dev.drp.su

Private Person  (Proxy Registrant)

Domain Information

The domain dev.drp.su is registered by proxy through R01-REG-FID and was originally registered in June of 2009. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
R01-REG-FID

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Wednesday, June 17, 2009

Expires date:
Friday, June 17, 2016

Root domain:

Scanner detections:
Detections  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Bundler.KuzyakovArtur.Meta (L), PUP.KuzyakovArturVyacheslavovichIP.N, Win32.Generic.KuzyakovArturVyacheslavovichIP.Installer.Meta, PUP.Bundler.KuzyakovArtur.Installer.Meta (L), PUP.Bundler.Kuzyakov.Meta (L), PUP.Bundler (L)
84.62%

Avira AntiVirus
SPR/Mrspt.A, APPL/Mrspt.A
46.15%

Rising Antivirus
PE:Trojan.RuMail!1.6574
35.90%

Antiy Labs AVL
Trojan/Win32.Patched.gen, Virus/Win32.Xpaj.gen
20.51%

Trend Micro House Call
TROJ_GEN.F47V0723, TROJ_GEN.F47V0808, TROJ_GEN.F47V0803, TROJ_GEN.F47V1222, TROJ_GEN.F47V0411, WORM_SPYBOT.BMH, TROJ_GEN.F47V0409
17.95%

Jiangmin
Trojan/Chifrax.fyc
12.82%

Kingsoft AntiVirus
Win32.Heur.KVMF43.hy.(kcloud)
7.69%

Dr.Web
Adware.Downware.9957
7.69%

Norman
Suspicious_Gen4.DUWHA
2.56%

Vba32 AntiVirus
Trojan.Genome.agxmv
2.56%

McAfee
Artemis!1321AE091430
2.56%

McAfee Web Gateway
BehavesLike.Win32.BadFile.tc
2.56%

The domain dev.drp.su has been seen to resolve to the following 12 IP addresses.

April 20, 2016

redstation.com
April 2, 2016

h188-227-175-225.host.redstation.co.uk
April 2, 2016

redstation.com
February 14, 2016

redstation.com
February 14, 2016

h88-150-206-2.host.redstation.co.uk
February 1, 2016

h88-150-137-207.host.redstation.co.uk
February 1, 2016

redstation.com
February 1, 2016

February 1, 2016

October 29, 2015

vps16008.5gbps.com
April 26, 2014

dedicated.coretek.ru
February 8, 2014

File downloads found at URLs served by dev.drp.su.

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../2903751030.exe  (a3adef08e3567db24ca7ce018ec57fe9)

1 / 68      (PUP)
http://dev.drp.su/download/drivers/.../3554550544.zip  (driverpack-online_2057143084.1451292654.exe)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../0090_sp38497.exe  (2b22e2dea785b983510e587aef11b95e)

1 / 68      (PUP)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../933401252.exe  (612a612ee5469471e3d175a0cc88b37b)

3 / 68      (PUP)
http://dev.drp.su/download/packer/.../8857_sp44320.exe  (5936dc5176ab89f526132f854cb76092)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../1141899515.exe  (12cf15948fcf1c4ba938b0e64449dd36)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../MDM_CXT.exe  (c4cf468e1900e4e09ca0f590b510acd7)

1 / 68      (PUP)
http://dev.drp.su/download/drivers/.../8810_driver_cardreader_ti_26871A.exe  (driverpack-17-online_1953676953.1447717529.exe)

2 / 68      (PUP)
http://dev.drp.su/.../DRPSu12.3-Lite.exe  (addf7180bb56a419b2c42cab3a4fed57)

1 / 68      (PUP)

4 / 68      (inconclusive)
http://dev.drp.su/download/packer/.../R227769.exe  (3915155d9c50580b1803fe58bf22ca31)

1 / 68      (PUP)
http://dev.drp.su/download/drivers/.../3138_sp44777.exe  (driverpack-online_178435651.1457107142.exe)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../8507337272.exe  (af06b827fac81f18e5b956ca91b22c4d)

1 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://dev.drp.su/.../DRPSu11-Final.rar  (driverpack-online_2057143084.1451292654.exe)

7 / 68      (PUP)
http://dev.drp.su/download/packer/.../9745507733.exe  (1321ae0914307b4213dbebe9008e5e49)

4 / 68      (PUP)
http://dev.drp.su/download/packer/.../1554761692.exe  (f6ddeff555b208143ef4dad8d477f9e9)

1 / 68      (PUP)
http://dev.drp.su/download/packer/.../4099735315.exe  (5ae89d8dd6092ad33865d8ea9a61e436)

1 / 68      (PUP)

4 / 68      (PUP)

3 / 68      (PUP)

3 / 68      (PUP)

4 / 68      (PUP)
http://dev.drp.su/download/packer/.../5533_sp36530.exe  (f3d265ed9b7954e5f51d18c1b42dc156)

4 / 68      (inconclusive)
http://dev.drp.su/download/packer/.../8363271609.exe  (337991c78d906b3a22ec2233a6224424)

 
Latest 30 of 41 download URLs

The following 13 files have been seen to comunicate with dev.drp.su in live environments.

 
Latest 20 of 49 files

URL:
http://dev.drp.su/

Title:
“Index of /”

Web server:
nginx

Facebook:
Shares:  1

Statistics are for the previous month.