Saturday, January 1, 2011

Blocking the Heihachi and 2x4.ru Networks

Lance Corporal Albert Miranda, Lance Corporal David Burdwell, and platoon Lieutenant Alec Bodenwiser hold Khe Sanh

USMC Lance Corporal Albert Miranda, Lance Corporal David Burdwell, and platoon Lieutenant Alec Bodenwiser hold Khe Sanh.

(photograph by David Douglas Duncan)


Heihachi Ltd. is a bulletproof, blackhat-hosting provider, located in the Russian Federation, which is a well known safe haven for Internet as well as, real world criminals. Heihachi hosts a large number of domains, the operators of which are engaged in hard core crime. The types of crimes these domains perpetrate include bank fraud, wire fraud, stolen credit card (carder), piracy, brand jacking, money mule recruiting, illegal drugs, illegal pornography, human smuggling, botnet operation, stealth malware, web site hacking, denial of service attacks, spam and phishing. It is more than disturbing that the Russian and Ukrainian governments shield these predators from prosecution. In December, Heihachi launched denial of service attacks against Spamhaus, and set up a mirror site from which it could attack the computers of those attempting to visit WikiLeaks. Heihachi Ltd. operates front companies in Panama and elsewhere.

Closely allied with Heihachi is the 2x4.ru network, operated from Moscow by Pavel Ivanov. Ivanov sits at the nexus between the criminality and terrorism. He is believed to have enabled terrorist activity. Ivanov operates shell companies in the Seychelles Islands and elsewhere (the address he used in registering these fronts in the Seychelles is actually that of a hotel).

This is transnational organized crime at its worst.

Heihachi-2x4.txt is a list of Heihachi and 2x4.ru domains, and you are well advised to add these to your DNS black hole and blocklists. You can freely download the file at:
http://www.jamesmcquaid.com/Heihachi-2x4.txt

James McQuaid
1-1-2011