down.fm-fm.com

Corp New Ventures Services

Domain Information

The domain down.fm-fm.com registered by Corp New Ventures Services was initially registered in April of 2015 through DOMAINJUNGLE.NET LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
DOMAINJUNGLE.NET LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Tuesday, April 21, 2015

Expires date:
Thursday, April 21, 2016

Updated date:
Monday, April 27, 2015

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Dr.Web
Trojan.PWS.Gina.82
100.00%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
100.00%

Reason Heuristics
PUP.BeijingYuJinChengTechnologyCo.I, PUP.BeijingYuJinChengTechnologyCo.M
100.00%

MicroWorld eScan
Gen:Variant.KillAV.2
50.00%

McAfee
Artemis!CE62AB8BAE7D
50.00%

Trend Micro House Call
TROJ_GEN.F47V0420
50.00%

Bitdefender
Gen:Variant.KillAV.2
50.00%

Lavasoft Ad-Aware
Gen:Variant.KillAV.2
50.00%

F-Secure
Gen:Variant.KillAV.2
50.00%

Emsisoft Anti-Malware
Gen:Variant.KillAV
50.00%

G Data
Gen:Variant.KillAV
50.00%

The domain down.fm-fm.com has been seen to resolve to the following IP address.

May 4, 2015

File downloads found at URLs served by down.fm-fm.com.

11 / 68    (Adware)

11 / 68    (Adware)

3 / 68      (Adware)
http://down.fm-fm.com/.../?????_45_007.exe  (极爽播放器_37_001.exe)

3 / 68      (Adware)
http://down.fm-fm.com/.../???????_37_001.exe  (极爽播放器_37_001.exe)

The following 2 files have been seen to comunicate with down.fm-fm.com in live environments.

URL:
http://down.fm-fm.com/

Web server:
Apache