319.tq8.huojiprogresso.com

Whois protection, this company does not own this domain name s.r.o.

Domain Information

The domain 319.tq8.huojiprogresso.com registered by Whois protection, this company does not own this domain name s.r.o. was initially registered in January of 2016 through HEBEI GUOJI MAOYI (SHANGHAI) LTD DBA HEBEIDOMAINS.COM. Currently this domain has been known to host various forms of malware. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrar:
HEBEI GUOJI MAOYI (SHANGHAI) LTD DBA HEBEIDOMAINS.COM

Server location:
Victoria, Australia (AU)

Create date:
Sunday, January 3, 2016

Expires date:
Tuesday, January 3, 2017

Updated date:
Sunday, January 3, 2016

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen
100.00%

ESET NOD32
Win32/Injector.CPKF trojan
100.00%

Kaspersky
Trojan.Win32.Kovter
100.00%

Reason Heuristics
Threat.Win.Reputation.IMP
100.00%

The domain 319.tq8.huojiprogresso.com has been seen to resolve to the following IP address.

lb-182-241.above.com
January 5, 2016

File downloads found at URLs served by 319.tq8.huojiprogresso.com.

4 / 68      (Malware)
http://319.tq8.huojiprogresso.com/.../FlashPlayer.exe  (52e59a6e3533edac58c4d71015d2bf5e)

The following 12 files have been seen to comunicate with 319.tq8.huojiprogresso.com in live environments.

URL:
http://319.tq8.huojiprogresso.com/

Title:
“huojiprogresso.com”

Web server:
Apache