lik-kuzbassa.ru

Private Person  (Proxy Registrant)

Domain Information

The domain lik-kuzbassa.ru is registered by proxy through REGRU-RU and was originally registered in June of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Kiev, Kyyiv within Ukraine which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Kyyiv, Ukraine (UA)

Create date:
Thursday, June 26, 2014

Expires date:
Sunday, June 26, 2016

ASN:
AS15626 ITLAS ITL Company, UA

Scanner detections:
Detections  (96% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallCube.ITHOLDING (M), PUP.InstallCube.DATAKOM (M), PUP.InstallCube.FISHNET (M), PUP.InstallCube.Narzan, PUP.InstallCube.KamaSoft (M), PUP.InstallCube.DISMTOV (M), PUP.ICLoader.Softstor (M), Adware.Bundler.SR.Meta (M), PUP.ICLoader.IPOKART, PUP.ICLoader.TEHNOARH (M), PUP.SmartIst (M), PUP.ICLoader.SoftTras (M), PUP.Adware.InstallCube (M), PUP (M), PUP.ICLoader (M)
96.15%

Dr.Web
Trojan.InstallCube.973, Trojan.InstallCube.1023
7.69%

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.85895
3.85%

ESET NOD32
Win32/Kryptik.ESZN trojan
3.85%

F-Secure
Variant.Adware.Strictor
3.85%

Norman
Gen:Variant.Adware.Strictor.85895
3.85%

The domain lik-kuzbassa.ru has been seen to resolve to the following 4 IP addresses.

August 15, 2016

July 28, 2016

July 7, 2016

silen649.vds
April 8, 2016

File downloads found at URLs served by lik-kuzbassa.ru.

The following 2 files have been seen to comunicate with lik-kuzbassa.ru in live environments.

URL:
http://lik-kuzbassa.ru/

Title:
“Скачать файл - Archive.rar”

Web server:
nginx (PHP/5.3.3)