Guest User

ColoCrossing ILLEGALLY hosting IRANIAN websites on AS61406

a guest
Mar 28th, 2013
332
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. (BUFFALO, NY) - MARCH 2013 : COLOCROSSING AKA JON BILOH HOSTING IRANIANS ILLEGALLY / VIOLATING IRAN USA TRADE EMBARGO
  2.  
  3.  
  4. This is a story about an internet provider, who built a low end marketplace under false pretenses.
  5.  
  6. Colocrossing, is a Buffalo, New York, company that specializes in colocation and dedicated server rentals.
  7.  
  8. The United States Treasury lists the Country of Iran on an embargo list. United States citizens and corporations are disallowed from conducting business or trade with Iranians.
  9. [link: http://www.treasury.gov/resource-center/sanctions/Programs/pages/iran.aspx]
  10.  
  11. This is how Colocrossing is engaged in business transactions with multiple Iranian companies. It involves both direct downstream peering to a company named Herodap Solutions E, which used a California apartment address for various registration details.
  12.  
  13. We show the peering this way:
  14.  
  15. Go to: http://bgp.he.net/AS36352
  16.  
  17. Click: Peers v4 ---> http://bgp.he.net/AS36352#_peers
  18.  
  19. *** notice #13 ***
  20. 13 AS61406
  21.  
  22. Click: AS61406 ---> http://bgp.he.net/AS61406
  23.  
  24. Click: Prefixes v4 ---> http://bgp.he.net/AS61406#_prefixes
  25.  
  26. Prefix Description
  27. 185.2.12.0/23 Herodap Solutions E
  28. 185.2.14.0/23 Herodap Solutions E
  29.  
  30. Note the Iranian flag.
  31.  
  32.  
  33. [source: http://www.ris.ripe.net/dashboard/AS61406 ]
  34.  
  35. Prefix Size Last seen First seen Whois Registry Peers seeing
  36. 185.2.14.0/23 23 2013-02-15 22:44:55 UTC 2012-12-03 21:31:02 UTC W RIPE NCC 103
  37. 185.2.12.0/23 23 2013-02-15 22:44:55 UTC 2012-12-03 21:30:31 UTC W RIPE NCC 103
  38.  
  39. [source: http://www.cidr-report.org/cgi-bin/as-report?as=AS61406&view=2.0]
  40. aut-num: AS61406
  41. as-name: HerodapSolutions
  42. descr: Herodap solutions E
  43.  
  44. Information related to 'AS61406'
  45.  
  46. aut-num: AS61406
  47. as-name: HerodapSolutions
  48. descr: Herodap solutions E
  49. org: ORG-HA311-RIPE
  50. import: from AS36352 accept ANY
  51. import: from AS57497 accept ANY
  52. export: to AS36352 announce AS61406
  53. export: to AS57497 announce AS61406
  54. admin-c: AH8153-RIPE
  55. tech-c: AH8153-RIPE
  56. mnt-by: RIPE-NCC-END-MNT
  57. mnt-by: AH86906-MNT
  58. source: RIPE # Filtered
  59.  
  60. organisation: ORG-HA311-RIPE
  61. org-name: Herodap solutions E
  62. org-type: OTHER
  63. address: Stenhammarsvagen 31 802 67
  64. mnt-ref: FH72714-MNT
  65. mnt-by: AH86906-MNT
  66. source: RIPE # Filtered
  67.  
  68. person: Abolfazl Hayati
  69. address: 435 Reflections Cir Apt 11 San Ramon Ca 94583
  70. phone: +19038904393
  71. nic-hdl: AH8153-RIPE
  72. mnt-by: AH86906-MNT
  73. source: RIPE # Filtered
  74.  
  75.  
  76. Now we have following points:
  77. AS61406
  78. Herodap Solutions E
  79. HerodapSolutions
  80. Abolfazl Hayati
  81. 435 Reflections Cir Apt 11
  82. 185.2.12.0/23
  83. 185.2.14.0/23
  84.  
  85.  
  86. 435 Reflections Cir Apt 11:
  87.  
  88. http://www.enom.com/whois/royal-servers-com.html
  89. ROYAL-SERVERS.COM
  90.  
