bkhvplfjf4h52vf.yeffet.ru

CORLEON GROUP LTD

Domain Information

The domain bkhvplfjf4h52vf.yeffet.ru registered by CORLEON GROUP LTD was initially registered in July of 2014 through REGRU-RU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Tuesday, July 1, 2014

Expires date:
Wednesday, July 1, 2015

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CORLEONGROUP.BB
100.00%

ESET NOD32
Win32/InstallMonstr.Q potentially unwanted application
100.00%

Dr.Web
Trojan.InstallMonster.242
100.00%

avast!
Win32:InstallMonstr-DY [PUP]
100.00%

VIPRE Antivirus
Threat.4845009
100.00%

MicroWorld eScan
Gen:Variant.Symmi.26453
100.00%

K7 AntiVirus
Trojan
100.00%

Bitdefender
Gen:Variant.Symmi.26453
100.00%

Agnitum Outpost
Riskware.Agent
100.00%

Emsisoft Anti-Malware
Gen:Variant.Symmi.26453
100.00%

F-Secure
Gen:Variant.Symmi.26453
100.00%

Sophos
Install Monster
100.00%

F-Prot
W32/A-8a9d1dfb
100.00%

Avira AntiVirus
APPL/InstallMonster.Gen
100.00%

G Data
Gen:Variant.Symmi.26453
100.00%

The domain bkhvplfjf4h52vf.yeffet.ru has been seen to resolve to the following IP address.

November 10, 2014

File downloads found at URLs served by bkhvplfjf4h52vf.yeffet.ru.

URL:
http://bkhvplfjf4h52vf.yeffet.ru/

Web server:
nginx/1.4.2 (PHP/5.4.17)