download.rafotech.com

Qing Ye Ke Ji Bei Jing You Xian Ze Ren Gong Si

Domain Information

The domain download.rafotech.com registered by Qing Ye Ke Ji Bei Jing You Xian Ze Ren Gong Si was initially registered in January of 2015 through HICHINA ZHICHENG TECHNOLOGY LTD.. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Washington, District of Columbia within the United States which resides on the SoftLayer Technologies Inc. network.
Registrar:
HICHINA ZHICHENG TECHNOLOGY LTD.

Server location:
District of Columbia, United States (US)

Create date:
Thursday, January 8, 2015

Expires date:
Monday, January 8, 2018

Updated date:
Thursday, January 8, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Detections  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Fafo.MB (M)
87.50%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
31.25%

Trend Micro House Call
Suspicious_GEN.F47V0522, Suspicious_GEN.F47V0515
12.50%

Dr.Web
Adware.Mutabaha.787, Adware.Mutabaha.787, Win32.Parite.2
12.50%

Norman
Win32.Parite.B, Gen:Variant.Adware.Ghoskwa.1
12.50%

F-Prot
W32/Parite.B
6.25%

Emsisoft Anti-Malware
Win32.Parite
6.25%

ESET NOD32
Win32/Parite.B virus
6.25%

avast!
Win32:Parite
6.25%

Microsoft Security Essentials
Threat.Undefined
6.25%

McAfee
Virus.W32/Pate.b
6.25%

F-Secure
Win32.Parite.B
6.25%

Kaspersky
Virus.Win32.Parite
6.25%

The domain download.rafotech.com has been seen to resolve to the following IP address.

c5.3e.559e.ip4.static.sl-reverse.com
February 9, 2016

File downloads found at URLs served by download.rafotech.com.

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (inconclusive)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://download.rafotech.com/.../download.php?cid=bxk  (mustang_setup_landpage_3090ce06-ff0c-9d43-bc05-256b083a972c_1.0.exe)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

 
Latest 30 of 40 download URLs

The following 9 files have been seen to comunicate with download.rafotech.com in live environments.

URL:
http://download.rafotech.com/

Web server:
nginx/1.8.0