robyego.ru

Private Person  (Proxy Registrant)

Domain Information

The domain robyego.ru is registered by proxy through REGRU-RU and was originally registered in January of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Paris, Ile-De-France within France which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Ile-De-France, France (FR)

Create date:
Monday, January 18, 2016

Expires date:
Wednesday, January 18, 2017

ASN:
AS12876 AS12876 ONLINE S.A.S.,FR

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.SearchGo.Meta (M)
62.50%

Emsisoft Anti-Malware
Gen:Trojan.Heur2.JP.zu0@a4ve5gdi, Gen:Trojan.Heur2.JP.zu0@aq7OK8mi, Win32.Ramnit.N
37.50%

avast!
Win32:Malware-gen, Win32:RmnDrp
37.50%

F-Secure
Trojan.Heur2.JP.zu0@aC70M!ai, Trojan.Heur2.JP.zu0@a4ve5gdi
25.00%

Norman
Gen:Trojan.Heur2.JP.zu0@aC70M!ai, Gen:Trojan.Heur2.JP.zu0@a4ve5gdi
25.00%

ESET NOD32
Win32/Adware.SearchGo.A application, Win32/Ramnit.H virus
25.00%

McAfee
Trojan.Artemis!64A8157837D5, Virus.W32/Ramnit.a
25.00%

AVG
Win32/Zbot.G
12.50%

F-Prot
W32/Ramnit.E
12.50%

Microsoft Security Essentials
Threat.Undefined
12.50%

Kaspersky
Virus.Win32.Nimnul
12.50%

Dr.Web
Win32.Rmnet.8
12.50%

The domain robyego.ru has been seen to resolve to the following 2 IP addresses.

62-210-6-46.rev.poneytelecom.eu
April 18, 2016

bin.kometa-software.ru
April 18, 2016

File downloads found at URLs served by robyego.ru.

9 / 68      (Infected)
http://robyego.ru/searchgo.dll  (769be9590349858f1106da9cf64fc1c5)

3 / 68      (PUP)
http://robyego.ru/searchgo.exe  (1e572812793e2f7672110617c8eb7c21)

1 / 68      (PUP)
http://robyego.ru/searchgo.dll  (0f21077acd26b74e219aaa824e7581c4)

4 / 68      (PUP)
http://robyego.ru/searchgo.exe  (64a8157837d5df49827f232f1295dec2)

4 / 68      (Malware)
http://robyego.ru/searchgo.exe  (e7dc5f07c89cc136b1087636579155a7)

1 / 68      (PUP)
http://robyego.ru/searchgo.dll  (41aa9ba47db027de7f6d68e0b027fc48)

1 / 68      (PUP)
http://robyego.ru/searchgo.dll  (59d05c0c9fdef13cab0d5fdde0836901)

1 / 68      (PUP)
http://robyego.ru/searchgo.dll  (f5be07212873eed2525fd219a500b960)

The following 13 files have been seen to comunicate with robyego.ru in live environments.