insider-plus.com

Privacy Protection Service INC d/b/a PrivacyProtect.org  (Proxy Registrant)

Domain Information

The domain insider-plus.com is registered by proxy through PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM and was originally registered in November of 2012. Currently this domain has been known to host various forms of malware. The hosted servers are located in Nuremberg, Bayern within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM

Server location:
Bayern, Germany (DE)

Create date:
Monday, November 26, 2012

Expires date:
Saturday, November 26, 2016

Updated date:
Tuesday, October 27, 2015

ASN:
AS24940 HETZNER-AS Hetzner Online GmbH,DE

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.KeylogCuliLTAG.Trojan
100.00%

MicroWorld eScan
Trojan.CryptRedol.Gen.1
100.00%

nProtect
Trojan.CryptRedol.Gen.1
100.00%

Quick Heal
Trojan.Napolar.r4
100.00%

McAfee
Artemis!64C7C1AD3532
100.00%

Malwarebytes
Trojan.Agent.BNS
100.00%

Zillya! Antivirus
Trojan.Agentb.Win32.1682
100.00%

K7 AntiVirus
Trojan
100.00%

Arcabit
Trojan.CryptRedol.Gen.1
100.00%

NANO AntiVirus
Trojan.Win32.Agentb.cvmgsn
100.00%

ESET NOD32
Win32/Napolar
100.00%

Trend Micro House Call
TROJ_SPNR.35JA13
100.00%

avast!
Win32:Napolar-F [Cryp]
100.00%

Kaspersky
Trojan.Win32.Agentb
100.00%

Bitdefender
Trojan.CryptRedol.Gen.1
100.00%

The domain insider-plus.com has been seen to resolve to the following IP address.

go.uhostmk2.info
January 28, 2016

File downloads found at URLs served by insider-plus.com.

38 / 68    (Malware)
http://insider-plus.com/?lr996h7yq9kog0=c0e120eb  (image_030-www.facebook.com.exe)

URL:
http://insider-plus.com/

Title:
“Home”

Description:
“www.insider-plus.com offers obtaining tips (prediction) that have been analysis and according to the information received by our team of experts have a great chance for win.”

Web server:
Apache