cor.gepseguridad.com

Grupo Isec S.L.

Domain Information

The domain cor.gepseguridad.com registered by Grupo Isec S.L. was initially registered in April of 2014 through OVH. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
OVH

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Saturday, April 26, 2014

Expires date:
Wednesday, April 26, 2017

Updated date:
Sunday, April 3, 2016

ASN:
AS16276 OVH OVH SAS,FR

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Trojan.Generic.14630398
100.00%

nProtect
Trojan.Generic.14630398
100.00%

Quick Heal
TrojanPWS.AutoIt.Zbot.F
100.00%

McAfee
Artemis!F843F9911A7A, Artemis!DBC4430C2829
100.00%

K7 AntiVirus
Trojan
100.00%

Arcabit
Trojan.Generic.DDF3DFE
100.00%

avast!
Win32:Malware-gen, Win32:Evo-gen [Susp]
100.00%

Kaspersky
Trojan-Dropper.Win32.Injector
100.00%

Bitdefender
Trojan.Generic.14630398
100.00%

Lavasoft Ad-Aware
Trojan.Generic.14630398
100.00%

Sophos
Mal/Generic-S
100.00%

F-Secure
Trojan.Generic.14630398
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Trend Micro
TROJ_GEN.R03AC0EFE15, TROJ_GEN.R0EAC0EFC15
100.00%

Emsisoft Anti-Malware
Trojan.Generic.14630398
100.00%

The domain cor.gepseguridad.com has been seen to resolve to the following IP address.

cluster007.ovh.net
April 4, 2016

File downloads found at URLs served by cor.gepseguridad.com.

29 / 68    (Malware)
http://cor.gepseguridad.com/?q=uTorrent32-64bits.exe  (f843f9911a7acf86d03970e2e4e556d6.exe)

26 / 68    (Malware)
http://cor.gepseguridad.com/?q=uTorrent32-64bits.exe  (dbc4430c28297229c159c89ba55246fe)

The following 3 files have been seen to comunicate with cor.gepseguridad.com in live environments.

URL:
http://cor.gepseguridad.com/

Web server:
Apache