qs7fuq-ch3302.files.1drv.com

Microsoft Corporation

Domain Information

The domain qs7fuq-ch3302.files.1drv.com registered by Microsoft Corporation was initially registered in August of 2013 through MARKMONITOR INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Redmond, Washington within the United States which resides on the Microsoft Corp network.
Registrar:
MARKMONITOR INC.

Server location:
Washington, United States (US)

Create date:
Monday, August 5, 2013

Expires date:
Wednesday, August 5, 2015

Updated date:
Tuesday, November 4, 2014

ASN:
AS8075 MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Application.Generic.749632
100.00%

Quick Heal
Trojan.Generic.g5
100.00%

McAfee
Artemis!566308D6EA42
100.00%

Norman
Suspicious_Gen4.GZASJ
100.00%

Trend Micro House Call
Suspicious_GEN.F47V0905
100.00%

Kaspersky
HEUR:Trojan.Win32.Generic
100.00%

Bitdefender
Application.Generic.749632
100.00%

Lavasoft Ad-Aware
Application.Generic.749632
100.00%

Sophos
Generic PUA HF
100.00%

Comodo Security
UnclassifiedMalware
100.00%

F-Secure
Application.Generic.749632
100.00%

G Data
Application.Generic.749632
100.00%

Baidu Antivirus
Trojan.MSIL.Agent
100.00%

ESET NOD32
Win32/Somoto
100.00%

Rising Antivirus
PE:Trojan.Win32.Generic.17433B4A!390282058
100.00%

The domain qs7fuq-ch3302.files.1drv.com has been seen to resolve to the following 2 IP addresses.

ch3302-g.1drv.com
May 3, 2015

ch3302-a.1drv.com
May 2, 2015

File downloads found at URLs served by qs7fuq-ch3302.files.1drv.com.

16 / 68    (Malware)
https://qs7fuq-ch3302.files.1drv.com/.../psemu3.exe  (566308d6ea424e35f7ad74eb16b6c559)

16 / 68    (Malware)
https://qs7fuq-ch3302.files.1drv.com/.../psemu3.exe  (566308d6ea424e35f7ad74eb16b6c559)

16 / 68    (Malware)
https://qs7fuq-ch3302.files.1drv.com/.../psemu3.exe  (566308d6ea424e35f7ad74eb16b6c559)

The following 2 files have been seen to comunicate with qs7fuq-ch3302.files.1drv.com in live environments.

URL:
http://qs7fuq-ch3302.files.1drv.com/

SSL certificate subject:
CN=storage.live.com, OU=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=WA, C=US

SSL certificate issuer:
CN=Microsoft IT SSL SHA2, OU=Microsoft IT, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Web server:
Microsoft-HTTPAPI/2.0