dc209.gulfup.com

FR Group

Domain Information

The domain dc209.gulfup.com registered by FR Group was initially registered in April of 2006 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Denver, Colorado within the United States which resides on the FDCservers.net network.
Registrar:
GODADDY.COM, LLC

Server location:
Colorado, United States (US)

Create date:
Thursday, April 6, 2006

Expires date:
Monday, April 3, 2023

Updated date:
Friday, June 13, 2014

ASN:
AS174 COGENT-174 - Cogent Communications,US

Root domain:

Scanner detections:
Malware distribution  (67% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%

avast!
MSIL:Dropper-AAE [Drp], MSIL:Agent-BZJ [Trj]
100.00%

Bitdefender
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%

Lavasoft Ad-Aware
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%

Emsisoft Anti-Malware
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%

F-Secure
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%

G Data
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%

ESET NOD32
MSIL/Bladabindi (variant), MSIL/Injector.DBQ (variant)
100.00%

K7 AntiVirus
Trojan
50.00%

Kaspersky
HEUR:Trojan.Win32.Generic
50.00%

VIPRE Antivirus
Backdoor.MSIL.Bladabindi.a
50.00%

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.B
50.00%

AhnLab V3 Security
Trojan/Win32.Generic
50.00%

Rising Antivirus
PE:Backdoor.MSIL.Bladabindi!1.9DE6
50.00%

IKARUS anti.virus
Trojan.Msil
50.00%

The domain dc209.gulfup.com has been seen to resolve to the following IP address.

admins.blacklistedhosting.com
April 16, 2014

File downloads found at URLs served by dc209.gulfup.com.

0 / 68

11 / 68    (Malware)
http://dc209.gulfup.com/UKydrf.exe  (fb hack v1.1.2.exe)

16 / 68    (Malware)
http://dc209.gulfup.com/IsoH26.exe  (صور مراتي الخاصة المتحركه.exe)

URL:
http://dc209.gulfup.com/

Web server:
Gulfup.com