  91. Registration Date: 31-Oct-2007
  92. Expiration Date: 31-Oct-2013
  93.  
  94. Status:ACTIVE
  95.  
  96.  
  97. Name Servers:
  98. ns1.royal-servers.com
  99. ns2.royal-servers.com
  100.  
  101.  
  102. Registrant Contact Details:
  103. Royal Server
  104. seyed jafar bagheri
  105.  
  106.  
  107. 435 Reflections Cir ,Apt 11
  108. Sah roman
  109. California,94583
  110. US
  111. Tel. +925.3894455
  112.  
  113.  
  114.  
  115. Domain Name: MAJMAELMI.COM
  116.  
  117. Registration Date: 01-Sep-2007
  118. Expiration Date: 01-Sep-2013
  119.  
  120. Status:LOCKED
  121.  
  122. Name Servers:
  123. ns1.mymizban.com
  124. ns2.mymizban.com
  125.  
  126. Registrant Contact Details:
  127. Sindad
  128. Morteza Soltani ([email protected])
  129. AmirAbad Shomali, Sindad Corp
  130. Tehran
  131. Tehran,94583
  132. IR
  133. Tel. +21.44008444
  134.  
  135.  
  136. Domain Name: MYMIZBAN.COM
  137.  
  138. Registration Date: 02-Jul-2006
  139. Expiration Date: 02-Jul-2013
  140.  
  141. Status:ACTIVE
  142.  
  143.  
  144. Name Servers:
  145. ns1.mymizban.com
  146. ns2.mymizban.com
  147.  
  148.  
  149. Registrant Contact Details:
  150. Sindad
  151. Morteza Soltani
  152.  
  153.  
  154. AmirAbad Shomali, Sindad Corp
  155. Tehran
  156. Tehran,94583
  157. IR
  158. Tel. +21.44008444
  159.  
  160.  
  161. Domain Name: MAHKAAME.COM
  162.  
  163. Registration Date: 19-Nov-2011
  164. Expiration Date: 19-Nov-2013
  165.  
  166.  
  167. Name Servers:
  168. ns1.pcosb.com
  169. ns2.pcosb.com
  170.  
  171.  
  172. Registrant Contact Details:
  173. Sindad
  174. Morteza Soltani ([email protected])
  175. AmirAbad Shomali, Sindad Corp
  176. Tehran
  177. Tehran,94583
  178. IR
  179. Tel. +21.44008444
  180.  
  181.  
  182. Domain Name: PCOSB.COM
  183.  
  184. Registration Date: 05-Mar-2011
  185. Expiration Date: 05-Mar-2014
  186.  
  187. Status:ACTIVE
  188.  
  189.  
  190. Name Servers:
  191. ns1.pcosb.com
  192. ns2.pcosb.com
  193.  
  194.  
  195. Registrant Contact Details:
  196. pcosb.com
  197. morteza hadizadeh paskiabi ([email protected])
  198. no77,mansor st,Motahari st
  199. Tehran
  200. ID,17657
  201. IR
  202. Tel. +98.02184318200
  203. Fax. +98.02184318200
  204.  
  205.  
  206. Domain Name: FARDA-OIL.COM
  207.  
  208. Registration Date: 14-Dec-2011
  209. Expiration Date: 14-Dec-2013
  210.  
  211. Name Servers:
  212. ns1.sindad.com
  213. ns2.sindad.com
  214.  
  215.  
  216. Registrant Contact Details:
  217. Sindad
  218. Morteza Soltani ([email protected])
  219. AmirAbad Shomali, Sindad Corp
  220. Tehran
  221. Tehran,94583
  222. IR
  223. Tel. +21.44008444
  224.  
  225. Domains hosted on as61406
  226. Domain IP Address
  227. jahanesanat.ir 185.2.12.13
  228. vahidhashemi.com 185.2.12.13
  229. bazykon.com 185.2.12.13
  230.  
  231.  
  232. Information related to 'jahanesanat.ir'
  233.  
