oksrv.ru

Private Person  (Proxy Registrant)

Domain Information

The domain oksrv.ru is registered by proxy through REGRU-RU and was originally registered in February of 2016. Currently this domain has been known to host various forms of malware. The hosted servers are located in Roubaix, Nord-Pas-De-Calais within France which resides on the RIPE Network Coordination Centre network.
Registrar:
REGRU-RU

Server location:
Nord-Pas-De-Calais, France (FR)

Create date:
Thursday, February 11, 2016

Expires date:
Saturday, February 11, 2017

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SilverSo (M), PUP (M)
100.00%

ESET NOD32
Win32/Kryptik.FAKL trojan
25.00%

Dr.Web
Trojan.LoadMoney.336
25.00%

The domain oksrv.ru has been seen to resolve to the following 2 IP addresses.

ns334112.ip-37-187-118.eu
August 17, 2016

mizma448.vds
July 9, 2016

File downloads found at URLs served by oksrv.ru.

1 / 68      (Malware)
http://oksrv.ru/1d4p?keyword=stalker-spetsnaz-mod-2015-torrent  (stalker-spetsnaz-mod-2015-torrent.exe)

1 / 68      (Malware)

1 / 68      (PUP)

3 / 68      (PUP)

URL:
http://oksrv.ru/

Title:
“Softportal - Самая большая база файлов c постоянным обновлением.”

Web server:
nginx/1.0.14 (PHP/5.3.10)