csiks.pl

Domain Information

Server location:
Wielkopolskie, Poland (PL)

ASN:
AS51290 HOSTEAM-AS HOSTEAM S.C. TOMASZ GROSZEWSKI BARTOSZ WASZAK LUKASZ GROSZEWSKI,PL

Scanner detections:
Malware distribution  (60% detected)

Scan engine
Details
Detections

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
70.00%

McAfee
Artemis!E0D83F558A84, Artemis!F9299DB302E9, RDN/Generic.dx!dj3, Artemis!EAC0528B87A7, RDN/Generic.dx!d2g, Artemis!141DAEEE5926
70.00%

Avira AntiVirus
TR/Spy.148258, TR/Spy.168143, TR/Rogue.84480.21, TR/Kazy.145408.4, TR/Kazy.145408.5, TR/Spy.Agent.162816.2
60.00%

IKARUS anti.virus
Trojan.Win32.Spy, Trojan.SuspectCRC, Trojan.Rogue, Win32.SuspectCrc
60.00%

Emsisoft Anti-Malware
Gen:Trojan.Heur.D.jmRfbeoqXGj, Gen:Trojan.Heur.D.kmRfbmgtgrj, Gen:Trojan.Heur.D.kmRfbOGQmUi, Gen:Variant.Kazy.513101, Gen:Trojan.Heur.D.kmRfbOYNVzj
50.00%

G Data
Gen:Trojan.Heur.D.jmRfbeoqXGj, Gen:Trojan.Heur.D.kmRfbmgtgrj, Gen:Trojan.Heur.D.kmRfbOGQmUi, Gen:Variant.Kazy.513101, Win32.Trojan.Agent.9EJBW5
50.00%

MicroWorld eScan
Gen:Trojan.Heur.D.jmRfbeoqXGj, Gen:Trojan.Heur.D.kmRfbmgtgrj, Gen:Trojan.Heur.D.kmRfbOGQmUi, Gen:Variant.Kazy.513101
40.00%

Norman
Suspicious_Gen5.AOSJF, Suspicious_Gen5.AROGG, Suspicious_Gen5.BAKFQ, Gen:Trojan.Heur.D.kmRfbOYNVzj
40.00%

Bitdefender
Gen:Trojan.Heur.D.jmRfbeoqXGj, Gen:Trojan.Heur.D.kmRfbmgtgrj, Gen:Trojan.Heur.D.kmRfbOGQmUi, Gen:Variant.Kazy.513101
40.00%

F-Secure
Gen:Trojan.Heur.D.jmRfbeoqXGj, Gen:Trojan.Heur.D.kmRfbmgtgrj, Gen:Trojan.Heur.D.kmRfbOGQmUi, Gen:Variant.Kazy.513101
40.00%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696
40.00%

Trend Micro House Call
Suspicious_GEN.F47V0614, TROJ_GEN.R08NH09HH14, TROJ_GEN.R047H09LK14
30.00%

Lavasoft Ad-Aware
Gen:Trojan.Heur.D.kmRfbmgtgrj, Gen:Trojan.Heur.D.kmRfbOGQmUi, Gen:Variant.Kazy.513101
30.00%

Qihoo 360 Security
HEUR/QVM31.1.Malware.Gen, Win32/Trojan.aaf
30.00%

AVG
Win32/DH
20.00%

The domain csiks.pl has been seen to resolve to the following IP address.

srv1007.htdedicated.pl
March 2, 2016

File downloads found at URLs served by csiks.pl.

6 / 68      (Malware)
http://csiks.pl/pliki/.../TrackerUI.DLL  (ee1ad4403e98fc9c66c622fa10f32cc0)

9 / 68      (Malware)
http://csiks.pl/pliki/.../TrackerUI.DLL  (90544363cdb47d7447ec414ee5141253)

5 / 68      (inconclusive)
http://csiks.pl/pliki/.../TrackerUI.DLL  (141daeee59264c5414075f984ff058eb)

13 / 68    (Malware)

13 / 68    (inconclusive)
http://csiks.pl/pliki/.../TrackerUI.DLL  (e0d83f558a84e88aefb9588df60759b5)

11 / 68    (Malware)
http://csiks.pl/pliki/.../TrackerUI.DLL  (f9299db302e9c8e81e67379dfcd8d190)

1 / 68
http://csiks.pl/pliki/.../TrackerUI.DLL  (3cb4f28c7667c4cb1a6925b19c06a665)

11 / 68    (Malware)
http://csiks.pl/pliki/.../TrackerUI.DLL  (eac0528b87a7d2d61b4b6ffd344e6020)

3 / 68      (inconclusive)
http://csiks.pl/pliki/.../TrackerUI.DLL  (5a0d047ff499a38337b7063cbadbf461)

11 / 68    (Malware)
http://csiks.pl/pliki/.../TrackerUI.DLL  (2baebf25ff09b2be61129eacfff670af)

April 6, 2016