  234. domain: jahanesanat.ir
  235. ascii: jahanesanat.ir
  236. remarks: (Domain Holder) Seyed mohamad ali eslami
  237. remarks: (Domain Holder Address) No.5,8th Alley,Dore shahr St.,Qom, IR3715646565, IR
  238. holder-c: ---
  239. admin-c: se55-irnic
  240. tech-c: se55-irnic
  241. bill-c: to52-irnic
  242. nserver: ns1.bazykon.com
  243. nserver: ns2.bazykon.com
  244. last-updated: 2012-10-26
  245. expire-date: 2015-12-06
  246. source: IRNIC # Filtered
  247.  
  248. nic-hdl: se55-irnic
  249. person: Seyed Mohammad Ali Eslami
  250. address: Doreshar, 8 Alley, No. 8, Unit 3,, Qom, Qom, IR
  251. phone: 09122524529
  252. fax-no: 09122524529
  253.  
  254.  
  255. tracepath jahanesanat.ir
  256. 6: nyk-bb1-link.telia.net 57.671ms asymm 7
  257. 7: buf-b1-link.telia.net 37.034ms asymm 8
  258. 8: giglinx-ic-155660-buf-b1.c.telia.net 32.716ms
  259. 9: host.colocrossing.com 40.298ms
  260.  
  261.  
  262.  
  263. Domain Name: VAHIDHASHEMI.COM
  264.  
  265. Registration Date: 31-Jan-2012
  266. Expiration Date: 31-Jan-2014
  267.  
  268. Name Servers:
  269. ns1.bazykon.com
  270. ns2.bazykon.com
  271.  
  272.  
  273. Registrant Contact Details:
  274. Sarreh
  275. Seyed Vahid Hashemi ([email protected])
  276. Tehran
  277. Tehran
  278. Tehran,560078
  279. IR
  280. Tel. +98.12345678
  281.  
  282.  
  283. tracepath VAHIDHASHEMI.COM
  284. 6: nyk-bb1-link.telia.net 29.005ms asymm 7
  285. 7: buf-b1-link.telia.net 37.001ms asymm 8
  286. 8: giglinx-ic-155660-buf-b1.c.telia.net 40.294ms
  287. 9: host.colocrossing.com 40.289ms
  288.  
  289.  
  290.  
  291. Domain Name: BAZYKON.COM
  292.  
  293. Registration Date: 14-Mar-2010
  294. Expiration Date: 14-Mar-2013
  295.  
  296. Name Servers:
  297. ns1.bazykon.com
  298. ns2.bazykon.com
  299.  
  300.  
  301. Registrant Contact Details:
  302. PrivacyProtect.org
  303. Domain Admin ([email protected])
  304. ID#10760, PO Box 16
  305. Note - Visit PrivacyProtect.org to contact the domain owner/operator
  306. Nobby Beach
  307. Queensland,QLD 4218
  308. AU
  309. Tel. +45.36946676
  310.  
  311.  
  312. tracepath ns1.bazykon.com
  313. 6: nyk-bb1-link.telia.net 28.723ms asymm 7
  314. 7: buf-b1-link.telia.net 37.049ms asymm 8
  315. 8: giglinx-ic-155660-buf-b1.c.telia.net 40.363ms
  316. 9: host.colocrossing.com 40.135ms
  317.  
  318. tracepath ns2.bazykon.com
  319. 6: nyk-bb1-link.telia.net 29.017ms asymm 7
  320. 7: buf-b1-link.telia.net 36.914ms asymm 8
  321. 8: giglinx-ic-155660-buf-b1.c.telia.net 32.865ms
  322. 9: host.colocrossing.com 39.041ms
  323.  
  324.  
  325.  
  326.  
  327. Domain Name: AMELBANA.COM
  328.  
  329. Registration Date: 14-Sep-2011
  330. Expiration Date: 14-Sep-2013
  331.  
  332. Name Servers:
  333. ns1.bazykon.com
  334. ns2.bazykon.com
  335.  
  336.  
  337. Registrant Contact Details:
  338. Amelbana
  339. Naser Aydani ([email protected])
  340. iran - tehran
  341. Tehran
  342. Tehran,560078
  343. IR
  344. Tel. +098.9124342811
  345.  
  346.  
