634.zzuk-nnz.xohkiatomic.net

Whois protection, this company does not own this domain name s.r.o.

Domain Information

The domain 634.zzuk-nnz.xohkiatomic.net registered by Whois protection, this company does not own this domain name s.r.o. was initially registered in January of 2016 through HEBEI GUOJI MAOYI (SHANGHAI) LTD DBA HEBEIDOMAINS.COM. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the OVH Hosting, Inc. network.
Registrar:
HEBEI GUOJI MAOYI (SHANGHAI) LTD DBA HEBEIDOMAINS.COM

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Monday, January 4, 2016

Expires date:
Wednesday, January 4, 2017

Updated date:
Monday, January 25, 2016

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Emsisoft Anti-Malware
Gen:Trojan.Heur.VP2.um1@auosgcii
100.00%

F-Secure
Gen:Trojan.Heur.VP2.um1@auosgcii
100.00%

Lavasoft Ad-Aware
Gen:Trojan.Heur.VP2.um1@auosgcii
100.00%

Kaspersky
Trojan.Win32.Kovter
100.00%

Norman
Gen:Trojan.Heur.VP2.um1@auosgcii
100.00%

avast!
Win32:Malware-gen
100.00%

Reason Heuristics
Threat.Win.Reputation.IMP
100.00%

ESET NOD32
Win32/Injector.CPKQ trojan
100.00%

The domain 634.zzuk-nnz.xohkiatomic.net has been seen to resolve to the following IP address.

ns523152.ip-158-69-225.net
February 8, 2016

File downloads found at URLs served by 634.zzuk-nnz.xohkiatomic.net.

8 / 68      (Malware)
http://634.zzuk-nnz.xohkiatomic.net/.../FlashPlayer.exe  (fb12c68af539ff3430339871cb4eeed8)

URL:
http://634.zzuk-nnz.xohkiatomic.net/

Title:
“xohkiatomic.net - This website is for sale! - xohkiatomic Resources and Information.”

Description:
“This website is for sale! xohkiatomic.net is your first and best source for all of the information you’re looking for. From general topics to more of what you would expect to find here, xohkiatomic.net has it all. We hope you find what you are s...”

Web server:
Apache (PHP/5.3.3-7+squeeze28)