syspro-file.ru

Artex Management S.A.

Domain Information

The domain syspro-file.ru registered by Artex Management S.A. was initially registered in April of 2015 through RU-CENTER-RU. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Thursday, April 9, 2015

Expires date:
Saturday, April 9, 2016

ASN:
AS48287 RU-SERVICE-AS RU-SERVICE Ltd,RU

Scanner detections:
Detections  (60% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.ZAXAR, Threat.1GB, PUP.SpeedChecker.Optional.Installer.Meta (L)
60.00%

Dr.Web
Adware.Zaxar.7, Trojan.Zadved.61
40.00%

AVG
Generic, Downloader
40.00%

Malwarebytes
PUP.Optional.Zaxar.A
20.00%

Trend Micro House Call
Suspicious_GEN.F47V0118
20.00%

G Data
Win32.Application.Zaxar
20.00%

McAfee
Artemis!B9D958C7DD4C
20.00%

ESET NOD32
Win32/ZaxarGames.D potentially unwanted (variant)
20.00%

Fortinet FortiGate
Riskware/ZaxarGames
20.00%

ESET NOD32
Win32/eTranslatorPro.A potentially unwanted application
20.00%

The domain syspro-file.ru has been seen to resolve to the following 3 IP addresses.

expirepages-kiae-2.nic.ru
April 20, 2016

expirepages-kiae-1.nic.ru
April 20, 2016

March 3, 2016

File downloads found at URLs served by syspro-file.ru.

4 / 68      (Adware)

9 / 68      (Adware)

0 / 68
http://syspro-file.ru/.../1e6ae614bc2297ee271aca61b16a701e.exe  (eaecd047-1fb3-446b-ad14-1f7d27ccafb1.exe)

1 / 68      (PUP)

4 / 68      (Adware)

0 / 68
http://syspro-file.ru/.../h-0975049a3a9ff137c00dae7dac843671.exe  (e47d1d1d-5137-46b3-ba88-7a6ed0b64015.exe)

The following 15 files have been seen to comunicate with syspro-file.ru in live environments.

URL:
http://syspro-file.ru/

Web server:
nginx/1.2.1 (PHP/5.4.45-0+deb7u2)