Download
Community
knowledgeBase
» a.proffi-sun.work
Overview
Analysis
IPs Addresses (1)
Downloads (1)
Network (11)
Related Domains (3)
a.proffi-sun.work
Domain Information
Server location:
Arizona, United States (US)
ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC,US
Root domain:
proffi-sun.work
Analysis
Scanner detections:
Malware distribution (100% detected)
Scan engine
Details
Detections
Reason Heuristics
Threat.Win.Reputation.IMP
100.00%
IPs Addresses
The domain a.proffi-sun.work has been seen to resolve to the following IP address.
50.63.202.71
ip-50-63-202-71.ip.secureserver.net
July 15, 2016
Downloads
File downloads found at URLs served by a.proffi-sun.work.
1 / 68 (Malware)
http://a.proffi-sun.work/hp/?q=LF2XT5f/.../FaA62GkVUJhQju4Y9ejJ5uUu2eVzK7q7aK KrE4JvraNUsQBJdS4G1kZaLqyriyG7yAQI8xq5zlunCLSuWdlC9AMzh0dSNBdzLu6P8nBnt5Gl3RhlB62tbjf1Iv2gLFly6vUTRlrzP5dKY&external_id=1437881604752656793
(eng.exe)
Network Communications
The following 11 files have been seen to comunicate with a.proffi-sun.work in live environments.
TCP »
50.63.202.71
:80
1ln100ct.crx
TCP »
50.63.202.71
:80
fbplugin.crx
TCP »
50.63.202.71
:80
oqjfm4vf.crx
TCP »
50.63.202.71
:80
ogw51u8t.crx
TCP »
50.63.202.71
:80
fbplugin.crx
TCP »
50.63.202.71
:80
fbplugin.crx
TCP »
50.63.202.71
:80
fbplugin.crx
TCP »
50.63.202.71
:80
fbplugin.crx
TCP »
50.63.202.71
:80
1gli2mii.crx
TCP »
50.63.202.71
:80
fbplugin.crx
TCP »
50.63.202.71
:80
ytd.exe (YTD Video Downloader by GreenTree Applications SRL)
Related Domains
androiddesktopremote.com
minecraftinstallers.com
savedazzle.com
X