ni220471_1.vweb02.nitrado.net

marbis GmbH

Domain Information

The domain ni220471_1.vweb02.nitrado.net registered by marbis GmbH was initially registered in January of 2005 through CPS-DATENSYSTEME GMBH. Currently this domain has been known to host various forms of malware. The hosted servers are located in Malsch, Baden-Wurttemberg within Germany which resides on the RIPE Network Coordination Centre network.
Registrar:
CPS-DATENSYSTEME GMBH

Server location:
Baden-Wurttemberg, Germany (DE)

Create date:
Friday, January 21, 2005

Expires date:
Saturday, January 21, 2017

Updated date:
Wednesday, January 6, 2016

ASN:
AS34309 LINK11 Link11 GmbH,DE

Root domain:

Scanner detections:
Malware distribution  (87% detected)

Scan engine
Details
Detections

Emsisoft Anti-Malware
Gen:Variant.Symmi.58342, Gen:Variant.Symmi.59468, Trojan.GenericKD.2930311, Gen:Variant.Symmi.58343, Trojan.GenericKD.3000350
76.19%

MicroWorld eScan
Gen:Variant.Symmi.58342, Gen:Variant.Symmi.59468, Trojan.GenericKD.2930311, Gen:Variant.Symmi.58343, Trojan.GenericKD.3000350, Trojan.GenericKD.2969499, Gen:Variant.Midie.3118, Gen:Variant.Strictor.76556
71.43%

Bitdefender
Gen:Variant.Symmi.58342, Gen:Variant.Symmi.59468, Trojan.GenericKD.2930311, Gen:Variant.Symmi.58343, Trojan.GenericKD.3000350
71.43%

G Data
Gen:Variant.Symmi.58342, Gen:Variant.Symmi.59468, Trojan.GenericKD.2930311, Gen:Variant.Symmi.58343, Trojan.GenericKD.3000350
71.43%

F-Secure
Gen:Variant.Symmi.58342, Gen:Variant.Symmi.59468, Trojan.GenericKD.2930311, Gen:Variant.Symmi.58343, Trojan.GenericKD.3000350
71.43%

McAfee
Artemis!C78E15F23023, Artemis!296EDC3328A5, Artemis!0A4161E3F1A0, Artemis!4BE54D5E46DF, Artemis!ABF5794AEE21, Artemis!3F5B867C9F77, Artemis!0D47B2A4DD89, Artemis!0DA1E4AF5CB6
66.67%

Lavasoft Ad-Aware
Gen:Variant.Symmi.58342, Gen:Variant.Symmi.59468, Trojan.GenericKD.2930311, Trojan.GenericKD.3000350, Gen:Variant.Symmi.58343
61.90%

Avira AntiVirus
TR/Symmi.2397696, TR/Symmi.2386944.2, TR/Symmi.2402304, TR/Symmi.2396160.2, TR/Symmi.2394112.1, TR/Rogue.1626112.39, TR/Rogue.1661952.3
61.90%

Arcabit
Trojan.Symmi.DE3E6, Trojan.Symmi.DE84C, Trojan.Generic.D2CB687, Trojan.Symmi.DE3E7, Trojan.Generic.D2DC81E, Trojan.Generic.D2D4F9B
61.90%

Qihoo 360 Security
Win32/Trojan.97a, HEUR/QVM19.1.Malware.Gen, HEUR/QVM33.0.Malware.Gen, Win32/Trojan.d6c
57.14%

Bkav FE
W32.HfsAutoB
42.86%

avast!
Win32:Evo-gen [Susp], Win32:Malware-gen, Win32:Apanas [Trj]
42.86%

AhnLab V3 Security
Trojan/Win32.Gen, Malware/Gen.Generic
42.86%

ESET NOD32
Win32/Packed.Themida suspicious (variant)
42.86%

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F], PE:Malware.Generic/QRS!1.9E2D [F]
42.86%

The domain ni220471_1.vweb02.nitrado.net has been seen to resolve to the following IP address.

vweb02.nitrado.net
February 2, 2016

File downloads found at URLs served by ni220471_1.vweb02.nitrado.net.

20 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (845373e5fe514037d6f447f1ae07aa4d)

7 / 68      (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (80ed68653652f832326cf207429fee9b)

1 / 68      (PUP)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (b6bd7e6d6d899a261ae245768555879f)

11 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (697f26b7eaf0c74424920021fa3bfaac)

1 / 68      (Malware)
http://ni220471_1.vweb02.nitrado.net/M2Bob - Patcher.exe  (7fcf3847acd93a3f52079aa1e2776bf5)

26 / 68    (PUP)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (bc8b5d85d061a663f2fc16561af9c6d8)

18 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (5f6dc939eacf61be86921719d7993aad)

21 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (cd31a63426a869b1e3df710401cab419)

3 / 68      (inconclusive)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (0da1e4af5cb646e0eb811405a49bca0f)

17 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (c78e15f2302318a13e6496f82d6857fe)

8 / 68      (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (bb8685e71742b0553671a48f2835d303)

14 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (4be54d5e46df7bf8da77e9d442127641)

12 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (296edc3328a57c4e4667aaaa479c5f77)

11 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (56a4b977424ac7831816416f514ceb21)

13 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (3f82ffba5f6589a67e9a9c89885ff65d)

11 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (9066c86ac4a22cc2e755738d762db55c)

14 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (0a4161e3f1a01a009976d90951604365)

0 / 68
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (c7caaa7ba0c01670689e6985db29e500)

21 / 68    (PUP)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (3f5b867c9f77404afe7dfc0da0b5f54c)

11 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (abf5794aee21f1b82d7b031f578ffe5a)

13 / 68    (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob.exe  (658c212b4dd418d7eb8b0123309a85bb)

4 / 68      (Malware)
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (0d47b2a4dd890484bdfd425d358ec5e7)

0 / 68
http://ni220471_1.vweb02.nitrado.net/.../M2Bob_Dll.dll  (69f5f7401400be8541dfb6e30518c001)

URL:
http://ni220471_1.vweb02.nitrado.net/

Title:
“Index of /”

Web server:
Apache/2.2.16