b4af1w.bl3302.livefilestore.com

Microsoft Corporation

Domain Information

The domain b4af1w.bl3302.livefilestore.com registered by Microsoft Corporation was initially registered in January of 2007 through CSC CORPORATE DOMAINS, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Redmond, Washington within the United States which resides on the Microsoft Corp network.
Registrar:
CSC CORPORATE DOMAINS, INC.

Server location:
Washington, United States (US)

Create date:
Tuesday, January 30, 2007

Expires date:
Saturday, January 30, 2016

Updated date:
Tuesday, January 27, 2015

ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

McAfee
Artemis!61BAF03AFF12
100.00%

Kaspersky
HEUR:Trojan.Win32.Generic
100.00%

Comodo Security
UnclassifiedMalware
100.00%

Baidu Antivirus
Trojan.MSIL.Agent
100.00%

Qihoo 360 Security
Win32/Trojan.e6d
100.00%

The domain b4af1w.bl3302.livefilestore.com has been seen to resolve to the following 4 IP addresses.

May 3, 2015

December 25, 2014

December 2, 2014

December 1, 2014

File downloads found at URLs served by b4af1w.bl3302.livefilestore.com.

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

5 / 68      (Malware)
https://b4af1w.bl3302.livefilestore.com/.../emu.exe  (61baf03aff12f15f2c65cfa9cca95974)

The following 33 files have been seen to comunicate with b4af1w.bl3302.livefilestore.com in live environments.

 
Latest 20 of 62 files

URL:
http://b4af1w.bl3302.livefilestore.com/

SSL certificate subject:
CN=storage.live.com, OU=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=WA, C=US

SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Web server:
Microsoft-HTTPAPI/2.0