sysfile-pro.ru

Artex Management S.A.

Domain Information

The domain sysfile-pro.ru registered by Artex Management S.A. was initially registered in April of 2015 through RU-CENTER-RU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Edinburgh, Scotland within United Kingdom which resides on the Latin American and Caribbean IP address Regional Registry network.
Registrar:
RU-CENTER-RU

Server location:
Scotland, United Kingdom (GB)

Create date:
Thursday, April 9, 2015

Expires date:
Saturday, April 9, 2016

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Trend Micro House Call
Suspicious_GEN.F47V0118, Suspicious_GEN.F47V0526
100.00%

G Data
Win32.Application.Zaxar, Trojan.GenericKD.2444130
100.00%

Malwarebytes
PUP.Optional.Zaxar.A
50.00%

Dr.Web
Adware.Zaxar.7
50.00%

McAfee
Artemis!B9D958C7DD4C
50.00%

ESET NOD32
Win32/ZaxarGames.D potentially unwanted (variant)
50.00%

Fortinet FortiGate
Riskware/ZaxarGames
50.00%

AVG
Generic
50.00%

Reason Heuristics
PUP.Installer.ZAXAR
50.00%

MicroWorld eScan
Trojan.GenericKD.2444130
50.00%

nProtect
Trojan.GenericKD.2444130
50.00%

Bitdefender
Trojan.GenericKD.2444130
50.00%

Lavasoft Ad-Aware
Trojan.GenericKD.2444130
50.00%

F-Secure
Trojan.GenericKD.2444130
50.00%

Emsisoft Anti-Malware
Trojan.GenericKD.2444130
50.00%

The domain sysfile-pro.ru has been seen to resolve to the following IP address.

March 31, 2016

File downloads found at URLs served by sysfile-pro.ru.

9 / 68      (PUP)
http://sysfile-pro.ru/.../h-0975049a3a9ff137c00dae7dac843671.exe  (521f722a-5fe1-4837-b770-ae512d45baf1.exe)

9 / 68      (Adware)

URL:
http://sysfile-pro.ru/

Web server:
nginx/1.2.1 (PHP/5.4.45-0+deb7u2)