article thumbnail

The Link Between AWM Proxy & the Glupteba Botnet

Krebs on Security

Things began looking brighter after I ran a search in DomainTools for web-site[.]ru’s ru’s original WHOIS records, which shows it was assigned in 2005 to a “private person” who used the email address lycefer@gmail.com. ” Finally, Russian incorporation documents show the company LLC Website (web-site[.]ru)was

Passwords 242
article thumbnail

15-Year-Old Malware Proxy Network VIP72 Goes Dark

Krebs on Security

An ad circa 2005 for A311 Death, a powerful banking trojan authored by “Corpse,” the administrator of the early Russian hacking clique Prodexteam. Image: Google Translate via Archive.org.

Malware 288
article thumbnail

Who and What is Behind the Malware Proxy Service SocksEscort?

Krebs on Security

That same IP was used to register the nickname “ Deem3n®, ” a prolific poster on Antichat between 2005 and 2009 who served as a moderator on the forum. Leaked copies of the hacked Antichat forum indicate the SSC identity tied to adriman@gmail.com registered on the forum using the IP address 71.229.207.214.

Malware 203