dlp4.mail.ru

MGL Mail.ru Internet Assets Limited

Domain Information

The domain dlp4.mail.ru registered by MGL Mail.ru Internet Assets Limited was initially registered in September of 1997 through RU-CENTER-REG-RIPN. Currently this domain has been known to host various forms of malware. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Saturday, September 27, 1997

Expires date:
Saturday, October 1, 2016

ASN:
AS47764 MAILRU-AS Limited liability company Mail.Ru,RU

Root domain:

Scanner detections:
Malware distribution  (88% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.MailRu.Q, PUP.Optional.MailRu.H, Win32.Generic, PUP.MailRu.Optional
100.00%

VIPRE Antivirus
Threat.4781975
14.29%

Emsisoft Anti-Malware
Gen:Variant.Application.LoadMoney.70
14.29%

ESET NOD32
Win32/LoadMoney.K potentially unwanted application
14.29%

F-Prot
W32/LoadMoney.A.gen
14.29%

AVG
Potentially harmful program MLoader.A
14.29%

Dr.Web
Adware.Downware.915, Trojan.Packed.24079
14.29%

avast!
Win32:LoadMoney-DW [PUP]
14.29%

Kaspersky
not-a-virus:HEUR:Downloader.Win32.LMN
14.29%

MicroWorld eScan
Gen:Variant.Application.LoadMoney.70
14.29%

McAfee
Downloader-FKW
14.29%

K7 AntiVirus
Trojan
14.29%

NANO AntiVirus
Riskware.Win32.Lmn.cgadbh
14.29%

Norman
Kryptik.TXY
14.29%

Bitdefender
Gen:Variant.Application.LoadMoney.70
14.29%

The domain dlp4.mail.ru has been seen to resolve to the following 2 IP addresses.

lfrd.mail.ru
April 3, 2016

lfrd.mail.ru
April 3, 2016

File downloads found at URLs served by dlp4.mail.ru.

The following 16 files have been seen to comunicate with dlp4.mail.ru in live environments.

 
Latest 20 of 21 files

URL:
http://dlp4.mail.ru/

Title:
“Mail.Ru: почта, поиск в интернете, новости, игры”

Description:
“Почта Mail.Ru — крупнейшая бесплатная почта, быстрый и удобный интерфейс, неограниченный объем ящика, надежная защита от спама и вирусов, мобильная версия и приложения для смартфонов. Доступ по IMAP, SMS-уведомления, интерфейс на разных языках и ...”

SSL certificate subject:
CN=*.mail.ru, OU=IT, O=LLC Mail.Ru, L=Moscow, S=RUSSIAN FEDERATION, C=RU

SSL certificate issuer:
CN=GeoTrust SSL CA - G3, O=GeoTrust Inc., C=US

Web server:
nginx/1.6.2