use-savv.ru

Private Person  (Proxy Registrant)

Domain Information

The domain use-savv.ru is registered by proxy through REGRU-RU and was originally registered in January of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
REGRU-RU

Server location:
Arizona, United States (US)

Create date:
Friday, January 22, 2016

Expires date:
Sunday, January 22, 2017

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc., US

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Amonitize (M), Adware.Amonetize.Amonitize.Meta (M), Adware.Amonetize (M)
98.00%

VIPRE Antivirus
Threat.4721115
2.00%

ESET NOD32
Win32/Sality.NBA virus
2.00%

F-Prot
W32/Sality.gen2
2.00%

avast!
Win32:SaliCode
2.00%

Microsoft Security Essentials
Threat.Undefined
2.00%

Emsisoft Anti-Malware
Win32.Sality
2.00%

The domain use-savv.ru has been seen to resolve to the following 2 IP addresses.

April 16, 2016

April 16, 2016

File downloads found at URLs served by use-savv.ru.

 
Latest 30 of 128 download URLs

URL:
http://use-savv.ru/

Title:
“Welcome to nginx!”

SSL certificate subject:
CN=sni141924.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
cloudflare-nginx