vertcoin.org

Poramin Insom

Domain Information

Currently this domain has been known to host various forms of malware. The hosted servers are located in San Francisco, California within the United States which resides on the CloudFlare, Inc. network. The domain uses the CloudFlare CDN, a distributed domain name server service which utilizes a number of reverse proxy IP Addresses (see below).
Registrar:
GoDaddy.com, LLC (R91-LROR)

Server location:
California, United States (US)

Scanner detections:
Malware distribution  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Win.Reputation.IMP
66.67%

ESET NOD32
Win32/BitCoinMiner.BJ potentially unsafe (variant)
66.67%

Panda Antivirus
Suspicious file
33.33%

VIPRE Antivirus
Trojan.Win32.Generic
33.33%

Antiy Labs AVL
Trojan[Downloader:not-a-virus]/Win32.Solimba.a
33.33%

The domain vertcoin.org has been seen to resolve to the following 2 IP addresses.

April 26, 2014

April 26, 2014

File downloads found at URLs served by vertcoin.org.

2 / 68      (Malware)
http://vertcoin.org/.../Vertcoin-setup.exe  (a207fd50d1810bf49650c51d5d61170b)

3 / 68      (PUP)
http://vertcoin.org/.../Vertcoin-setup.exe  (dcb82ddb1b5ed64167e91910b9ae97cc)

2 / 68      (Malware)
http://vertcoin.org/.../Vertcoin-setup.exe  (8472343c40214c6c97c4c84853d33b73)

September 4, 2014

URL:
http://vertcoin.org/

Title:
“Vertcoin – Bitcoin Upgraded”

SSL certificate subject:
CN=ssl6712.cloudflare.com, O="CloudFlare, Inc.", L=San Francisco, S=CA, C=US

SSL certificate issuer:
CN=GlobalSign Organization Validation CA - G2, O=GlobalSign nv-sa, C=BE

Web server:
cloudflare-nginx (PHP/5.3.10-1ubuntu3.13)