www.raidcall.com

Chang You Rui Ke

Domain Information

The domain www.raidcall.com registered by Chang You Rui Ke was initially registered in September of 2009 through GODADDY.COM, LLC. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Portland, Oregon within the United States which resides on the Amazon.com, Inc. network. The domain uses the Amazon Web Services (AWS) cloud computing platform from the US West (Oregon) region datacenter.
Remove Malware from www.raidcall.com - Powered by Reason Core Security
Registrar:
XIN NET TECHNOLOGY CORPORATION

Server location:
Oregon, United States (US)

Create date:
Wednesday, September 16, 2009

Expires date:
Friday, September 16, 2016

Updated date:
Wednesday, June 10, 2015

ASN:
AS16509 AMAZON-02 - Amazon.com, Inc.,US

Root domain:

Scanner detections:
Detections  (54% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Optional.KORAMGAMESLIMITED.N, PUP.Optional.KORAMGAMESLIMITED.I, PUP.Optional.KORAMGAMESLIMITED.M, PUP.Optional.KORAMGAMESLIMITED.F
76.47%

Bkav FE
HW32.CDB, W32.Clod7de.Trojan
23.53%

Antiy Labs AVL
Virus/Win32.Xpaj, Trojan/Win32.SGeneric
11.76%

Avira AntiVirus
W32/Mabezat
5.88%

AegisLab AV Signature
W32.Sality
5.88%

ViRobot
Backdoor.Win32.A.Ceckno.3220289
5.88%

Dr.Web
Trojan.DownLoader8.47960
5.88%

F-Prot
W32/Symmi.AJ.gen
5.88%

The domain www.raidcall.com has been seen to resolve to the following 11 IP addresses.

d4.2b.9905.ip4.static.sl-reverse.com
November 25, 2015

2.3e.9905.ip4.static.sl-reverse.com
November 25, 2015

75.126.156.66-static.reverse.softlayer.com
May 5, 2015

108.168.201.242-static.reverse.softlayer.com
May 5, 2015

184.173.77.146-static.reverse.softlayer.com
May 4, 2015

184.173.77.148-static.reverse.softlayer.com
May 4, 2015

ec2-54-186-8-207.us-west-2.compute.amazonaws.com
April 26, 2014

ec2-54-186-112-252.us-west-2.compute.amazonaws.com
April 26, 2014

ec2-54-186-65-91.us-west-2.compute.amazonaws.com
April 26, 2014

75.126.20.67-static.reverse.softlayer.com
August 4, 2013

173.192.186.9-static.reverse.softlayer.com
August 4, 2013

File downloads found at URLs served by www.raidcall.com.

1 / 68      (PUP)

2 / 68      (PUP)
http://www.raidcall.com/.../raidcall_v7.1.0.exe  (a5fc63770533e64b4ec7406e4f5f1b20)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall_v7.1.6.exe  (7ba9bf644177dcac5997398253439eb8)

0 / 68
http://www.raidcall.com/.../raidcall_v7.1.8.exe  (d46815f85012dcfd7cdb451520c0f145)

2 / 68      (PUP)
http://www.raidcall.com/.../raidcall_6.3.0.exe  (796e7f9b51eed042911ad62f847eb806)

1 / 68      (PUP)

4 / 68      (inconclusive)
http://www.raidcall.com/.../raidcall_6.0.8.exe  (c951abed76c52c771079293c08c8cacb)

0 / 68
http://www.raidcall.com/.../raidcall_v7.0.2.exe  (4aa6f7de21772ab9be894f73d6b50e3d)

1 / 68      (PUP)

1 / 68      (PUP)

0 / 68
http://www.raidcall.com/.../raidcall_v7.0.2.exe  (9a80711607cf5037f5f9a7504e1218b0)

0 / 68
http://www.raidcall.com/.../raidcall_v7.1.8.exe  (48791223034cd92000648037ffaf3a1a)

1 / 68      (PUP)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall.exe  (0ce25152a877f5053ef9702f26e380bd)

1 / 68      (PUP)

3 / 68      (PUP)

1 / 68      (PUP)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall_v7.2.0.exe  (e0ac83657256d510374ef11d7ee04b7f)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall_v7.1.8.exe  (809ea488cf5a288f16b49adfdbb7fda7)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall_v7.2.2.exe  (29e221ad6f9bdcb73c7820eb23b4f437)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall.exe  (e7e9218ee41986049b8c04827c5c8c1f)

1 / 68      (PUP)

1 / 68      (PUP)
http://www.raidcall.com/.../raidcall_v7.2.0.exe  (0cd2dc2019cd3f755dc7083f74d76ff0)

 
Latest 30 of 30 download URLs

The following 7 files have been seen to comunicate with www.raidcall.com in live environments.

URL:
http://www.raidcall.com/

Google Analytics:
UA-48035923

Title:
“RaidCall - 100% БЕСПЛАТНАЯ программа для группового общения -сообщения, групповая связь и голосовое общение”

Description:
“RaidCall - бесплатная и простая программа, позволяющая моментально связаться с друзьями. Она вобрала элементы мгновенной передачи сообщений, групповую связь и голосовое общение в профессиональную программу для группового общения.”

Network:
Amazon Web Services (AWS), running an EC2 instance

Web server:
nginx (PHP/5.3.10-1ubuntu3.11)

Facebook:
Likes:  194
Shares:  376
Comments:  759

Statistics are for the previous month.

Remove Malware from www.raidcall.com - Powered by Reason Core Security