform you that, at present, developments, we can conclude that the data remained in a virtual hosting is not corrupted backup servers.

Power lines, diesel generators, switchboards, optical backbone is not affected and have switched to the second premise datacenters, which was scheduled to launch in 3[rd] quarter of 2010.

At present, work is underway to restore the efficiency of virtual hosting and construction of racks to move the unaffected servers. It is primarily about servers with letter indices A, B, C, D, G. Information from the server, the indexes that begin with E and F is beyond repair, users of these servers will provide new dedicated server.

Some of the bad sites formerly hosted with Hosting.ua have migrated to the US, according to HostExploit.com

The cause of the fire is also unknown, but Armin of HostExploit cited unconfirmed reports from the Ukraine suggesting that fire alarms at the site may have been deliberately disconnected, providing circumstantial evidence of arson.

HostExploit.com has pictures of the aftermath of the fire at Hosting.ua in an informative blog entry here. ®

Ensure Ease of Recovery with Asigra’s Agentless Software

Not Da Boy Scouts...

I suspect that some of their former customers may have gotten a bit upset at their attempt at disengagement.

Expect more of the same, including murder. The Russians are a tough crowd, and it's been a long time since spotty-faced kids were the ones doing the hacking.

Just wait until the rival gangs start going after each other, like we have in the US...

3
0

Just a matter of time

"Expect more of the same, including murder."

All the more reason for law enforcement (or vigilantes, doesn't matter) to track down the *real* people behind this stuff and nail their sorry asses to the wall. How bad do things have to get before governments/etc wake up? Probably pretty bad, like a crosswalk where dozens of people have to get run over and killed before the powers-that-be deign to install a stoplight.

1
0

Destroy the evidence

"fire alarms at the site may have been deliberately disconnected"

Maybe the owners trying to cover their tracks even more. Who knows what *else* might have been on the servers there.... hmm.... or not.

1
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats