m.xxxl84675900374.com

DSL

Domain Information

The domain m.xxxl84675900374.com registered by DSL was initially registered in February of 2015 through TODAYNIC.COM, INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Saint Petersburg, Saint Petersburg City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
TODAYNIC.COM, INC.

Server location:
Saint Petersburg City, Russia (RU)

Create date:
Thursday, February 12, 2015

Expires date:
Sunday, February 12, 2017

Updated date:
Thursday, November 26, 2015

ASN:
AS44050 PIN-AS Petersburg Internet Network ltd.,RU

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
HW64.Paked, W64.HfsAutoA
100.00%

McAfee
Artemis!EEDB9D86AE8A, Artemis!9D8F08C4F840
100.00%

Agnitum Outpost
Trojan.CoinMiner
100.00%

Trend Micro House Call
TROJ_GEN.R0CBH05I314, TROJ_GEN.R08NC0RE615
100.00%

Comodo Security
UnclassifiedMalware
100.00%

ESET NOD32
Win64/CoinMiner.J trojan, Win64/CoinMiner.X trojan
100.00%

IKARUS anti.virus
Trojan.Win64.CoinMiner
100.00%

AVG
Skodna.BitCoinMiner, Atros
100.00%

Baidu Antivirus
Hacktool.Win32.Bitcoinminer, Hacktool.Win64.BitCoinMiner
100.00%

VIPRE Antivirus
Threat.4150696
100.00%

F-Secure
Trojan:W32/BitCoinMiner.G, Trojan.Generic.13166951
100.00%

F-Prot
W64/BitCoinMiner.E
100.00%

Kaspersky
not-a-virus:RiskTool.Win64.BitCoinMiner
100.00%

Emsisoft Anti-Malware
Application.Bitcoinminer.HH, Trojan.Generic.13166951
100.00%

Rising Antivirus
PE:Trojan.Win32.Generic.1724D5DA!388290010
50.00%

The domain m.xxxl84675900374.com has been seen to resolve to the following IP address.

February 9, 2016

File downloads found at URLs served by m.xxxl84675900374.com.

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

23 / 68    (Malware)

 
Latest 30 of 47 download URLs

URL:
http://m.xxxl84675900374.com/

Web server:
nginx/1.2.1 (PHP/5.4.41-0+deb7u1)