setup.pereday.ru

Private Person  (Proxy Registrant)

Domain Information

The domain setup.pereday.ru is registered by proxy through ARDIS-RU and was originally registered in February of 2008. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Steinsel, Luxembourg within Luxembourg which resides on the RIPE Network Coordination Centre network.
Registrar:
ARDIS-RU

Server location:
Luxembourg, Luxembourg (LU)

Create date:
Friday, February 1, 2008

Expires date:
Wednesday, February 1, 2017

ASN:
AS5577 ROOT root SA,LU

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.RECORD, PUP.RECORD (M), PUP.RECORD.Installer (M), Threat.Win.Reputation.IMP
78.95%

Bkav FE
W32.HfsAdware
63.16%

Dr.Web
Adware.Downware.10568, Program.VKontakteDJ.1
63.16%

IKARUS anti.virus
AdWare.AdInstaller
63.16%

AVG
AdInstaller.kontakte
57.89%

McAfee
Artemis!0DA8CB2323C1, Artemis!C601DC226BD3, Artemis!6E4D8719F28D, Artemis!AECF9C605B98, Artemis!0F5CF592E0CE, Artemis!28F52DD6EE7D
52.63%

VIPRE Antivirus
Trojan.Win32.Generic, Adware AdInstaller.kontakte
52.63%

MicroWorld eScan
Gen:Variant.Application.Downloader.207
47.37%

K7 AntiVirus
Adware , Riskware
47.37%

Bitdefender
Gen:Variant.Application.Downloader.207
47.37%

Lavasoft Ad-Aware
Gen:Variant.Application.Downloader.207
47.37%

F-Secure
Gen:Variant.Application.Downloader
47.37%

Avira AntiVirus
TR/Dldr.Agent.244408, TR/Dldr.Agent.241848.2, TR/Dldr.Agent.230072, TR/Dldr.Agent.230072.5, TR/Dldr.Agent.244408.1, TR/Dldr.Agent.232632.1
47.37%

G Data
Gen:Variant.Application.Downloader.207
47.37%

Trend Micro House Call
Suspicious_GEN.F47V0501, Suspicious_GEN.F47V0507, Suspicious_GEN.F47V0430, Suspicious_GEN.F47V0510, Suspicious_GEN.F47V0617
42.11%

The domain setup.pereday.ru has been seen to resolve to the following 2 IP addresses.

ip-static-94-242-221-153.as5577.net
July 16, 2015

July 1, 2015

File downloads found at URLs served by setup.pereday.ru.

20 / 68    (Adware)
http://setup.pereday.ru/.../?advert_key=ZWMwMDAxMDBiNDAwMDFmZjAwMDAwMWVkMDAwMWVkMDAwMWVkZmIyMDRmYWEwMg==&name=???? "????????"(?.???????) - Muzyk nocy(Live)  (☆crazy town - [come my lady]come my lady come, come my lady you're my butterfly sugar baby come my)

16 / 68    (Adware)

16 / 68    (Adware)
http://setup.pereday.ru/.../?advert_key=ZWMwMDAxMDBiNDAwMDFmZjAwMDAwMWVkMDAwMWVkMDAwMWVkZmIyMDRmYWEwMg==&name=null - null  (ebru gundes - tesekkur ederim by_farmakoloq - ebru gundes - tesekkur ederim.exe)

16 / 68    (Adware)

7 / 68      (Adware)

1 / 68      (Adware)

16 / 68    (Adware)

 
Latest 30 of 59 download URLs

The following 2 files have been seen to comunicate with setup.pereday.ru in live environments.

URL:
http://setup.pereday.ru/

Web server:
nginx