ddriver.ru

Private Person  (Proxy Registrant)

Domain Information

The domain ddriver.ru is registered by proxy through REGRU-RU and was originally registered in May of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Berlin, Berlin within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Berlin, Germany (DE)

Create date:
Friday, May 22, 2009

Expires date:
Monday, May 22, 2017

ASN:
AS24940 HETZNER-AS Hetzner Online GmbH,DE

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.ROSTPAY.R, PUP.MediaFrog.ROSTPAY.Installer (M)
100.00%

Trend Micro House Call
TROJ_GEN.F47V0313
50.00%

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
50.00%

Rising Antivirus
PE:Malware.XPACK/RDM!5.1
50.00%

Dr.Web
Program.Unwanted.328
50.00%

The domain ddriver.ru has been seen to resolve to the following 2 IP addresses.

ddriver.ru
April 6, 2016

ddriver.ru
April 16, 2014

File downloads found at URLs served by ddriver.ru.

2 / 68      (PUP)

2 / 68      (PUP)

4 / 68      (PUP)
http://ddriver.ru/reklama/.../driverupdater_daj.exe  (1b8fd43d729a930ba5ffb140e1660197)

URL:
http://ddriver.ru/

Google Analytics:
UA-10441239

Title:
“Дай драйвер! - портал поиска драйверов”

Description:
“Дай драйвер! - портал поиска драйверов”

SSL certificate subject:
CN=www.ddriver.ru, OU=Domain Control Validated

SSL certificate issuer:
CN=GlobalSign Domain Validation CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Web server:
nginx

Facebook:
Likes:  5
Shares:  9

Statistics above are for the previous month of May 2017.