avallon2013.ru

Private Person  (Proxy Registrant)

Domain Information

The domain avallon2013.ru is registered by proxy through R01-RU and was originally registered in June of 2013. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
R01-RU

Server location:
Moscow City, Russia (RU)

Create date:
Tuesday, June 25, 2013

Expires date:
Saturday, June 25, 2016

ASN:
AS48287 RU-SERVICE-AS RU-SERVICE Ltd,RU

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Adware.Agent.PFT
100.00%

nProtect
Adware.Agent.PFT
100.00%

McAfee
Artemis!73FF527AABB7
100.00%

K7 AntiVirus
Adware
100.00%

NANO AntiVirus
Riskware.Win32.FileTour.dnmpve
100.00%

Trend Micro House Call
Suspicious_GEN.F47V0130
100.00%

avast!
Win32:Adware-gen [Adw]
100.00%

Kaspersky
UDS:DangerousObject.Multi.Generic
100.00%

Bitdefender
Adware.Agent.PFT
100.00%

Lavasoft Ad-Aware
Adware.Agent.PFT
100.00%

Emsisoft Anti-Malware
Adware.Agent.PFT
100.00%

F-Secure
Adware.Agent.PFT
100.00%

VIPRE Antivirus
Adware.Crossid
100.00%

Sophos
Generic PUA KO
100.00%

ESET NOD32
Win32/Adware.FileTour.NG (variant)
100.00%

The domain avallon2013.ru has been seen to resolve to the following 2 IP addresses.

expirepages-kiae-1.nic.ru
July 16, 2016

expirepages-kiae-2.nic.ru
July 16, 2016

File downloads found at URLs served by avallon2013.ru.

24 / 68    (PUP)

The following 15 files have been seen to comunicate with avallon2013.ru in live environments.

URL:
http://avallon2013.ru/

Web server:
nginx

30 of 35 related domains