rfr.agent.mail.ru

MGL Mail.ru Internet Assets Limited

Domain Information

The domain rfr.agent.mail.ru registered by MGL Mail.ru Internet Assets Limited was initially registered in September of 1997 through RU-CENTER-REG-RIPN. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Moscow, Moscow City within Russia which resides on the RIPE Network Coordination Centre network.
Remove Malware from rfr.agent.mail.ru - Powered by Reason Core Security
Registrar:
RU-CENTER-RU

Server location:
Moscow City, Russia (RU)

Create date:
Saturday, September 27, 1997

Expires date:
Saturday, October 01, 2016

ASN:
AS47764 MAILRU-AS Limited liability company Mail.Ru

Root domain:

Scanner detections:
Detections  (92% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.Task.N, PUP.Optional.Installer.R, PUP.Optional.MailRu.J, PUP.Optional.Installer.L, PUP.Optional.Installer.S, Win32.Generic
100.00%

Kingsoft AntiVirus
Win32.HeurC.KVM019.a.(kcloud), Win32.TrojDownloader.Agent.yn.(kcloud)
33.33%

Sophos
RsMall
33.33%

VIPRE Antivirus
Trojan.Win32.Generic!SB.0
25.00%

Antiy Labs AVL
Worm/Win32.VB, Trojan[Backdoor]/Win32.Yobdam
16.67%

Bkav FE
W32.HfsAdware
16.67%

The domain rfr.agent.mail.ru has been seen to resolve to the following 10 IP addresses.

exe.agent.mail.ru
May 5, 2015

exe.agent.mail.ru
May 5, 2015

mra.mail.ru
December 1, 2014

mra.mail.ru
December 1, 2014

neck3.mail.ru
April 16, 2014

neck2.mail.ru
April 16, 2014

neck.mail.ru
January 23, 2014

neck6.mail.ru
January 23, 2014

neck5.mail.ru
January 23, 2014

neck4.mail.ru
January 23, 2014

File downloads found at URLs served by rfr.agent.mail.ru.

1 / 68      (Malware)
http://rfr.agent.mail.ru/magent_rfr1079.exe  (magent_rfrtoken_1079.exe)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)
https://rfr.agent.mail.ru/magent_rfr1496.exe  (magent_rfrset_damigo.exe)

2 / 68      (PUP)
https://rfr.agent.mail.ru/magent_rfrnavi.exe  (magent_rfrset_damigo.exe)

0 / 68
http://rfr.agent.mail.ru/magent_rfr1314.exe  (magent_rfrset_damigo.exe)

2 / 68      (PUP)
https://rfr.agent.mail.ru/magent.exe  (magent_rfrset_damigo.exe)

2 / 68      (PUP)

2 / 68      (PUP)
https://rfr.agent.mail.ru/magent_rfr1551.exe  (magent_rfrset_damigo.exe)

2 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68
http://rfr.agent.mail.ru/magent_rfrset.exe  (magent_rfrset_damigo.exe)

0 / 68
http://rfr.agent.mail.ru/magent.exe  (magent_rfrset_damigo.exe)

4 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)

2 / 68      (PUP)
http://rfr.agent.mail.ru/AgentWin8.exe  (217bd8a69c6aaa1cef8f7e4084a672ad)

The following 6 files have been seen to comunicate with rfr.agent.mail.ru in live environments.

URL:
http://rfr.agent.mail.ru/

SSL certificate subject:
CN=*.agent.mail.ru, OU=IT, O=LLC Mail.Ru, L=Moscow, S=RUSSIAN FEDERATION, C=RU

SSL certificate issuer:
CN=GeoTrust SSL CA - G3, O=GeoTrust Inc., C=US

Web server:
nginx/1.7.6

Remove Malware from rfr.agent.mail.ru - Powered by Reason Core Security