kapq5300u940dif.battletrek.ru
Private Person (Proxy Registrant)
Domain Information
The domain kapq5300u940dif.battletrek.ru is registered by proxy through REGRU-REG-RIPN and was originally registered in July of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrant:
Private Person
Server location:
Noord-Holland, Netherlands (NL)
Create date:
Thursday, July 31, 2014
Expires date:
Friday, July 31, 2015
Scanner detections:
Detections (100% detected)
Scan engine
Details
Detections
Reason Heuristics
PUP.CORLEONGROUP.?, PUP.CORLEONGROUP.L, PUP.InstallMonster.CORLEONG (M)
100.00%
VIPRE Antivirus
Threat.4845009
28.57%
avast!
Win32:InstallMonstr-DY [PUP]
28.57%
NANO AntiVirus
Trojan.Win32.InstallMonster.dbipfy
28.57%
Sophos
Install Monster
28.57%
Avira AntiVirus
TR/Fraud.Gen7, APPL/InstallMonster.Gen
28.57%
G Data
Application.InstallMonster, Win32.Application.Installmonstr
28.57%
Vba32 AntiVirus
Signed-Downware.InstallMonstr, BScope.Downware.InstallMonstr
28.57%
Panda Antivirus
PUP/InstallMonstr
28.57%
herdProtect (fuzzy)
a variant of dc3983b76a155333a4fb5c5fa312612afa4c42d3, a variant of 8f1a71d31f1b2348a89057b10a72b9899d26cd67
28.57%
McAfee
Trojan.Artemis!6CE08F703E9E, Trojan.Artemis!E45C33D560A6
28.57%
Dr.Web
Trojan.InstallMonster.242
14.29%
MicroWorld eScan
Application.InstallMonster.F
14.29%
K7 AntiVirus
Unwanted-Program
14.29%
Bitdefender
Application.InstallMonster.F
14.29%
The domain kapq5300u940dif.battletrek.ru has been seen to resolve to the following IP address.
File downloads found at URLs served by kapq5300u940dif.battletrek.ru.
URL:
http://kapq5300u940dif.battletrek.ru/
Web server:
nginx/1.4.2 (PHP/5.4.17)
Related Domains