rejetto.webfactional.com

Swarma Limited

Domain Information

The domain rejetto.webfactional.com registered by Swarma Limited was initially registered in May of 2006 through TUCOWS DOMAINS INC.. Currently this domain has been known to host various forms of malware. The hosted servers are located in Amsterdam, Noord-Holland within Netherlands which resides on the RIPE Network Coordination Centre network.
Registrar:
TUCOWS DOMAINS INC.

Server location:
Noord-Holland, Netherlands (NL)

Create date:
Tuesday, May 23, 2006

Expires date:
Monday, May 23, 2016

Updated date:
Thursday, February 5, 2015

ASN:
AS36351 SOFTLAYER - SoftLayer Technologies Inc.,US

Root domain:

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

ESET NOD32
Win32/Server-Web.HFS (variant), Win32/Server-Web.HFS.A potentially unsafe (variant)
60.00%

Baidu Antivirus
Trojan.Win32.Server-Web, Adware.Win32.Server-Web, Hacktool.Win32.HFS
60.00%

Reason Heuristics
Threat.Win.Reputation.IMP
60.00%

K7 AntiVirus
Trojan
40.00%

AhnLab V3 Security
HackTool/Win32.HFS, Trojan/Win32.Generic
40.00%

Kaspersky
not-a-virus:Server-FTP.Win32.SFH, Virus.Win32.Nimnul
40.00%

Trend Micro House Call
TROJ_GEN.F47V0302
20.00%

Sophos
Generic PUA NG
20.00%

IKARUS anti.virus
not-a-virus:Server-FTP.Win32.SFH
20.00%

Fortinet FortiGate
Riskware/SFH
20.00%

VIPRE Antivirus
Threat.4732184
20.00%

ESET NOD32
Win32/Ramnit.H virus
20.00%

avast!
Win32:RmnDrp
20.00%

F-Prot
W32/Ramnit.B!Generic
20.00%

Dr.Web
Win32.Rmnet.8
20.00%

The domain rejetto.webfactional.com has been seen to resolve to the following IP address.

web314.webfaction.com
September 4, 2014

File downloads found at URLs served by rejetto.webfactional.com.

8 / 68      (Infected)
http://rejetto.webfactional.com/.../hfs.exe  (cd89df848b046080d24fc0627edcc227)

1 / 68      (Malware)
http://rejetto.webfactional.com/.../hfs.exe  (9edf7f1457d5ccd8dffa67f74a23fdff)

3 / 68      (Malware)
http://rejetto.webfactional.com/.../hfs.exe  (c019d10f80409fc4c7d45ebfa48b0076)

9 / 68      (PUP)
http://rejetto.webfactional.com/.../hfs.exe  (52364cf04ff8fb1834971de14ec7a7e3)

5 / 68      (Malware)
http://rejetto.webfactional.com/.../hfs.exe  (1c14ece37d3872a0ddd31ea68ac26b14)

URL:
http://rejetto.webfactional.com/

Web server:
nginx