down1.optimizedisk.com

New Ventures Services, Corp

Domain Information

The domain down1.optimizedisk.com registered by New Ventures Services, Corp was initially registered in April of 2016 through TURBONAMES LLC. Currently this domain has been known to host various forms of malware. The hosted servers are located in Road Town, British Virgin Islands within VG which resides on the Confluence Networks Inc network.
Registrar:
TURBONAMES LLC

Server location:
British Virgin Islands, VG (VG)

Create date:
Saturday, April 16, 2016

Expires date:
Sunday, April 16, 2017

Updated date:
Saturday, April 23, 2016

ASN:
AS40034 CONFLUENCE-NETWORK-INC - Confluence Networks Inc,VG

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Bkav FE
HW32.Packed
100.00%

MicroWorld eScan
Gen:Variant.Kazy.537936
100.00%

F-Prot
W32/Threat-HLLIE-based
100.00%

Trend Micro House Call
TROJ_GEN.R047H09BO15
100.00%

avast!
Win32:Dropper-gen [Drp]
100.00%

Bitdefender
Gen:Variant.Kazy.537936
100.00%

Lavasoft Ad-Aware
Gen:Variant.Kazy.537936
100.00%

Emsisoft Anti-Malware
Gen:Variant.Kazy.537936
100.00%

F-Secure
Gen:Variant.Kazy.537936
100.00%

VIPRE Antivirus
Trojan.Win32.Generic
100.00%

Avira AntiVirus
TR/Kazy.2782720
100.00%

G Data
Gen:Variant.Kazy.537936
100.00%

McAfee
Artemis!259B612B11D4
100.00%

IKARUS anti.virus
Win32.SuspectCrc
100.00%

Qihoo 360 Security
HEUR/QVM18.1.Malware.Gen
100.00%

The domain down1.optimizedisk.com has been seen to resolve to the following IP address.

July 25, 2016

File downloads found at URLs served by down1.optimizedisk.com.

24 / 68    (Malware)
http://down1.optimizedisk.com/AFF/.../performance.exe  (259b612b11d4a9f9150393e5670b2c09)

The following 2 files have been seen to comunicate with down1.optimizedisk.com in live environments.

URL:
http://down1.optimizedisk.com/

Web server:
Apache