wih8wzoa2a2i3s1.paradyse.ru

Private Person  (Proxy Registrant)

Domain Information

The domain wih8wzoa2a2i3s1.paradyse.ru is registered by proxy through REGRU-RU and was originally registered in March of 2016. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Frankfurt Am Main, Hessen within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Hessen, Germany (DE)

Create date:
Monday, March 28, 2016

Expires date:
Tuesday, March 28, 2017

ASN:
AS28753 LEASEWEB-DE Leaseweb Deutschland GmbH, DE

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.InstallMonster, PUP.InstallMonster.AuditFir (M)
100.00%

The domain wih8wzoa2a2i3s1.paradyse.ru has been seen to resolve to the following 2 IP addresses.

domainparking.ru
April 17, 2016

March 1, 2016

File downloads found at URLs served by wih8wzoa2a2i3s1.paradyse.ru.

URL:
http://wih8wzoa2a2i3s1.paradyse.ru/

Title:
“Domain paradyse.ru maybe for sale”

Web server:
lighttpd/1.4.33 (PHP/5.5.9-1ubuntu4.14)