  347. nslookup amelbana.com
  348. Server: 127.0.0.1
  349. Address: 127.0.0.1#53
  350.  
  351. Non-authoritative answer:
  352. Name: amelbana.com
  353. Address: 185.2.12.13
  354.  
  355. tracepath amelbana.com
  356. 6: nyk-bb1-link.telia.net 27.774ms asymm 7
  357. 7: buf-b1-link.telia.net 36.913ms asymm 8
  358. 8: giglinx-ic-155660-buf-b1.c.telia.net 32.865ms
  359. 9: host.colocrossing.com 40.278ms
  360.  
  361.  
  362.  
  363. Domain Name: ETTELAATHEKMATVAMAREFAT.COM
  364.  
  365. Registration Date: 25-Apr-2007
  366. Expiration Date: 25-Apr-2013
  367.  
  368.  
  369. Name Servers:
  370. ns1.bazykon.com
  371. ns2.bazykon.com
  372.  
  373.  
  374. Registrant Contact Details:
  375. tlgtco
  376. uae
  377. dubai
  378. Dubai,560078
  379. AE
  380. Tel. +021.12345678
  381.  
  382. Administrative Contact Details:
  383. tlgtco
  384. uae
  385. dubai
  386. Dubai,560078
  387. AE
  388. Tel. +021.12345678
  389.  
  390.  
  391. nslookup ettelaathekmatvamarefat.com
  392. Non-authoritative answer:
  393. Name: ettelaathekmatvamarefat.com
  394. Address: 185.2.12.13
  395.  
  396.  
  397. tracepath ettelaathekmatvamarefat.com
  398. 6: nyk-bb1-link.telia.net 29.035ms asymm 7
  399. 7: buf-b1-link.telia.net 38.302ms asymm 8
  400. 8: giglinx-ic-155660-buf-b1.c.telia.net 32.896ms
  401. 9: host.colocrossing.com 38.986ms
  402.  
  403.  
  404. Domain Name: KETABETTELAAT.COM
  405.  
  406. Registration Date: 17-Dec-2009
  407. Expiration Date: 17-Dec-2013
  408.  
  409. Status:ACTIVE
  410.  
  411.  
  412. Name Servers:
  413. ns1.bazykon.com
  414. ns2.bazykon.com
  415.  
  416.  
  417. Registrant Contact Details:
  418. tlgtco
  419. uae
  420. dubai
  421. Dubai,560078
  422. AE
  423. Tel. +021.12345678
  424.  
  425. Administrative Contact Details:
  426. tlgtco
  427. uae
  428. dubai
  429. Dubai,560078
  430. AE
  431. Tel. +021.12345678
  432.  
  433. Technical Contact Details:
  434. tlgtco
  435. uae
  436. dubai
  437. Dubai,560078
  438. AE
  439. Tel. +021.12345678
  440.  
  441.  
  442. nslookup ketabettelaat.com
  443. Non-authoritative answer:
  444. Name: ketabettelaat.com
  445. Address: 185.2.12.13
  446.  
  447.  
  448. tracepath ketabettelaat.com
  449. 6: nyk-bb1-link.telia.net 51.575ms asymm 7
  450. 7: buf-b1-link.telia.net 37.009ms asymm 8
  451. 8: giglinx-ic-155660-buf-b1.c.telia.net 34.081ms
  452. 9: host.colocrossing.com 38.955ms
  453.  
  454.  
  455.  
  456.  
  457. Domain Name:OSTAN.ORG
  458. Created On:20-Nov-2007 10:40:56 UTC
  459. Last Updated On:08-Nov-2012 18:33:00 UTC
  460. Expiration Date:20-Nov-2013 10:40:56 UTC
  461. Sponsoring Registrar:PDR Ltd. d/b/a PublicDomainRegistry.com (R27-LROR)
  462. Status:OK
  463. Registrant ID:DI_11332140
  464. Registrant Name:m rab
  465. Registrant Organization:tlgtco
  466. Registrant Street1:uae
  467. Registrant Street2:
  468. Registrant Street3:
  469. Registrant City:dubai
  470. Registrant State/Province:Dubai
  471. Registrant Postal Code:560078
  472. Registrant Country:AE
  473. Registrant Phone:+021.12345678
  474. Registrant Phone Ext.:
  475. Registrant FAX:
  476. Registrant FAX Ext.:
  477. Registrant Email:[email protected]
  478. Admin ID:DI_11332140
  479.  
