colorfashionbox.com

Corp New Ventures Services

Domain Information

The domain colorfashionbox.com registered by Corp New Ventures Services was initially registered in July of 2015 through DOMAINSOFTHEDAY.NET LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
DOMAINSOFTHEDAY.NET LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Sunday, July 12, 2015

Expires date:
Tuesday, July 12, 2016

Updated date:
Saturday, July 18, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
W32.GenericPhorpiexL.Trojan
100.00%

MicroWorld eScan
Trojan.GenericKD.2236917
100.00%

nProtect
Trojan.GenericKD.2236917
100.00%

Quick Heal
Trojan.IRCbot.g8
100.00%

McAfee
GenericR-DGM!5B0501733CFB
100.00%

Malwarebytes
Trojan.Downloader.Agent
100.00%

Zillya! Antivirus
Trojan.Inject.Win32.160194
100.00%

K7 AntiVirus
P2PWorm
100.00%

Arcabit
Trojan.Generic.D2221F5
100.00%

NANO AntiVirus
Trojan.Win32.DarkKomet.dpkbev
100.00%

ESET NOD32
Win32/AutoRun.IRCBot.JD
100.00%

Trend Micro House Call
WORM_PHORPIEX.UHZ
100.00%

avast!
Win32:Injector-CPK [Trj]
100.00%

Clam AntiVirus
Win.Trojan.Agent-859870
100.00%

Kaspersky
Trojan.Win32.IRCbot
100.00%

The domain colorfashionbox.com has been seen to resolve to the following IP address.

April 21, 2016

File downloads found at URLs served by colorfashionbox.com.

35 / 68    (Malware)
http://colorfashionbox.com/upd.exe  (5b0501733cfb63edd5188bf60aec2fbd)

The following 2 files have been seen to comunicate with colorfashionbox.com in live environments.

URL:
http://colorfashionbox.com/

Web server:
Apache