956.m-tnkuu.xeihapolytechnique.com

Whois protection, this company does not own this domain name s.r.o.

Domain Information

The domain 956.m-tnkuu.xeihapolytechnique.com registered by Whois protection, this company does not own this domain name s.r.o. was initially registered in November of 2015 through HEBEI GUOJI MAOYI (SHANGHAI) LTD DBA HEBEIDOMAINS.COM. Currently this domain has been known to host various forms of malware. The hosted servers are located in Beaumaris, Victoria within Australia which resides on the Asia Pacific Network Information Centre network.
Registrar:
HEBEI GUOJI MAOYI (SHANGHAI) LTD DBA HEBEIDOMAINS.COM

Server location:
Victoria, Australia (AU)

Create date:
Tuesday, November 17, 2015

Expires date:
Thursday, November 17, 2016

Updated date:
Tuesday, November 17, 2015

ASN:
AS133618 TRELLIAN-AS-AP Trellian Pty. Limited,AU

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Microsoft Security Essentials
Threat.Undefined
100.00%

Dr.Web
Trojan.Kovter.118
100.00%

avast!
Win32:Malware-gen
100.00%

Emsisoft Anti-Malware
Gen:Variant.Jaik.9532
100.00%

ESET NOD32
Win32/Injector.CMMX trojan
100.00%

McAfee
Trojan.GenericR-FCN!1CE2189F190D
100.00%

VIPRE Antivirus
Threat.4150696
100.00%

Norman
Gen:Variant.Jaik.9532
100.00%

Lavasoft Ad-Aware
Gen:Variant.Jaik.9532
100.00%

Kaspersky
Trojan.Win32.VBKryjetor
100.00%

Sophos
Virus 'Troj/VBInj-MJ'
100.00%

The domain 956.m-tnkuu.xeihapolytechnique.com has been seen to resolve to the following IP address.

January 4, 2016

File downloads found at URLs served by 956.m-tnkuu.xeihapolytechnique.com.

11 / 68    (Malware)

The following file have been seen to comunicate with 956.m-tnkuu.xeihapolytechnique.com in live environments.

URL:
http://956.m-tnkuu.xeihapolytechnique.com/

Title:
“xeihapolytechnique.com”

Web server:
Apache