6a0b0voptk.1fichier.com

Yohan TORDJMAN

Domain Information

The domain 6a0b0voptk.1fichier.com registered by Yohan TORDJMAN was initially registered in December of 2009 through ONLINE SAS. Currently this domain has been known to host various forms of malware. The hosted servers are located in Paris, Ile-De-France within France which resides on the RIPE Network Coordination Centre network.
Registrar:
ONLINE SAS

Server location:
Ile-De-France, France (FR)

Create date:
Monday, December 7, 2009

Expires date:
Wednesday, December 7, 2016

Updated date:
Sunday, July 6, 2014

ASN:
AS198792 DSTORAGE DSTORAGE s.a.s.

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Microsoft Security Essentials
Threat.Undefined
100.00%

avast!
SaliCode
100.00%

Emsisoft Anti-Malware
Win32.Sality
100.00%

Dr.Web
Win32.Sector.30
100.00%

VIPRE Antivirus
Threat.4721115
100.00%

McAfee
Virus.W32/Sality.gen.z
100.00%

ESET NOD32
Win32/Sality.NBA virus
100.00%

Lavasoft Ad-Aware
Win32.Sality.3
100.00%

F-Prot
W32/Sality.gen2
100.00%

Kaspersky
Virus.Win32.Sality
100.00%

AVG
Win32/Sality
100.00%

F-Secure
Win32.Sality.3
100.00%

Norman
Win32.Sality.3
100.00%

Sophos
Virus 'Mal/Sality-D'
100.00%

Bkav FE
W32.Sality.PE
100.00%

The domain 6a0b0voptk.1fichier.com has been seen to resolve to the following IP address.

www.1fichier.com
November 7, 2015

File downloads found at URLs served by 6a0b0voptk.1fichier.com.

37 / 68    (Infected)
http://6a0b0voptk.1fichier.com/  (tor_portable_multiversion_online.exe)

The following 14 files have been seen to comunicate with 6a0b0voptk.1fichier.com in live environments.

URL:
http://6a0b0voptk.1fichier.com/

SSL certificate subject:
CN=*.1fichier.com, OU=Domain Control Validated - RapidSSL(R), OU=See www.rapidssl.com/resources/cps (c)15, OU=GT91339487

SSL certificate issuer:
CN=RapidSSL SHA256 CA - G3, O=GeoTrust Inc., C=US

Web server:
[Sep 28 2015 11:12:16]