down.ancamera.co.kr

Domain Information

Server location:
Seoul-T'Ukpyolsi, Korea (KR)

ASN:
AS9848 GNGAS Enterprise Networks,KR

Root domain:

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.EbizNetWorks.Installer (M), PUP.EbizNetW.Installer (M)
83.33%

Malwarebytes
Adware.KorAd, Adware.Nieguide
22.22%

Avira AntiVirus
ADWARE/Adware.Gen
16.67%

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
16.67%

IKARUS anti.virus
Win32.AdWare, Win32.SuspectCrc
16.67%

McAfee
Artemis!5B11DA60200F, Artemis!E424EE71C756
11.11%

Trend Micro House Call
Suspicious_GEN.F47V0616, ADW_NIEGUIDE
11.11%

Agnitum Outpost
PUA.Nieguide
11.11%

Comodo Security
UnclassifiedMalware
11.11%

ESET NOD32
Win32/Adware.Nieguide.AD (variant), Win32/Adware.Nieguide.AC (variant)
11.11%

AVG
Generic5, Skodna.Generic
11.11%

VIPRE Antivirus
Trojan.Win32.Generic
5.56%

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
5.56%

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
5.56%

Trend Micro
ADW_NIEGUIDE
5.56%

The domain down.ancamera.co.kr has been seen to resolve to the following IP address.

February 27, 2016

File downloads found at URLs served by down.ancamera.co.kr.

13 / 68    (PUP)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

6 / 68      (PUP)

1 / 68      (Adware)

7 / 68      (PUP)

1 / 68      (Adware)

1 / 68      (Adware)
http://down.ancamera.co.kr/app/.../ancamcorder_custom_simfile_3.0.exe  ({win32.adware}{trojan.trojan.win32.generic!bt}{adware.korad}{trojan.adkor.194}2dad6135f6ab94dbe42)

3 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
http://down.ancamera.co.kr/.../AnCamCorder_UpdateVer_3.3.3.exe  ({win32.adware}{trojan.trojan.win32.generic!sb.0}{adware.korad}{trojan.adkor.194}18181fc0c7b83d3e4)

1 / 68      (Adware)

1 / 68      (Adware)
http://down.ancamera.co.kr/.../AnCamCorder_UpdateVer_3.4.2.exe  ({win32.suspectcrc}{adware.korad}{trojan.adkor.194}9c0a99250a3f8543cebe3392081ebf5f.exe)

4 / 68      (Adware)