setup.testtraff.ru

Centr Informacionnykh Tekhnologiy, LLC

Domain Information

The domain setup.testtraff.ru registered by Centr Informacionnykh Tekhnologiy, LLC was initially registered in October of 2014 through REGRU-RU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Steinsel, Luxembourg within Luxembourg which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Luxembourg, Luxembourg (LU)

Create date:
Tuesday, October 21, 2014

Expires date:
Wednesday, October 21, 2015

ASN:
AS5577 ROOT root SA,LU

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Avira AntiVirus
APPL/OpenCandy.sger, ADWARE/MediaDrug.372736.1
75.00%

ESET NOD32
Win32/OpenCandy (variant), Win32/MediaDrug.A potentially unwanted (variant)
75.00%

Reason Heuristics
PUP.Installer.TOVAKVAPOLYANA.I, PUP.MediaDrug.Installer.Meta, PUP.Outbrowse.TOVAKVAPOLYANA.Bundler (M)
75.00%

K7 AntiVirus
Trojan , Adware
50.00%

Trend Micro House Call
Suspicious_GEN.F47V0113, TROJ_GEN.R047C0OEG15
50.00%

McAfee
Artemis!6C2EFCB33EA2, Artemis!E136BA668300
50.00%

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen, Win32/Virus.Adware.8e1
50.00%

Sophos
Generic PUA GE
25.00%

Baidu Antivirus
Adware.Win32.OpenCandy
25.00%

Malwarebytes
PUP.Optional.MediaDrug.C
25.00%

NANO AntiVirus
Trojan.Win32.DownLoader12.dqeumy
25.00%

avast!
Win32:Malware-gen
25.00%

Agnitum Outpost
Riskware.Agent
25.00%

Dr.Web
Trojan.DownLoader12.56194
25.00%

VIPRE Antivirus
Trojan.Win32.Generic
25.00%

The domain setup.testtraff.ru has been seen to resolve to the following IP address.

ip-static-94-242-221-153.as5577.net
April 7, 2015

File downloads found at URLs served by setup.testtraff.ru.

 
Latest 30 of 35 download URLs

The following 2 files have been seen to comunicate with setup.testtraff.ru in live environments.

URL:
http://setup.testtraff.ru/

Web server:
nginx