Sponsored by..

Friday 3 December 2010

Evil network: Asociatia Family Network Connections / FAMILY-NETWORK AS49253 (95.64.110.0/23)

Asociatia Family Network Connections / FAMILY-NETWORK is a Romanian network, and their AS49253 netblock seems to have suddenly turned evil.

The SiteVet report for this AS shows a sudden increase in recent weeks, with over 1500 sites that may be malicious included in the 95.64.110.0/23 block. Most of these evil sites are on just one host, 95.64.110.100. There may be some legitimate sites here, but probably too few to worry about.

Most sites registered here appeared to be Russian, some are registered through Chinese registars. The owner of this block is listed as:

inetnum:        95.64.110.0 - 95.64.111.255
netname:        FAMILY-NETWORK
descr:          Asociatia Family Network Connections
country:        RO
admin-c:        CS6903-RIPE
tech-c:         CS6903-RIPE
status:         ASSIGNED PA
mnt-by:         NETSERV-MNT
mnt-routes:     FAMILY-NETWORK-MNT
mnt-domains:    FAMILY-NETWORK-MNT
source:         RIPE # Filtered

person:         Claudiu Sandulescu
remarks:        Asociatia Family Network Connections
address:        Str. Vlahita nr.4, Bl. PM8, Ap. 72
address:        Sector 3, Bucuresti
phone:          +40728188052
mnt-by:         FAMILY-NETWORK-MNT
abuse-mailbox:  claudiusandulescu@gmail.com
nic-hdl:        CS6903-RIPE
source:         RIPE # Filtered

route:          95.64.110.0/23
descr:          FAMILY-NETWORK
origin:         AS49253
mnt-by:         FAMILY-NETWORK-MNT
source:         RIPE # Filtered

Added: the owner of this netblock says that it is no longer in use, so it does appear that it has been hijacked somehow.. that would be consistent with the suddenly bad rankings.

You can see a CSV of domains and MyWOT ratings here, but there are too many domains to list here. Some of the domains have come from MD-ISP-MONITORING in Moldova.

Currently active IPs are:
95.64.110.36
95.64.110.37
95.64.110.43
95.64.110.45
95.64.110.48
95.64.110.50
95.64.110.66
95.64.110.100
95.64.110.105
95.64.111.11
95.64.111.12
95.64.111.14
95.64.111.15
95.64.111.16
..although to be honest, you should just block the lot of them.

3 comments:

Unknown said...

i have to make a correction to this article: FAMILY-NETWORK is stopped from may 2010, but I didn.t ask RIPE to remove informations about AS and assigned block.

As you can see, in the past 90 days is not logged any activity for our network:

http://bgp.he.net/AS49253#_asinfo

I cannot explain why our IPs are reachable in internet.

Conrad Longmore said...

It looks like the netblock has been hijacked somehow, I don't know how. It would explain why the rankings suddenly got very bad indeed when before there was no problem (I added a note to the post to clarify)

Unknown said...

Asociatia Family Network Connections / FAMILY-NETWORK is not registered any more with RIPE.
Thanks for notice me.