nqxov7tshgg7jr9.pishchulin.ru

Private Person  (Proxy Registrant)

Domain Information

The domain nqxov7tshgg7jr9.pishchulin.ru is registered by proxy through REGRU-RU and was originally registered in April of 2015. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Monday, April 6, 2015

Expires date:
Wednesday, April 6, 2016

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/InstallMonstr.KL potentially unwanted application
100.00%

Dr.Web
Trojan.InstallMonster.1230
100.00%

VIPRE Antivirus
Threat.4150696
100.00%

Sophos
PUA 'Install Monster'
100.00%

K7 AntiVirus
Unwanted-Program
100.00%

Agnitum Outpost
Trojan.InstallMonster
100.00%

Reason Heuristics
Threat.Win.Reputation.IMP
100.00%

AVG
Adware BundleApp
100.00%

herdProtect (fuzzy)
a variant of 57a64a9fa17279f4009d9ea01847fb35637be769
100.00%

Emsisoft Anti-Malware
Application.Agent.JJ
100.00%

Lavasoft Ad-Aware
Application.Agent.JJ
100.00%

F-Secure
Riskware.Application.Agent.JJ
100.00%

The domain nqxov7tshgg7jr9.pishchulin.ru has been seen to resolve to the following IP address.

May 7, 2015

File downloads found at URLs served by nqxov7tshgg7jr9.pishchulin.ru.

URL:
http://nqxov7tshgg7jr9.pishchulin.ru/

Title:
“Domain is parked”

Web server:
nginx/1.4.2 (PHP/5.4.17)