rfr.agent.mail.ru

MGL Mail.ru Internet Assets Limited

Domain Information

The domain rfr.agent.mail.ru registered by MGL Mail.ru Internet Assets Limited was initially registered in September of 1997 through RU-CENTER-REG-RIPN. Currently this domain has been known to host various forms of malware. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Saturday, September 27, 1997

Expires date:
Saturday, October 01, 2016

ASN:
AS47764 MAILRU-AS Limited liability company Mail.Ru

Root domain:

Scanner detections:
Malware distribution  (81% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Installer.L, PUP.Optional.Installer.R, PUP.Optional.Installer.Y, PUP.Optional.Installer.N, PUP.Optional.Installer.S, Win32.Generic.MailRu.Installer.Meta
100.00%

Sophos
RsMall
17.65%

Antiy Labs AVL
Worm/Win32.VB, Trojan[Backdoor]/Win32.Yobdam
17.65%

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
14.71%

Kingsoft AntiVirus
Win32.TrojDownloader.Agent.yn.(kcloud)
11.76%

Avira AntiVirus
APPL/LoadMoney.O.2
5.88%

Comodo Security
UnclassifiedMalware
5.88%

Bkav FE
W32.HfsAdware
5.88%

Trend Micro House Call
TROJ_GEN.F47V1030
2.94%

avast!
Win32:Downloader-TPW [PUP]
2.94%

Vba32 AntiVirus
Downware.LMN.gen
2.94%

AVG
MalSign.Generic
2.94%

The domain rfr.agent.mail.ru has been seen to resolve to the following 10 IP addresses.

exe.agent.mail.ru
May 5, 2015

exe.agent.mail.ru
May 5, 2015

mra.mail.ru
December 1, 2014

mra.mail.ru
December 1, 2014

neck3.mail.ru
April 16, 2014

neck2.mail.ru
April 16, 2014

neck.mail.ru
January 23, 2014

neck6.mail.ru
January 23, 2014

neck5.mail.ru
January 23, 2014

neck4.mail.ru
January 23, 2014

File downloads found at URLs served by rfr.agent.mail.ru.

1 / 68      (PUP)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfrnavi.exe  (magent_rfrtoken_navi.exe)

3 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (PUP)
http://rfr.agent.mail.ru/magent.exe  (magentsetup_rfrib.exe)

4 / 68      (PUP)

2 / 68      (PUP)
https://rfr.agent.mail.ru/magent_rfr1312.exe  (magent_rfrset_damigo.exe)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfrdamigo.exe  (magent_rfrtoken_damigo.exe)

2 / 68      (PUP)

2 / 68      (PUP)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfr1082.exe  (magent_rfrtoken_1082.exe)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfr1112.exe  (magent_rfrtoken_1112.exe)

0 / 68
http://rfr.agent.mail.ru/magent_rfrset.exe  (b4712ebf9dd802df5067fb44b6eaf561)

0 / 68

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfr1316.exe  (magent_rfrtoken_1316.exe)

4 / 68      (PUP)
http://rfr.agent.mail.ru/magent_rfr1080.exe  (magent_rfrset_gamecenter.exe)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfrdamigo1313.exe  (magent_rfrtoken_damigo1313.exe)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfr1079.exe  (magent_rfrtoken_1079.exe)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfrdamigo1079.exe  (magent_rfrtoken_damigo1079.exe)

1 / 68      (PUP)

0 / 68
http://rfr.agent.mail.ru/magent_rfrtoken.exe  (867052a14fbd00947d5463c8d8e3b6fc)

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfrdamigo1316.exe  (magent_rfrtoken_damigo1316.exe)

1 / 68      (Malware)
https://rfr.agent.mail.ru/magent_rfrdamigo1394.exe  (magent_rfrtoken_damigo1394.exe)

3 / 68      (PUP)

2 / 68      (PUP)

0 / 68

7 / 68      (PUP)

1 / 68      (Malware)

 
Latest 30 of 241 download URLs

The following 52 files have been seen to comunicate with rfr.agent.mail.ru in live environments.

 
Latest 20 of 112 files

URL:
http://rfr.agent.mail.ru/

SSL certificate subject:
CN=*.agent.mail.ru, OU=IT, O=LLC Mail.Ru, L=Moscow, S=RUSSIAN FEDERATION, C=RU

SSL certificate issuer:
CN=GeoTrust SSL CA - G3, O=GeoTrust Inc., C=US

Web server:
nginx/1.7.6