dlm.mail.ru

MGL Mail.ru Internet Assets Limited

Domain Information

The domain dlm.mail.ru registered by MGL Mail.ru Internet Assets Limited was initially registered in September of 1997 through RU-CENTER-REG-RIPN. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Remove Malware from dlm.mail.ru - Powered by Reason Core Security
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Saturday, September 27, 1997

Expires date:
Saturday, October 01, 2016

ASN:
AS47764 MAILRU-AS Limited liability company Mail.Ru

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Dr.Web
Adware.Downware.179
100.00%

Avira AntiVirus
APPL/LoadMoney.A.16
100.00%

ESET NOD32
Win32/Toolbar.MailRU
100.00%

Rising Antivirus
PE:Trojan.RuMail!1.6574
100.00%

Reason Heuristics
PUP.Optional.MailRu.u
100.00%

XVirus List
Win.Detected
100.00%

Agnitum Outpost
PUA.Toolbar.MailRU
100.00%

F-Prot
W32/Backdoor2.HTQA
100.00%

Antiy Labs AVL
Trojan/Win32.Tgenic
100.00%

Commtouch SDK
W32/Backdoor.TIVC-2005
100.00%

The domain dlm.mail.ru has been seen to resolve to the following IP address.

kojura.mail.ru
January 6, 2014

File downloads found at URLs served by dlm.mail.ru.

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_6f6c635c17f767b00865b42e4677b086.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_23cbaf7fd7c4c8c456ac1a141d890689.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_0311edd2b5449d975c75382a4c4a85c0.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_abd69f042b816bf709b34df457a239ff.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_4a80ad827fad60c44756d12a51021f71.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_2f354a09f12124bb446d509c4e6f5e31.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_5dd5c52b945e56a70016ecb1116f8e52.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_3a053f0726fd7c4894ec97a4f0e92d6f.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_4ef4d15a4c02302033122904c19b272f.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_462b2c3808ab64caf2c908a0dd055dbc.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_5dc6b793ceabfecf5ed70957d2ca1786.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_66e81fed39078f2b7479d500bab1bf24.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobit_9e2ee19caa3c2a8af1e6db44950fad30.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_c695335b10608a817c7e7b2e11e577e4.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_211cdc98bb39da955ad46055e995b020.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_0e15dae23a5e40ffa9e6c4d3f486524d.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_db82806f543630dee9951c8e904b0d41.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_690df745ee3df40f9bf7034a3ce85800.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_ce1fe7528f68653150236c900a128551.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_1ecdabbe1ba544a377c0f383faf51f43.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobit_f6de1f0408598403e1dfa1d05a20f4ef.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_90e7750017d494cae0fb5be36346e929.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_973e11e4b6b5ed57cc4749f6c34c2929.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_c48bc0ba51e5caeb928f580b3e124a4d.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_5ba8f0f0da37cb2d7b082f309785b8e1.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobitua_ccf25bca45319b9411acdbdc7e76330a.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_8f5f33795b0a35539420196614554255.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobit_91e5ce17ec19747a1deff74a5f7e260e.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_turbobit_6e169f5aacde101b6ac5cc4872270276.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

10 / 68    (PUP)
http://dlm.mail.ru/downloader_fmr_dd4009a3f4d350df803095a6c70842cd.exe  (downloader_turbobit_40b2130728658de68e71c01412ec2400.exe)

 
Latest 30 of 38 download URLs

The following 36 files have been seen to comunicate with dlm.mail.ru in live environments.

 
Latest 20 of 36 files

URL:
http://dlm.mail.ru/

SSL certificate subject:
CN=*.mail.ru, OU=IT, O=LLC Mail.Ru, L=Moscow, S=RUSSIAN FEDERATION, C=RU

SSL certificate issuer:
CN=GeoTrust SSL CA - G3, O=GeoTrust Inc., C=US

Web server:
nginx

Twitter:
Shares:  4

Statistics are for the previous month.

Remove Malware from dlm.mail.ru - Powered by Reason Core Security