qlsndkebt7t77fw.assbreak.ru

Private Person  (Proxy Registrant)

Domain Information

The domain qlsndkebt7t77fw.assbreak.ru is registered by proxy through REGRU-RU and was originally registered in August of 2014. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Edinburgh, Scotland within United Kingdom which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrar:
REGRU-RU

Server location:
Scotland, United Kingdom (GB)

Create date:
Saturday, August 16, 2014

Expires date:
Sunday, August 16, 2015

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ProfitServis.J, PUP.ProfitServis.Q, PUP.ProfitServis.Bundler (M)
100.00%

VIPRE Antivirus
Threat.4150696, Trojan.Win32.Generic
66.67%

Emsisoft Anti-Malware
Trojan.Agent.BFAK, Gen:Variant.Graftor.157854
66.67%

ESET NOD32
Win32/InstallMonstr.FL potentially unwanted application, Win32/InstallMonstr.FM potentially unwanted application
66.67%

Dr.Web
Trojan.InstallMonster.953
66.67%

AVG
Adware Generic5.BKKV
66.67%

avast!
Win32:InstallMonstr-GC [PUP]
66.67%

MicroWorld eScan
Trojan.Agent.BFAK, Gen:Variant.Graftor.157854
66.67%

K7 AntiVirus
Unwanted-Program
66.67%

NANO AntiVirus
Trojan.Win32.InstallMonster.demprd, Trojan.Win32.InstallMonster.dewbsi
66.67%

Norman
InstallMonstr.S
66.67%

Bitdefender
Trojan.Agent.BFAK, Gen:Variant.Graftor.157854
66.67%

Agnitum Outpost
Riskware.Agent
66.67%

Lavasoft Ad-Aware
Trojan.Agent.BFAK, Gen:Variant.Graftor.157854
66.67%

Sophos
Install Monster
66.67%

The domain qlsndkebt7t77fw.assbreak.ru has been seen to resolve to the following IP address.

October 9, 2014

File downloads found at URLs served by qlsndkebt7t77fw.assbreak.ru.

URL:
http://qlsndkebt7t77fw.assbreak.ru/

Web server:
nginx/1.4.2 (PHP/5.4.17)