chelmonline.pl

Domain Information

Server location:
Mazowieckie, Poland (PL)

ASN:
AS60782 INTERPLUS Inter Plus Sp. z o.o., PL

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Variant.Graftor.140290, Trojan.Inject.AQQ
66.67%

McAfee
Artemis!F0DD53D2E97F, RDN/Spybot.bfr!l
66.67%

Malwarebytes
Spyware.Zbot.ED, Spyware.ZeuS
66.67%

Kaspersky
Trojan.Win32.Reconyc, Trojan.Win32.Inject
66.67%

Bitdefender
Gen:Variant.Graftor.140290, Trojan.Inject.AQQ
66.67%

Lavasoft Ad-Aware
Gen:Variant.Graftor.140290, Trojan.Inject.AQQ
66.67%

Emsisoft Anti-Malware
Gen:Variant.Graftor.140290, Trojan.Inject.AQQ
66.67%

F-Secure
Gen:Variant.Graftor.140290, Trojan.Inject.AQQ
66.67%

Sophos
Troj/Wonton-CA, Mal/Zbot-QT
66.67%

Microsoft Security Essentials
VirTool:Win32/CeeInject.gen!KK, VirTool:Win32/Injector.gen!ET
66.67%

AhnLab V3 Security
Trojan/Win32.Ransomlock
66.67%

G Data
Gen:Variant.Graftor.140290, Trojan.Inject.AQQ
66.67%

Panda Antivirus
Trj/CI.A, Trj/Genetic.gen
66.67%

ESET NOD32
Win32/Injector.BCYH (variant), Win32/Injector.BCXR (variant)
66.67%

Qihoo 360 Security
Win32/Trojan.Multi.daf, HEUR/Malware.QVM19.Gen
66.67%

The domain chelmonline.pl has been seen to resolve to the following 2 IP addresses.

April 8, 2016

May 7, 2014

File downloads found at URLs served by chelmonline.pl.

1 / 68      (Malware)
http://chelmonline.pl/?0r6eyp=6ae9e3bf13cb66  (beautiful_photo_album.jpg.exe)

15 / 68    (Malware)
http://chelmonline.pl/?x9j9zoulr67n90=7a7037bfd027ed43bc5c  ({395a7992-07ce-7b67-b550-8f92395a7992}.exe)

15 / 68    (Malware)
http://chelmonline.pl/?gxiikmy=32d6c75e94fe1c924a  ({395a7992-07ce-7b67-b550-8f92395a7992}.exe)

35 / 68    (Malware)