dc209.gulfup.com
FR Group
Domain Information
The domain dc209.gulfup.com registered by FR Group was initially registered in April of 2006 through GODADDY.COM, LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Denver, Colorado within the United States which resides on the FDCservers.net network.
Registrar:
GODADDY.COM, LLC
Server location:
Colorado, United States (US)
Create date:
Thursday, April 6, 2006
Expires date:
Monday, April 3, 2023
Updated date:
Friday, June 13, 2014
ASN:
AS174 COGENT-174 - Cogent Communications,US
Scanner detections:
Malware distribution (67% detected)
Scan engine
Details
Detections
MicroWorld eScan
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%
avast!
MSIL:Dropper-AAE [Drp], MSIL:Agent-BZJ [Trj]
100.00%
Bitdefender
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%
Lavasoft Ad-Aware
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%
Emsisoft Anti-Malware
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%
F-Secure
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%
G Data
Gen:Variant.Barys.20644, Gen:Variant.Kazy.347104
100.00%
ESET NOD32
MSIL/Bladabindi (variant), MSIL/Injector.DBQ (variant)
100.00%
K7 AntiVirus
Trojan
50.00%
Kaspersky
HEUR:Trojan.Win32.Generic
50.00%
VIPRE Antivirus
Backdoor.MSIL.Bladabindi.a
50.00%
Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.B
50.00%
AhnLab V3 Security
Trojan/Win32.Generic
50.00%
Rising Antivirus
PE:Backdoor.MSIL.Bladabindi!1.9DE6
50.00%
IKARUS anti.virus
Trojan.Msil
50.00%
The domain dc209.gulfup.com has been seen to resolve to the following IP address.
admins.blacklistedhosting.com
April 16, 2014
File downloads found at URLs served by dc209.gulfup.com.
URL:
http://dc209.gulfup.com/