sdance.su

Private Person  (Proxy Registrant)

Domain Information

The domain sdance.su is registered by proxy through RUCENTER-REG-FID and was originally registered in April of 2012. Currently this domain has been known to host various forms of malware. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
RUCENTER-REG-FID

Server location:
Moscow City, Russia (RU)

Create date:
Thursday, April 5, 2012

Expires date:
Tuesday, April 5, 2016

ASN:
AS48287 RU-SERVICE-AS RU-SERVICE Ltd,RU

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Trojan.GenericKD.2260781, Trojan.GenericKD.2262459
100.00%

K7 AntiVirus
Trojan , Trojan-Downloader
100.00%

Bitdefender
Trojan.GenericKD.2260781, Trojan.GenericKD.2262459
100.00%

Kaspersky
Trojan-Dropper.Win32.Sysn, Trojan-Downloader.Win32.Genome
100.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2260781, Trojan.GenericKD.2262459
100.00%

Sophos
Troj/DarkCom-Z, Troj/Agent-AMJN
100.00%

F-Secure
Trojan.Delf.QDR, Trojan-Downloader:W32/Onkods.A
100.00%

Emsisoft Anti-Malware
Trojan.GenericKD.2260781, Trojan.GenericKD.2262459
100.00%

G Data
Trojan.GenericKD.2260781, Trojan.GenericKD.2262459
100.00%

ESET NOD32
Win32/Injector.BXGJ (variant), Win32/TrojanDownloader.Tiny.NLQ (variant)
100.00%

Panda Antivirus
Generic Suspicious, Trj/CI.A
100.00%

AVG
BackDoor.Ircbot, Downloader.Generic14
100.00%

nProtect
Trojan.GenericKD.2262459
50.00%

Quick Heal
TrojanDownloader.gen.r4
50.00%

McAfee
RDN/Generic Downloader.x!nd
50.00%

The domain sdance.su has been seen to resolve to the following 3 IP addresses.

May 20, 2016

expirepages-kiae-1.nic.ru
April 12, 2016

expirepages-kiae-2.nic.ru
April 12, 2016

File downloads found at URLs served by sdance.su.

32 / 68    (PUP)
http://sdance.su/.../d.exe  (62b5382e51328836194273760b9a5bd3)

12 / 68    (Malware)

The following 15 files have been seen to comunicate with sdance.su in live environments.

URL:
http://sdance.su/

Web server:
nginx

30 of 35 related domains