lp1.bongacams24.com

1&1 Internet Inc

Domain Information

The domain lp1.bongacams24.com registered by 1&1 Internet Inc was initially registered in July of 2014 through 1&1 INTERNET SE. Currently this domain has been known to host various forms of malware. The hosted servers are located in Hollywood, Florida within the United States which resides on the Prolexic Technologies, Inc. network.
Registrar:
1&1 INTERNET SE

Server location:
Florida, United States (US)

Create date:
Monday, July 14, 2014

Expires date:
Thursday, July 14, 2016

Updated date:
Thursday, March 17, 2016

ASN:
AS32787 PROLEXIC-TECHNOLOGIES-DDOS-MITIGATION-NETWORK - Prolexic Technologies, Inc.

Root domain:

Scanner detections:
Malware distribution  (94% detected)

Scan engine
Details
Detections

Reason Heuristics
Trojan.Downloader (M)
97.78%

AegisLab AV Signature
DangerousObject.Multi.Gen
33.33%

Dr.Web
Trojan.Coinbit.43, Trojan.Siggen6.55013
26.67%

Malwarebytes
Riskware.BitcoinMiner, Trojan.Dropper.Script
26.67%

Zillya! Antivirus
Tool.BitCoinMiner.Win64.3, Adware.OutBrowse.Win32.80053
11.11%

AVG
BitCoinMiner.D, Generic36
11.11%

IKARUS anti.virus
not-a-virus:RiskTool.BitCoinMiner, Backdoor.Win32.Wencho
4.44%

McAfee
RDN/Generic PUP.x!cmq
2.22%

K7 AntiVirus
Trojan
2.22%

ESET NOD32
Win64/BitCoinMiner.U potentially unsafe (variant)
2.22%

avast!
Win64:Rootkit-gen [Rtk]
2.22%

Clam AntiVirus
Win.Trojan.Bitcoinminer-81
2.22%

Kaspersky
not-a-virus:RiskTool.Win64.BitCoinMiner
2.22%

Sophos
Internet Download Manager - Miner (PUA)
2.22%

G Data
Win64.Riskware.BitCoinMiner
2.22%

The domain lp1.bongacams24.com has been seen to resolve to the following 2 IP addresses.

unknown.prolexic.com
July 24, 2016

February 27, 2016

File downloads found at URLs served by lp1.bongacams24.com.

0 / 68
http://lp1.bongacams24.com/taskmgr.exe  (0cd57ae2c9c2f8f4a2a4aa0270ab718c)

0 / 68
http://lp1.bongacams24.com/csrss.exe  (3e7e505886720a3ce8152cb66a1195e6)

The following 244 files have been seen to comunicate with lp1.bongacams24.com in live environments.

 
Latest 20 of 250 files

URL:
http://lp1.bongacams24.com/

Title:
“Loading. Please wait...”

Web server:
nginx/1.8.1