  480.  
  481. nslookup ostan.org
  482. Non-authoritative answer:
  483. Name: ostan.org
  484. Address: 185.2.12.13
  485.  
  486. tracepath ostan.org
  487. 6: nyk-bb1-link.telia.net 28.968ms asymm 7
  488. 7: buf-b1-link.telia.net 36.917ms asymm 8
  489. 8: giglinx-ic-155660-buf-b1.c.telia.net 34.105ms
  490. 9: host.colocrossing.com 40.200ms
  491.  
  492.  
  493. Domain Name: SARREH.COM
  494.  
  495. Registration Date: 26-Aug-2009
  496. Expiration Date: 26-Aug-2013
  497.  
  498. Status:ACTIVE
  499.  
  500.  
  501. Name Servers:
  502. ns1.bazykon.com
  503. ns2.bazykon.com
  504.  
  505.  
  506. Registrant Contact Details:
  507. tlgtco
  508. uae
  509. dubai
  510. Dubai,560078
  511. AE
  512. Tel. +021.12345678
  513.  
  514. nslookup sarreh.com
  515. Non-authoritative answer:
  516. Name: sarreh.com
  517. Address: 185.2.12.13
  518.  
  519. tracepath sarreh.com
  520. 6: nyk-bb1-link.telia.net 27.761ms asymm 7
  521. 7: buf-b1-link.telia.net 38.116ms asymm 8
  522. 8: giglinx-ic-155660-buf-b1.c.telia.net 32.873ms
  523. 9: host.colocrossing.com 38.964ms
  524.  
  525.  
  526.  
  527. Domain Name: JAHANESANAT.COM
  528.  
  529. Registration Date: 06-Nov-2004
  530. Expiration Date: 06-Nov-2013
  531.  
  532. Status:ACTIVE
  533.  
  534.  
  535. Name Servers:
  536. ns1.bazykon.com
  537. ns2.bazykon.com
  538.  
  539.  
  540. Registrant Contact Details:
  541. PrivacyProtect.org
  542. Domain Admin ([email protected])
  543. ID#10760, PO Box 16
  544. Note - Visit PrivacyProtect.org to contact the domain owner/operator
  545. Nobby Beach
  546. Queensland,QLD 4218
  547. AU
  548. Tel. +45.36946676
  549.  
  550.  
  551. nslookup jahanesanat.com
  552. Non-authoritative answer:
  553. Name: jahanesanat.com
  554. Address: 185.2.12.13
  555.  
  556. tracepath jahanesanat.com
  557. 6: nyk-bb1-link.telia.net 61.554ms asymm 7
  558. 7: buf-b1-link.telia.net 38.252ms asymm 8
  559. 8: giglinx-ic-155660-buf-b1.c.telia.net 40.292ms
  560.  
  561.  
  562.  
  563. Domain Name: NAREIN.COM
  564.  
  565. Registration Date: 22-Feb-2010
  566. Expiration Date: 22-Feb-2013
  567.  
  568. Name Servers:
  569. ns1.bazykon.com
  570. ns2.bazykon.com
  571.  
  572.  
  573. Registrant Contact Details:
  574. Sarreh
  575. Seyed Vahid Hashemi ([email protected])
  576. Tehran
  577. Tehran
  578. Tehran,560078
  579. IR
  580. Tel. +98.12345678
  581.  
  582. nslookup narein.com
  583. Non-authoritative answer:
  584. Name: narein.com
  585. Address: 185.2.12.13
  586.  
  587. tracepath narein.com
  588. 17: buf-b1-link.telia.net 45.858ms
  589. 18: giglinx-ic-155660-buf-b1.c.telia.net 44.558ms asymm 17
  590. 19: host.colocrossing.com 38.262ms asymm 18
  591.  
  592.  
  593. Domain Name: ROMANTACO.COM
  594.  
