dlp2.mail.ru

MGL Mail.ru Internet Assets Limited

Domain Information

The domain dlp2.mail.ru registered by MGL Mail.ru Internet Assets Limited was initially registered in September of 1997 through RU-CENTER-REG-RIPN. Currently this domain has been known to host various forms of malware. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Saturday, September 27, 1997

Expires date:
Saturday, October 1, 2016

ASN:
AS47764 MAILRU-AS Limited liability company Mail.Ru,RU

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.MailRu.O, Win32.Generic
93.33%

F-Prot
W32/LoadMoney.A.gen
13.33%

avast!
Win32:LoadMoney-CW [PUP], Win32:LoadMoney-BU [PUP]
13.33%

VIPRE Antivirus
Threat.4781975
13.33%

ESET NOD32
Win32/LoadMoney.D potentially unwanted application, Win32/LoadMoney.L potentially unwanted application
13.33%

McAfee
Downloader-FKW, Program.Downloader-FKW
13.33%

Dr.Web
Adware.Downware.915
6.67%

AVG
Win.Threat.Medium
6.67%

MicroWorld eScan
Gen:Variant.Application.LoadMoney.70
6.67%

Malwarebytes
PUP.Optional.LoadMoney
6.67%

K7 AntiVirus
Trojan
6.67%

NANO AntiVirus
Riskware.Win32.Lmn.cgadbh
6.67%

Bitdefender
Gen:Variant.Application.LoadMoney.70
6.67%

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
6.67%

Lavasoft Ad-Aware
Gen:Variant.Application.LoadMoney.70
6.67%

The domain dlp2.mail.ru has been seen to resolve to the following 2 IP addresses.

lfrd.mail.ru
March 1, 2016

lfrd.mail.ru
March 1, 2016

File downloads found at URLs served by dlp2.mail.ru.

The following 16 files have been seen to comunicate with dlp2.mail.ru in live environments.

 
Latest 20 of 21 files

URL:
http://dlp2.mail.ru/

Title:
“Mail.Ru: почта, поиск в интернете, новости, игры”

Description:
“Почта Mail.Ru — крупнейшая бесплатная почта, быстрый и удобный интерфейс, неограниченный объем ящика, надежная защита от спама и вирусов, мобильная версия и приложения для смартфонов. Доступ по IMAP, SMS-уведомления, интерфейс на разных языках и ...”

SSL certificate subject:
CN=*.mail.ru, OU=IT, O=LLC Mail.Ru, L=Moscow, S=RUSSIAN FEDERATION, C=RU

SSL certificate issuer:
CN=GeoTrust SSL CA - G3, O=GeoTrust Inc., C=US

Web server:
nginx/1.6.2