reqrypt.org

Whois Privacy Protection Service, Inc.  (Proxy Registrant)

Domain Information

The domain reqrypt.org is registered by proxy through Name.com, LLC (R1288-LROR). Currently this domain has been known to host various forms of malware. The hosted servers are located in Phoenix, Arizona within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
Name.com, LLC (R1288-LROR)

Server location:
Arizona, United States (US)

ASN:
AS13335 CLOUDFLARENET - CloudFlare, Inc.,US

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP
100.00%

Trend Micro House Call
TROJ_GE.E090923C, Suspicious_GEN.F47V1108
66.67%

Bkav FE
HW32.Packed
33.33%

Vba32 AntiVirus
Downloader.Agent
33.33%

The domain reqrypt.org has been seen to resolve to the following 3 IP addresses.

May 26, 2016

May 26, 2016

May 1, 2014

File downloads found at URLs served by reqrypt.org.

1 / 68      (Malware)
https://reqrypt.org/.../TallowBundle-0.5-beta-install.exe  (71d99df8c281a7345abf34d5f0e9757a)

4 / 68      (Malware)
http://reqrypt.org/.../TallowBundle-0.3-beta-install.exe  (2ece9388e438124e98790fb5ab3ed2e1)

2 / 68      (Malware)
http://reqrypt.org/.../TorWall-install.exe  (423d99556cf688d1958326a869209924)

URL:
http://reqrypt.org/

Title:
“ReQrypt”

Web server:
X