cdn.besplatnyeprogrammy.ru

Private Person  (Proxy Registrant)

Domain Information

The domain cdn.besplatnyeprogrammy.ru is registered by proxy through NAUNET-RU and was originally registered in November of 2008. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Gunzenhausen, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
NAUNET-RU

Server location:
Bayern, Germany (DE)

Create date:
Monday, November 3, 2008

Expires date:
Thursday, November 3, 2016

ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Kaspersky
UDS:DangerousObject.Multi.Generic, not-a-virus:HEUR:Downloader.NSIS.SoftBase, not-a-virus:Downloader.NSIS.SoftBase
79.55%

Baidu Antivirus
PUA.Win32.Softobase, Adware.Win32.Agent
79.55%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
77.27%

ESET NOD32
Win32/Softobase.C potentially unwanted, Win32/Softobase.D potentially unwanted
77.27%

McAfee
Artemis!BA24EDBAE10B, Trojan.Artemis!9DA84DBA8A84, Artemis!F913DA976D1B, Artemis!C6EA1BD95E59, Artemis!42717BAA869E, Artemis!B99934DE94BC, Artemis!4238086CF186, Artemis!795C1D752964, Artemis!E43A1EE1C573, Artemis!12D5B45D4ABC, Artemis!314AFEBD3738, Artemis!80C707A3F4CD, Artemis!0C5439086057, Artemis!1E0462DDDF0E, Artemis!793154C7BA0D, RDN/Generic.dx!dqj, Artemis!04975059FCF0
70.45%

Trend Micro House Call
Suspicious_GEN.F47V0324, Suspicious_GEN.F47V0413, Suspicious_GEN.F47V0503, Suspicious_GEN.F47V0421, TROJ_GEN.R00UH06E315, TROJ_GEN.R00UH06E215, Suspicious_GEN.F47V0423, TROJ_GEN.R047H05DU15, TROJ_GEN.R0EBH06DS15
47.73%

K7 AntiVirus
Adware
27.27%

Sophos
Generic PUA PK, Generic PUA FB, Generic PUA BG, Generic PUA AP (PUA), Generic PUA NI (PUA), Generic PUA MJ (PUA), Generic PUA OJ (PUA)
25.00%

VIPRE Antivirus
Trojan.Win32.Generic
25.00%

Norman
Suspicious_Gen4.IGHVE, Suspicious_Gen4.IGRQC, Suspicious_Gen4.IHASW, Suspicious_Gen4.IIMWU, Suspicious_Gen4.IHNUH, Suspicious_Gen4.IHCML, Suspicious_Gen4.IGHLY, Suspicious_Gen4.IGMQA
20.45%

avast!
Win32:Malware-gen, Win32:Adware-gen [Adw]
15.91%

NANO AntiVirus
Trojan.Nsis.SoftBase.dsgvph, Trojan.Nsis.SoftBase.dsycco
15.91%

ViRobot
Trojan.Win32.S.Agent.243347[h], Trojan.Win32.S.Agent.226436[h], Trojan.Win32.S.Agent.243329.B[h], Trojan.Win32.S.Agent.242315[h]
13.64%

Reason Heuristics
PUP.INSITEGROUP.Installer (M), PUP.INSITEGR.Installer (M)
13.64%

Trend Micro
TROJ_GEN.R0EBC0OE115, TROJ_GEN.R03EC0OHK15, TROJ_GEN.R0EBC0ODS15, TROJ_GEN.R01TC0EFE15, TROJ_GEN.R000C0EG415
11.36%

The domain cdn.besplatnyeprogrammy.ru has been seen to resolve to the following 3 IP addresses.

static.85-10-196-94.clients.your-server.de
May 5, 2015

85-10-200-21.clients.your-server.de
May 5, 2015

static.158.40.63.178.clients.your-server.de
May 5, 2015

File downloads found at URLs served by cdn.besplatnyeprogrammy.ru.

13 / 68    (PUP)

2 / 68      (PUP)
http://cdn.besplatnyeprogrammy.ru/FBReader_Rus_Setup.exe  (663906b4c5e5411ca04097b695b1859e)

1 / 68      (Adware)

10 / 68    (PUP)
http://cdn.besplatnyeprogrammy.ru/Recuva_Rus_Setup.exe  (04975059fcf0a6fe97e782ee34883a8e)

2 / 68      (PUP)
http://cdn.besplatnyeprogrammy.ru/IrfanView_Ru_Setup.exe  (9885bc456e3e3275110a3aa37f95855a)

9 / 68      (PUP)
http://cdn.besplatnyeprogrammy.ru/uTorrent_Rus_Setup.exe  (2bc094269953e1efafa2213da97fedd4)

7 / 68      (PUP)
http://cdn.besplatnyeprogrammy.ru/AIMP_Rus_Setup.exe  (793154c7ba0d039c85949f40600f6835)

10 / 68    (PUP)
http://cdn.besplatnyeprogrammy.ru/Firefox_Rus_Setup.exe  (80c707a3f4cdbb52eb8e09d26208ba92)

1 / 68      (Adware)

15 / 68    (PUP)
http://cdn.besplatnyeprogrammy.ru/Alcohol52_Rus_Setup.exe  (1e0462dddf0ea592006ff0d870bc4777)

13 / 68    (PUP)

8 / 68      (PUP)

11 / 68    (PUP)

7 / 68      (PUP)

12 / 68    (PUP)

12 / 68    (PUP)
http://cdn.besplatnyeprogrammy.ru/Mp3DirectCut_Setup.exe  (e6f644f3bb7ff37f03650355f6a855da)

1 / 68      (Adware)
http://cdn.besplatnyeprogrammy.ru/Dropbox_Rus_Setup.exe  (de94196a2a9f35657065b6086a45d008)

3 / 68      (inconclusive)

8 / 68      (PUP)

6 / 68      (PUP)

8 / 68      (PUP)

4 / 68      (PUP)

7 / 68      (PUP)

7 / 68      (PUP)

5 / 68      (PUP)

6 / 68      (PUP)

5 / 68      (PUP)

7 / 68      (PUP)
http://cdn.besplatnyeprogrammy.ru/CoolNovo_Rus_Setup.exe  (e43a1ee1c5737f4416e63404ad220031)

9 / 68      (PUP)
http://cdn.besplatnyeprogrammy.ru/Maxthon_Rus_Setup.exe  (a7726234514b902b0809c87b861a5c5b)

6 / 68      (PUP)

 
Latest 30 of 44 download URLs

The following 7 files have been seen to comunicate with cdn.besplatnyeprogrammy.ru in live environments.