ztfzjapnd5rau39.wahand.ru

CORLEON GROUP LTD

Domain Information

The domain ztfzjapnd5rau39.wahand.ru registered by CORLEON GROUP LTD was initially registered in July of 2014 through REGRU-REG-RIPN. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-REG-RIPN

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Saturday, July 5, 2014

Expires date:
Sunday, July 5, 2015

ASN:
AS59711 FORTUNIX-AS Fortunix Networks L.P.,GB

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

avast!
Win32:Malware-gen, Win32:Trojan-gen
100.00%

Kaspersky
Trojan.Win32.Inject
100.00%

ESET NOD32
Win32/InstallMonstr.EN potentially unwanted application, Win32/Hoax.ArchSMS.AHD.Gen application
100.00%

Malwarebytes
Trojan.SMSHoax
100.00%

VIPRE Antivirus
Threat.4150696
66.67%

Lavasoft Ad-Aware
Application.Generic.674116
66.67%

AVG
Adware Skodna.ArchSMS.CIV
66.67%

MicroWorld eScan
Application.Generic.674116
66.67%

K7 AntiVirus
JokeProgram
66.67%

NANO AntiVirus
Trojan.Win32.Inject.deifrs
66.67%

Agnitum Outpost
Trojan.Inject
66.67%

Comodo Security
UnclassifiedMalware
66.67%

F-Secure
Application.Generic.674116
66.67%

Sophos
Generic PUA GJ (PUA)
66.67%

Avira AntiVirus
TR/Fraud.Gen7
66.67%

The domain ztfzjapnd5rau39.wahand.ru has been seen to resolve to the following IP address.

July 31, 2014

File downloads found at URLs served by ztfzjapnd5rau39.wahand.ru.

URL:
http://ztfzjapnd5rau39.wahand.ru/

Web server:
nginx/1.4.2 (PHP/5.4.17)