Posts tagged as:

Atrivo-Intercage

Citizen Of the Internet

by certifiedbug on October 6, 2008

in Security

Gadi Evron’s Time for self reflection after the downfall of Atrivo-Intercage.

{ 0 comments }

Intercage, gone with the wind again

by certifiedbug on September 26, 2008

in Security

Backbone provider Global Crossing, which previously “de-peered” from Atrivo/Intercage, More on Atrivo-Intercage-Estdomains, has negated the decision by transit provider UnitedLayer to give Intercage upstream service.

“It has come to our attention that United Layer is now routing traffic for Intercage (AS 27595) over the Global Crossing network,” Andrew Ramsey, Global Crossing’s manager of information security operations, wrote in an email sent to UniterLayer on Wednesday morning. “Intercage was removed from our network for violating our acceptable use policy, and is not welcome to return under any circumstance.”

The Register: Net pariah Intercage back among the dead

Edit:
Robert McMillan, IDG News Service.

After being notified of more problems on the network this week, UnitedLayer pulled the plug on Intercage late Thursday afternoon, said UnitedLayer Chief Operating Officer Richard Donaldson. “We decided that, given the stuff that was going on and with a couple of infractions that we were made aware of, that they needed to purge themselves of any [malicious] stuff that remained,” he said.

Notorious ISP Intercage goes dark again

Hat Tip to Sandi at Spyware Sucks: Atrivo/Intercage have been knocked offline again?

The Report for AS27595 remains as it was before UnitedLayer became Intercage’s provider.
Certifiedbug; September 22, 2008. Atrivo-Intercage offline

{ 0 comments }

Intercage back

by certifiedbug on September 23, 2008

in Security

Apprantly IP transit provider UnitedLayer has agreed to provide upstream service to Intercage after Intercage agreed to completely sever ties with Esthost.

Intercage, Inc’s website has a holding page, it looks strangely familiar…

UnitedLayer operates out of the same San Francisco colocation facility as Intercage and Pacific Internet Exchange (PIE).

Kind of reminds me of Lizards that give up their tail to escape.

Is anyone else feeling dizzy yet.

Sources:
Report for AS27595
Controversial ISP Intercage now back online
‘Malware-friendly’ Intercage back among the living

{ 0 comments }

Atrivo, a.k.a Intercage, Washington Post

by certifiedbug on September 22, 2008

in Security

Internet Shuns U.S. Based ISP Amid Fraud, Abuse Allegations

“The truth is that nobody’s been reporting this stuff, but it’s illegal for me to just sniff around each and every site on my network and say, ‘Hey, what are you up to?,’” Kacperski said. “But if there’s a complaint, then I can deal with it, I have to deal with it. Instead of complaints, I get people labeling me as some kind of mafia kingpin or crime boss.”

nobody’s been reporting this stuff,” ?

http://www.google.com/search?hl=en&q=atrivo+malware
http://www.google.com/search?hl=en&q=intercage+malware

No doubt people will keep monitoring…

{ 0 comments }

Atrivo-Intercage offline

by certifiedbug on September 22, 2008

in Security

AS Report.

Report for AS27595

Name

INTERCAGE - InterCage, Inc.

NOT Announced

This AS is not currently used to announce prefixes in the global routing table, nor is it used as a visible transit AS.

Prefixes added and withdrawn by this origin AS in the past 7 days.

- 64.28.176.0/20 Withdrawn
- 67.210.0.0/21 Withdrawn
- 67.210.8.0/22 Withdrawn
- 67.210.14.0/23 Withdrawn
- 69.22.162.0/23 Withdrawn
- 69.22.168.0/21 Withdrawn
- 69.22.184.0/22 Withdrawn
- 69.31.64.0/20 Withdrawn
- 69.50.160.0/19 Withdrawn
- 85.255.113.0/24 Withdrawn
- 85.255.114.0/23 Withdrawn
- 85.255.116.0/22 Withdrawn
- 85.255.120.0/23 Withdrawn
- 85.255.122.0/24 Withdrawn
- 216.255.176.0/20 Withdrawn
- 216.255.176.0/22 Withdrawn
- 216.255.180.0/22 Withdrawn
- 216.255.184.0/22 Withdrawn
- 216.255.188.0/22 Withdrawn

http://cidr-report.org/cgi-bin/as-report?as=AS27595

NANOG:
Atrivo/Intercage: NO Upstream depeered at 2:25am est

Emil Kacperski started this topic: Re: Atrivo/Intercage: NO Upstream depeer

It gets a little heated, I guess this sums it up.

> Anything else you’d like to throw at me here on NANOG?
Sure, but I havn’t figured out how to hit someone with a two-by-four
over the Internet.

{ 1 comment }

Domains Hosted By Intercage

by certifiedbug on September 16, 2008

in Security

Alex Eckelberry,

So… what kind of domains are on Intercage?

Gary Warner wanted to find out and has now posted the Mother of all Lists of (almost) all Intercage domains.

What kinds of domains does Intercage host?

{ 0 comments }

More on Atrivo-Intercage-Estdomains

by certifiedbug on September 7, 2008

in Security

In a follow up to his article Report Slams U.S. Host as Major Source of Badware Brian Krebs reports that Global Crossing has “de-peered” from Atrivo/Intercage.

Krebs has a short Quick Time movie he made that shows this de-peering in action.

WVFiber has decided to drop Atrivo as a customer, leaving Bandcon the single upstream provider for Atrivo.

Edit: Please see comment by Todd Braning below.

Also the update from Brian Krebs, Washington Post.

Update, Monday, Sept 8, 12:00 p.m. ET: Todd Braning, vice president of BandCon, just e-mailed me to say that BandCon also has stopped providing connectivity to Atrivo/Intercage. From his e-mail: “Intercage, a new customer, was connected to the BandCon Network for total of about a week. Once we recognized and issue with Intercage, BandCon took immediate action and terminated services. We are no longer providing services to AS27595. This can be confirmed here.”

/edit.

Furthermore, nLayer Communications has demanded Atrivo return roughly 7,400 IP addresses by Sept 30.

Scammer-Heavy U.S. ISP Grows More Isolated

Busy day, Russ at Intercage on NANOG.
InterCage, Inc. (NOT Atrivo)

Good morning.
Seeing the activity in regards to our company here at NANOG, I believe this is the most reasonable and responsible place to respond to the current issues on our network. We hope to obtain non-bias opinion’s and good honest and truthful information from the users here.

Being that there are much larger operators here then us, what kind of insight can you give to the issues that have arisen?

We’ve near completely removed (completion monday 09/08/08) Hostfresh from our network. 2 of their /24’s have been removed:
58.65.238.0/24 dropped
58.65.239.0/24 dropped
The machine’s they leased from us have been canceled.

What do you suggest for the next move?

Thank you for your time. Have a great day.


Russell M.
InterCage, Inc.

“what kind of insight can you give to the issues that have arisen?”

Biting my tongue….

{ 4 comments }