download-cdn.drp.su
Private Person (Proxy Registrant)
Domain Information
The domain download-cdn.drp.su is registered by proxy through R01-REG-FID and was originally registered in June of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrant:
Private Person
Server location:
Arizona, United States (US)
Create date:
Wednesday, June 17, 2009
Expires date:
Friday, June 17, 2016
ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc., US
Scanner detections:
Detections (78% detected)
Scan engine
Details
Detections
Reason Heuristics
Win32.Generic.KuzyakovArturVyacheslavovichIP.Meta, Win32.Generic.KuzyakovArturVyacheslavovichIP.Installer.Meta, Adware.Bundler.Meta (M)
100.00%
Microsoft Security Essentials
Threat.Undefined
5.56%
avast!
Win32:SaliCode
5.56%
F-Secure
Win32.Sality.3
5.56%
Emsisoft Anti-Malware
Win32.Sality
5.56%
Dr.Web
Win32.Sector.22
5.56%
F-Prot
W32/Sality.gen2
5.56%
McAfee
Virus.W32/Sality.gen.z
5.56%
Norman
Win32.Sality.3
5.56%
Lavasoft Ad-Aware
Win32.Sality.3
5.56%
Kaspersky
Virus.Win32.Sality
5.56%
ESET NOD32
Win32/Sality.NBA virus
5.56%
The domain download-cdn.drp.su has been seen to resolve to the following 6 IP addresses.
File downloads found at URLs served by download-cdn.drp.su.
URL:
http://download-cdn.drp.su/
SSL certificate subject:
CN=ssl256375.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated
SSL certificate issuer:
CN=COMODO RSA Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB
Web server:
cloudflare-nginx