fileshare7520.depositfiles.org

SONGUL CORPORATION

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in Steinsel, Luxembourg within Luxembourg which resides on the RIPE Network Coordination Centre network.
Registrar:
EuroDNS S.A.

Server location:
Luxembourg, Luxembourg (LU)

ASN:
AS5577 ROOT root SA,LU

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

MicroWorld eScan
Gen:Heur.Crifi.2
100.00%

K7 AntiVirus
Trojan
100.00%

Agnitum Outpost
HackTool.Crack
100.00%

Trend Micro House Call
TROJ_GEN.RCBH1K2
100.00%

Kaspersky
Trojan.Win32.Chifrax
100.00%

Bitdefender
Gen:Heur.Crifi.2
100.00%

NANO AntiVirus
Trojan.Win32.Crack.wovtt
100.00%

Sophos
Mal/Chifrax-A
100.00%

F-Secure
Gen:Heur.Crifi.2
100.00%

Trend Micro
TROJ_SPNR.0CCR12
100.00%

G Data
Gen:Heur.Crifi
100.00%

ESET NOD32
Win32/HackTool.Crack (variant)
100.00%

Rising Antivirus
Dropper.Win32.Droper.cdd
100.00%

Fortinet FortiGate
W32/Chifrax.A!tr
100.00%

The domain fileshare7520.depositfiles.org has been seen to resolve to the following 12 IP addresses.

ip-static-94-242-227-203.as5577.net
April 19, 2016

ip-static-94-242-227-195.as5577.net
April 19, 2016

ip-static-94-242-227-191.as5577.net
April 19, 2016

ip-static-94-242-227-187.as5577.net
April 19, 2016

ip-static-94-242-227-167.as5577.net
April 19, 2016

ip-static-94-242-227-163.as5577.net
April 19, 2016

ip-static-94-242-227-147.as5577.net
April 19, 2016

ip-static-94-242-227-135.as5577.net
April 19, 2016

ip-static-94-242-236-65.as5577.net
April 19, 2016

ip-static-94-242-236-57.as5577.net
April 19, 2016

ip-static-94-242-236-45.as5577.net
April 19, 2016

ip-static-94-242-227-207.as5577.net
April 19, 2016

File downloads found at URLs served by fileshare7520.depositfiles.org.

The following 5 files have been seen to comunicate with fileshare7520.depositfiles.org in live environments.

 
Latest 20 of 27 files

URL:
http://fileshare7520.depositfiles.org/

Title:
“DepositFiles”

Description:
“DepositFiles provides you with a legitimate technical solution, which enables you to upload, store, access and download text, software, scripts, images, sounds, videos, animations and any other materials in form of one or several electronic fil...”

Web server:
nginx