uuzmu1matzec9z8.faphib.ru

CORLEON GROUP LTD

Domain Information

The domain uuzmu1matzec9z8.faphib.ru registered by CORLEON GROUP LTD was initially registered in June of 2014 through REGRU-REG-RIPN. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-REG-RIPN

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Tuesday, June 24, 2014

Expires date:
Wednesday, June 24, 2015

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Root domain:

Google Safe Browsing:
malware

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.CORLEONGROUP.f, PUP.CORLEONGROUP.T
100.00%

VIPRE Antivirus
Threat.4845009
100.00%

avast!
Win32:InstallMonstr-DY [PUP]
100.00%

NANO AntiVirus
Trojan.Win32.InstallMonster.dbipfy
100.00%

Avira AntiVirus
APPL/InstallMonster.Gen
100.00%

Sophos
Install Monster
100.00%

G Data
Win32.Application.Installmonstr
100.00%

Vba32 AntiVirus
BScope.Downware.InstallMonstr
100.00%

Rising Antivirus
PE:Trojan.Agentb!6.211
100.00%

Panda Antivirus
PUP/InstallMonstr
100.00%

McAfee
Trojan.Artemis!6BFBD618CFC0, Trojan.Artemis!E45C33D560A6
100.00%

herdProtect (fuzzy)
a variant of a8fbd2b30047200b040e03549272165f488fabe9, a variant of 8f1a71d31f1b2348a89057b10a72b9899d26cd67
100.00%

The domain uuzmu1matzec9z8.faphib.ru has been seen to resolve to the following IP address.

August 17, 2014

File downloads found at URLs served by uuzmu1matzec9z8.faphib.ru.

URL:
http://uuzmu1matzec9z8.faphib.ru/

Web server:
nginx/1.4.2 (PHP/5.4.17)