  595. Registration Date: 01-Aug-2012
  596. Expiration Date: 01-Aug-2013
  597.  
  598. Name Servers:
  599. ns1.bazykon.com
  600. ns2.bazykon.com
  601.  
  602.  
  603. Registrant Contact Details:
  604. tlgtco
  605. uae
  606. dubai
  607. Dubai,560078
  608. AE
  609. Tel. +021.12345678
  610.  
  611.  
  612. nslookup romantaco.com
  613. Non-authoritative answer:
  614. Name: romantaco.com
  615. Address: 185.2.12.13
  616.  
  617.  
  618. tracepath romantaco.com
  619. 17: buf-b1-link.telia.net 37.951ms
  620. 18: giglinx-ic-155660-buf-b1.c.telia.net 49.870ms
  621. 19: host.colocrossing.com 38.652ms asymm 18
  622.  
  623.  
  624.  
  625. thunderlights.com
  626.  
  627. vphost.org?
  628.  
  629.  
  630.  
  631. http://www.irnike.com/ --- was hosted in december - 185.2.12.34
  632.  
  633. http://spsdevnic.net/
  634.  
  635. http://7servers.net/
  636.  
  637. Administrator:
  638. name: SPS Developing Group
  639. mail: [email protected] tel: +98.1712325140
  640. fax: +98.1712325140
  641. org: Poshtibanan Pardazesh Aseman Inc.
  642.  
  643. address: No. 9, 6th Floor, Morvarid Tower, Valiasr St.,
  644. city: Gorgan
  645. province: Golestan
  646. country: IR
  647. postcode: 4916619394
  648.  
  649. Technical Contactor:
  650. name: SPS Developing Group
  651. mail: [email protected] tel: +98.1712325140
  652. fax: +98.1712325140
  653. org: Poshtibanan Pardazesh Aseman Inc.
  654.  
  655. address: No. 9, 6th Floor, Morvarid Tower, Valiasr St.,
  656. city: Gorgan
  657. province: Golestan
  658. country: IR
  659. postcode: 4916619394
  660.  
  661.  
  662. nslookup 7servers.net
  663. Non-authoritative answer:
  664. Name: 7servers.net
  665. Address: 185.2.12.51
  666.  
  667.  
  668. tracepath 7servers.net
  669. 17: buf-b1-link.telia.net 37.995ms
  670. 18: giglinx-ic-155660-buf-b1.c.telia.net 77.696ms
  671. 19: host.colocrossing.com 43.791ms asymm 18
  672.  
  673.  
  674.  
  675.  
  676. 185.2.12.0/23 (EU ) Faraso Samaneh Pasargad Ltd.
  677. 185.2.14.0/23 (EU ) Faraso Samaneh Pasargad Ltd.
  678.  
  679.  
  680.  
  681. http://www.webhostingtalk.ir/f15/66607/
  682.  
  683.  
  684.  
  685. http://blog.dynamoo.com/2012/12/zbot-sites-to-block-51212.html
  686.  
  687. Poshtibanan Pardazesh Aseman
  688.  
  689. mail.9movie.ir
  690. 9movie.ir
  691. ofoghnews.ir
  692. dibisolutions.info
  693. bazykon.com
  694. froodgolf.com
  695. iihsep.com
  696. iihsep.ir
  697. golestanmet.ir
  698. ferdowsifinance.ir
  699. irpoultry.net
  700. rahpuyan-car.com
  701. rahbord.info
  702. rahpuyan-kar.com
  703. tamebartar.com
  704. golbto.com
  705. usaip.eu
  706. arpj.net
  707. GoLbTo.com
  708. MirBehBahAni.com
  709. vorkan.ir
  710. bema.biz
  711. aaico.net
  712. e-pnu.com
  713. aatbiz.com
  714. www.Behfarm.com
  715. avdco.net
  716. porosha.com
  717. iranoilseeds.com
  718. Talashgroupco.com
  719. Tobnoxel.com
  720. ganrrc.org.ir
  721. gup.ir
  722. emexinvestment.com
  723. bushoo.com
  724. thunderlights.com
Advertisement
Add Comment
Please, Sign In to add comment