fd7072243b76f704202d4af5fdc56757.renovacaofatura.com

China Capital Investment Limited

Domain Information

The domain fd7072243b76f704202d4af5fdc56757.renovacaofatura.com registered by China Capital Investment Limited was initially registered in April of 2015 through REGISTER.COM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Dallas, Texas within the United States which resides on the Rackspace Hosting network.
Registrar:
REGISTER.COM, INC.

Server location:
Texas, United States (US)

Create date:
Thursday, April 30, 2015

Expires date:
Saturday, April 30, 2016

Updated date:
Monday, November 2, 2015

ASN:
AS33070 RMH-14 - Rackspace Hosting,US

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Variant.Kazy.16724
100.00%

Bitdefender
Gen:Variant.Kazy.16724
100.00%

Trend Micro House Call
TROJ_GEN.R047B01EG15
100.00%

avast!
Win32:Dropper-gen [Drp]
100.00%

Kaspersky
Trojan-Downloader.Win32.Genome
100.00%

Lavasoft Ad-Aware
Gen:Variant.Kazy.16724
100.00%

F-Secure
Gen:Variant.Kazy.16724
100.00%

VIPRE Antivirus
Trojan.Win32.Generic.pak!cobra
100.00%

Emsisoft Anti-Malware
Gen:Variant.Kazy.16724
100.00%

Avira AntiVirus
TR/VB.Downloader.Gen
100.00%

G Data
Gen:Variant.Kazy.16724
100.00%

McAfee
Artemis!82E5357A2C32
100.00%

Baidu Antivirus
Trojan.Win32.Downloader
100.00%

ESET NOD32
probably unknown NewHeur_PE
100.00%

Fortinet FortiGate
W32/VB.ZIL!tr.dldr
100.00%

The domain fd7072243b76f704202d4af5fdc56757.renovacaofatura.com has been seen to resolve to the following IP address.

50-56-218-189.static.cloud-ips.com
March 2, 2016

File downloads found at URLs served by fd7072243b76f704202d4af5fdc56757.renovacaofatura.com.

The following 58 files have been seen to comunicate with fd7072243b76f704202d4af5fdc56757.renovacaofatura.com in live environments.

 
Latest 20 of 58 files

URL:
http://fd7072243b76f704202d4af5fdc56757.renovacaofatura.com/

Web server:
nginx/1.8.0