Costin Raiu
craiu's profile header
Costin Raiu

@craiu@infosec.exchange

Threat intelligence, Yara, reversing and everything APT.

November 4, 2022

I'm trying to understand why one of the worst bulletproof hosting providers out there today -- Russia-based Prospero OOO -- is now getting transit to the larger internet via the antivirus and security firm Kaspersky Lab?

cidr-report.org/cgi-bin/as-rep

Prospero (AS200593) has been tied to multiple bulletproof hosting providers advertising on Russian cybercrime forums that say they will ignore all abuse complaints. It operates an insane amount of phishing domains at any given time, and it's been connected with ransomware C2s and distribution of ransom-adjacent malware operations like SocGholish and GootLoader. But don't take my word for it. Have a look at just the recent stuff:

urlscan.io/search/#page.asn%3A

virustotal.com/gui/search/as20

intrinsec.com/prospero-proton6

I understand that Kaspersky Lab (AS209030) provides DDoS protection as one of its services, and its networks do indeed seem to include several large banks (Alfa Bank, and the Russian police, e.g.). But if that's really what this is, that's almost worse than Kaspersky just letting these providers transit their network.

Older posts from other instances may not be displayed.
Open in original site

Elk Logo

Welcome to Elk!

Elk is a nimble Mastodon web client. You can login to your Mastodon account and use it to interact with the fediverse.

Expect some bugs and missing features here and there. Elk is Open Source and we're actively improving it as a community project. Join us and let's build it together!

If you'd like to report a bug, help us testing, give feedback, or contribute, reach out to us on GitHub and get involved.

To boost development, you can sponsor the Team through GitHub Sponsors. We hope you enjoy Elk!

TAKAHASHI ShuujiJoaquín SánchezPatakAnthony Fu三咲智子 Kevin DengDaniel Roe

The Elk Team