www.papyon.co

Mageist

Domain Information

The domain www.papyon.co registered by Mageist was initially registered in September of 2015 through DOMAIN.COM LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Scottsdale, Arizona within the United States which resides on the GoDaddy.com, LLC network.
Registrar:
GODADDY.COM, INC.

Server location:
Arizona, United States (US)

Create date:
Wednesday, September 30, 2015

Expires date:
Thursday, September 29, 2016

Updated date:
Wednesday, September 30, 2015

ASN:
AS26496 AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC

Root domain:

Scanner detections:
Detections  (67% detected)

Scan engine
Details
Detections

avast!
Win32:BHO-ALF [Trj], Win32:Malware-gen
83.33%

G Data
Win32.Trojan.Agent.M7EJ61, Win32.Trojan.Agent.PMBWYO, Win32.Trojan.Agent.MZ524U, Win32.Trojan.Agent.RU71JA
66.67%

Qihoo 360 Security
Win32/RootKit.Rootkit.7e5, HEUR/Malware.QVM06.Gen, Win32/Trojan.65b
50.00%

McAfee
Artemis!253403603B8B, Artemis!40AD37D03792
33.33%

IKARUS anti.virus
Win32.BHO.ALF
33.33%

ESET NOD32
MSIL/StartPage.AT trojan
33.33%

Norman
Suspicious_Gen4.FSRFX
16.67%

Panda Antivirus
Trj/BHO.IB
16.67%

Total Defense
Win32/Tnega.ISRNMT
16.67%

Trend Micro House Call
TROJ_GEN.R0CBH01LP13
16.67%

Reason Heuristics
PUP.iSoft.Bundler.Meta (M)
16.67%

Dr.Web
Trojan.StartPage1.757
16.67%

VIPRE Antivirus
Threat.4150696
16.67%

F-Secure
Variant.Kazy.390954
16.67%

The domain www.papyon.co has been seen to resolve to the following 3 IP addresses.

ip-50-63-202-61.ip.secureserver.net
April 12, 2016

139-168-238-213.ip.idealhosting.net.tr
December 1, 2014

196-166-238-213.ip.idealhosting.net.tr
June 21, 2014

File downloads found at URLs served by www.papyon.co.

6 / 68      (Malware)

3 / 68      (inconclusive)

3 / 68      (inconclusive)

6 / 68      (PUP)
http://www.papyon.co/indir.php  (flv-player.exe)

The following 64 files have been seen to comunicate with www.papyon.co in live environments.

 
Latest 20 of 64 files

URL:
http://www.papyon.co/

Web server:
Microsoft-IIS/7.5 (ASP.NET) (Version: 4.0.30319)