longhanbi.client.jp

Samurai Factory Inc.

Domain Information

The domain longhanbi.client.jp registered by Samurai Factory Inc. was initially registered in January of 2010. Currently this domain has been known to host various forms of malware. The hosted servers are located in Tokyo, Tokyo within Japan which resides on the Asia Pacific Network Information Centre network.
Server location:
Tokyo, Japan (JP)

Create date:
Monday, January 25, 2010

Expires date:
Tuesday, January 31, 2017

Updated date:
Monday, February 1, 2016

ASN:
AS23637 BI-CDN-IX Bit-isle Co.,Ltd.,JP

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

K7 AntiVirus
Riskware
100.00%

ESET NOD32
Win32/LockScreen.AGD
100.00%

F-Prot
W32/Agent.P.gen
100.00%

avast!
Win32:Malware-gen
100.00%

Kaspersky
Trojan-Ransom.Win32.PornoAsset
100.00%

Bitdefender
Trojan.Generic.KDV.286352
100.00%

Sophos
Mal/Generic-L
100.00%

Comodo Security
Heur.Suspicious
100.00%

F-Secure
Trojan.Generic.KDV.286352
100.00%

Dr.Web
Trojan.Winlock.3300
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Avira AntiVirus
TR/Ransom.PornoAsset.ajb
100.00%

Emsisoft Anti-Malware
Trojan-Ransom.Win32.PornoAsset!IK
100.00%

G Data
Trojan.Generic.KDV.286352
100.00%

AhnLab V3 Security
Trojan/Win32.PornoAsset
100.00%

The domain longhanbi.client.jp has been seen to resolve to the following IP address.

td1.shinobi.jp
May 18, 2016

File downloads found at URLs served by longhanbi.client.jp.

18 / 68    (Malware)
http://longhanbi.client.jp/xxx_video.exe  (1023d60bf9b7a24dfc638e841694d346)

The following file have been seen to comunicate with longhanbi.client.jp in live environments.

URL:
http://longhanbi.client.jp/

Web server:
Apache (PHP/5.5.9)