vc02.free.fr

Free SAS  (Proxy Registrant)

Domain Information

The domain vc02.free.fr is registered by proxy through ONLINE SAS. Currently this domain has been known to host various forms of malware. The hosted servers are located in Bezons, Ile-De-France within France which resides on the RIPE Network Coordination Centre network.
Registrar:
ONLINE SAS

Server location:
Ile-De-France, France (FR)

ASN:
AS12322 PROXAD Free SAS,FR

Root domain:

Scanner detections:
Malware distribution  (60% detected)

Scan engine
Details
Detections

Norman
Suspicious_Gen4.DWRDF, Suspicious_Gen2.UJZFE
50.00%

Reason Heuristics
(M), PUP.Softpulse.VolvanPremium.Installer (M)
50.00%

Total Defense
Win32/Tnega.ARWO
25.00%

McAfee
Artemis!6EE146AC3110
25.00%

Trend Micro House Call
TROJ_GEN.F43BZC4
25.00%

Sophos
Mal/Generic-L
25.00%

McAfee Web Gateway
Artemis!6EE146AC3110
25.00%

ViRobot
Trojan.Win32.A.Downloader.1421794
25.00%

VIPRE Antivirus
Trojan-Downloader.Win32.Agent
25.00%

The domain vc02.free.fr has been seen to resolve to the following IP address.

perso154-g5.free.fr
November 19, 2013

File downloads found at URLs served by vc02.free.fr.

0 / 68
http://vc02.free.fr/barre.exe  (4883d9c28bab47d105aac2720f55c88a)

3 / 68      (inconclusive)
http://vc02.free.fr/planet-english-fr.exe  (8706507ab8fc0e8d7634aeb966be8401)

1 / 68      (PUP)
http://vc02.free.fr/setup.exe  (717471a3aa624470d39a12bb9a4d051b)

1 / 68      (Malware)
http://vc02.free.fr/setup.exe  (aa034ab0ca27087607da259e9db0ef59)

6 / 68      (Malware)
http://vc02.free.fr/planet-english.exe  (6ee146ac3110de47baadff6604a06609)

The following 4 files have been seen to comunicate with vc02.free.fr in live environments.

URL:
http://vc02.free.fr/

Title:
“Horoscopes, astrologie, vie amoureuse, prénoms, langage des fleurs, diététique, régimes”

Web server:
Apache/ProXad [Jul 22 2015 14:50:04] (PHP/4.4.3-dev)