radelab.ru

Private Person  (Proxy Registrant)

Domain Information

The domain radelab.ru is registered by proxy through REGRU-RU and was originally registered in December of 2010. Currently this domain has been known to host various forms of malware. The hosted servers are located in Berlin, Berlin within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Berlin, Germany (DE)

Create date:
Wednesday, December 8, 2010

Expires date:
Thursday, December 8, 2016

ASN:
AS24940 HETZNER-AS Hetzner Online AG,DE

Google Safe Browsing:
unwanted

Scanner detections:
Malware distribution  (75% detected)

Scan engine
Details
Detections

K7 AntiVirus
Riskware
66.67%

ViRobot
Trojan.Win32.A.Badur.25357675[h], Trojan.Win32.A.Badur.25357701[h]
66.67%

McAfee
Artemis!E4A85B781C8E, Artemis!C3F7BC4533EA
66.67%

IKARUS anti.virus
Trojan.Win32.Badur
66.67%

Norman
Obfuscated.gen!r
33.33%

Trend Micro House Call
TROJ_GEN.R047H05BJ15
33.33%

Kaspersky
Trojan.Win32.Badur
33.33%

Vba32 AntiVirus
Trojan.Badur
33.33%

ESET NOD32
Win32/Muter.A potentially unsafe
33.33%

VIPRE Antivirus
Trojan.Win32.Generic
33.33%

Avira AntiVirus
TR/Agent.25357701
33.33%

G Data
Win32.Trojan.Agent.2RMO92
33.33%

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
33.33%

Fortinet FortiGate
W32/Badur.MQBJ!tr
33.33%

Qihoo 360 Security
Win32/Trojan.55d
33.33%

The domain radelab.ru has been seen to resolve to the following 2 IP addresses.

ns5.wmrs.ru
April 21, 2016

static.141.249.243.136.clients.your-server.de
May 5, 2015

File downloads found at URLs served by radelab.ru.

11 / 68    (Malware)
http://radelab.ru/.../redsurf_setup_v.2.1.exe  (c3f7bc4533ea7f9a8e4f5cf2e6c726ad)

1 / 68      (PUP)
http://radelab.ru/.../redsurf_setup_v.2.1.exe  (1ad5212bf372f67af30373658bab95b9)

8 / 68      (Malware)
http://radelab.ru/.../redsurf_setup_v.2.1.exe  (e4a85b781c8e63c38c03784103e1f7bc)

0 / 68
http://radelab.ru/.../redsurf_setup_v.1.05.exe  (14d601bcd06bc931ebf22d64094633b3)

The following file have been seen to comunicate with radelab.ru in live environments.

URL:
http://radelab.ru/

Title:
“Лаборатория Рэйд. Разработка веб-сайтов, приложений, продвижение.”

Web server:
nginx/1.0.15