down1.topsadon1.com

topsadon

Domain Information

The domain down1.topsadon1.com registered by topsadon was initially registered in January of 2016 through MEGAZONE CORP. DBA HOSTING.KR. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Seoul, Seoul-T'Ukpyolsi within Korea which resides on the Asia Pacific Network Information Centre network.
Registrar:
MEGAZONE CORP. DBA HOSTING.KR

Server location:
Seoul-T'Ukpyolsi, Korea (KR)

Create date:
Sunday, January 24, 2016

Expires date:
Tuesday, January 24, 2017

Updated date:
Sunday, January 24, 2016

ASN:
AS3786 LGDACOM LG DACOM Corporation, KR

Root domain:

Scanner detections:
Detections  (93% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Neomedia (M)
64.29%

ESET NOD32
Win32/AdWare.KeywordFind.D application
50.00%

F-Prot
W32/Themida_Packed
35.71%

VIPRE Antivirus
Backdoor.Win32.Ircbot.gen, Threat.4412848
21.43%

ESET NOD32
Win32/AdWare.KeywordFind (variant)
14.29%

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen, HEUR/QVM39.1.Malware.Gen
14.29%

Avira AntiVirus
TR/Crypt.TPM.Gen
7.14%

MicroWorld eScan
Gen:Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

Arcabit
Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

Bitdefender
Gen:Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

AegisLab AV Signature
W32.W.AutoRun
7.14%

Lavasoft Ad-Aware
Gen:Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

Emsisoft Anti-Malware
Gen:Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

F-Secure
Gen:Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

G Data
Gen:Trojan.Heur2.CTR.26C5aaGMKIhc
7.14%

The domain down1.topsadon1.com has been seen to resolve to the following IP address.

May 27, 2016

File downloads found at URLs served by down1.topsadon1.com.

2 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1j.dll  (faf2c4a9b29a874497cfca7f2a2cc9ff)

3 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1c.exe  (9cc85f84dfedf5c8b391049a3e22b39b)

0 / 68
http://down1.topsadon1.com/.../sqlite3.dll  (b09588d000ef4bf2a3dddd85bd701423)

1 / 68      (PUP)
http://down1.topsadon1.com/.../chk1.exe  (db66571991c3959e84c0ac15e9bf5db0)

2 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1j.dll  (b4f2ed2a2376094b5aa16323b01bca7a)

1 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1j.dll  (59accdc7486eccdc5807a742a543e886)

2 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1j.dll  (c6b77f39d43beb0c7b4564db184e62c2)

2 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1j.dll  (69931fb4f46fc9194b9aa389009f40f8)

1 / 68      (PUP)
http://down1.topsadon1.com/.../uninstall.exe  (68806f44be024e20b0ec9c1ccb9bf4c6)

1 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1j.dll  (453e11f2b8035cadb5862e840ef590ad)

3 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1c.exe  (fec2b2fa68cd4b48fe59bd0ddd94b529)

5 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1.dll  (6a082e4930376f037198658c4241eb12)

5 / 68      (PUP)
http://down1.topsadon1.com/.../topsadon1u.exe  (bac896ee1de6d8394f19495b8f7c0048)

12 / 68    (PUP)
http://down1.topsadon1.com/.../topsadon1.dll  (d837b969ae7c49eccd0d98facbcba98f)

1 / 68      (PUP)